Ep 71: Lessons From 34 Years in OT Cybersecurity: Growth, Challenges, and Leading Change with Scott Rosenberger | PrOTect IT All
HomeEpisodes › Episode 71
Episode 71
Episode 71 Interview

Lessons From 34 Years in OT Cybersecurity: Growth, Challenges, and Leading Change with Scott Rosenberger

Aug 25, 2025 00:55:32 with Scott Rosenberger
OT SecurityCritical InfrastructureRisk ManagementNetwork SecurityLeadership

Watch This Episode

In this episode, host Aaron Crow sits down with longtime friend and colleague Scott Rosenberger, the cybersecurity leader for Vistra Corporation’s generation fleet. Together, they take a deep dive into Scott’s fascinating journey from an engineering background in nuclear power to overseeing cybersecurity across a sprawling, nationwide utility portfolio.

You’ll hear insightful stories from the early days of OT cybersecurity - before most of today’s tools even existed - and how foundational principles like alignment, engagement, and standardization have driven years of progress. 

Scott and Aaron reflect on the importance of building cross-disciplinary teams, developing strong communication strategies, and embracing the reality that real security is about continuous improvement, collaboration, and sometimes learning from mistakes.

From tales of rolling out firewalls at power plants and negotiating with skeptical vendors, to lessons in leadership, trust-building, and the ever-evolving challenges of protecting critical infrastructure, this episode is packed with practical wisdom, industry anecdotes, and a look at what’s coming over the cybersecurity horizon. Whether you’re just entering the field or a seasoned pro, grab your headphones - you won’t want to miss this candid, insightful conversation.

Key Moments: 

04:37 Bridging IT and Cybersecurity

08:40 Revolutionizing Program Development Together

10:08 Building Consensus Through Communication

12:33 "Business Insights and NERC SIP Evolution"

17:18 Utility's Major Implementation Challenge

20:08 Corporate Cybersecurity Challenges Uncovered

21:58 "Automated Inventory and Cybersecurity Insight"

27:21 Optimizing Cybersecurity and Metrics

30:56 Essential Infrastructure Basics Lacking

34:17 "Identifying and Resolving Hidden Issues"

37:21 Encouraging Change in Industrial Practices

42:11 "Finding the Right Team Mindset"

46:11 "Importance of Pre-Job Briefs"

About the guest: 

Scott Rosenberger is currently the manager of Operational Technology for Luminant.  He developed the Luminant program to address the reliability, security and ongoing maintenance of Operational Technology for Luminant’s Fossil Generation Fleet.  He has a Bachelor of Engineering from Stevens Institute of Technology and is a registered professional Engineer in Texas.  In his 23+ years with Luminant he has worked in nuclear and fossil plants, many corporate roles and for 3 years as Director of IT Security and Compliance.  Scott also spent 3 years as a member of the NERC CIP drafting team.

Links to connect Scott: 

https://www.linkedin.com/in/scottrosenberger/

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

04:37Bridging IT and Cybersecurity
08:40Revolutionizing Program Development Together
10:08Building Consensus Through Communication
12:33Business Insights and NERC SIP Evolution
17:18Utility's Major Implementation Challenge
20:08Corporate Cybersecurity Challenges Uncovered
21:58Automated Inventory and Cybersecurity Insight
27:21Optimizing Cybersecurity and Metrics
30:56Essential Infrastructure Basics Lacking
34:17Identifying and Resolving Hidden Issues
37:21Encouraging Change in Industrial Practices
42:11Finding the Right Team Mindset
46:11Importance of Pre-Job Briefs
Read the full transcript

Aaron Crow (0:2.360): Thank you for joining me today on the protected all podcast. I'm super excited about this one. this man right here, I've known for a very long time. in fact, we were chatting this morning and I've actually known him. I think, I was working at the company that we met, and my son was about a year old when I started working there. So Scott is, we kind of joined in or kind of my path into OT cybersecurity was because of the work that we did together. So Scott, with all that to say, thank you for taking the time today and why don't you introduce yourself? Tell us who you are and a little bit about your back.

Scott Rosenberger (0:32.910): Well, thing, Aaron. Thanks very much for having me. My name is Scott Rosenberger and I work for Vistra Corporation and we are a competitive utility headquartered in Irving, Texas. My responsibility is around our generation fleet and I'm responsible for cybersecurity. We've got about 41,000 megawatts for nuclear plants and a whole bunch of fossil renewable plants. And so it's been an exciting opportunity.

