Ep 59: From Plant Operator to OT Security: Stories of Failures and Breakthroughs | PrOTect IT All
HomeEpisodes › Episode 59
Episode 59
Episode 59 Interview

From Plant Operator to OT Security: Stories of Failures and Breakthroughs

May 26, 2025 01:25:34 with Gavin Dilworth
OT SecurityCritical InfrastructureRisk ManagementPen TestingLeadership

Watch This Episode

In this episode, host Aaron Crow dives deep into the intersection of IT and OT cybersecurity with special guest Gavin Dilworth—a plant operator turned automation engineer and cybersecurity expert. Listen in as Gavin shares his candid and often humorous journey from factory floors to global consulting, including how a workplace near-miss sparked his “lightbulb moment” about the similarities between health and safety and cybersecurity.

Aaron and Gavin discuss everything from operators’ creative workarounds on the plant floor, to the importance of trust and rapport between IT and OT teams, and why having hands-on experience is key to building effective cybersecurity programs in critical infrastructure environments. 

You’ll also hear real-world stories of technology mishaps, the critical role of plant culture, and the practical challenges organizations face in securing legacy systems while keeping operations running.

If you want honest, relatable insights and actionable advice on bridging the IT-OT divide—and a few laughs along the way—this episode is for you.

Key Moments: 

10:12 Operator Rounds and RFID Challenges

12:56 Operators' Ingenuity and Knowledge

21:29 IT vs. OT: Firmware Update Challenges

26:49 Understanding and Accepting Risk

28:12 Standards, Frameworks, and Continuity

33:08 High Voltage Safety Precautions

40:41 Bridging OT and IT Skills

43:46 Cybersecurity Cross-Training Surge

52:38 CISO Knowledge Gap in OT Security

54:32 "Experience: Essential for Understanding"

01:03:34 DCS System Configuration Challenges

01:06:52 Neglecting Redundancy Risks Operations

01:11:00 Optimizing Underutilized IT Resources

01:20:04 "Understanding Systems Before Advice"

01:22:06 Old Cables Remain Untouched

About the guest : 

Gavin Dilworth’s career took an unconventional path. As a plant operator, he was tasked with keeping production running smoothly and monitoring sensor readings, both on the computer and around the factory. However, Gavin was never quite the model operator—rather than dutifully making rounds and comparing readings, he often found himself absorbed in books, dreaming of a future in IT. Though he laughs about being a “pretty terrible operator,” Gavin’s story reflects his early drive to pursue his true interests in technology, even when duty called elsewhere.

How to connect Gavin : 

Linkedin : https://www.linkedin.com/in/gavin-dilworth/

Website: https://assessmentplus.co.nz/

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

10:12Operator Rounds and RFID Challenges
12:56Operators' Ingenuity and Knowledge
21:29IT vs. OT: Firmware Update Challenges
26:49Understanding and Accepting Risk
28:12Standards, Frameworks, and Continuity
33:08High Voltage Safety Precautions
40:41Bridging OT and IT Skills
43:46Cybersecurity Cross-Training Surge
52:38CISO Knowledge Gap in OT Security
54:32Experience: Essential for Understanding
01:03:34DCS System Configuration Challenges
01:06:52Neglecting Redundancy Risks Operations
01:11:00Optimizing Underutilized IT Resources
01:20:04Understanding Systems Before Advice
01:22:06Old Cables Remain Untouched
Read the full transcript

Aaron Crow (0:1.452): Awesome. Hey, thank you for joining me on another episode of protected all podcast today. I'm excited to have a, guest Gavin on the call. So Gavin, why don't you tell us who you are a little bit about your background and we'll roll into this thing,

Gavin Dilworth (0:14.220): Yeah, as you said, Gavin, thank you for having me. I am a former operator, plant operator. It's not code for vegan. It's just generally, so many works at a factory. Yes, I'm still using that joke. And then from there, I became an industrial automation engineer. And then as a hobby, I studied cyber security. So when I went to the UK, everything's just sort of like merged and then came back to New Zealand. And now I'm just working for myself and been doing that for quite some time.

Gavin Dilworth (0:43.892): And yeah, it's a, I've got full origin story of how that all transcribed. If you're, if you're keen on that. Well, it's people tell me I should tell it more often because it's actually quite funny. But so I thought, I'll give it a crack. So as I said, plant operator, you know, for those that don't know what that means, it's you're running around the factory. You sort of, you know, keeping the production going and looking at things and the really, really good operators. They sort of look at the scarlet screen.

Aaron Crow (0:48.132): Yeah. Absolutely love to hear it. Why don't let's dig in, man.

Gavin Dilworth (1:13.870): And then they walk around the plant and go, yes, yes, that reading is what I was seeing at the computer. I didn't do that. I was a pretty terrible operator. I had the idea in my head that I was going into IT. And so instead of doing everything I was supposed to do, I'll be reading books, looking at the scatter screen. Yeah, everything's still good. And then how do you build like a domain controller? And how do you create a file server and what have you?

Aaron Crow (1:22.896): haha

Gavin Dilworth (1:43.630): I stumbled into cyber security as an option. That stage was already like a Microsoft certified professional. And I was studying all this during my off time, off shift. And I really found it fascinating because the concept of cyber security was just brand new. This is like early 2000s. It wasn't on anyone's real radar. And I just found that this particular book, what it did was

Gavin Dilworth (2:13.046): If you had an SSH server, you could connect the host to itself and then fire that protocol down the SSH tunnel and pop up. I was like, why would you do that? they're like, hackers. If you're using HTTP and you have a username and password, you know, cause HTTPS wasn't that common back then. This encapsulates it. So then your tunnel is encrypted and they can't actually siphon that information off the network. And I thought that was just, you know, absolute magic.

Gavin Dilworth (2:43.122): ended up using that several times throughout my control system engineering career. Because sometimes you get security controls in place that inhibit your ability as an engineer to do a job. So, you know, being part of the problem, once again, I executed that and did everything you weren't supposed to. So, yeah, at that stage, I was, you know, again, studying IT and helping out in the local community, doing remote access and small business stuff, you know, getting their backups.

Gavin Dilworth (3:12.822): what have you. But what happened was I was changing out a CIP pipe and a lot of people who probably don't know what that is, it stands for clean in place. Okay, so the particular machine I was working on is a dryer and it dries stuff, but it's massive. You know, it goes up several stories and know, stairs are a nightmare. Didn't like the lifts, so I always walked up to, didn't trust the lift.

Gavin Dilworth (3:39.622): Built in like 1968. So you saw like So I'm changing out the pipe so so we could see I pay this thing clean it And Dry being a dryer it gets really really hot. So it's jacketed meaning there's thermal protection, but it's hot to touch and I had My boots were worn Okay, so my PPE equipment basically wasn't up to the task And I ended up slipping

Aaron Crow (3:43.486): Mm-hmm.

Gavin Dilworth (4:10.826): So that made me fall forward and I immediately stuck my arm up like that in my head, my arm went into the dryer. I got a nice burn mark down there. So this is like, cause at that time they were doing a massive revamp on health and safety. like, you you must do this and here's the safety pyramid. And you got to remember I was like a teenager in early twenties. So.

Gavin Dilworth (4:39.574): I was literally just did not care. I was like, what is this health and safety thing? just they're making far too much noise, you know the worst kind of person you want As an operator taking this health and safety not seriously at all, but I'm I blame my impetuous young self, you know with different ideas Have definitely changed my ways since then though, but So with this health and safety stuff now, got a burn mark. I've got to go down and fill out form

Gavin Dilworth (5:8.654): And so we get to the form section and the supervisor's what's happened. Oh, I've burnt my arm. And they're like, oh, OK. Fill out the form. And it was right on end of shift. And I'm like, it's night shift too. So nobody really around for the supervisor and a couple other operators. I look at the near miss form, one page. And I look at the full health and safety form. And I'm like, yeah, nah, screw that. I'm going to fill out the near miss form.

Aaron Crow (5:35.408): All right.

Gavin Dilworth (5:35.438): So I filled out the Neomist form and I said, know, like nearly hit head. So that makes it a Neomist. Nearly hit head, got a minor burn. Everything's all good. I wrote a few other things and then submitted it. Didn't even apply first date. I just went home and sleep. And then a couple shifts later, come back, shift this time. And it's like the health and safety officer wants to see you. It's like, oh God, what does he want? You know, really wasn't.

Aaron Crow (5:40.655): Yep.

Gavin Dilworth (6:3.766): enjoying this this part of the process so he pulls me into the office and he goes he had an accident i was like well it was a near miss i nearly hit my head he goes i see that in the form he goes can i can i just clarify a few things with you i was like yeah sure sure what do want to know and he goes right so you got here nearly hit head that's why you i assume you think it's a near miss i'm like yep he goes that so burnt your arm so yep

Gavin Dilworth (6:30.862): I see there's no first aid record. Did you get first aid? was like no. And he goes, um, this last bit I just want to make sure it's correct. I was like, okay. Yep. Ask away. And he goes, so you wrote this doesn't really matter anyway. Chicks dig scars. So my arm's okay. And so is my head. Is that, is that 100 % correct? I'm like, yep. Yep. That's 100 % correct. And he was just like, right.

Gavin Dilworth (7:0.846): Let me show you the, you know, the safety pyramid, know, near misses, minor injury, major injury, you know, all leads to a fatality. So you filling out a form wrong is completely incorrect. So I got, I got thrown through the ringer and then at the end of it, I'm like, okay, I get this now. I understand why this is important and what have you, but driving home from that shift on the way home, I was sitting there thinking like, okay, it's health and safety thing. I definitely did the wrong approach around this thing.

Gavin Dilworth (7:29.406): and everybody's regulations and what have you. And then I sort of went back to my cyber security stuff that I was currently studying and I was like,

Gavin Dilworth (7:40.288): Cybersecurity is health and safety for computing devices. And it was just that light bulb moment. But that was like, yeah, 20 years ago, I came to that. So I was like, yeah, cybersecurity is going to be a massive deal once people figure that out. yeah, essentially, I thought I'm going to go down the cybersecurity route. Like, that's what I'm going to go do. I'm not just going to do IT. I'm going to go straight for cybersecurity. Well, back in like 2003, 2004, no one in New Zealand was doing cybersecurity. There were no firms. There were no...

