In this episode of Protect It All, host Aaron Crow sits down with Steve Kiss, founder and CEO of IPMeter, for an eye-opening discussion on the future of OT (Operational Technology) and IT cybersecurity. With over 25 years of hands-on experience, Steve shares his journey from network engineering to designing practical cybersecurity tools for real-world OT environments.
They dive into the unique challenges faced by operators in sectors like wastewater treatment, building management, and power utilities—where frontline professionals often shoulder critical cybersecurity responsibilities without formal training or extensive resources. Steve and Aaron emphasize the urgent need for simple, scalable, and reliable tools that empower these “full stack” operators to secure critical infrastructure effectively.
From bridging the IT-OT divide to managing legacy system risks and improving procurement practices, this conversation offers actionable insights for municipalities, utilities, and smaller organizations aiming to take greater ownership of their cyber defenses. Packed with real-world examples, strategic advice, and a touch of industry humor, this episode is essential listening for anyone focused on protecting essential services and strengthening community resilience.
Key Moments:
10:40 Understanding Factory Acceptance Test (FAT)
16:41 Transitioning to Local Water Management
19:52 Compliance and Cybersecurity Standards
25:03 "Digital Spins on Security Concepts"
32:30 Standardizing Power Systems Configurations
35:00 Basic Security Steps for Operators
40:28 Balancing IoT Features and Control
45:01 Durability and Setup for Rail Tech
48:58 "Basic Network Foundations Needed"
54:35 Wastewater's Overlooked Importance
About the guest:
Steve Kiss is a seasoned cybersecurity leader with over two decades of experience in engineering, infrastructure security, and strategic leadership. As the inventor of IPMeter™ and a contributor to the NIST 800-53 SP2 standards, he has played a pivotal role in advancing vulnerability management practices. Throughout his career, Steve has been deeply involved in the design, construction, and security of critical infrastructure across sectors such as aviation, defense, data centers, and utilities.
His expertise uniquely bridges the worlds of operational technology (OT) and information technology (IT), addressing the evolving challenges of modern network environments. In addition to founding multiple companies focused on infrastructure security, Steve regularly shares his insights at industry events, including the IMRON Security & Safety Summit at SoFi Stadium.
He also publishes a weekly newsletter, HOTw (Hack of the Week), spotlighting trends and incidents in OT cybersecurity. Through his latest venture, IPMeter, Steve continues to drive innovation in cybersecurity testing and resilience.
How to connect Steve :
Website for IPMeter
https://www.linkedin.com/in/stevekiss/
Blog (once to twice a month- includes HOTw (IoT hack of the week)
Contact for IPMeter demos
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:1.144): Awesome. Hey, thank you for joining me today. Again, another podcast of a protected all, Steve, thank you for joining me, taking time out of your day. We've been kind of tangentially, connected as a, as I mentioned before, I played around with your product a bit and all that. So why don't you introduce yourself, tell our audience who you are and, kind of your journey into this cyber OTE type space.
Steve Kiss (0:22.136): Sure. So Steve Kiss, I'm founder and CEO of a company called IP Meter. We provide appliances and tools for testing OT in an operational setting. got into this business years ago, let's say 25 years ago. I got into this business out of college doing network engineering. I worked for a network equipment manufacturer as an engineer for those folks.
Steve Kiss (0:50.354): Did a lot protocol analysis and low level activities, routing and switching, OSPF, BGP, that sort of thing. And as I kind of worked through those activities, I really found myself gravitating towards large scale projects. And those projects led me to train airport, casino, hotels, healthcare, that sort of thing.
Steve Kiss (1:19.042): just building large construction pieces. So I ended up in the field in different capacities, either at a manufacturer or integrator or customer, building infrastructure. In that journey, it became really clear that there was starting to be a separation of operational networks from IT networks. The operational networks that were out there were serial-based,
Steve Kiss (1:48.792): did a lot of work in that arena. But as we started to build networks that were higher speed, greater capacity in different ways, shared medium, we needed to have some network expertise in that arena. So I lived in that for years and years and years and just built anything that I could get my hands on, worked for a lot of general contractors and electrical contractors and so forth, doing those low voltage systems, everything from SCADA.
Aaron Crow (2:11.461): Okay.
Steve Kiss (2:18.208): access control, video surveillance, that sort of thing. That's kind of the first kind of part of my journey. Kind of along the way, I started to realize that I needed to do a lot of pre-configuration, pre-testing. The general contractors were really pushing for me to do what's called factory acceptance testing in cybersecurity, in performance analysis, that sort of thing. So I started building labs for these projects.
Aaron Crow (2:38.150): Mm-hmm.
Steve Kiss (2:49.050): And as part of those labs, I build tools in that environment. And about four or five years ago, I started to realize that I could downscale those tools. Me working as a little cottage industry, making my own little quilt, while there were other quilt makers making their quilt, didn't really scale out. So it was time to just to build tools that can be used by a wider audience. So not cybersecurity experts, not.
Steve Kiss (3:17.472): network people that can basically plug something in and get results out to know what the status of their environment is. That's kind of the journey of IP meter.
Aaron Crow (3:29.130): I love it. I my career has been similar and coming from working in network engineering and architecture and systems administration and all that kind of stuff, really starting out in the IT world and then kind of transitioning into this space. Most of the people that we work with in these OT spaces are not technologists. They're not network engineers. They're definitely not cybersecurity people, but they are the ones usually that they take the
Steve Kiss (3:53.933): Right.
Aaron Crow (3:57.466): control system engineer and they give him the hat, him or her the hat that says, you're now the technology person. You are responsible for the switches and the servers and all the things, even though they don't have a CCNA like I did and a CISSP and an MCSE and I'm dating myself with all the certifications I've had in my past, but all of those things are there, they're responsible for it, but they don't fully understand it. So they may have tools, but they don't even necessarily know them. So having tools that are super simple.
Steve Kiss (4:9.666): Yeah.
Steve Kiss (4:16.077): Okay.
Aaron Crow (4:25.776): that I can take out, plug in and just not have to be a doctorate in cybersecurity to be able to get value out of it, right?
Steve Kiss (4:25.826): Yeah.
Steve Kiss (4:32.627): Yeah, look, there's a couple of ways to look at this. One way is to say there's other parts of our industry that do this right. Like it's really simple to take a Fluke meter and measure cable. And you don't have to be a near end crosstalk expert in order to know that the cables either pass the green button that says test in some models, auto test in other models. Those two pieces kind of drive that. think I've always had a little bit of a
Steve Kiss (5:0.686): slight against the IT side frankly because it's this it's this specialization where in the the OT people that I'm around in my world, they're full stack people right like in the the in development world We call them full stack. They do the HMI. They do the cabling they you know, even in big plants there's kind of a There's not so much segmentation. So to take a person that's got a chemistry background or a biology background
Steve Kiss (5:30.186): in a water treatment environment and assimilate them into our world is not as big a challenge as it should be. The challenge, I think, is that the tools that they get to use are incredibly complex to configure, set up, and operate. It's not so much that you have to be a network expert. It's that you have to start out being a Unix expert in order to get the tools off the ground. And that's a challenge.