Aaron Crow (0:58.560): And all that has grown since I was there because of acquisitions and things. Because when I was there, I think we had 40 something plants, one nuclear facility. And that and all of that was in the state of Texas. And now you're nationwide and have them all over the place, which is super awesome. The other thing I want to dig into is, you know, you when we met, both of us were new to O.T. cybersecurity. Obviously, I had a technology background. But talk a little bit, because a lot of folks are coming into this space and they're coming from different backgrounds.

Scott Rosenberger (1:14.350): I'm in the car.

Aaron Crow (1:28.514): They can make them from business and make them from engineering and make them from operations. Your background is exciting and different and interesting. So why don't you talk a little bit about because I know you started out in nuclear and you started out in as an engineer and all that kind of stuff. So share a little bit about how you got into the space and even into this world of O.T. cyber security.

Scott Rosenberger (1:46.552): Sure thing. Well, you know, it's interesting. I was just thinking about the past for a little while as we're getting ready to do this. And I grew up in the Northeast. And when I was picking a university, I chose Stevens Institute Technology in Hoboken, New Jersey. And one of the reasons was it was the first, and this is back in the day, The first university in the country to require the purchase of a personal computer as part of the curriculum.

Scott Rosenberger (2:14.016): In fact, I remember going to a university that I looked at and they the old punch card systems. So, I these things were still apparently in use. I've never used one, but they had one there. I was like, my gosh, look at this. I remember my dad talking about those. And so I left with a bachelor's of engineering in mechanical engineering. And the utility industry has been part of my family history. My uncle actually was a mechanical engineer and he worked at Shippingport for Duquesne Light, the first commercial nuclear power plant in the country.

Scott Rosenberger (2:43.656): And I worked for Stono-Wipster in Boston, an architect engineering firm. And they sent my wife and I, actually I got, I'm fortunate, I have one number to remember. I've been in Texas, I've been married and I've worked for the same company all for 34 years. So we got married and they shipped us off to Texas to go work at Comanche Peak as a result of Three Mile Island, getting operating nuclear plants became a lot harder, a lot more paperwork fell out. So I ended up starting there as a design engineer.

Scott Rosenberger (3:13.638): I then worked as a system engineer, spent about five years in nuclear. was very interesting, but different. I then moved over to the fossil space and worked at a gas plant, where I went from being one of many engineers working at a nuclear plant to being the plant engineer. And so that was the thing I was looking for. I wanted to be exposed to more things. I never wanted to be a specialist. I wanted to understand the big picture and see more things.

Aaron Crow (3:30.893): Mm-mm.

Scott Rosenberger (3:40.896): In my 34 years, I probably had 14 or 15 different jobs working for the company. Half of them or so were in engineering roles. We ended up moving into the corporate office. And so I had a lot of opportunities that got created as a result of that. I've always had a bent for technology. Back when Palm Pallets, Blackberries were a thing, all the executives had them and I had one. And then I was helping them figure out how to make them work.

Scott Rosenberger (4:8.798): And I find that the skill set of an engineer and what I find in cybersecurity feels very similar. The problem solving, the fact finding, the tool belt is different. I'm working with a different set of tools. So I had opportunities to learn about how technology works. And I think a key to that for myself was just asking questions. If I'm in a meeting and somebody says something I don't understand, I ask a question. It's like, we just can't gloss over that because I'll be lost in the future. I'm not improving.

Scott Rosenberger (4:38.958): So I'm pretty free to ask questions when I don't understand things, just to get context and understand how things operate. so I became a, this is back, we've gone through many company name changes, TXU, Energy Future Holdings, Vistra, Energy Vistra Corp. And I became a technology specialist. Actually, in fact, in the business, I was the only technology specialist. I was the liaison between our IT group.

Scott Rosenberger (5:8.430): and the business trying to help to translate some of the things that they said. This is back when IT would come in and the executives would say, I hear you talking, but you're talking in Greek. I don't understand a word that you're saying. And so I worked to try to help facilitate that. And then I do remember the day I ended up in an IT role. It was very odd. It's like, oh no, I'm one of them. But today I work in the technology services group.