Gavin Dilworth (8:9.422): things. So that was that career out the window. And fundamentally, I the maintenance manager tap me on the shoulder and say, do you want to work in the industrial automation department? And I was like, I have no idea what that is. He's like, you've been using that HMI, the PLC, you know, the SCADA systems. And they look after that. And I was like, oh, that sounds cool. And so became industrial automation engineer, trail system engineer. And that was essentially it. went, did that for a career.

Gavin Dilworth (8:36.684): eventually the cyber security stuff because I already knew like a bit of pen testing and mapping and you know like I said it was a bit of a hobby when it came when OT security became a thing I happened to be in the UK and yeah my career just took off then so you know the moral of the story is that you know chicks do digs us because I'm married now so clearly it no obviously yeah cyber security

Aaron Crow (9:0.122): That's right.

Gavin Dilworth (9:5.697): Health and safety, same thing, but for computing devices.

Aaron Crow (9:9.604): Yeah, it's so funny that you say that again. my background coming from, you know, operation side as well, I worked in IT and, but you know, I was working for a power utility asset owner, you know, and I started out in the technology side before cybersecurity was really anything. And I was doing, I was rolling out operator handhelds for operators, like yourself.

Aaron Crow (9:33.680): where they would go do those rounds and they were digitized rounds and they would scan an RFID tag. put RFID tags on all the equipment because these were in coal fire power plants. You can't use barcodes because it's too dirty. So we had to use, you know, intrinsically safe things that, you know, were dust and all of the certification, right? But we were having problems with the rounds not being accurate and not being used and not getting the benefit out of the rounds, the operator rounds, right?

Gavin Dilworth (9:50.254): expensive.

Aaron Crow (10:3.050): And so that one of the things in addition to upgrading the technology, because the operators were complaining about the technology, I was at a plant and I was just doing a walk down and one of the operators were showing me like doing, you know, walking me through around. So we had one of the handhelds and we were going through and, you know, looking at all the spaces and all the tags were reading and we weren't having any issues. And then we stopped by the break room because it was, it was about lunchtime. So we were sitting there and we were eating lunch and, there were, you know,

Aaron Crow (10:32.720): 10 or 15 in America, we play dominoes a lot, lot of the operators would do that. So the guys are sitting there eating lunch, shooting the shit and playing dominoes. And I see one of them play a domino, lean back in his chair with a handheld in his hand, and he scanned an RFID tag on the back wall, entered some information and kept playing dominoes. And it caught my eye. I didn't say anything. I just sat there and watched him. He played for a few more minutes. He leaned back.

Aaron Crow (11:0.728): scanned another RFID tag, entered some information, and he did this for 30 minutes. So after he was done, of course, I'm the administrator of the system, I log into the system and look at his round and at the information he put in. He was completing his, he had a tag, he had recreated every single RFID tag on his route and put a spare right behind him in the break room. So he never had to leave the break room to do his round.

Aaron Crow (11:29.070): And when we asked him about it, very similar to when the health and safety person set you down and asked you about it, we were talking about it. And his response was, he said the exact thing you did. It doesn't matter anyways. Nobody looks at the data. I can put 9 million degrees and nobody says anything. You're just trying to make sure that I'm working. It's busy work. And then it clicked with me. It was like, wait, it's not a technology problem. They don't see the value in it, so they're not doing it to their

Aaron Crow (11:59.084): every one of those guys, and this was again, this is back in early 2000s, the good operators are the ones that could walk out and they saw a reading, but they put their hand on the thing and they knew, Hey, there's something wrong with this device. Cause they've seen it. They'd been doing it for 40 years, all that type of stuff. Right. But it goes into exactly what you're saying is we have to understand. And cyber is that thing. Like, I can't tell you how many conversations I've had with people in, these spaces where they don't get it. So they find workarounds. Like you said, right? I'm going to, I'm going to tunnel in. I'm going to.

Gavin Dilworth (12:26.029): Yes.

Aaron Crow (12:28.368): plug in a wire around the firewall, because I need to do my job and you don't know what I have to do. So I'm just going to tell you, okay, go away. And then I'm going to find a way around it.

Gavin Dilworth (12:37.358): Oh, absolutely. The thing with operators is they've got so much spare time in their shift capacity. They can come up with very, very creative ways to get around stuff. Very creative. It reminds me of a guy called Arthur, right? He was in the factory when it was built in like 1958. And he would literally walk around and everyone's sort of scratching their heads going, why is this pipeline not working properly? Like, it's meant to be the product. And Arthur was like a chain smoker.

Gavin Dilworth (13:6.858): And you know, just like cigarette out of his mouth and just walks up with a hammer and he's like, bang, bang. And then the whole thing kicks off. He's like, how did you know that? He's like, I've been working here since I was 16 and the dude was like 60, you know? So it's that crazy knowledge of they just know exactly where, how everything just interconnects. I'll just switch up. Sorry.

Aaron Crow (13:24.685): Exactly.

Gavin Dilworth (13:31.682): bright sun coming through in the morning.

Gavin Dilworth (13:37.824): Sorry about that.

Aaron Crow (13:39.024): That's right.

Gavin Dilworth (13:42.987): Yeah, well that's the thing like operators will do stuff if they don't see the value they'll definitely go the other way and I'll certainly a case for that and I've seen it many times since. It's why I always put on the control room desk I make sure that there is a powered USB plug so that you know they're not meant to have laptops not to have phones tablets you know but you know the games on this Sunday and they're going to watch it so they'll smugger it in.

Gavin Dilworth (14:11.230): and just having that ability to charge the phone just takes it away. Otherwise they're plugging into your OT service and that's what's happening.

Aaron Crow (14:20.560): 100 % well and from from a from a technology perspective, it's really easy from the outside looking in. This is you know, I've built teams and brought in you know, IT people, cyber security people from the IT side of the business side and you know they just don't seem to grasp the concept. Will just force them will reboot him like timeout stop like you're not going to do that. I'm not going to reboot a system that's in the control room that an operator sitting at controlling a process without his perspective without his permission. I'm going to go ask him.

Aaron Crow (14:49.292): Is it okay if I use this machine like every single time? I can't just do things to them because again, they'll kick you out. And that's where, know, one of things that you said earlier, right? It's building those credentials and making them trust me, right? The biggest thing that I have to do when I'm walking into a facility as a cyber security person in this place is make sure that they understand a that's why I have hard hats. That's why I wear PPE. It's why I've done all and I don't just, I'm not, I'm not cosplaying. Like I've worked.

Aaron Crow (15:18.768): plenty of outages and done all of these things. I've earned my stripes in that. I want them to understand not to show off or not to, know, know, lift myself up, but more so that I make them feel comfortable that I've been in your shoes. I'm not going to do anything to you. I'm here to help you. And I'm, I'm actually the thing that's more on your side than the IT people. I'm going to fight for you and make sure they don't break your shit.

Gavin Dilworth (15:45.038): Yeah, eyes that rapport building is huge and having had that experience, know, like you say, the PPE and going in and you've had to do things. It really helps. I think the best situation that I've ever had was, you know, OT, cyber security guys coming to do an audit, you know, consultant contractor. So everybody's like, don't touch my systems. And then you're like lean over and they're having a particular problem. And I'm like, oh, it's your PLC is doing this. And also you

Gavin Dilworth (16:14.670): your analytics really terrible. should have a code standard guys. Come on. and they're like, I thought you were the OTC sub security guys. Like, yeah, but I used to be a Charles's mentioned that I have programmed that to you particular brand of PLC, like 50,000 times, you know, and then immediately they're like, this guy's all right. He's seen stuff. So we they're like, what do you want to know? So yeah, that experience does help.

Aaron Crow (16:25.764): Right. Yep.

Aaron Crow (16:33.401): Right. It's priceless, right? It's one of the reasons why, you know, I worked for big, big, you know, big four consulting firms and, and did this. And it's a reason why they would send me into these places because, you know, you send some kid straight out of college that's never even seen an OT site or been to a power plant or manufacturing facility or whatever the thing is. They can read that off of them from a mile away from the shoes that they're wearing to the shoe, you know,

Aaron Crow (17:1.476): the way they have their PPE on, you can just tell they don't fit. Like it's, they're wearing a new suit that they've never put on before and it's itchy and they're not sure what to do in it. It just exude from them. I don't know what the hell I'm doing.

Gavin Dilworth (17:12.194): Yep.

Gavin Dilworth (17:15.350): Yeah, yeah, they see like steam leaking from a pipe on site and they're like, is that is that dangerous? It's like well don't don't go near it. But yeah, no, you're fine. You're fine That's why we're in the walk path and not in the hazardous area that has the stripes, know things like that You know what your way around but I have seen that in both australia new zealand and the uk where it's not just big four just general sort of like it mssp's they're like, we're gonna this ot thing's like a thing and

Aaron Crow (17:26.988): Exactly.

Gavin Dilworth (17:45.358): We're gonna do it and we're gonna grab some graduates and I'm like that business model isn't gonna work and you try to explain it to them and They're like, oh that sounds really expensive We have to get like a really senior OT security guy to come in and do everything But we just wanted the cookie cutter like send the graduate and tick tick tick because it's always it's all Windows XP, right? So it should be should be easy. You know, I know it's not how it works then So yeah, I've seen that in the UK NZ and Australia Businesses trying to spool up an OT department

Gavin Dilworth (18:14.814): not understanding it and trying to do that security audit and then ultimately fail and then try it two or three times and then I haven't seen I've only seen ones that are successful are just pure OT. So it's very very hard for organizations to have that. It can be done it's just normally what they've done is they've finally understood the commitment and they've really gotten someone that is a senior that's been doing this like 10 plus years just OT, straight.

Gavin Dilworth (18:44.670): that knows like knows NERC CIRP and knows 64.3 and NIST 882 like off the back of their end type thing that can lead the department. Yeah I don't know if that happens in the US.