Steve Kiss (5:59.458): You know, that is a challenge. If you think about it in a couple of ways, one is this kind of full stack component of the types of people that we interface with on pipelines, on water plants, on building control systems. They are people that are capable of this. There is no shortcoming in their intelligence. It's just giving them things they can use. The second part is
Steve Kiss (6:27.754): We've got to get serious about the fact that we don't have the staff we need. And there are, you know, there's a huge shortage. There's just this massive shortage of folks. There's a quarter million people short in the cybersecurity industry. And I'd argue that in the OT side of that, the problem's worse because you also have to this expertise in whatever operating facility you're running, baggage handling or...
Steve Kiss (6:57.922): whatever they are. So we don't have a choice. We've got to convert these people. We've got to assimilate them into our world of cyber. And I think we're starting to see that happen.
Aaron Crow (7:8.506): Yeah, I completely agree. know, I worked at a power utility and I was the OT cybersecurity manager responsible for, and all that meant was anything technology at a power plant was my responsibility. So switches, to your point, we called them multi-skilled, but it's the same thing. First time I've heard the full stack, but that's exactly what we were. My team had to support everything from VMware to Windows servers, to patching servers, the backup server, the antivirus server, the firewalls, the switches.
Steve Kiss (7:20.962): Yeah.
Steve Kiss (7:23.746): Yeah, yeah,
Steve Kiss (7:28.813): Yeah.
Steve Kiss (7:35.020): Yep.
Aaron Crow (7:36.740): the, the, the, all, all the layers of the OSI model, every single layer we were responsible for from end to end. So my guys had to be an inch deep and a mile wide. Like they weren't firewall experts, but they had to be good enough in firewall that they could make sure that it worked. and, and I say this all the time, the IT side of the business. So this is working for a power utility, right? Their entire product is power generation. That the company that I worked for, right? That was their only product. And, and the,
Steve Kiss (7:40.162): Yep. Yeah.
Steve Kiss (7:45.655): Yeah.
Steve Kiss (7:49.133): Right.
Steve Kiss (7:51.607): Right.
Aaron Crow (8:5.506): IT organization had hundreds of people, teams dedicated to networking and another firewall team, another VMware team and all these huge groups. And I had six people on my team, plus some contractors, but let's say 10. And I was supporting almost 50 power plants across the state of Texas. So it was so much more responsibility and difficulty. And my thing was the thing that was directly correlated to the business making money.
Steve Kiss (8:16.908): Yeah. Yep. Yeah.
Steve Kiss (8:22.754): Wow. Yeah.
Steve Kiss (8:33.602): Yeah, yeah.
Aaron Crow (8:34.102): And it was completely inverse of, in my perspective, how much, not that I should take, and I don't want to say that I should take away from the IT because that's important too. That's our first layer of defense. But, but the fact that they had such large teams and such large budgets and such mature processes, and we had a team of six and we were just flying by the seat of our pants says that it's missing something.
Steve Kiss (8:54.339): Yeah.
Steve Kiss (8:56.898): Yeah, think that, you know, but I would argue that, you know, the kind of NERC FERC component of the business provides the structure to incorporate performance testing, incorporate cybersecurity into it. So we have these very mature processes that deliver water, hour, or movement elevator up and down without someone falling through to the pit. All of those things have already laid the groundwork for
Steve Kiss (9:26.654): all of the operating technology systems to bring in cyber and performance analysis into the environment, right? The only thing that's really missing is tool sets and a method to basically bring in capabilities, right? Like to bring in, you'd like to actually execute it. So it is interesting that we're kind of at that space. We don't have a choice to get our way out of it by doing it with just consultants. We don't have a choice by bringing in
Steve Kiss (9:56.406): IT to do it or bringing in IT tools, we've got to create tools inside of the OT workflow that can be run by non-technical people. It's very insulting to say that someone that's got a degree in chemistry is not technical, but they may not be clickety clack IT VM experts, but we've got to basically build that out. We've got to be part of that solution.
Aaron Crow (10:12.486): They're very technical.
Aaron Crow (10:23.610): Well, and I love what you said. those of us that worked and have worked in OT obviously understand the factor acceptance test, FAT, or side acceptance test. know, both of those are in the vernacular that we're used to hearing, but many people in the IT world may not hear that or understand what that term means. But the whole idea behind setting up that factor acceptance test, doing that lab environment. So I did very similar things at a lot of different places.
Steve Kiss (10:34.179): Yeah.
Steve Kiss (10:40.642): Yeah.
Aaron Crow (10:52.100): but both as an asset owner and as a consultant building them for other clients, building that staging floor, that factor acceptance test where I'm going through and I build it and I test it before I ever take it to production. Right. And it's very obvious why we do that in an OT world because the, the, the, impact of it not working is super high. And the really bad things happen if this thing's, you know, a power plant or a train or these things, like there's, there's real adverse impacts to.
Steve Kiss (10:57.846): Yes.
Steve Kiss (11:3.960): Right.
Steve Kiss (11:12.128): Right. Right.
Aaron Crow (11:20.282): this thing not working as expected. Whereas on the IT side, I kind of do it on the fly. I have a maintenance window, yeah, test it. But I get virtualization. Like there's all these ways that we can do it in an IT world safely, but it's different in an OT world.
Steve Kiss (11:30.188): Yes,
Steve Kiss (11:33.430): Yeah, absolutely. And the way I think that we can enter into this in one, you know, it's how do you how do you start to build this workflow, right? It's you could do it per vertical. You could say I'm going to do this only in dams and water, or I could do it in, you know, transportation only. But I think the right way to build it in is on a is on a project basis because you already have the tools you need in the construction.
Steve Kiss (12:3.274): arena in the construction workflow through a hundred years of thousand years of building things. You already have a workflow and it's just a matter of using the same workflow that's used in that factory acceptance test, in the system and unit level test, kind of in that process. And then when you turn over to the owner, to the operator, they already have a system and they can frankly use your same methodology to continue forward.
Steve Kiss (12:32.940): Right? where there may be some.
Steve Kiss (12:38.478): reluctance to build out facilities by the construction company. They now are under liability reasons. They've got to start looking at cybersecurity. They got to start looking at performance. They're having shared networks with all these different subsystems that need to have a shared network. And the end result is they're under the gun. They're putting the process. They're holding the manufacturers and integrators feet to the fire. And then by end result, we can start kind of
Steve Kiss (13:8.024): bringing in the local operational teams during our handover phase. So kind of builds from there. That's how I see this going down.
Aaron Crow (13:17.990): 100%. And to your point, we've been doing factory acceptance tests in these spaces for decades. This is not a new concept. This is not a cybersecurity concept. This is a concept that we've been doing forever, right? The difference is how many people, because again, I started doing this back in 2010 when we were doing FATs and I was incorporating all the cyber and technology side into those FATs that they weren't really in scope in the beginning. Like I had to force those into the scope of the project.