Scott Rosenberger (5:37.326): completely focused on cybersecurity for our generation fleet, which our generation fleet, in my experience, it's a very good fit, both the nuclear side, the fossil side. So that part has been really good. So half of my career as an engineer and the other half in the technology world, I did spend a little bit of time as the director of IT security from the company perspective. So I got exposed to PCI and some of the retail things, but my heart is in the generation business.

Aaron Crow (6:6.636): Well, you know, that was funny. says, when, we first met Scott and I and, and my manager at the time sent me over, I think it was actually my manager's manager sent me over and said, Hey, I need you to go to our corporate headquarters. Cause I was not working at the corporate headquarters. I need you to meet this guy, Scott Rosenberger. And I didn't know why just he's on this floor and we met, I think we talked for, I don't know, 10 or 15 minutes. And I'm like, okay, well, nice to meet you. And I went on and I think like a week later, he's like, I had a one-on-one meeting with, with him, Chris.

Aaron Crow (6:34.062): And he's like, so I have a great opportunity for you. I'm like, okay. He goes, you're going to be working for Scott Rosa burger. Who's who's that? He's the guy you met a couple of weeks ago and you're going to be doing. I don't remember what it was called because I don't even think it was called OT at the time. It was like technology support for, you know, fossil generation. And I'm like, okay. And it's cause of my background. Obviously I had the skillset, but it was this new role and it was compliance and NERC SIP and, and I hadn't even been there that long, but, um, you know, it, it, turned into.

Aaron Crow (7:2.286): 10 years of us working together and doing really cool stuff from control system upgrades and segmentation and NERC SIP compliance and throwing in technology. And all of this was before most of the current tools that are out there, the OT specific tools, none of them existed. Like it's before Dragos, it's before Nozomi. None of those things even existed yet, much less were an option for us to use. And we were using all this new stuff. that...

Aaron Crow (7:30.474): It's been a passion of mine ever since then. It's because you and I in some of those rooms where sometimes we agreed and sometimes we would argue for an hour about it. But the cool thing and what I loved about you and what I respect about you and why I've always wanted to maintain our relationship. And obviously I've left since then, but in all of those times, it was just about the problem. You and I never had a personal problem, even when we disagreed. It was always just about the thing. We were talking about, like, you may see it from a different perspective than me.

Aaron Crow (8:0.033): and we would argue about the solution or the outcome, but it was never personal. was never an attack either direction. was, yes, we would get passionate because we're both opinionated and we have opinions around those things. But when we were done, it was done. It was never a, I'm mad at you or I dis, like it was always that. So I always enjoyed that because I knew that you would challenge me. I knew that you would push me.

Scott Rosenberger (8:15.971): Yeah.

Aaron Crow (8:25.074): And you wouldn't just say, Aaron said so, I guess that's good enough. You would always challenge anything I said or anyone for that matter. And that helped us be better. It pushed us to push the envelope. And it's why I think our solution, even back then in 2012, was so advanced because we were never, you you pushed us to be able to answer the questions that the C-suite was gonna ask instead of just saying, because Aaron's smart and you should just trust him.

Scott Rosenberger (8:51.842): Yeah, it was a great time. remember even just a little bit before that, I think my dipping my toes into the generation cybersecurity world was when we started going from purpose-built proprietary systems to common off the shelf, know, COTS systems with IP-based networks. And we realized we should put some firewalls in place to protect these things from our corporate network. And I spent years developing

Scott Rosenberger (9:19.264): We brought a company in to help us to develop what we call the standard security architecture, the SSA. And that was a boundary DMZ remote access zone. I was just starting down this path and really just starting to create the vision for what this would be like and really relied on this vendor to help us get started. And then I remember growing beyond them. wanted to standard architecture that they delivered across all of their.

Scott Rosenberger (9:47.182): companies that they supported and at a certain point it just didn't work for us any longer. And we had disagreements about the outcomes we were trying to drive to. And that was really when the program became ours and you were, I mean, instrumental in building that program from what it started out to be to what it's now become. you know, those days at old Navy Air Force building,

Aaron Crow (9:52.557): Right.