Aaron Crow (18:56.080): It takes that. Yeah, absolutely, man. It's exactly the same, right? As is, you know, and I've seen it everywhere. You know, I've done some work in, you know, Scotland and Ireland and, you know, in power utilities over there. And it's, the same thing. Like it's, it's a universal truth of, you know, it and OT. And one of the things that, that, know, kind of got us connected was, you know, that, that it and OT conversation. And it really leads into this, what we're talking about here is, you know, I've done again, as an asset owner,

Gavin Dilworth (19:20.248): Yes.

Aaron Crow (19:25.710): You know, when I was in charge of, you know, OT cyber security for power utility in the States here, you know, my CISO hired one of the big four to come in and do an assessment on the IT side. And of course the, the, the big four said, Hey, we should do OT as well. Like, cause we're here and it's important. And you know, same thing you just said, right? So they sent these, you know, PWC type folks, big four consultant folks.

Aaron Crow (19:51.184): um, you know, to power plants and they wanted to do 45 power plants across all of my, all of my environment. And I said the same thing, what you just said, you're not touching my stuff. Like you can tell me what you want to do and I'll do, I'll get you the data you're looking for, but you're not plugging in anything. You're going to sit in that conference room over there. You tell me what you want. I'll go do it and I'll come back to you and I'll give you your data. And that's what's going to be. Um, and we did that and we were successful with it because I had the credibility and, I had built a rapport with all of those plants. Otherwise we wouldn't have gotten anything.

Aaron Crow (20:20.772): Like they would have just said, there's the parking lot. See you later.

Gavin Dilworth (20:24.290): Yeah, yeah, that resistance is there. It's been well earned. like anything sort of, as we said, you've got to have that sort of street cred or rapport to be able to go in and actually get that sort of stuff. yeah, the original reason I contacted you was that colonial pipeline talk with the IT terms, OT, IT. And it's kind of funny because I was sort of on the other side of the foot where I've always explained that, you know, like a domain controller.

Gavin Dilworth (20:54.702): in the OT space is OT. They're like, oh, but it's an IT equipment. It's like, well, yeah, it's an IT function. Sure, like a domain controller is a domain controller. But the difference is you're applying a different criteria to what you need to do. You don't build a domain controller and a brand new forest tree and have it take over the other one and completely dosh yourself. That's the sort of nuances that you have to go through.

Gavin Dilworth (21:24.162): you know, like network switches. You're like, it's a network switch. I could, I can just update the firmware. And it's like, no, that's connected to a PLC. If you do that, you have loss of visibility. Now you might be able to do that, but you've got to tell the operator service that they've got an outage for like 15 minutes and you better have a space that's sitting ready with the config, ready to go to DRAC and check in if you need to get things operational very, very quickly. And, you know, again, those, those slight things, the IT approach versus OT is sort of like you call it OT.

Gavin Dilworth (21:53.088): even though it's a file server, even though it's a domain control, even though it's a firewall, it's OT because you're applying a different sort of rigor standard criteria to it to make sure you think about the consequences of anything you do. And the other thing I try to do is specifically for policies, procedures, and that high level government stuff is I generally call out what is IT, what is OT.

Gavin Dilworth (22:19.906): What is industrial control slash industrial automation control systems? You know, like HMI. HMI can be Windows. It could be Windows embedded where it's firmware that gets updated. You're not probably going to patch that. So if you've got that distinction that a level two device could be OT as in full Windows, or it could be an HMI, you've got to apply different criteria to that. Same with obviously a controller PLC.

Aaron Crow (22:45.861): Yep.

Gavin Dilworth (22:48.750): Anyone who's updated a PLC firmware knows how interesting that could go. I always like to do it over a dodgy internet connection with low battery on my laptop just to make it extra fun. On a Friday evening, that's right. Yeah, just to make sure. But yeah, so having those terminologies like ITOT, ICS and what constitutes and even mapping it to the Purdue model. And I know a lot of people are like, Purdue model is dead.

Aaron Crow (22:55.984): Mm-hmm.

Aaron Crow (23:0.878): Right. On a Friday evening also.

Gavin Dilworth (23:19.094): Everybody seems to teach it. having that sort of terminology seen as it's permeated across, it's within our space all the time, people talk about it. It just helps facilitate the understanding and then you can actually have better conversations. So yeah, I find that the terminology seems to always jump around. doesn't matter what organization you go with and the rule of thumb is you always adapt to the organization's way of calling it.

Gavin Dilworth (23:48.696): But those terms are important. But ultimately, your conclusion was it's all operational risk. And that's in your previous talk. And that's completely right. That's what I've seen as well. It doesn't matter if, I mean, the executive board or the company does not care that it's OT-specific risk. It's just risk. And that's, yes, that's it. That's all there. Are you?

Aaron Crow (24:9.136): did it impact my site?

Aaron Crow (24:14.126): What was it that was it the trash can, the parking lot? Was it the, you know, the, the janitor? don't care what happened. How do we make sure it doesn't happen again and make sure that, you know, we can continue doing business. Are we safe to start back up and start producing whatever we produce again?

Gavin Dilworth (24:17.902): you

Gavin Dilworth (24:29.646): That's it. Yeah. And it's always interesting having people that don't grasp that concept where sometimes you just got to look at them and go, what's your interest of saying this isn't an OT attack or an OT impact? And generally it's because they're trying to sell a report or write a blog post. I've found if you just pull apart a few threads, you can actually find the motivation of why they're saying it's OT or not OT.

Gavin Dilworth (24:59.436): end of the day, it's operational risk. So the terms matter, but all we're dealing with is facilitating risk. And if you go to a board and say, here's your risks, and they're like, we accept 90 % of them, it's like, well, I've done my job, it's documented, they've accepted, all right, cool. Out. It's really painful as a consultant and like people that, know, you and I have both worked in these environments where you want to protect them. But when you've got an organization that's like, you know, we could...

Gavin Dilworth (25:28.206): It's like, what do do? You can't do anything. You've informed them and they've accepted it. So you just have to move on. Can't help everybody.

Aaron Crow (25:35.376): I'm sure it's like a mechanic. I'm sure it's like a mechanic when you bring it, you know, when somebody brings in a car and like, you know, the brakes are shot and their tires are bald and you know, they don't have any power steering fluid and, they don't have any money either. They're like, all these things are broken. You really shouldn't drive it. And they're like, I'm good. I'll take the risk. Okay. But I don't think you should, but you it's, it's so

Gavin Dilworth (25:53.067): Yeah, shit.

Gavin Dilworth (25:56.673): It's on you, buddy. Yeah, that's a good analogy.

Aaron Crow (26:3.362): It's frustrating to me because again, I've worked in all, I've been an asset owner. was CTO of a software company and providing a product in this space. I've been a consultant at big four and now I'm at a different consulting company. So I've been in all of those seats. And for me, I want to help people to understand where they're at to your point, right? You look at the frameworks, whether it's NIST,

Aaron Crow (26:29.872): you know, CSF, whether it's, 853, 882, you know, six to four for three, like all these different standards, it doesn't matter. And the way I've always looked at these standards is it is the language that we're going to use to be able to make sure that you and I are communicating the same thing. What is the risk? What is the definition? Where is the gray area? Who is responsible? Like, what is our because when I'm to your point, like if I'm going to present these risks,

Aaron Crow (26:58.032): And many times these, boards or these plant managers or whomever, they're accepting the risk. I, I sometimes believe they don't really understand the risks that they're accepting because if they did, it's kind of like the car analogy. I was just saying, like you're going to lose a tire and you're going to die in a fiery ball of fire a mile down the road. You're not going to accept that if you have a baby in the backseat. Um, you know, but if you're a 19 year old kid and you're in, you know, you full of piss and vinegar.

Gavin Dilworth (27:20.503): Yeah. Yeah.

Aaron Crow (27:25.072): Yeah, you're probably going to take that risk and drive on down the road. We all made stupid mistakes in our teens, right?

Gavin Dilworth (27:30.414): Yes, mine is definitely my operator career. I think I highlighted that stuff. yeah, the car analogy I've always used when trying to get my point across for me is generally, it's like I'm the world's safest driver. And they're like, what are you talking about? It's like, world's safest driver. I've never been in a car accident. There you go, world's safest driver. it's like, oh, well, there's other factors involved. It's like, oh, is there?

Aaron Crow (27:36.177): That's right.

Gavin Dilworth (27:59.086): And then they're like, oh, I see what you're trying to say. it helps generate the cogs turning to get the conversation across and get the value. But jumping back to standards and frameworks and what have you, I generally like to do 64 for free purely because people are like, OK, what happens if you leave? You're like, Uber consultant, you can do all these things, former control system engineer. You perish. You move away. Whatever happens.

Gavin Dilworth (28:28.334): Like, how do we know that what you've done is good or how do we continue it? It's like, well, you can do the training, but it's online. There's an official process and structure in place for you to pick up and go. So I know a lot of people, ironically enough, still use NIST controls. So you do the 62443 process, but you don't do 3-3. You actually end up doing NIST 882 controls. And that's fine. What you're doing is mapping controls to security levels. And so as long you know that's what you're doing,

Gavin Dilworth (28:57.698): There's again that structure that conversation that terminology all comes in and everybody's now Communicating effectively because they're all saying the same thing and means they know what you mean when you say stuff So yeah, that's that's that's my take on it anyway, and that's why I like 64 for free because it's just you can throw the training

Aaron Crow (29:14.682): Well, and it's amazing because in OT, know, we do things so differently again, coming from the operation side, we use phonetic alphabet, right? We use three-way communication. We use stop on unsure. Like we do all of these things because of the whole safety culture. So we do these things inherently. Our IT brethren don't necessarily do those things. Like they're not doing safety moments before they, you know,

Gavin Dilworth (29:28.568): He

Aaron Crow (29:42.082): run a patch on a Windows server, right? They're not doing a job safe briefing. They're not doing lockout, tag out, you know, when they're unplugging a server, right? They're just not doing those things because the risks are different. I'm not saying we're better. I'm not saying that they should do all of those things. I'm just saying we look at things because coming from a planned environment, we look at things because people die. Like literally, no exaggeration. I've been on an outage when multiple people have died for different reasons.

Gavin Dilworth (29:50.242): Yeah.

Gavin Dilworth (29:55.032): Yes.