Steve Kiss (13:25.056): Right. Right.
Steve Kiss (13:31.458): Yeah.
Steve Kiss (13:45.517): Yeah.
Aaron Crow (13:47.590): because I wanted them to test their cyber tools and validate that it worked before they shipped it to site.
Steve Kiss (13:50.029): Yeah.
Steve Kiss (13:53.260): Yep, I mean, I'm in the same boat. We're still in that same role. Like, let's just take something really nuts and bolts. Why are we still talking about Telnet in these environments, right? Why do we still have, I don't know, 80 % of our traffic in OT still is not, the transport's not secure. There's a disconnect there, right? The specification needs to include these documents and it needs to be tested.
Steve Kiss (14:22.382): can't have Telnet into these devices. And then at the same time, you have to hold responsibility and say, we're going to test for that. And if you don't meet that requirement, back to the drawing board. You're not getting paid to list things resolved. So it's kind of a
Aaron Crow (14:36.208): Yeah. Well, it comes back to again, coming back from my experience firsthand was the vendors want to do the right thing, but they have, you you look at, I'm not, I'm not calling on anybody by name just to be rude, but GE, one of the largest control vendors in the world. Everybody knows who GE is, right? GE has amazing stuff. I am not dogging on them at all. They've spent a lot of, they do great things. love GE, but
Steve Kiss (14:44.845): Yeah.
Steve Kiss (14:48.492): Yeah.
Steve Kiss (14:54.638): All right.
Aaron Crow (15:1.254): GE has to be, they have to come up with a standard and a process because they're trying to standardize and make it where they can cookie cutter this out for all of their customers as much as they can. So they standardize on a certain thing. And sometimes that may mean that the lowest common denominator may be Telnet because this one client in wherever can't support whatever SSH for whatever reason. So they just say, okay, we'll just standardize on Telnet because that works across the board every.
Steve Kiss (15:21.036): Right? Right.
Steve Kiss (15:25.101): Right.
Steve Kiss (15:29.463): Yeah.
Aaron Crow (15:29.530): but it takes a customer to have a standard and say, nope, you're not doing Telnet in my space. I don't care what your standard is everywhere else. Here, we're doing it differently.
Steve Kiss (15:39.138): Yeah, yeah. And I think we've gotten, we've had a pretty good runway over last four or five years with CISA and some kind of pieces from the federal government. And this is not at all to be a political discussion. But as we start to think about downsizing the federal government, I'm getting more phone calls from municipalities, right? Like I know I'm gonna have to take care of those. I don't have EPA likely doing some of these things and making enforcements.
Steve Kiss (16:9.554): What am I going to do? And I have had a significant uptake recently in municipalities starting to actually take ownership of their own cybersecurity and not saying, hey, I got this EPA test I'm to pass. What's the minimum requirement I can do? Because that shift back to the municipalities is going to create a really different environment for us. And I'm already seeing it. I'm already seeing those local water guys, water and wastewater.
Steve Kiss (16:38.538): start to say, I'm not really as concerned about your audit tool capability, that's great, stop talking about that. How do I actually get the test to run and what are the things that I can do once I find things? What do your tests look like that I can then, how do I action these things? And so we're sitting in a really weird spot, right? We don't have the labor to do the job. We don't have as much
Steve Kiss (17:6.754): federal oversight that we're going to have. And we have to employ tools that operators can use and execute. You go back to that kind of full stack comment. That comes out of the development world, right? Like this, when you talk about, since we have kind of a development arm to do our software, you look for these 10x developers, people that can code better than the next guy. But really what they are are full stack guys. They just...
Aaron Crow (17:32.880): Sure. Yeah.
Steve Kiss (17:35.704): They just have the capability to go top to bottom. And when you find those folks inside of the operational environment, baggage handling, water, electrical, your background, these sorts of things, they can take this work on. They can add this to their workload as long as they know, as long as they have a mechanism. And we talked about one half of that, which is making the tools easy to operate. Like my appliances,
Steve Kiss (18:5.004): headless, no keyboard, no mouse. The design is to power it up, just like you would a flute mute. But on the other side of that, we need baseline scaling on the output that tells the user good, bad, indifferent, log, don't care, whatever. And we have mechanisms for that. have international and nationally recognized standards that can be used.
Aaron Crow (18:10.606): Right. Yeah.
Steve Kiss (18:33.494): Just in the same way, can look at edge cases for water. The water has too much of this chemical in it. You can turn around and use the same model to say, we're right at the level that we've got to take action on this thing. And that's, think, the other half of the story is getting solutions that are easy for people to consume the data. Like, this is not good. You need to fix it.
Steve Kiss (19:2.336): Why is Telnet a problem still? Well, it's, you know, it, you know, we can solve this, right? Do you, you know, and the manufacturers to your point, I think are ready for, they have the stuff built in, right? From the board to the operating system, to the system level and wider, the manufacturers have the parts, it's just a matter of turning them.
Aaron Crow (19:4.751): Yeah.
Steve Kiss (19:30.958): It's just a matter of configuring them in the proper way.
Aaron Crow (19:34.884): Yeah, absolutely. You know it's it's you know, it's like I I tell my kid to clean his room and he's going to clean it to a certain level that he thinks he can get by with, but he's not getting down on the ground with a toothpick or a toothbrush and scrubbing the floor, right? That's what his mom would like, but that's not what happens unless she she makes that requirement. Then he's going to do just enough to check the box, and sometimes that's what compliance is. You know, again, coming from the power utility world, NERC SIP is a great. You know, if you look at the critical infrastructure, 17 critical infrastructures in this country.
Steve Kiss (19:46.880): Right. Yeah.
Steve Kiss (19:52.119): Right.
Steve Kiss (19:56.033): Right.
Aaron Crow (20:4.494): I would say that unarguably NARC SIP is probably the reason why the power utility is a leader in cybersecurity in the space. And on the flip side, there's a lot of companies that just check a box to be compliant and skirt around actually implementing security policies because they've done NARC SIP. What else do I need? I've done all that I have to do and I'm not gonna do more.
Steve Kiss (20:26.188): Yeah, yeah. I think it's really, you you kind of hit something that's a nerve for me because, you know, the great thing about power utilities is there is the central binding in the transmission. So there is some relationship. There are other critical infrastructure.
Steve Kiss (20:48.052): Items that have much more siloed where there's no connectivity building management You don't connect to the building down the street and therefore you have a group that has to have a certain Standard across the board if you're running a water utility in one city. It doesn't affect what happens in the other city. So, know I I am most careful with those Critical infrastructure components that have the least amount of interface with other
Steve Kiss (21:16.182): other activities because there's no like, you know, what is it? Rising tide raises all ships. Yeah, NERC SIP raises all the ships. Doesn't exactly work that way in building management, right? You know, your elevator control system, which is now connected to the internet for a number of reasons, is one where it's lowest cost and minimum configuration and great, we're complete.