Scott Rosenberger (10:18.851): no windows in the environment at all, but we did a ton of great work there. And it's, mean, it's just continuing to progress as we were trying to build capabilities into the environments that didn't exist and bring structure. Before it was all the plants were just kind of doing their own things. Even corporately, we went through changes, as the market changed and it used to be, the individual plants kind of operated as islands and they did their own thing and money was

Scott Rosenberger (10:46.990): was given to the best storyteller. And then we started to realize that, we need to be a fleet and operate in this competitive environment differently. And the business changed and we started doing what's the best thing for the business, not the best thing for my site and my facility. But that was just a really interesting times. I think it was just about the time that we met, I was actually involved in the NERC SIP drafting team for version five. That actually maybe before that, because that started in 2008, I believe.

Scott Rosenberger (11:13.890): And that was a really interesting experience in my history. I think I learned a lot of different things. I'm fortunate, I think, in that I just have a vision for that kind of environment where multiple, and the drafting team works by, take each of the sections and different teams went off and started working on drafting those things. And I learned a lot of people wanted to just jump into, let's figure out what the words need to be. And I realized that,

Scott Rosenberger (11:42.702): I don't, we're using words, but I don't think those words mean the same thing to us. Let's say it longer. Let's get the concepts down that we're trying to accomplish, that we're trying to drive towards, and then figure out how to say those things. Because we found a lot of times we weren't agreeing on the words because they didn't mean the same things to us. And I have this just uncanny ability to find when we're using the same word to mean different things or different words to mean the same thing. So as we would review

Scott Rosenberger (12:12.078): the different sections of NERC-CIVP, we'd be like, think we're saying the same thing here differently. it also taught me a lot about, there's, we'll probably talk about Dale Higginbotham some more as we talk about our journey together. But he's always said all business is the people business. And I think I learned a lot about people and the process in the drafting team is about gaining consensus and the.

Aaron Crow (12:25.583): Mm-hmm.

Scott Rosenberger (12:41.646): the times you spend with people to gain agreement on things that then you bring back. And now when you say it, other people are agreeing that there's a momentum that gets carried forth with that. And at the time that I joined the NERC SIF drafting team, it was mostly T and D folks. And so I was there waving the flag for generation, saying that low impact should be low. It was a hard thing to... How do you...

Scott Rosenberger (13:7.374): argue against doing good things. It's like, hey, we can't have all these requirements on those. It'll take our focus off of the things that are really important because there's so many more low impact assets that are out there. And so that was a key element. And then the same thing for understanding as we were going from either your high impact or your nothing. Version 5 was all about everything should be done. Something should be done on everything, just various levels based on your impact.

Aaron Crow (13:31.576): Right.

Scott Rosenberger (13:38.030): And so there was the opportunity to figure out, where is that? And in our cut, used to be called spinning reserve. The megawatts that are available to pick up the load showed a unit trip. And we've got two nuclear plants in Texas. And so we have 23 now. I think it's like 2,500 megawatts of available spinning reserve. So I argued for hire, but we ended up at 1,500 megawatts to create that cutoff.

Scott Rosenberger (14:5.026): So that was a really great experience and I think helped set the stage because I've seen and I think this still exists today that where you have high compliance requirements, one, you can get into box checking activities, which is not good, which I think I've seen where back in the old program when you were either high impact or not at all, spent a of money, a lot of effort to protect one asset. A lot of it was

Aaron Crow (14:19.256): Yep.

Scott Rosenberger (14:34.638): check in the box, and some of it was for security, but no appetite to do anything else beyond that. So low impact, low effort has really created, set the stage for what we've done where we're doing the right thing from a cybersecurity perspective because our compliance obligations are aligned with the risk that a generator produces to the bulk electric system.

Aaron Crow (14:57.411): Yeah, real quick to go back on the, the, the Dale quote. say that all the time, like all businesses are people business. And, and, you know, I don't actually call him by name, but I say one of my mentors said this and I repeat it all the time. Cause it's so true. And it, you know, there there's a couple of things that I want to double click on there. And, and obviously all of your time in that NERC SIP space and how far it's calm. Like obviously we were supporting NERC SIP and I remember those, those early days when we were going to those plants and

Aaron Crow (15:26.319): we were showing up and we didn't have budget. Like, so we were having to take away budget from them to deploy this stuff, which meant they weren't doing, you know, bowler feed pump maintenance or, you know, something else. So we were taking 200, $300,000 away from this upcoming outage and bolt it. Like you can't, know, and I also remember, and I'm going to call them out by name because they've changed it since then. But at the time Foxboro, cause we were doing Foxboro control system upgrades and they had a secure

Aaron Crow (15:52.993): and an insecure control system upgrade project. And we're like, you can't choose the insecure version. I'm sorry. And they actually called it that. And like, well, how did you call it insecure? Like, no.