Aaron Crow (30:9.136): doing an outage, they did all the safety stuff and they still passed away, right? It's awful. Nobody likes it. And it's horrible to see those people didn't go home to their families, right? These are dire consequences we're talking about. Like we're not, we're not talking just bits and bytes and email and, you know, being, can't get to, you know, Facebook or watch the football game. We're talking about somebody's father didn't come home. Like these are big, these are big deals that we're talking.

Gavin Dilworth (30:18.882): No.

Gavin Dilworth (30:36.066): Yeah, that's the thing. The stakes are higher, if you will. people who have actually experienced a death on site knows that it's very eerie. The mood just... tone and the mood just changes almost instantly. It's very, very bleak. And like you say, it could be someone's father, mother, brother, sister that's not going home that day. And yeah, so we do take that really seriously.

Gavin Dilworth (31:6.450): Especially those that are trained in functional safety, machine safety. So I did machine safety. not as sexy as process safety. Machine safety is like put a gate around it, de-energize stuff. It's relatively simple stuff. But it is interesting talking to another sort of control system engineer, cyber security, tester, so electrician, engineer.

Aaron Crow (31:21.114): That's right.

Gavin Dilworth (31:33.762): Got into cyber security, pen test, consultant. He said, you always seem to say, and it seems to be like a functional safety thing, everyone in that space seems to always bring up safe, reliable operations or safe, reliable productivity. And it's like, well, that's what you need as a foundation. And he had never done machine safety or functional safety. he's still safety conscious.

Gavin Dilworth (32:2.562): But it is interesting when you go down that path of actually has hopping and jazz hop and, you know, Loper going through that process, like really digging into what is the risks then coming from that sort of engineering side and then going, what are the risks from cybersecurity? You, I don't know. I guess you're more tuned to it because you've had that exposure. And so you see the potentials for more hazards, I guess. But yeah, I don't know. you, sorry.

Aaron Crow (32:29.156): Well, in... Go ahead.

Gavin Dilworth (32:32.352): I know I was just gonna say, did you ever do machine safety, functional safety at all or did you notice that well? Yep.

Aaron Crow (32:36.900): yes, yeah for sure. know, all and it's so funny because or not funny, but you know, we just look at things. It changes. It changed my perspective on absolutely everything right? Even going into, know, I do assessments on, you know, enterprise environments and all that kind of thing. And I just, I look at things differently because of the things that I saw in that space. And I'm not just talking about the, you know, the deaths and that kind of stuff, because obviously that didn't happen all that often. But

Aaron Crow (33:5.636): but still just the possible, once you understand that light switch is like, I remember seeing a safety video, because again, I worked in power utility, so we're working with these giant high voltage devices and we had to wear arc flash protector and when they have these machines that would rack in these big relays and they would make us watch these safety videos.

Aaron Crow (33:29.444): because the equipment that you have to put on like it's like a full hazmat suit and it's big and bulky it looks like something like the dogs the dog people wear you know when the dogs are attacking them like super protecting this big shield but then when you see an arc flash and you see what happens it's terrifying and I'm not recommending you go look but if you're interested go google that it's disgusting and not something it's very fun to see but it literally vaporizes people like nothing left

Gavin Dilworth (33:33.548): Yeah.

Gavin Dilworth (33:36.514): We.

Aaron Crow (33:57.668): And it's terrifying and it happens in a split second because they had a metal ring on their finger or their screwdriver crossed a bar or something like something happened and they're gone. Like there's no existence left. just like burns the skin, their clothes onto them. Like it's just really bad. So when you see that type of stuff, you look at things differently.

Gavin Dilworth (34:3.512): Yes.

Aaron Crow (34:24.176): you're approaching risk in a different way than something that is just, again, an email server going down. So when I'm looking at an assessment and I'm looking at IT versus OT, which is why I get so passionate, so frustrated when I oh, well, that wasn't even an OT attack. I don't care. Like, I don't care where it started. I don't care that it was an IT. I care if it can impact this site, then it's an OT attack. Plain and simple.

Aaron Crow (34:50.372): It didn't come in from OT. It wasn't focused in OT, but it impacted OT. It impacted my plant process. It impacted the potential safety and viability of this facility. That's an issue. And the fact that you're arguing over whether it was IT or OT, you're missing the forest for the trees, buddy.

Gavin Dilworth (35:7.382): Yeah, no, I concur. The reality is if you've got operators that are not making productive material, whether that is clean water or treating water or electricity or an iPhone, then you're not producing. If you're not producing, that's an operational impact. So, yeah, speaking of, you know, the arc flash and stuff, know, ring hands and this is my, yeah, my wife's okay with it. But it's just, why does that happen?

Aaron Crow (35:35.738): Mine's silicone.

Gavin Dilworth (35:37.835): there you go. It's just one of those things where you've seen it, like injuries happen in the workplace and you're like, yeah, no, it's not worth the risk of, Interestingly enough, the ARC flash suit, I was still an engineer when that sort of really came through in New Zealand and the movie Hurt Locker came out at the exact same time. yeah, so we always refer to it as the Hurt Locker suit.

Aaron Crow (35:59.044): Yes. Yeah, it looks like that.

Gavin Dilworth (36:6.030): So, and Suit Up, because I think I forgot the TV show that was off. But Suit Up meant Hurt Locker Suit. So, yeah. So yeah.

Aaron Crow (36:11.172): Yeah, yeah, yeah.

Aaron Crow (36:16.430): You know, it really gets back to when you're looking at these frameworks and you're looking at all these things. For me, you know, when people are talking about it doesn't matter if you're wastewater, if you're a small manufacturing, big manufacturing, electricity, it doesn't matter. You're all doing something and it's using, you know, O.T. as physical processes. It's really about defining. And unfortunately, what I see too many times is when I walk into these places, there's a lot of gray area. There's a lot of assumptions and there's a lot of unknowns.

Aaron Crow (36:44.204): IT has a good understanding of their stuff to a certain point. And then OT operations has an understanding of their stuff to a certain point. Usually there's a lot of gray in the middle that nobody really knows who owns and who supports and whose responsibility it is. And sometimes it's IT, you mentioned it earlier, IT supports the switches. They support the firewalls. They support the active directory maybe. You know, some of those types of things. Those are IT type systems.

Gavin Dilworth (37:6.798): Yeah. Yes.

Aaron Crow (37:11.834): but we've got to get out of the mindset of to your point and what I talked about before on that other example in my other episode, active directory, if it is serving a function and OT, it is an OT system every single time. It's why I don't commingle active directory with IT and OT systems. It's just, I don't do that firewalls, same thing switches, same thing, VMware backups, you name it. It doesn't matter if it's an IT type product. It matters what it's doing. What function is it serving?

Gavin Dilworth (37:23.362): Yeah.

Aaron Crow (37:40.472): and is it serving an OT function, an OT system, then it becomes part of that system.

Gavin Dilworth (37:47.448): Yep, yep, completely agree. Where I've seen, definitely if you can, obviously active directory separation, where you have IT looking after all the things. Generally what happens in that scenario is it's an education piece and awareness piece. Stop updating those network switches, you're gonna upset operations. And that's why IT department tends to have a bad reputation.

Gavin Dilworth (38:17.100): from that. But there are a lot of places and one of the fortunate things was, you know, I've come from water and waste and manufacturing and food and beverage and what have you. And I've also was fortunate enough when I got back to New Zealand to go into oil and gas. One of the things that really struck me was like, wow, you guys have budgets for firewalls. Like genuine, it's a line item.

Gavin Dilworth (38:41.484): You know, I was like, I have to fight too for now just to get a firewall and you know, like a water treatment facility and the parallels are just so well to part. So I've really been fortunate enough to learn what you can do with less and that can also help generate value a lot, a lot sooner. The reason I bring that up is there's a lot of factories out there. There's a lot of operations, if you will, where

Aaron Crow (38:41.806): Right.

Gavin Dilworth (39:9.986): You don't even have engineers. You've got industrial artiticians and instrument techs and they are looking after the equipment. They can't even get an OT guy in. So yes, IT is facilitating the OT Active Directory and the OT Network switches. And realistically, it's just trying to give them the best toolset and awareness, you know, so that they keep operations running. I mean, every assessment I've gone to...

Gavin Dilworth (39:37.638): You come up with risk scenarios and it's like, okay, have you ever heard of Nesiscan? It's like, boy, we have an OT. IT has taken us down four times this year. And you're like, okay, well that's a risk scenario. Every time there's something like that or a firmware update, someone just updated the hypervisors and it's like, but it's standard procedure. And once again, they haven't taken it into account. So in those really like places where you've got like electricians doing a really good job.

Gavin Dilworth (40:4.962): But they're doing controls even though they're not fully engineers and they're maintaining the intellectual instrumentation, all that stuff. And they're expected to know TCPIP networking and Active Directory. And it's a lot. So making sure that IT guys can facilitate and help is a big deal. When you get to like oil and gas energy, generally there's a full OT team. So there's like engineers and then there's like an OT team up to like helping with Active Directory and all those things, firewall rules and.

Gavin Dilworth (40:33.196): You can afford switches and firewalls is great.

Aaron Crow (40:37.453): and tools and process and training and all that fun stuff. But to your point, like for me, it's always been, it's been training, right? And when I started this out, again, I was an asset owner and OT didn't exist. Like that term wasn't even a thing, especially OT cybersecurity. So I was recruiting people that had a skillset like mine, but there aren't many.

Gavin Dilworth (40:39.868): Yeah, that's it.

Aaron Crow (41:2.692): people like me and you, and there are some of us out there, but there's not that many people that have an operations background, came from working in manufacturing or in a plant environment or whatever that environment is, and also has the technology side of things too, and kind of gets both of those worlds. So I was recruiting a lot from IT, had never been in a plant of any kind whatsoever, but they had the technical chops, they were network admins or they were active directory or all that kind of stuff. And then I was also...

Gavin Dilworth (41:20.526): Hmm?

Aaron Crow (41:30.648): recruiting from operators, right? I would get operators from plants. This guy's been there. One of the guys that I hired, one of the best, you know, became one of the best OT guys that I had. He'd been a plant operator and an INC technician and you know, instrumentation and controls was the title. And he'd been an INC guy for 30 years and worked in all these power plants.