Aaron Crow (21:21.050): Razor ships. Yeah.
Steve Kiss (21:43.468): Let's get back in the truck, put the ladder back on the roof and go, right? So, you know, it's a challenge. you know, and that's gonna be building managers that put that into their contracts.
Aaron Crow (21:57.242): Absolutely. And, you know, I'm actually an advisor for building cybersecurity, which is a nonprofit organization. Lucian is the CEO and founder of it. And he really, he came out of out of government and he built this organization because there were so few building management folks that really understood the risks that they had in their environments other than what their vendors told them, et cetera. But he really understood that they, and they don't know where to start. Like,
Steve Kiss (22:17.218): Yeah.
Aaron Crow (22:24.376): Many of them, even if they understand they need to do something, they don't know where to begin. So so he started this to help that conversation, right? Like give them an easy way to start. Here's a here's a nest, you know, kind of a framework type thing that you can use in your environment. You know, a step by step process of what to do. But to your point that they don't really understand what it's there and they may have six buildings and they're not interconnected and they have different stuff in them and all that kind of stuff. And again, they're real estate people, they're business people. They're not.
Steve Kiss (22:28.109): Yeah.
Steve Kiss (22:31.843): Yeah.
Steve Kiss (22:37.486): Damn.
Steve Kiss (22:48.344): Yeah.
Aaron Crow (22:54.074): To your point though, doesn't mean they're not technical. Doesn't mean they're not capable of understanding it. They're super intelligent and capable. It's just not what they grew up and they don't have 25 years experience like you and I do doing this, right? So they need people like us to help them understand what do need to do? Most of the people want to have a safe building. They want to have the elevator work. They want to have their tenants and the people in there to be safe and the building be reliable and them to be able to lease it, like all that type of stuff. And they're willing to do the work if they know what to do and how to do it.
Steve Kiss (22:57.774): Yeah.
Steve Kiss (23:13.432): Yeah.
Steve Kiss (23:23.726): The way that we've penetrated that, frankly, is we know there's all these different systems in the building, right? Conveyance, cooling, all these different systems. But the group that really has a definite understanding of the overall cybersecurity vision is the physical security folks. So it's interesting. You might start out with the physical security.
Steve Kiss (23:48.590): person and they kind of push you back a little bit and like, this is really complex. There's a lot of nuts and bolts and clickety clack and buzz, buzz, buzz. but it's the same concepts, right? It's perimeter, it's center, it's separation. It's all the things that they do that happen in physical security. We've copied in the cyber security, physical security was long or, know, putting a rock in front of your cave was around a long, long, long time before.
Steve Kiss (24:15.714): before we had cybersecurity and we've copied those folks. when I've done things like I've embedded my software into a physical security company, into an access control system, but that conversation started by me kind of learning that language and making sure that I was using their language. What I found in physical security is they use the same, they invented that language, right? They invented the terms that we all use in cybersecurity.
Steve Kiss (24:45.294): kind of an interesting piece. Yeah. Yeah.
Aaron Crow (24:45.816): Absolutely. Right. It came from, from those concepts came from physical security, layered defense, defense in depth, you know, perimeters, all we, we, firewall, like all of these things came from them. And these are not new concepts. We're just putting digital spins on them. and, trying to use it. But the good thing is that is it's easy to, to your point, it's easy to communicate those terms. Cause we're, we're, and that's the way I look at frameworks, right? Is I don't look at missed or.
Steve Kiss (24:52.876): Yeah.
Steve Kiss (24:58.188): Yeah. Yeah. Yeah.
Steve Kiss (25:10.926): in.
Aaron Crow (25:12.918): 62443 or any of these these standards is which one's better I hear that all the time which standard should I use at the end of the day from my perspective and people will probably you know want to throw arrows at me for saying this I don't think it matters whichever one that you're gonna do and use and be able to use and communicate and document and actually follow it's just like a workout plan or a diet which diet should you use I'm not a doctor but whichever diet you'll stick to is the diet that will work best for you
Steve Kiss (25:31.490): Yeah.
Steve Kiss (25:34.402): Yeah.
Steve Kiss (25:40.492): Yep. Yeah, I couldn't agree more. think that, you know, it kind of bends a different point too, which is we know we have all these shared systems that are going into buildings and other facilities. We're kind of staying on this kind of building management component. But if we can, if you as a system operator of one of those systems or a system integrator of one of those systems can become the expert in that building, you become the expert for
Steve Kiss (26:10.098): all of the systems. So it's self-serving. So one of the things that I convey as I try to get people to kind of strength the Kool-Aid is to think about the fact that, you know, there's 12 other companies that are servicing your customer in other disciplines. You're being asked to be on a shared network. Do you want to be the one that runs that shared network or do you want to be a victim? Do you want to be, you know, at someone else's, you know, beholden to someone else?
Steve Kiss (26:38.882): Definitely seen enough of that, where from a performance, we talk a lot about cybersecurity and protecting that, but cybersecurity to me goes hand in hand with performance analysis too. And as you start blending these networks together, people get stepped on, networks get out of control and that's an important piece.
Aaron Crow (26:57.818): Well, yeah. And to that, know, because, and this is very common in OT, IT is, it's very standardized. I'm using, you you're using my hardware, it's in the cloud or it's on my iron. We're using VMware. I've got a standard template of, you know, things that when I spin up, I'm turning these services off. I'm disabling Telnet. I'm disabling, you know, SNMP, you know, all that little type of stuff. We've done this for so long. We have these playbooks.
Steve Kiss (27:11.981): Yeah.
Steve Kiss (27:25.068): Yeah. Yeah.
Aaron Crow (27:26.874): But these OT spaces, building management, like you just talked about, there's 10 or 15 vendors. Maybe there's five vendors, maybe there's three. However many there are, every place is different. But all three of them, they only know about their spots. So when you do a factor acceptance test with the elevator controls, they're only testing their system. They're not testing their system connected to all the other systems you have at your building, right? There's no way that they could be an expert in those things.
Steve Kiss (27:45.710): Yeah.
Aaron Crow (27:52.932): when I did factor acceptance tests, I would force all of my vendors to bring all of their gear to my party. And I'd do a factor acceptance test in my lab. And I'd have all the control vendors, all of their cybersecurity tools connected on the network and then make them play together. Cause that's how it's going to be when they plug it in in the building. That's the real test.
Steve Kiss (28:2.936): Yeah.
Steve Kiss (28:11.308): Yeah, yeah, for sure, for sure. Yeah, look, ITU, IT is a 20 year relationship with three vendors. You have your backend vendor that does your servers. You have your operating system vendor that does the operating system and you have your transport vendor that's your network vendor. OT is a 50 year relationship with 30 vendors. And there are huge organizations that don't ever, they're never going to...