Scott Rosenberger (16:0.142): Do you remember that? That's Bonnie.

Scott Rosenberger (16:5.230): Yeah. That's funny.

Aaron Crow (16:8.227): But it was hugely, it was hugely, it was a struggle and it was my first obviously impact into, up until that my career, I had been super technical and hands-on and that was my world, right? And all the work that we did, and I talk about it all the time with the leadership circle and how much I hated the leadership circle at first, thought it was stupid and didn't wanna do it. And why am I reading books? I'm not in college anymore, like all of those things.

Aaron Crow (16:35.927): And now looking back, I'm so grateful for it, like that there's a reason why there's a bunch of books behind me. And and there's a reason why I've done other coaching and things like that since then, because I saw the value in those soft skills to your point and and Adele's point of, you know, all business of people business. And I have to sell like you also said earlier, the the the person who or the group or whatever that can sell their idea is the one that got the money. Right. So you had to be able to tell that story. And how many times you said like.

Aaron Crow (17:3.821): What is the story around this thing? Like, yes, Aaron, the technical design, you're right, that's it. But this, you know, Bob is not gonna understand this. We have to sell the story of why this is valuable. We have to build a PowerPoint deck. We have to have the story, the elevator pitch to be able to convince them of why our thing is important in terms that they understand. It doesn't make them feel stupid, but also you have to sell them that. And they're not looking at your architecture because they don't care about the tech. They want the outcome and the value, reducing the risk. And that story is what we had to sell.

Aaron Crow (17:33.677): that was the hard lessons I learned along that way is the technology, yes, I have to be good in that, but I also have to be good in these other things if I want to go and be able to sell these ideas and get to that next level, whether it's pushing the things that we really think need to happen or you want to take that next step and get into that next role, that what got you here won't get you there mindset, right?

Scott Rosenberger (17:53.378): So true. Yeah, it's interesting, know, Dale's retired from Vistra, but I get to see him pretty much every week. We go to church together and we were just having a conversation with him about how much I appreciated him developing these leadership circles and what a difference it made in my career from, you know, when I first started, I used to think that I need people to know how difficult, how complicated what I'm doing is. And that is like

Scott Rosenberger (18:20.910): the farthest from the truth. I got coached along the way. Simplify, simplify, make the story simple. And leadership circles really helped with crafting your message to your audience, to think about the words you're choosing. Engineers typically would put a PowerPoint presentation that's just words and then read it to you. And so I was like, I'm not sure why I need you.

Aaron Crow (18:41.303): line by line.

Scott Rosenberger (18:45.190): And so I learned a lot about thinking big picture and expanding my, what's the cost? And I can also even remember, another thing that was very influential is the very first time that I can remember making a recommendation that they said, you know, that's a good idea, we should do that. was like, hey, my fingerprints are on that. I suggested that. And that was so rewarding that influence is what I think of leadership is your ability to influence.

Scott Rosenberger (19:14.890): And in leadership over other people, you're expanding your ability to accomplish that. I'm getting more done because I'm not an individual contributor having to do it all myself. And that I think it's equally important that technology skills of being able to set up a good program and the leadership skills, especially in the roles that we're in, of being able to create a program and move it forward.

Scott Rosenberger (19:43.102): Without those, you just really struggle with helping people to understand what it is that you're wanting to do. And the leadership circles that we went through just did a ton of that, and thinking through PowerPoint presentations and story and the impact on the business and the things that you need to be thinking about when it comes to asking for money and how you tell that story. What's the storyline that you're going to take that is meaningful to that audience, which is different based on where you are.

Scott Rosenberger (20:12.583): in the organization, who you're talking to.

Aaron Crow (20:14.607): Yeah. Talking to the C-suite is different than talking to the plant manager. That's different than talking to the control system engineer. Right? Those are three different stories and you have to be able to sell them all. Um, and that was hugely impactful for me. You know, obviously I ended up leaving Vistra and went to work at Ernst and Young and doing this at, know, across multiple organizations. And that was the one thing I think, not the one thing, there was a lot of things that, and the skillset and the value that in the experiences that I had, but that was one of the things that stood out to me was, you know, this was a, it was at a large power utility,

Aaron Crow (20:44.217): probably the largest, think it's if not the largest, one of the largest in the country, especially at that time. And we were doing this massive, you know, three to five year across 3000 sites, like big implementation, you know, oil and gas and solar renewables and fossil fuels and nuclear, like all their entire fleet, right. And it was all approved by the board. They got the funding and then, you know, they kind of handed it to me and said, OK, design it and then go implement it. But then we spent the next nine months

Scott Rosenberger (20:48.963): Mm-hmm.