Aaron Crow (41:51.554): He knew every person. He knew every system. He knew every how all the control systems work. He programmed every PLC. He'd done absolutely everything in all these spaces. So he got his instant credibility. And he also was a great as we're running, Hey, we want to do this, this and this. And he'd be like, this is the resistance you're going to get. And this is how we can talk to them and do it in a safe way. They may be okay with right. And that was, that was priceless to us. So, so my, my pitch to anyone listening to this,

Aaron Crow (42:20.996): If you have IT providing services to these things, either get an operations person on your team to help you with that, or send your IT team to the sites that they're actually supporting and make them work an outage. And then they'll have a better understanding of why these guys are so hesitant for you to make changes at Friday night with your low internet connection as you're upgrading the firmware.

Gavin Dilworth (42:33.133): Yeah.

Gavin Dilworth (42:42.572): Yep, yep. No, I completely agree with that. In fact, I have one guy that, same deal, cybersecurity is like, I've been doing this OT thing for a while, but I've now gone to this energy company. I've done a little bit of energy, but I know what to do. It's like, okay, there will be, you know, like a shutdown for a substation. Make sure you're part of that team and learn how to bring a substation back online and into production. And I was like, the value you'll get from that would be outstanding.

Aaron Crow (43:1.946): Yep. Yep.

Gavin Dilworth (43:11.694): And yet he took that on board and this is exactly what he did. And he's like, I've got such a understanding of what goes on now and why, you know, and that's, that's the thing. But every time you grab like an IT guy and go, you're coming to the OT team. I've always noticed like the, after a while, their eyes just light up, you know, they're like, Oh man, this is cool. Like, you know, you explaining like a process like, yeah, that machine. Yeah. That, um, that feeds the retro and capital and retro and Capulet.

Gavin Dilworth (43:37.710): and that kickstarts the flux capacitor and they're like, oh man, that process is amazing. I've been stuck in IT all these years and you had all this cool stuff sitting here. It's like, yeah, yeah. So yeah, I've seen that. And obviously massive uptick I've noticed in the past three, four years, electricians, instrument techs, control system engineers wanting to do cyber security. It's actually jumping. And as you say, those guys are usually really, really effective, especially in their home turf. And it's definitely a...

Aaron Crow (43:42.224): you

Gavin Dilworth (44:7.102): either option having both come in and have them teach themselves you know so you've got the IT guy and the controls guy teaching controls the IT guy the IT guy teaching you know like networking and Active Directory really really does help having that cross-pollination of training I suppose

Aaron Crow (44:26.212): Yeah, a hundred percent. mean, it's a price to say it's really the only way to do it. Right. And, know, I, I, I made different process. We did things differently in the OT side than we did in the IT side. I would always tell, in fact, I had an IT guy come to my team and he rebooted a machine at a power plant from four hours away and, on a Friday afternoon and, my punishment was him. I told him like, get in your car, drive to that plant.

Gavin Dilworth (44:51.550): You're going. Yep.

Aaron Crow (44:53.616): He goes, well, it came back up. I'm like, get in the car, drive to that plant, walk up to that operator, explain to him what you did and why you did it. And you're going to sit there and make sure everything is okay. Well, it's probably going to be fine. Yeah. But you're going to go make that. Cause if you don't, we've burned a bridge and they're never going to let us touch their stuff again. Like you have to eat crow. It's not even, you know, a pond, but you know, you have to go shut, put your head hat in your hand and say, I'm sorry, I did this to you instead of with you. And, and, and once I started,

Gavin Dilworth (45:6.146): Make sure.

Aaron Crow (45:24.004): kind of building that camaraderie with him and the team. To your point, the lights came on and he understood it. To your point, on the other side, the electrical, the electricians and the instrumentation guys and the operators, these guys are super capable. They're very technically smart. They're managing these systems. They're programming these PLCs. They're doing networking. They may not even understand exactly how they make it work, but they can. They're very capable. They just don't have an IT background.

Gavin Dilworth (45:41.838): Hmm?

Aaron Crow (45:52.716): no different than you or I, if we had no training and they throw us into an operation space, how would we expect to be successful? Right? It doesn't mean we're not capable of learning it. It's just not something we've experienced before. So use that to your advantage. We're all one team. And that's the biggest thing that I try to tell people is, we've got to remember it's like a, it's like a husband and wife. If you're arguing about something, remember we're on the same team here. We're trying to get to the same place. We're trying to raise kids. We're trying to pay our bills.

Aaron Crow (46:19.524): You know, we're trying to get along and have fun and, you know, build a cool life. We may have different directions or ideas on how we get there, but we're still going the same direction. So let's try to find a compromise and one that we can both agree with and go with that, right?

Gavin Dilworth (46:34.128): yeah, absolutely. Effective communication and reiterating that we're all on the same side and we're all trying to do the same thing. Even with, so I worked for an OT, Network Contrusion Detection System company, and it didn't matter what shirt you were wearing, where it was yellow, pink, green, blue, red. It's like, look, we're all competitors, but at end of the day, we're trying to protect critical infrastructure. So we can just let that go and just get on with it.

Gavin Dilworth (47:3.246): It's like, yes, you won that client and we really wanted to win it, but we're here to help. yeah, it's just one of those things where I think the community can do quite well when they're all on the same page and everybody's working to the same objectives. But sometimes people get a little emotional. As engineers, as operations, you can get a bit precious about your plant, rightly so. Sometimes you just got to sort of like, how and how and let's just write.

Aaron Crow (47:7.876): Exactly.

Aaron Crow (47:26.960): Mm-hmm.

Gavin Dilworth (47:30.764): What are you trying to achieve? Okay, I can help facilitate that. And that's probably the best objectives you can, or outcomes, sorry, you can get from it. Yeah.

Aaron Crow (47:41.466): So we have very similar backgrounds and experiences and all the different things, obviously in different ponds. But it's really no different. I guarantee if I walked into a power plant in New Zealand or Scotland or any place else, they're pretty much the same. Their accents a little different than my East Texas accent, but that's okay. But how do you differentiate and how do you, because every vendor,

Gavin Dilworth (47:46.094): Hmm.

Gavin Dilworth (47:58.690): Yeah.

Aaron Crow (48:7.536): every news article, every everything is like fear, you know, the sky's falling, Russia's going to hack us, you know, all the FUD that comes out about all of this. My, know, again, I was an asset owner. I was also a CTO selling a product. So obviously marketing and we're, trying to get you to convince you to get our thing. But how do we get through that and, and, and narrow those things down to, you can't say that, you know, to your, you knew as you analogy earlier and I've heard it a thousand times. Well, we've been running this power plant for 40 years and it's never been.

Gavin Dilworth (48:12.728): Fud.

Aaron Crow (48:36.580): Why would it be hacked now?

Gavin Dilworth (48:39.042): Yeah, yeah, yeah, yeah, there's definitely, well, there's a vested interest in bad actors, if you will, that want to, and you got problems with, as you say, FUD, know, fair uncertainty and doubt being thrown at you constantly. And people get pretty, know, thick skinned with it. They're like, we hear this every week. You know, what do we do? I think generally having a pragmatic approach and saying them to them, look, not everything's a risk.

Gavin Dilworth (49:6.830): But some things are and you do need to take this seriously. I remember it was very, very long ago now, 2017. So we call it size. I just found out that that's that's only a New Zealand. Yeah, there's probably.

Aaron Crow (49:23.684): We call them CISOs. That's weird. You probably call it a bonnet too. Don't you.

Gavin Dilworth (49:29.762): Yeah, it's a New Zealand thing. I always thought the rest of the world called them Sizos and it's like, no, no, the rest of the world calls them CISOs. You're the ones that are weird. It's like, okay. So CISO was like, no, there's you know, vendor, OT vendor, their firewalls and switches. there's like 20 CVEs read 999.99. You know, it's just doom and gloom. goes, you must patch, you must patch now. Like this is a problem because we...

Gavin Dilworth (49:58.198): Some of the firewalls are the gateway between IT and OT. And I like, I sent an email back saying, no, we don't have the patch. And here's why. We're not IT, so we don't expose the management interface to just anyone. Like you actually have to be on plant. And it was one of those plants that didn't allow remote access. This was before COVID when that was almost standard practice. Yep. So in order for you to actually access

Aaron Crow (50:22.266): standard opposite aperture, yeah.

Gavin Dilworth (50:27.362): the firewalls and the network switches, the management interface, you had to get into site and then log in. If you got into the OT network or ICS network or whatever, it's not the CVs that are gonna be problem. It's the username admin, password admin that is everywhere. That's the risk. So no, we don't have to do the CV patching, you know, and that's that again, that lose bulletin, see so overreacts as you do.

Gavin Dilworth (50:56.998): and just be having the credibility and the ability to just actually look at it. And that's why you have that risk-based approach to vulnerability management. think DHS, that flow chart DHS did years ago, which is still great. You know, that type of thing. It's just, okay, we've got these threat actors coming at us. It's like, I heard people when Russia invaded Ukraine, they're like, right.

Gavin Dilworth (51:25.548): Russia has invaded Ukraine, we are air gapping our OT environment. You're like, okay, that's a fair move. But for how long? Like, are you pulling that cable just to go, all right, where are we? Like, do we need to look at something? Are we being targeted? Like, okay, but are you gonna be air gapped for the next 50 years? Like, what's the end goal here? So people can overreact. So it's really just, we've got some information. Let's...

Aaron Crow (51:33.136): Sure. Right.

Gavin Dilworth (51:54.784): actually apply some common sense and again that risk conversation of what is the real risk you know and that's generally how I sort of tackle those things but as for like the specific we're not a threat it's like well my government and probably yours has been saying for quite some few decades now it's like yes we are targets and yes they are looking coming for these things and much like the you know

Gavin Dilworth (52:23.766): on the world's safest driver analogy. That's generally helps get the ball rolling. What's your approach to the FUD?

Aaron Crow (52:33.992): You know it same thing right and I usually come back to unfortunately I don't believe that especially at the board of directors level the CISO level they truly understand the risk especially in this O.T. space. I think they do a better job of understanding the I.T. space probably because most of those CISO type folks came from that business in that world.