Steve Kiss (28:41.230): Never is a long time. It would be very rare for them to get in each other's shorts. So if you make elevators, you probably aren't going to make air conditioners. mean, there's multinationals that do that, but within the product lines, you're not going to have a combination elevator cooling system. It's not going to be combined. that in and of itself changes the dynamic of how to approach operational technology from a non-IT perspective, because you have
Steve Kiss (29:11.010): where you have more embedded, bigger vendors, like more by number, that have longer contracts, and they are not providing technology, they're providing equipment that provides something else, right? The technology, yeah. Right. Yeah. And so it makes the situation kind of interesting because when you do those factory acceptance tests, and now part of the factory acceptance test,
Aaron Crow (29:27.398): They're providing a system, not a server, they're an entire system, right?
Steve Kiss (29:41.186): Let's take video surveillance at scale. You're going to do license plate readers in the cloud.
Steve Kiss (29:50.786): Are you going to measure the cloud? Because that's going to be a big component of checking that box that makes sure that the license plate reader works. Otherwise, you're going to have a disqualifying component on your test. And so it's an interesting model that you bring up about bringing everybody together, not just everybody together, but you need to identify that you're taking this out. One of these systems is going out to the cloud. Now I've got to create in my lab environment a test to get to the cloud because you're doing LPR, doing license plate reading in the cloud.
Steve Kiss (30:20.259): You now are, I now need to make sure on behalf of my customer that we're testing that, right? That that's going to work, right? So, up a can of worms. So, you know.
Aaron Crow (30:29.636): Yeah, it is. And you know, another, another thing, and you may have run across this as well with the, with these control vendors is in it. If I install windows, I don't have to install it exactly the way that, you know, Microsoft says I have to install it to get support. Right. Whereas if I buy a GE target control system, the switches that they deploy and the HMIs and all the things, if I change a component, if I add anything to it or whatever,
Aaron Crow (30:59.236): the control vendors, their initial response, which you can push back on. I'm telling you, if you have this pushback, you're the customer push back on these things, but their initial response and all of these OT owners are concerned that their vendor is no longer going to support their product. If I make a change and I change the switch configuration or I disable Telnet, then the control vendor is no longer going to support.
Steve Kiss (31:7.490): Yeah.
Steve Kiss (31:13.612): Yep. Yeah.
Steve Kiss (31:18.486): Yeah. Yeah. Do you think some of that, I'm going to turn this around. Do you think some of that revolves around the fact that the owner relies on long-term contracts from the installer and integrator? Like in other words, I've got a 30 year relationship with someone to operate the SCADA system on my water plant. This is the way they've always done it. Like do you think part of that is due to that relationship versus the quick turnover of I need another MSP?
Aaron Crow (31:32.187): Yes.
Steve Kiss (31:47.640): Who's got a pulse? Bring him in here.
Aaron Crow (31:50.246): 100 % and again going back to you know the GE's of the world and again I just bring up GE because they're probably one of the largest you know that everybody will have heard of and probably dealt with in one way and they cross all verticals so that obviously they make trains they make turbines they make all sorts of stuff so they're kind of their hands are in everything you know one of the oldest country or companies in our country very very old anyways they they they have to support power plants and trains and all these different things so
Steve Kiss (31:58.700): Yeah.
Steve Kiss (32:7.502): Right.
Aaron Crow (32:19.970): It makes sense that they want to standardize on an architecture and that they can't support an infinite number of configurations. Now you and I understand that it worked 20 years ago, right? When they had proprietary systems and they knew exactly how their thing worked. And if you mess with the secret sauce, it doesn't work. It'd be like, you know, the same reason why you can't go throw a supercharger on your car and expect the...
Aaron Crow (32:47.728): the vehicle manufacturer to actually, you know, warranty it, right? If you blow your motor because you put aftermarket parts on it, it's, your warranty is null and void. So that's kind of the mindset that they've had this entire time, but we're not talking about putting a supercharger on it. We're talking about adjusting how fast the fan with intolerance runs on my air conditioner.
Steve Kiss (32:50.594): Yeah. Yeah.
Steve Kiss (33:9.688): Yeah.
Aaron Crow (33:11.044): Right? I'm not changing it. I'm not replacing it. I'm not, I'm having it run in nominal places. I'm just wanting it to, I want to disable remote access to my car while I'm driving down the road. For instance, a prime example of, don't want anybody to be able to remotely control my car as I'm driving 90 miles an hour on the highway or 60 miles an hour on the highway. I drive fast. I live in Texas. So.
Steve Kiss (33:22.306): Yeah. Yeah.
Steve Kiss (33:29.731): Yeah.
Steve Kiss (33:33.794): Yeah, absolutely. I think your point is well taken. And so some of that comes from the documents in procurement. It comes from the procurement path that the owners need to take the standards and the good work that's been done in the standards committees and feed that into their documents and see what comes back and see if they will find that
Aaron Crow (33:44.206): Right. Yes.
Steve Kiss (34:2.510): people will accommodate it or people will ignore it until the time comes for non-compliance and then someone's gonna eat it, right? And that's kind of how this all, to me, how this all started is that all of a people like you and I started shoving things in in the procurement stage and some poor estimator somewhere is like, yeah, yeah, whatever, that's subsection G will go on. And all of a sudden, wait a second,
Steve Kiss (34:31.744): I said that this was going to be stored securely, and it doesn't appear that you have this stored securely, and then all hell breaks loose, right, on a project. Yeah, yeah. So that's kind of a way to start that for those kind of operators that are looking for a way to enter into this and figure out how to do it is to figure out, like you say, what standard is going to work, but to kind of use some basics. It doesn't matter.
Aaron Crow (34:40.504): No, uh-oh.
Steve Kiss (35:0.470): In the IT world, would be, you know, PCI or HIPAA or whatever. It really doesn't matter. How do you prevent unauthorized access? How do you get notified if there is unauthorized access? How do you secure the transport? How do you secure it at rest? These things are very, very basic concepts that all systems operators should be asking of their integrators, partners.
Steve Kiss (35:29.472): Manufacturers that sort of thing and and we wouldn't be left with 97 or 98 percent of the IOT traffic or the ot traffic Being open being you know, you throw a sniffer My racer a sniffer on an environment. It's it's kind of appalling really. There's no there's no excuse for it, know, and I get it a Turban is a very expensive piece of equipment and if it has a daughterboard on it as an ethernet port
Steve Kiss (35:59.170): that was built years and years ago, it might not have the compute power to do encryption. And so, you we talk about these high in the sky things about, you know, each device having all of its own security and being secured. It's unrealistic. That's a million dollar piece of equipment that's not going away. You'll be dead before that thing moves, you know, and that and that's the reality of it. So now we've got to come up with what kind of interface we're to put in front of that.
Steve Kiss (36:26.871): What kind of firewalling are we going to do? How are we going to segment that out? What can we do to kind of mitigate that? Because that thing's going to outlive you. You're going to be dead in dust long before that device comes out of the environment. So it's just kind of the way it goes.