Aaron Crow (21:14.349): nine months to 12 months, obviously building the program and all that. But the other thing that we were doing is going to the business because the business was never part of the conversation when management said we're doing this. And then we went to the business and they're like, you're not doing that in my space. Like, no. So we had to convince them and make it be part of their idea and their solution. So they felt part of the team and not this is being done to me. We're doing this with you. Right. And that was

Scott Rosenberger (21:26.712): Yeah, we're here to help.

Aaron Crow (21:42.671): You know, I learned that the hard way with, with, with Kevin at, at Forney, right? When we took over Forney and Lamar and he had his way of doing things and we're trying to bring him in and he was completely against us at first and despised me, I think in the beginning. And now we're friends and, and, and still talk to this day, but it was that how do I, how do I win friends? How do I convince him that, Hey, Hey, we understand his problem and we're not going to try to make him.

Aaron Crow (22:6.645): make it worse, we're actually gonna make it better. And you talk to him now and he'd be like, that was the best thing we did and it was way easier than the way that I was doing it. I just didn't trust you. And once I started trusting you, then I was able to open my mind to actually see that the things you guys are doing can actually help me do the thing that we're doing in a better way.

Scott Rosenberger (22:23.290): Yeah, it's interesting. of the things, kind of a philosophy is trying to create an environment where people can say whatever they're thinking, right? Because sometimes I think in that situation, there was a misunderstanding that existed that you had to uncover, whether it was distrust or not understanding what your goals were or not understanding what you were even saying. A lot of times people are afraid to say, don't know what you're talking about. And so you have to kind of uncover that sometimes. I can remember going to plants and

Scott Rosenberger (22:52.288): And they didn't mean to lie. They just didn't think about things in the right perspective. So we had to end up asking questions from different angles. And we don't have any remote access. And then find out later that the vendors were voting in. It's like, I thought, how is that happening? OK, so you do. And these are things that we knew existed. We just had to figure out the right questions to ask to get them to respond. And this gets back to terminology. You might say control system or DCS. And different people have different views of what that is. DCS, that was just.

Scott Rosenberger (23:21.570): just this, my boiler control system, it's my turbine control system. And a lot of different views on that. using the right words and having to uncover that.

Aaron Crow (23:31.547): And that brings back memories of one of your famous sayings of, you don't have that except for where you do.

Scott Rosenberger (23:33.742): Thanks a lot.

Scott Rosenberger (23:37.998): Right. Yeah.

Aaron Crow (23:39.939): And we would find that all the time. We would walk in, I don't have remote access, but what about those dial-up modems that are over there? well, that's just for my third party stuff. And that's just the vendor getting in so they can control it. So are they here? No, they're in Georgia. So that would be remote access.

Scott Rosenberger (23:54.028): Yeah, right. And that's actually won over the kind of the origin for me of where that came from. I can remember filling out a survey. I was actually in the in our corporate offices and it was really about the corporate environment and it was a kind of an assessment of your cybersecurity posture and ask questions like, do you use antivirus? Well, yes, except for where we don't. that realization that

Scott Rosenberger (24:19.998): That's where it matters, right? People are gonna ask you what good things you're doing and people want to tell you. My own team oftentimes wants to try to reduce, they're getting much, much better at this. But when we first started out, wanted to reduce scope so they could say they were successful. And that was, in my view, just a skewed view of what success is. Success isn't just accomplishing something, success is knowing what the status is. And if I got some stuff done,

Scott Rosenberger (24:46.690): There's usually good reasons why I didn't get those other things done. Technology's too old. Plant said no. know, whatever those reasons are. But the story is, know, scope is 100%. What did we actually get done? Don't change the scope so you can say I got 100%, which is really 70%. And that, for where we don't, has been a mantra for me for years and years and years of like, I'm trying to uncover that we're good, except for where we're not. And that's what I want to know. Where is that? Because I can't fix problems that we don't know.