Aaron Crow (52:56.792): So they have a better way to grasp the risks and the understanding of, you know, Active Directory and Exchange and cloud and all that kind of stuff. But they don't truly understand the OTSpace. So when someone we're talking about risks in these spaces and we're talking about Windows XP and we're talking about, you know, unsecure protocols and admin admin and not patching and all this type of stuff, it just it sends their spotty senses off because

Aaron Crow (53:22.460): It goes against everything, their entire playbook that they do in the IT space. And they judge it based upon the same device in an IT space because it's in a DMZ that's accessible by the internet. And I've got third party contractors that are logging into it and they don't understand. And again, it goes back to kind of like what I said before, the best way I do this is I take people to those places. Like, okay,

Aaron Crow (53:51.620): The only way you can get to this control system is if you're sitting in this room and there's only 10 people that have access to this room and they've all worked here for five plus years. They all know each other. They're on the same softball team together. So if you walk into this room and they don't know who you are and you sit down at that chair, they're gonna tackle you. No questions asked. I don't care who you are. I don't care if you're the CISO, if you're the CEO, you don't need to be sitting in that seat and you are not authorized to be there and they're gonna stop you. And it happens, like it's just part of it, right?

Gavin Dilworth (54:8.844): Yeah.

Aaron Crow (54:21.002): And they don't grasp that there's other mitigating factors that go into these things beyond just patching and secure mode access and firewalls and all those things are good and we absolutely need to do all of those things. But it's not the same in an IT space as is OT space. And once you understand that and the only way to grasp that from my perspective or the best way, it's like, you me trying to explain to my 16 year old life lessons that I learned on why he doesn't need to do something or why should do something right.

Aaron Crow (54:48.834): If he has an experience, there's just like, yeah, dad's old. He didn't know what the hell he's talking about, right? Versus when he's done it himself and he, you know, he hits his head against the wall. It's like, shit, that hurt. Maybe I shouldn't do that again.

Gavin Dilworth (55:1.250): Yep, yep. It's one of those things where having those conversations, sorry, cats.

Aaron Crow (55:9.873): I've got mine locked out because she constantly tries to come in here.

Gavin Dilworth (55:13.391): Yep, yep. She's like, aren't you sitting in the sun? This is where I, you know, this is my time. But yeah, the conversations with the executives, they really don't care that, you know, no, no, this is OT risk and OT is different. It's just you've got to, I find you just got to channel it to a sense where it's like, well, no, actually, we've got to, we have compensating controls, you know, it's not just fix the problem. There are other mitigating circumstances. So let's,

Aaron Crow (55:18.199): Exactly.

Gavin Dilworth (55:41.132): look at credibility, let's look at target attractiveness, let's look at exposure. And then, you know, and those those words, can generally pick up and go, okay, so it's like, well, as we go down, that sort of means that these things just drop off and that risk is actually quite low. And that generally has a more facilitating things. I previously tried to go no, OT is different and OT you do this, this and this and this is why and it's just the eyes glaze over.

Gavin Dilworth (56:9.304): They're like, no, it's the domain control. So IT stuff, do IT things. yeah. Different countries, same problems.

Aaron Crow (56:12.292): Yeah, same thing, same, same.

Aaron Crow (56:19.880): It's universal like it really is. You know, I've talked to people on this. I had Peter Jackson from New Zealand at one of the Kiwi buddies the other day on here and you know, I talked to people like set up Scottish electric in in London and in the Middle East and you know, I had somebody from Saudi Arabia on the other day and you know it's it's the same everywhere we go. This is a common use case and in part it really goes to.

Gavin Dilworth (56:27.470): That's sweet.

Aaron Crow (56:48.560): the overall design, like our systems in OT were designed to run for 40 years, right? We aren't upgrading them every year. We're not trying to get the new fangle technology. It's the same reason why, ironically, we buy, at least in the United States, I don't know how bad it is there, but here, every time a new iPhone comes out, you have to get the new iPhone, right? It may not have any much difference. It looks the same. If you put two up next to each other, you probably can't tell them the difference. Maybe the camera's a little bit better.

Aaron Crow (57:17.092): Maybe it's got a little bit faster processor and it's another, you 500 bucks more expensive than the last one, right? I got to buy a new case, all that kind of stuff, right? But the four year old version of the iPhone is more than I really need. It works just fine. My kids use it. It takes great pictures. It does everything they needed to do. OT is more like that. Like it's more like my grandparents that lived through the great depression in the United States that

Aaron Crow (57:41.786): They never threw anything away. They repaired stuff. If it ain't broke, don't fix it, right? I'm not going to replace it with a new iPhone because mine's working fine. Like I'm not going to rip out my control system and upgrade it from Windows XP to Windows 11. Yes, I can't patch Windows XP, but you know what? It's stable and it doesn't have to connect to the internet and it doesn't have to be on a cloud. And there's all those other problems that you bring in that, yes, you're solving one problem and you're bringing in 12 more. And that's the thing that we sometimes miss.

Aaron Crow (58:10.348): in these in these discussions is you're you're you're forgetting all the new problems you're adding by trying to solve one you're adding 12 and those 12 are way worse than the one because I can mitigate that other one a hell of a lot easier than I can those 12 that you just brought in and I can't do anything.

Gavin Dilworth (58:25.688): Well, that's the old adage, you know, there are no solutions, only trade-offs. And it's like, you're introducing new problems and by solving others, it's just cat and mouse sort of thing. yeah, new technology coming in, it's like, yes, now I've solved for this. like, you know, the grandparent analogy, this is sort of like, no, I'll just stick to my SMS text messaging. I can message you, it works.

Gavin Dilworth (58:53.550): And you understand that I'm gonna just respond to a text or phone call or whatever and they're happy they're like no, that's it That's the right criteria. I mean like it's also seeing industrial plants like on the old coax cable running at one megabit per second and people like Wow, that's really slow and you're like, no, that's all it needs so You can you you that life cycle is just going to take a lot longer. I mean we haven't sold for that I don't see us updating plcs every five years

Aaron Crow (58:57.914): And that's what I'm gonna do.

Aaron Crow (59:5.956): Yeah. Yep.

Gavin Dilworth (59:23.342): It brings too many risks with it. It's the best way to go.

Aaron Crow (59:26.778): Well, and again, but why? It's not the model that America, especially America does, like we're this consumption, know, capitalistic economy where we throw everything away, we buy something new, you know, I have to get on to my kids and my wife and myself because it's very easy to just say, I'll just go buy another one, right? When, you know, again, 10 years ago, we didn't have Amazon, I couldn't order something and have it show up same day.

Aaron Crow (59:54.128): Sometimes where I live, I can order something and literally that afternoon, a freaking driver brings it to my house in a box, right? Used to you have to get in the car, you're driving, especially if you live down the country, that could be a two hour long thing just to drive into town, get something and come back. So you're really intentional about when you did those things. And if you could fix it without having to go to town or buy a new thing, that's what you're gonna do, right? That's the reason why people had old trucks and they ran, they drove them until...

Aaron Crow (60:21.124): forever and they handed him down to their kids and their grandkids and all that kind of stuff. Like how many people have a car that they've lasted more than three years in the States? It doesn't happen very often anymore. I just bought my son. just turned 16. We bought him a 2004 Lexus GX 470. So it's like a, you know, the forerunner or whatever, but the Lexus version, it's got 272,000 miles on it, but that thing will run for 500, 600,000 miles of it if it's taken care of and it's in good shape. So.

Gavin Dilworth (60:47.822): That's right. Yeah, yeah, it's like it's fit for purpose for him and you know, low cost entry for him as well or you know, so it.

Aaron Crow (60:56.748): Exactly him. He saved up money. He worked all summer. He's a lifeguard and he saved up money. He bought that car. I mean, I had to help him a little bit because it was a little bit more expensive than he intended, but still 90 % of the money came from him and he worked for it. So he's super proud of it and it's a great vehicle for him, right? But it's not a you know, a brand new whatever. But at the same time, that car will probably outlast any brand new car we bought him if we were going to buy him a brand new thing, because it probably would have fallen apart in the next two years.

Gavin Dilworth (61:26.642): yeah, computer software updates over the air and you know, it gets bricked and yeah, there's again like say great, there's some great benefits from it, but there's also risk involved and you know, the good years of like 2004, like any mechanic could probably fix it or that they're gone. You have to get the old vendor plug-in and yeah. So much like that in an industrial space, you know, they've tried to go down and box you in. So you have to do things their way otherwise.

Gavin Dilworth (61:55.724): you your non-compliance and your warranty is gone and it's just, it's infuriating, but we're never going to get away from it.

Aaron Crow (61:58.319): Yep. And that, that, that, that, that's one of the big things that always here as well. And again, working in the plants, I understood it. If I make changes to those switches, you talked about, you know, a lot of times the vendors will bring in, you know, let's say a Cisco switch 2960, an old, old, old switch 2960. Yes. And those switches are still running in a lot of places. I've got some here in my lab actually. I can, it's a, it's a Cisco switch. The same thing you'd see in an, in an IT world in a business environment in a data center.

Aaron Crow (62:27.096): It's the same Cisco iOS. There's nothing proprietary about it. It's just Cisco. But if I change that configuration to something that the vendor doesn't support and it breaks it, the vendor won't support the process because you changed the configuration. So they will, it's like, good luck. Like they're not gonna not support it. They're not gonna tell you that you can't use it, but they're gonna say it's up to you to fix it because you changed our configuration. If you wanna put it back to the, it's kinda like if you put,

Aaron Crow (62:52.206): You know, you buy a brand new car and you throw a supercharger on it and you take it to the dealership because the engine blew. They're like, yeah, sorry, buddy. That's you.

Gavin Dilworth (62:58.510): Yep, yeah, it's it's unfortunate, but that's this this where we're at and You know, there's that there's been I've done assessments I've gone, you know, hey Honeywell, can I make these changes and they're like, ah, we've got to go to global About four to eight months later to come back and they're like, yep, you can do those changes. We're happy with that. So Excellent. That took a while. But yeah, but at least you got something and then there's there's other vendors that are like no you cannot

Aaron Crow (63:20.816): Thank you.