Aaron Crow (36:43.684): Yeah, and you hit something really important to think through there, right? And a couple of points I want to bring out. A, you talked about the fact that we put it in the sourcing, right? It's supply chain. As we're signing these T's and C's, as we're doing this statement work, as we're buying these things, put that language in there then. That's when you have the power, right? When you've already signed the contract and you're two years down the road, it's really hard to go back and add things in because they're going to charge the heck out of you. Or they're just going to say, no, this is the contract. You agree to it.
Steve Kiss (36:53.699): Yeah.
Steve Kiss (37:3.371): like
Steve Kiss (37:10.562): Yeah, yeah, yeah.
Aaron Crow (37:11.792): But it works the opposite direction as well. Like if you put that stuff in there, they have to follow that contract too.
Steve Kiss (37:17.376): Yeah, for sure. And that's kind of why I lean on that. And your operational teams don't have the power to do that lift themselves either. So there's kind of three places you could enter in. You could do it in the document writing, in the scoping portion of the business. You could do it during installation, or you could do it as part of your operational piece. But your operational team doesn't have the bandwidth to be able to take that on. So really you're talking about trying to do, as you're doing plant upgrades,
Steve Kiss (37:46.444): You're talking about starting to add this in on a piece by piece basis. People ask all the time, how do I do this? right? Well, you do this one bite at a time. You do it by taking the next time you're doing a plant upgrade. That thing's coming down for a bearing replacement anyway. This would be a great time to look at the comms system as part of that activity. You're coming up on this maintenance window anyway. And the maintenance windows are so different in OT.
Steve Kiss (38:15.566): than IT. This isn't like Thursday nights a good night because less people are trading stock. Yeah, these maintenance windows are, we're taking down, you know, it's winter and so one of the cogen facilities is coming offline so we can do any current testing. Well, you have a great window right there, right? It's a matter of aligning that window. So anyway, that's
Aaron Crow (38:19.824): for two hours.
Aaron Crow (38:31.782): Right. Yep.
Aaron Crow (38:40.090): Yeah. Well, and the other piece to this, and I love this, right, it's just like with everything. OT is no different. Cyber security is no different. It's people, process and technology. I can't just buy a tool and expect, you know, the analogy, I say this all the time. People probably get tired of me saying this, but it's like, I can, I can have the nicest woodworking tools in the world in my garage, but I can't just put.
Aaron Crow (39:3.950): wood in there with the tools and expect that I'm going to open the garage door and there's going to be like a cabinet or something beautiful that's built. I have to go in there and do something with that and actually do the work to make it happen. And if I don't know what I'm doing, it doesn't matter that I've got great tools. I still don't know how to use them. So I'm not going to be able to create anything beautiful either unless I get the knowledge on how to use the tools and the overall process of that. the understanding that and putting yourself into that mix is an important piece too.
Steve Kiss (39:9.826): Yeah.
Steve Kiss (39:31.630): And that sort of goes back to kind of why I built this IP meter product, right? Like when I get down to it, it's because I needed a tool that was not, first of all, bringing all of your pieces to work and building a tool out of components is foolishness, right? It's just not reproducible. It's not scalable. if the first thing you did to build a car was to like start assembling a socket wrench by hand and molding the metal and making a, you know,
Steve Kiss (40:0.952): building tips for your screwdriver, that would be foolish. No one would find that acceptable. But yet in other parts of the industry, that's been the method. So what can I build that I can just, what requires power? Like just plug it in, ethernet, what's the minimum that I can do? And why don't I have a reproducible alliance that does that? And kind of along that same lines, why am I only looking if I'm truly gonna be forced into this shared network medium?
Steve Kiss (40:30.732): which creates all these opportunities for feature set. I'm going to share all this data and then I can use my modeling to determine things. the benefit of converged systems is feature set increase or performance analysis or whatever the case may be. But the downside of that is I got to have a clear control plane. I got to have quality control plane activities.
Steve Kiss (40:59.820): And so I've now got to start thinking about not just whether or not the tool is reporting the right temperature, but whether the control plane that sits below that is operating efficiently, securely, highly reliable, those sorts of things. So there is a trade-off between new feature set, buzz, buzz, buzz, IoT, and all these great things that the vendor is telling you you're going to get when you install this new blower motor.
Steve Kiss (41:30.275): These things are going to be great, but the downside is you're going to have to have better control of the control plane that's independent of the manufacturer's ability to look at their own data, right? Because they don't even, they might not even look at whether the control plane is operating. They just know that it stops sending data, right? So to know whether these lower level control planes, I look at the world, it's control plane data plane. And in that control plane world,
Steve Kiss (41:58.670): We've got a job to do there because we're being asked to share the data or to share the plane, and we're being asked to secure the plane. And it's not a big ask, right? At the surface level, you get benefit from having these new features, increased efficiency, reduced staffing, whatever the reason is, increased feature set. But there's a trade-off. And the trade-off is you have a shared medium.
Steve Kiss (42:27.758): And you have a medium that is now less secure than when you started. So you got to start putting that stuff into those pieces. that's been the model for our business, really, is just going into those facilities and creating an appliance that people can plug in, operate, and then get data out of their environment on supply chain performance and cyber. As simple as that, VA.
Aaron Crow (42:55.268): So you're typical, let's talk about a, I won't say typical, let's talk about the building management or a wastewater individuals. These are small, and the reason I wanna focus on those is because they're not the Duke energy of the world that has $150 million OT cybersecurity program, right? It's not that, right? It's an individual site that may have one guy and he or she is the multi-skilled full stack person that has to do it all.
Steve Kiss (43:10.668): Right. Yeah, yeah, Yeah. Yeah.
Aaron Crow (43:24.196): and they're not trained in any of this stuff doesn't mean they're not capable. It's just they have five jobs and this just happens to be one of them that they have to do. So what is the, what is the use case for them? What are they looking for? What is your product doing for them? And, and how quickly can they start seeing value by plugging it into the network and starting to get some of that data.
Steve Kiss (43:29.484): Right. Right.
Steve Kiss (43:42.604): Yeah, so we only offer through partners and resellers because we want to be in that food chain. And the partners and resellers are not reselling our product necessarily. They're already in there doing the systems work that they're doing. And so that's the first kind of differentiator is we're coming in through the normal channels. The second piece is I kind of alluded to this because I've
Steve Kiss (44:8.334): kind of backhand that group all the time that says, we'll just download this code, create a VM, stick this stuff. It's just, yeah, I'll do that at lunch. There's just no capability time. So ship them something that's usable, like that's a usable component that they can start collecting data immediately. And in that environment, make sure that the device is ready to go. It's hardened environmentally. It's foolish to think that you can put this all on a laptop.