Aaron Crow (25:2.809): Right.

Scott Rosenberger (25:17.048): So I thought.

Aaron Crow (25:17.197): Well, and if you look at the attacks that happen, you look at target, you look at a lot of these things that happen, it's, those it's never, you know, when target got hit, you know, it was not target front end. was some third party contractor that had a VPN in the back door and everything up here was fine except where it wasn't. And that's how they got in. Right.

Scott Rosenberger (25:31.554): Yeah. Correct.

Scott Rosenberger (25:37.070): Yeah, so that 100 % is like part of when we think about metrics, you know, this is another challenge is we are working really hard to make sure that we understand what the scope is. It gets back to, just the basics of knowing your inventory, right? If you don't know what you have, how do you protect it? And so as we are building out the capabilities for automated inventory collection, I'm always asking the team, what's our out of band validation that the data that we're collecting is all the data that we need?

Scott Rosenberger (26:6.974): So you might talk to a person who's at the plant and say, well, how many Windows servers do you actually have there? one, two, three, four, like out of band verification that I think there's 47. That's interesting, we only have 42 in the inventory. So where are those other ones that are missing? Because that's the ones where you have to be able to measure. Because we're really driving toward, I'm not going say automation, the automated collective inventory of configuration. that our goals today are to

Scott Rosenberger (26:36.428): be taking a cybersecurity framework, which is a great basis for these are all the things you should do. But cybersecurity frameworks are outcome-based. Achieve this outcome. And it's like, OK, great. What does that mean for me? What am I doing to achieve that outcome? And what can I measure to say if I'm doing that? When we first started with metrics, I think it was a challenge because people would think about what information do I have, but not what information do I need.

Scott Rosenberger (27:4.782): How do I know that I'm good? And you got this smattering of data, data points, and it's like, hmm, we need to think. So when I think about metrics, we've talked about health. Are all the things that I need running? Scope, like we think about antivirus. Is it installed everywhere that it could be installed, that it should be installed? So scope is an important one. Life cycle, are we maintaining the assets? Is the software being updated? Is the hardware current, those kinds of life cycle would be?

Scott Rosenberger (27:32.982): Are the licenses, are we paying for all the licenses that we're actually using and not overpaying or underpaying? Health scope lifecycle, critical configuration, that's a really big one in my mind. So when I think about our firewall, creating perimeter security, what about that firewall is important? Things like at least privileges, justifications, threat enabled on all rules, wildfire, well, potpourl.

Scott Rosenberger (28:1.179): antivirus enabled on all rules and things like that. I can remember back before we started measuring this, I would tell you, yes, we use multifactor authentication for all remote users until we measured it and found out there were four users that didn't have it turned on. And so that ability to identify what good looks like for you, for me, and then how can I go measure that? So you again have a big picture view of what does good look like.

Scott Rosenberger (28:29.314): not, well, here's the data points that I have. Scoping and then a piece of that.

Aaron Crow (28:33.101): Well, yeah, yeah. And the big piece with that, and it really also comes to the culture of the place, right? So one of the big things and obviously to power utility and at you know, Vistar for sure, it was we had this culture of having a questioning attitude. You and I talked about this all the time. We told our team, I want you to have a questioning attitude. When you go into these meetings, you need to be asking. Don't assume that they know what they're talking about. Ask those questions, right? And we also had the mindset of

Aaron Crow (29:2.049): It's okay to make mistakes. I'd rather you find the mistake and fix it than cover it up. Or like you said, change the scope so it looks better on paper. That's not what we want. Like we want to find the problems. We want to find the misconfigurations. Those are good things. I'd rather you find them and say, we missed one, then pretend it didn't happen. And, and, you know, I know we had a couple of incidents where we had people do things remotely and they didn't, they didn't call the plant and make a change.

Aaron Crow (29:30.031): And they rebooted a system in a control room, which is a no-no. And we told them those things, but it's way better to know that you did it say, crap, and then pick up the phone and call the operator and say, hey, I did that. That way they don't think there's something going on with their system and trip the unit because there's an issue, right?

Scott Rosenberger (29:45.870): or a remote until workstation and blank their screen out. Those are bad things. Right, bad days. Yeah.