Gavin Dilworth (63:27.502): touch our switches and everything has to be completely flat and and and and and and also I found with these warranty contracts with particular vendors too that's the understanding can be quite confusing because you put in look at a new DCS system and won't name names but put in a new DCS system and new cyber security stuff you know we've got logging we've got decent remote access we've got

Aaron Crow (63:47.322): Yep. Sure.

Gavin Dilworth (63:57.378): you know, endpoint agents and we're going to do application and allow listing. Okay, cool. This is all good. come back eight months later and the control system engineer from the vendor is like, I can't get this thing to work. I'm like, what do mean? He's got, I've had to rebuild this machine like six or seven times. And I'm like, Ooh, what are you doing? And he's, he's like, well, look, I update the screen. I update the image, but I'm also updating these files. I was like,

Gavin Dilworth (64:26.990): have you updated the application allow listing server to say that those executables for the DCS are safe? He's like, what's the application allow listing? Like, So you take them over and then it just works. And so again, disconnect between the cybersecurity and maintaining the warranty. Some of the vendors are actually not really training their staff on the new stuff that they need to support as well. And the...

Gavin Dilworth (64:54.062): having talked to those vendors, control system engineers, they're like, we're controls guys, we don't wanna do that. We don't wanna look after Active Directory, give that to somebody else. But then the vendor company says, you're not allowed to look after Active Directory, we have to. So you're like stuck in limbo. So yeah, problematic.

Aaron Crow (65:0.816): So, yep.

Aaron Crow (65:10.365): And it goes back to that gray area where, you know, the systems engineers, the control vendors that they come out, they're controls people. And maybe they have some experience or they got some training at the thing, at Active Directory or switching, but usually they're running a script. Again, that's what happened in the example I gave last time about Active Directory. It was a control system person and she,

Gavin Dilworth (65:33.667): Mm-mm.

Aaron Crow (65:37.412): didn't she wasn't a technologist. She followed the script and when it didn't work, she did what the script told her to do and she broke everything. Again, she didn't, she wasn't doing it maliciously. It wasn't a bad actor. She just made a mistake. It was anybody could do it. I've made lots of mistakes like that, but I've also done it enough times. I knew why it was a problem and I wouldn't do that in a production environment, right? But that's what happens in these spaces. And because they don't truly understand what they're doing, it's like, you you took it to your

Aaron Crow (66:6.394): you took your car to your plumber and he's pretty handy. Maybe he can fix it, but he's not a mechanic. So if he puts in the wrong part or he breaks something, is it really a surprise when you took your car to your plumber? Like take it to a mechanic. If you want it to be done right, it's gonna be more expensive, but it's gonna be worth it.

Gavin Dilworth (66:27.342): Yeah. Yes. And that's biggest problem that we have, I think, in the industry is actually showing the value, like communicating the value. They're like, no, you can't just send your mechanic to a plumber to go fix a car. You actually need the correct skill set and trying to explain that to a business and show it in a business risk format in a way that you can get buy in and say, look, your business requirements say you need to do accomplish X. We're facilitating that.

Gavin Dilworth (66:56.396): Here's your strategy, here's your roadmap. And we're going to do that with this technology, with this process, and with these people. It's very, very hard to get that structure in place and to show that value. I mean, we try, but generally, like most things, not even a cybersecurity thing, just trying to get, like at a water treatment facility, having two OPC servers, because, you know, redundancy is nice. And they're like, no, we don't want to spend the extra, like, 2,000. You're like, well...

Gavin Dilworth (67:24.044): It's We're not talking about a boatload of money here and engineering efforts going to be the same. And they're like, no. And then they have a plant outage and the OPC server, they can handle like 15 minutes, half an hour, an hour, two hours. But you're going to hit that time window where it's like, well, we don't know what our plant's actually doing. It's controlling, it's working. We've got no idea what it's doing. So we're to have to hit that big old e-stop for the entire plant. And you're like, all this could have been saved if we spent the two grand.

Aaron Crow (67:52.944): by $2,000.

Gavin Dilworth (67:54.466): Yep. So, and we're having that problem with cybersecurity as well. It's like, the value's here, but trying to get that through is still, I think, going to take time. That awareness hasn't permeated through. You know, we're slowly getting secure by design, which is nice as well. But yeah, I see it as the biggest problem we have to tackle is trying to demonstrate to business leaders why you do the things that you do. Regulation certainly helps.

Gavin Dilworth (68:23.746): really does help I think it seems to be the biggest thing to get them on the radar but aside from that if you don't have it like New Zealand doesn't have a lot of regulation around OT cybersecurity or critical infrastructure and you can see that it's definitely not a priority for them so that

Aaron Crow (68:39.488): It's hard, you know, again, I came from power utility and I think that's why, you know, 70 critical infrastructures in the United States and power utility is the most advanced and oil and gas is right behind it just because oil and gas, there are regulations there, but they also have the most funding. you know, power utility just is that way because they have to be and oil and gas is that way because they have the money and it's a big enough risk that they don't want to go down because they lose huge amounts of money. So they put their money in it, but to your point, wastewater.

Gavin Dilworth (68:54.434): Mm-hmm.

Aaron Crow (69:9.092): they're gonna not choose a $2,000 option because maybe they don't have $2,000. It's rolling that dice hoping it doesn't happen. It's not changing your oil in your car. It's worked so far for a hundred thousand miles. I've never changed my oil. So I guess you don't have to change your oil, right? Until you do.

Gavin Dilworth (69:24.908): Yep. That's it. It's always when there's an impact, suddenly there's cash. And that's, remember a community event, one of our very first ones in New Zealand, and one gentleman, you know, he goes, look, this is all well and good for you guys, because you've all been impacted. You've all had something happen. How do I, who've never had an impact, get OT security funding? And everyone just went, you know, crickets.

Aaron Crow (69:30.830): Right. Yeah.

Gavin Dilworth (69:53.678): It's like, well, until something happens, nobody really wants to deal with it. So it's that wishful thinking.

Aaron Crow (69:58.554): So it sounds like we need to start up a new business that we go and just lightly attack people so they can have justification. And I'm completely kidding by the way, just to make sure everybody hears this, I am kidding. I don't actually think that we should do that, but you're right. It's always like, it's never happened to me. It's never happened to me. Why should I spend money on this? Because this money could go, when I first started this, we were literally taking budget out of plant management, plant maintenance during an outage. So they didn't do bowl or tube,

Gavin Dilworth (70:3.980): Hahaha

Aaron Crow (70:28.056): replacement because they had to take $200,000 out of that budget and they turned off one thing they were doing and gave me the money because they only had a finite amount. Like it's not like they printed money on trees.

Gavin Dilworth (70:40.536): Yeah, a lot of some of the stuff I put in was cheap, cheap and effective. Upgraded scatter system. There's some spare service and spare workstations. Slapping network card in there. PFSense, you've now got Firewall. There's remote access in there. We can lock down the ports. You can now access rockwellautomation.com to get your user manuals. Some people are like, no, you don't want internet activity. It's like, well, given the engineers stuff they need, it kind of helps.

Aaron Crow (70:50.990): Right. Yep.

Aaron Crow (71:6.628): Yeah. Yeah, it does.

Gavin Dilworth (71:10.434): It's like, again, risk conversation. It's like, well, we're happy with that. So those types of things really help. And like logging service, there's free logging service and NASs. And you just sort of make do with what you got. So generally, that's how I start when I do assessments. It's like, what are the tactical quick wins? what have you already got that's underutilized? Because we're forever hearing, even in the IT thing, it's like,

Gavin Dilworth (71:38.094): Oh, we install CrowdShark everywhere. Everything's amazing. It's like anyone looking at it, anyone actually configured some of these things and they're like, oh, there's this one guy, Jeff, I think. And yeah, okay. Good luck, Jeff. yep, yep. So yeah, there's plenty of opportunities to uplift OTC cybersecurity using underutilized stuff. Even turning on like provided you a vendor let you.

Aaron Crow (71:42.586): Eh.

Aaron Crow (71:50.288): Yeah. Hope Jeff didn't get hit by a bus.

Gavin Dilworth (72:6.004): like radius or tachx on your network switches, you know, can solve a lot of problems from a shared login point of view.

Aaron Crow (72:12.154): Setting up logging, sending those logs from those switches. I can't tell you how many times and that's the other piece to this that I say and then we'll kind of wrap this up. But I say this all the time, like the cybersecurity thing, when I was pitching this in the beginning, I never pitched it as cybersecurity because nobody'd heard what it was. Nobody knew what it was. Nobody cared. I would pitch it to my plant managers of I can get you more visibility. I can make your system more reliable. So one of the first sites we did, we turned on logging, just like you said.

Aaron Crow (72:41.624): and they had a fully redundant system. The control system had, you know, every switch was redundant. They had redundant past everything they thought. There was a switch that was sitting in the control room or in the, in the electronics room and it had basically powered itself down and nobody knew about it, right? It was just sitting in a cabinet and it it's so loud in there. You can't hear it. It was beeping and, you can't, there's blinky lights and noise and all the things you can't usually have PPE in anyways. Like there's just so much going on.

Gavin Dilworth (72:49.816): Yeah.

Aaron Crow (73:11.396): You don't know what's there. We turned on logging and all this stuff and within five minutes we started getting this, it rose to the top really quickly. And we saw this, this, this switch was, was complaining. Basically we walked over to the switch and it was, it was, it had shut itself down for, for heat issues. Like it wasn't able to cool itself. It was saying fan failure. So we walk up to the switch, we looked at the back of the switch and there was a zip tie that was in the fan shroud.

Aaron Crow (73:40.098): and was stopping the fan from being able to spin. I pulled the zip tie out, the fan started spinning, it booted up, and now you had redundancy. So this was one of their core switches. It was one of a redundant pair. So they didn't have an outage because it was a redundant and the other one was doing the load. But if anything had happened to that other switch, they would have, they had a false sense of security because they thought they had a redundancy, but they didn't. And they didn't know about it. And who knows how long it had been doing that.