Steve Kiss (44:37.966): and go out to a can in the field and with no air conditioner and get it to run for 24 hours, you know, go to a rail yard in the middle of and expect that this thing's going to go into the case at a crossing and you'll come back 24 hours later and it won't be slagged piece of plastic. So, so dust protection, kind of environmental, environmental protection, kind of those pieces, just being, just being respectful to the industry that
Aaron Crow (44:40.902): with no air conditioner.
Steve Kiss (45:7.118): It's insulting, frankly, if you're going to show up with something that's not even going to work in the environmental environments that people are used to working in. So then once the unit is installed, which basically plug in, you connect to it via a browser, and you set a few things. What's the serial number of the device so that we get some authentication? What IP address area do you want to scan?
Aaron Crow (45:7.536): Yep. Yeah.
Steve Kiss (45:37.332): And when do you want to do it? Pretty much that's about it. We don't do a lot of custom configuration because there's no reason to. We'll throw the data out that the customer doesn't want. So then we run that activity, and then we securely send it either to something on site or up into the cloud. And then we process that data and display it. So soup to nuts, like from the beginning of that install to when we start saying you have a critical vulnerability,
Steve Kiss (46:6.658): Here's the CDE that you need to read. This is the firmware update that you should be doing on your system is three days, right? It's three days that they can start using those activities. And what are we doing to get there? The federal government's already provided, they've for years have been trying to get operators to do things. They've poured billions of dollars into activities that allow us to help, you know, say, hey, this is our...
Aaron Crow (46:28.934): Mm-hmm.
Steve Kiss (46:35.190): Rockwell device. I know what this is and this is the problem with that thing and this is how to fix it. So we have kind of a whole sleuthing mechanism as well as a remediation component. And that's the core of the product. just how hard is that? It's just understanding the workflow that the OT folks do need to have in play in order to enter into that facility. They're not going to sit there with a bunch of nuts and bolts and a welding rod.
Steve Kiss (47:5.152): and put something together and do that. They just don't have this time, skill or patience and they shouldn't. They shouldn't be insulted, right? They should have a tool that they can put in. Nobody expects them to build their own crescent wrench.
Steve Kiss (47:21.772): Yeah, just kind of a.
Aaron Crow (47:22.654): They need a tool that can easily pull out of the toolbox, plug it in and it work reliably every time they need it to work. And then they put it back in the toolbox, you know, in the Crescent Ridge example, and they put it back in the toolbox until they need it right?
Steve Kiss (47:25.664): Yeah.
Steve Kiss (47:31.650): Yeah. Yeah. And I love when, yeah. And I love when our appliances, like it's going out because someone's already going to a lift station. And so while they're out there, Hey, would you plug this thing in while you're out there? And I love it when it's just sitting in the back of the, you know, on the back seat of the pickup in the crew cab and it's on the back seat, right? Because that's how it should be treated. We should have tools that do that. And you treat your, you know, chips in a Pelican case.
Aaron Crow (47:56.100): Yeah. Yep.
Steve Kiss (48:1.108): obvious reasons, but beyond that, it should be treated like another tool and we should really allow the operator to have those capabilities to do that.
Aaron Crow (48:13.138): I love that. And you know, it's so funny. You know, I've been doing this a long time, as we've said, and you know, and I've been in and I was a CTO of a product company in this space. So I've been the been the, know, on that side of the business, I've been the asset owner, I've been the consultant, I've worn a lot of those hats. And there's a lot of there's a lot of need and a lot of gap in our space, especially in OT, in the tool space. And there's, there's some really amazing, super complex, capable
Aaron Crow (48:42.554): buzzwordy things that'll do all sorts of fancy stuff. And then those are great and there is a space for those. And if you're a really mature environment and you're trying to get to that next level, those are good. But many times when I'm walking into places as a consultant, I'm talking to people that have done little or nothing and they're looking for basic foundational stuff. It's not sexy, it's not fancy, it doesn't need.
Steve Kiss (48:54.222): Yeah.
Steve Kiss (49:1.271): Yep.
Steve Kiss (49:5.815): Yeah.
Aaron Crow (49:8.356): bells and whistles and AI and all the things that they just need to understand what's on their network and what's communicating and the basic level type stuff that you and I take for granted, but they don't have.
Steve Kiss (49:15.756): I think it's...
Steve Kiss (49:23.372): I brought a salesperson on board a while back and he comes from a giant manufacturer and we were going through the product features the first time as I was displaying the product to him. He said, well, what about inventory? I'm like, well, of course we have to have inventory because we're fingerprinting everything. What are you talking about? Like that foolishness. goes, no, no, no, no, no, but you don't understand. So many people don't have a grasp of their own inventory.
Steve Kiss (49:53.206): It really caused me to kind of rethink a little bit of the software, making sure that I at least mention, and I didn't do it in this, which just shows that like when you get around other OT people, you miss the fact, you often miss the fact that people might not even have an inventory of their own environment that they can work in. Now, energy probably they do, nuke they do, like there's certain places where that probably is not as applicable, but building management.
Steve Kiss (50:23.618): you know, hey, we just plugged in that RF system so that we can get a data that us we were doing ice management on the roof, right? That just was five more connections you added, you know, four years ago to do, you know, to do ice measurement on the, on the roof. That's great. You know, let's maybe that should actually be documented somewhere. Right. So, so yeah, your point is valid. Sometimes it's the simplest things that people need and it's about creating that environment for them.
Aaron Crow (50:43.366): Well, and...
Aaron Crow (50:50.662): Well, and even in these high, so I supported a nuclear power plant and I supported, know, coal fire power plants and wastewater plants and critical manufacturing and it kind of everything in between. even those power utilities that had NERC SIP compliance, their NERC SIP documentation was perfect, but not everything is NERC SIP applicable. Meaning some of their assets were documented in their asset inventory for that. And others that weren't required to be weren't.
Steve Kiss (51:18.892): Yeah, I mean, this is the greatest. This is the greatest thing. This is always how I got drug in when I was doing protocol analysis and just doing sniffing early in my career. People would do like a PCI audit. And the first question was, what can we get off this PCI network and put somewhere else? So it's not part of it. It's like, you're fundamentally missing the point, right? The point of this isn't to like reduce the set. So you pass. It's to be inclusive. And it was always comical to me to watch.
Aaron Crow (51:18.926): and they didn't necessarily know about them.
Steve Kiss (51:48.930): who in the chain of command would be the first to say, this is definitely out of scope. Like that was my favorite. that doesn't matter how insecure that thing is, it's out of scope, right? Yeah.
Aaron Crow (52:2.470): 100 % and it happens all the time and you know, I've seen it enough that it, you know, it's just normal. But when you tell, especially IT people that don't have that experience or understanding that, you know, there's a Windows XP machine that's running, you know, the nuclear power plant and a lot of these critical systems and it's going to stay there and it's fine. You have to segment it and mitigate it differently, but it's going to stay there because it's millions of dollars to replace that whole entire turbine to get that thing out of there, right?
Steve Kiss (52:21.538): Yeah. Yeah.