Aaron Crow (74:9.614): We found it in five minutes and fixed it. And I went to the plant manager and said, this is why we do it. We're doing this, right? It's not for cybersecurity. Those things are good. I see those as bolt-ons. If we can have these conversations of making these things more reliable, more resilient, more redundant, more capable and available, and I can get more data to my engineers, I can make them more efficient. They can get their manuals online, like all that type of stuff. That's the conversation we'd have. And by the way, I'll also make it more secure.

Gavin Dilworth (74:36.654): Yeah, while you're there. It's just like yeah as a offshoot. Well, yeah very similar story not not cable time and fan but That's sort of realizing get some logs getting some visibility I've you know, I've been doing this like, you know, eight nine ten eleven. It was like, okay We've got an OPC server that OPC server has SNMP functionality. How about we go ask this? Graff Graff

Aaron Crow (74:38.264): Right. It's a byproduct.

Aaron Crow (74:59.472): You're not my problem.

Gavin Dilworth (75:5.486): via SNMP, grab the switch details and see where we're at. And you're to get more visibility from that and actually put it onto the SCADA screen. And soon the operators, they could find the page and they're like, that's weird, that port's down. No wonder I'm having issues. then just giving them that thing, the fault diagnosis just really helps. And then it became standard to have network switches with management interfaces. So you could pull them for data and put that on the SCADA screen.

Aaron Crow (75:31.514): Correct.

Gavin Dilworth (75:34.316): was just like, okay, this is great. Again, not a cyber security thing. It was just like, it visibility, make it, yeah.

Aaron Crow (75:40.112): because it's part of the system. It's part of what, because if you take that network switch out, so prime example here guys, and we're going to, this is the meat for me, the meat of this conversation. That Cisco switch, that Active Directory server, the system cannot function without it. The network, goes across that network traffic, it goes across that route. So if I take those route switches out, the control system dies. Now, a lot of times the plant will continue to run.

Aaron Crow (76:8.836): because the PLCs are hardwired and all that stuff. It'll just continue to run. But what happens in that place when an operator can't control the system, they hit that big red button like you talked about and they punch it out because they can't control it. They can't see what's going on. So obviously they need to shut it down because it could, it could something bad could happen and we don't want that. Right. So looking at a Cisco switch, a Cisco switch is an OT device. If it isn't an OT system, an active director is an OT system. If it is serving an OT function, like

Aaron Crow (76:37.028): That is the moral of this story. So stop arguing about is it an OT attacker and IT attack and look at what function it's serving because that's what matters.

Gavin Dilworth (76:48.024): That's it. That's all there is. I completely agree with that.

Aaron Crow (76:53.272): So, so all this to say, let's wrap up with my, with my favorite question. did prep you about it a little bit, but you know, the next five to 10 years, what's something coming over the horizon that's exciting and maybe something that's concerning that you see that, could be, you know, impacting us in the, these things that we were talking about today or something completely off the shelf, completely up to you.

Gavin Dilworth (77:15.678): One of the, it's both the concerning and the winning at the same time. I've been noticing for a while now OPC UA is finally getting some uptick. OPC UA and MQTT. And a lot of vendors now, they're like, no, no, you don't have the option of doing plain text. You, by default, now that you've installed an OPC UA server, you are doing a certificate. We've got one self-signed. Or you can do your own, you know? So.

Gavin Dilworth (77:44.322): That's good in the sense that PLCs have OPC UA servers in them now. So it is no longer let's have a proprietary thing. And from a monitoring point of view, what connects? Imagine you had OPC UA is your visibility. It goes to your plant screens. It goes to the historian server, collects the data. Cool. Well then what's going to use the native protocol for Modbus TCP? Let's say it's a Schneider Modicon. OK, so Modbus TCP, PLC to PLC coms.

Aaron Crow (77:59.248): Sure. Yep.

Gavin Dilworth (78:13.952): Engineering. Okay. So if you ever see an out-of-band Modbus TCP con It now makes it easier to sort of diagnose because you've sort of got a separation of protocols there. So that's And there's a lot more advanced stuff in OPC UA on a PLC that I just I'm genuinely excited about some security features But it all hinders on the certificate stuff and what scares me is I've seen this a few times now where they're like we will go self-signed because we don't want to do PKI and

Gavin Dilworth (78:43.982): properly in OT because it's a massive dependency and it is, it really is. You've really got to get that down right. But then they just sort of go, okay, cool, we've installed it. And you're like, well, what's the lifetime of the certificates? And they're like, It's us. It's surely it's like 20 years. It's like, you don't know? When was the first time you installed this Enabler's technology? seven years ago. So it's like, well, you're going to DOS yourself. Yeah.

Aaron Crow (78:46.756): Yeah. Yeah.

Aaron Crow (79:9.584): It's ticking time bomb that you don't know when it's gonna go off.

Gavin Dilworth (79:12.886): It's basic asset management, but I just see people not really sort of going into that level and going, actually, we need to take care of this. So OTPKI, very, very complex problem. A lot of infrastructure has to go in place to support that if you were to run it. But the disadvantages of going with like a self-signed is that it's not being managed and therefore there's no automatic renewal. There's no, you know,

Gavin Dilworth (79:42.902): Like let's just if it's compromised we're gonna have to reissue all the certificates is there's a lot of downfalls As there is windfalls from it So i'm glad that's where we're going down a vendor neutral path and people can talk in the same protocol My mqtt seems to be everywhere same with opcua But at the same time, there's a lot of complexity now Going right back to the start. Well, not the very start, but there are only trade-offs no solutions yourself

Aaron Crow (80:11.108): Right?

Gavin Dilworth (80:12.352): solved for problem, but you've introduced them all. anyway, that's.

Aaron Crow (80:18.272): The moral of that story to me is that, it gets back to every assessment I think I've ever done, or every time I've walked into a place and trying to figure out what's going on, most of the time it starts out with, do I have? And understanding from an asset inventory, from a network architecture, from a system design, from how everything functions, and do they have one control vendor or two or five or 12, how does everything sit together? And until I really have that good understanding,

Aaron Crow (80:46.732): I, it's hard for me to make a recommendation on what you need to do. You know, yeah, I can tell you how many Windows XP machines need to be patched and how you need to update your firewall. And any asshole can tell you that. That's not the value that I bring. I don't want to talk to, I'll talk to your IT guy. I'm going to talk to him for about five minutes. I'm going to shoot him out of the room. And then I'm to talk to your control system engineer and your ICS guys and your, your, your, your, you know, your operators. Cause that's where I really understand how the system works.

Aaron Crow (81:13.452): and which devices are critical and which devices, they go down, break the stuff. Because they know. They know which system don't touch, don't breathe on, don't reboot it. Or as soon as there's an issue, they run over to that machine because they know that's the thing that went down. Or they're looking at that, yep, that port went down again. Let's go jiggle that cable because it'll come back online when we jiggle that cable.

Gavin Dilworth (81:36.014): Yep, yes, I've definitely seen that. There's been a few times where you've done an assessment and the operator or lead, a guy that's been there for ages, electrician, control system engineer, you're opening up panels and he's like, don't touch that. I was like, why's that? he's like, well, I'll use a pen, I'm safe, I know how to do cable tracing. He goes, no, no, I know. goes, that thing's temperamental. If you just lightly tap it, it drops the entire rack.

Gavin Dilworth (82:5.326): and then the process has an upset. know, okay. So, you know, that critical stuff, they just know how the plant and where the pain points are and you can get a lot of value when you do those assessments for sure out of that. yeah, bringing it.

Aaron Crow (82:20.016): All right. So, so last question and see if it's the same in, in, in over in your neck of the woods, in my neck of the woods, especially in power plants and things, when I'm running new things, we don't get in the cable tray. We just add new cables on top. don't remove any of the existing stuff. We just rewire on top of it. So there's 40, 50, 60, 70 years worth of dead end of life cables that are just sitting there for the exact reason you just said, because they're afraid if I touch anything, it's going to break things that they have no idea where it goes.

Gavin Dilworth (82:48.942): Yes, yeah, no, there's definitely elements of that to be sure. There's even just like the old server is right next to the new server and the old server is right next to the old server and we've got this. And it's like just in case we lose something, we can go back to the old system. yeah, you just sit there and go, what system is this? And then like DOS, and it's like, wow, we've got a DOS machine.

Aaron Crow (83:7.300): That guy's still there.

Gavin Dilworth (83:18.232): So you go on the, yeah, yeah. And you're like, okay, well on the plus side, hackers probably don't know how to write exploit code for it anymore. So here's that.

Aaron Crow (83:18.414): It's still fires up. We fired up once a year.

Aaron Crow (83:26.604): Exactly. Exactly. All right, man. So how, how do people get ahold of you? Call the action. Anything you want people to know how to reach out to you? All the good stuff.

Gavin Dilworth (83:38.318): Yeah, obviously like I said, is Gavin Doerff. I work in New Zealand, although I do consulting globally and you can reach me at Assessment Plus or on LinkedIn. So yeah, just hit me up if you have any questions on OT cybersecurity. I'm more than happy to help.

Aaron Crow (83:55.920): Awesome. Hey man, this was an awesome conversation. I think we could have talked for another couple of hours, like we said in the beginning, maybe we'll do a round two of this in the future and dive into some more. So, but I really appreciate you reaching out. I appreciate you taking time today and, you know, kind of sharing your message with the crowd here. And, you know, the whole point, and I think I see it in so many individuals like you and I is that,

Gavin Dilworth (84:2.151): Yep.

Aaron Crow (84:19.642): We just wanna get the message out there. We wanna help. If you don't choose me, I do consulting, you do consulting, technically we're competitors. I don't see us that way. There's plenty of fish in the sea. If I can help you, if you can help me, if I can help people on that, that's the reason I do this podcast. It's the reason I speak at conferences and I'm always willing to answer questions, whether I'm your customer or your vendor or whatever, I don't care. I want to better the world than when I came into it.

Aaron Crow (84:47.832): And anything I could do to help that, that's what I want to do.

Gavin Dilworth (84:51.698): I feel the same, And thank you for having me. It's been a blast and there probably will be a 2.0. So look forward to that.

Aaron Crow (84:58.724): That's right. All right, man. Well, have a good one, and I appreciate your time.

Gavin Dilworth (85:4.792): Thank you.

Aaron Crow (85:5.658): Later, man.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.