Steve Kiss (52:29.986): Yeah. Yeah. And that's exactly it. That is the crux of the whole thing. Absolutely. I'm a pilot. There's navigation equipment that is in aircraft that is so hard to pry out of that equipment that the only time it's starting to be changed is because they can no longer get the screen for it because the manufacturer's not making the screen. And that's the time it gets changed, right?
Steve Kiss (52:59.478): And that is the story of OT. Bless you. That is the story of OT, right? Is that you are the tail of the system. You are not dog of the system. And you need to learn that lesson day one, is you're providing services that have nothing to do with moving zeros and ones. They have to with moving water and power and whatever else they do, right? So that's the crux of it.
Aaron Crow (53:24.422): 100%.
Aaron Crow (53:27.376): Well, and it's just a different mindset. it's different again in an IT world. If I try to bring a Windows XP machine and plug it into a corporate network, they're not even going to let it on the network. It's just going to get booted off, you know, whatever lockdown and the answer is to be like tough. You're not bringing that onto my network. Here's a brand new laptop. Use this one, right? I can't have that perspective when I walk into an OTS space. I can't just expect, well, you should just block that. You should just not do it. Let's just send patches because Microsoft released them. We should patch it now. It's it's it's it's critical.
Steve Kiss (53:37.184): Right. Right.
Steve Kiss (53:44.556): Right.
Steve Kiss (53:51.491): Yeah.
Steve Kiss (53:54.946): Right. Yeah. Yeah. Yeah.
Aaron Crow (53:57.690): Yes, but if you break something, it's more critical that you just crashed the control system and the power plant or the plane than it was some hypothetical thing that hasn't happened that I have other mitigating factors around. It's better to not patch many times in OT than it is to patch for obvious reasons.
Steve Kiss (54:10.862): Thank
Steve Kiss (54:13.922): Well, I think that it's even less dramatic than that. There's also the situation where there's one vendor that makes that thing or two vendors that make that thing. And they custom build that for your environment. And you operate that thing forever. And there are lots of OT environments that have that critical component of operation that is not
Steve Kiss (54:42.658): that is not often well understood, I think, by the wider community is that you have this risk to wastewater. I actually love wastewater in a weird way because it is a bellwether for the whole critical infrastructure world. It's not interconnected. It's run often at the municipal level. It doesn't have a lot of pizzazz and
Steve Kiss (55:10.614): Nobody thinks it's sexy to work in wastewater. Except for when you go to flush the toilet, you're like, hey, that worked all right. But what is the downside? What is the downside for when those plants go offline and they do go offline from time to time? bigger reserve tanking, better storage. But at the end of the day, when it becomes a cyber problem, it's about shipping that material somewhere else and letting another plant take it. It's a huge risk.
Steve Kiss (55:39.776): And who's helping those folks out? You're right. I'm a little more downscale in some of the things I talk about. I love to work in big, big, big industrial systems. Super sexy. your local wastewater guys are doing a full stack deal every day. And every time you do a deal, they're taking care of your deal.
Aaron Crow (56:4.614): Correct, 100%. So speaking of that, so we've talked about a lot here, the next five to 10 years, what's something that is concerning and maybe something that's exciting coming up over the horizon with all this that we've been talking about? Yep.
Steve Kiss (56:15.948): Yeah. Okay. So I mentioned the staffing problem, right? Like there's this huge staffing problem, quarter million shortage in the U S alone in cybersecurity staffing, got to get tools that are not more complex, but are simpler to use. they, so it can be more inclusive to people that aren't cybersecurity experts to give them the tools. That's the first kind of, that's the first thing that I think in the, in, the horizon that we're seeing. the second thing is I'm just continually.
Steve Kiss (56:45.366): I see myself as a plumber, right? I mean, I'm a pretty sophisticated plumber, but I'm a plumber. I'm putting networks together. I'm putting infrastructure together for people. But it is great to see what the people, when I stick my head out of my hole, what people are doing with the stuff that I'm building that low-level infrastructure for. The way that things are integrated make them more efficient. They make it easier to use.
Steve Kiss (57:14.798): It's just amazing to see in buildings the reduction in power in power requirements. You we talk about you mentioned like coal-fired power plants, nuclear power plants, solar. Like we have all these different ways to produce power. But when we start to think about consumption related savings that we can offer, it's dramatic. It's absolutely dramatic.
Steve Kiss (57:44.312): Right. And so, you know, those pieces really get me excited, both the feature set capability of getting all this data to work together and doing these great things so that when I have proximity, that when I come up to the building, it's already set for me. When I, when I go to my workspace, I already have, you know, it's already set inside of my environment and my environmental variables are controlled. All of these things are great. mean, I'm just super excited for it.
Steve Kiss (58:12.722): And the fact that we can do it efficiently and with less waste, I think is what I see on the horizon. And I just want to keep building plumbing to do that. Simple. Yeah, I'm great being a plumber, right? Like that's what it is. Being in support of that infrastructure allows great things to happen. So that's my outlook. We're going to continue to do just awesome, great things.
Aaron Crow (58:23.494): I'm okay being a plumber. Yeah.
Steve Kiss (58:39.810): But we've got to tighten up that infrastructure to allow those things to happen.
Aaron Crow (58:42.362): Yeah. I love it. Yeah. So how do people find out about you? Call to action. Like how do they find out about you? Where do they find your spot? All that kind of stuff.
Steve Kiss (58:48.643): Yeah.
Steve Kiss (58:52.258): Find me on LinkedIn. IPmeter.net is our website for our product. Sales at IPmeter.net. Reach out to me. Reach out to my team. We're into this. We're into this deep. We like to solve the problem. We like to ship things to people that they can plug in and operate and use. So the call to action is reach out, tell us about your operational environment, and we'll tell you how you can stiffen it up.
Steve Kiss (59:21.048): how you can make it more reliable and safer for the communities that you serve.
Aaron Crow (59:27.512): Awesome, I love it. everybody, everything will be in the show notes. So links to get a hold of Steve, links to the website, all the things that we talked about in here, we'll make sure that we post in the show notes. Definitely reach out. All of those small municipalities, the wastewaters, the building managements, those are the unsung heroes that show up every day wearing all those hats, or they're the full stack developers that are trying to find the tools that they can support and not have to.
Aaron Crow (59:56.274): I love the analogy of they're not expected to build their own tool set. They're not expected to build their crescent wrench. They should be able to pick something up off the shelf and have it be value add to them, not just something they stick in their toolbox and don't ever use.
Steve Kiss (60:9.528): Yeah, for sure, absolutely. So yeah, so reach out to us. We're ready to help. That's our job.
Aaron Crow (60:16.066): Awesome. I love it. Hey, man. Thank you so much for your time. I really enjoyed the conversation. There's a lot of value and folks will really enjoy it. So thank you. I really appreciate your showing up here and talking with me.
Steve Kiss (60:26.894): Aaron, thank you so much. It was great spending time with you.
Aaron Crow (60:30.062): Absolutely.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.