Aaron Crow (29:51.400): They are very bad things. So what are some of the, you mentioned a few of them. Obviously it's been a long time and you've been continuing to grow this, which is it's amazing to see. And you and I've talked about it offline, but you know, share a little bit that you're comfortable with of some of the things that you guys are focusing on. and, kind of the, the, what is the next level? Like how do you continue to progress this? And it, and I know anybody that's listening, you're never done.

Aaron Crow (30:18.531): Right? When Scott talked about when he first did this, he just rolled out firewalls at power plants. And I remember him and I going to all these power plants and every plant, almost every plant manager would be like, well, we already have a firewall, so we're good, right? We don't need anything else. And we had to really unveil the, okay, this is never done. You're constantly going to have to be enhancing and improving and all these types of things. But I also remember when we pitched this in the beginning, it was,

Aaron Crow (30:46.371): we were not pitching security. We were more pitching A, compliance, but B, operational reliability and availability. Like that was the thing that the plant managers cared about. So going back to the, do you pitch this and sell this? You know, that was the conversation we had, because nobody cares about cyber. They care about the outcome. Nobody wants a firewall. They want the security, right? It's so, yeah. Yeah. So how are y'all doing it today? And what is your focus?

Scott Rosenberger (31:3.854): He's doing insurance policy that I hope I never get.

Aaron Crow (31:10.583): And like, what is that messaging now? Like I'm guessing it's probably a little bit better because they're used to hearing those things now as opposed to back then. They didn't even know what a firewall was.

Scott Rosenberger (31:19.800): Well, it's funny, as I think through this, I have the perspective that we're just doing what really is basic cybersecurity hygiene, right? Just the basics at our power plants. But really doing it, that is the goal, right? To be able to just understand what assets do I have? Have I applied the right protections? To be able to look at what are the risks that we're facing and do we have the right things in? know, that except for...

Scott Rosenberger (31:46.584): where we're not is probably my biggest thing. We end this call at the end with that. That's my biggest concern of us not knowing something that's not good. Yes, not knowing something that's not good, double negative, but I think that's correct. We want to know that it's good. So, I mean, a lot of this is about being able to collect the information from the assets. I'm looking for cybersecurity drift. I want to set a posture that says this is risk balanced.

Scott Rosenberger (32:14.230): We allow remote access because the business requires it. It'd be great to not do that, but the business requires it. So we have to facilitate that. So we're looking to lease privilege on that access, MFA on all of the remote access, recorded sessions. What are the things we can put in place? What's my cybersecurity posture that we want to have in place? And then to monitor that over time. the automation of inventory, collection of the data that we need.

Scott Rosenberger (32:40.622): to produce metrics, which we've been working on for quite some time. And it's a lift, for sure, to be able to ask yourself, what does good look like, and how can I measure that? One of the great things about the generation business is that it's incredibly diverse. think there's not any two plants that are identical. They get built from all kinds of different systems. So we've got a lot of diversity. So that is great from an atomic perspective.

Scott Rosenberger (33:6.830): I have a special view around making sure that nothing that we've introduced is creating additional risk into the environment where we don't put all our eggs into one basket. There's no centralized things across these facilities. They're like separate companies, little mini separate companies that we're trying to interact with. So we maintain that level of security. So a ton of effort is going into it. And we started...

Scott Rosenberger (33:32.032): I think what I just say with the basics, right? We just talked about what are the long poles in the tent related to cybersecurity that we need? Remote access, secure file transfer, multi-factor authentication, antivirus, identity management, just the backups and recovery, just the basic things. And we started, let's build out metrics, let's build out processes around those. Now we're going back and, hey, let's use, we chose the SCF, framework.

Scott Rosenberger (33:58.290): as a model to let's build our program based on that and just driving good hygiene into processes and coming with fleet processes, recurring tasks, those types of activities, procedure-based work. So we can do, like I said, it feels like just the basics, but there's a lot of effort into being able to say that we know that we're going to be talking about dragos in the environment.

Scott Rosenberger (34:28.431): I think when we, I put together a multi-year program starting in 2019 that were in continuing to roll out and started with NERC-ZIP low impacts. There's a compliance aspect of this. Let's get the physical security plans in place that are required. We put brand new firewalls in the environment, centrally managed those, got rid of tons of.

Scott Rosenberger (34:55.648): existing rules that had just made their way over time. Some of our acquisitions, thousands of rules that we got rid of and really driving towards least privilege, made sure we understand why those rules existed, justified all of them. So we knew exactly what business purpose they were facilitating. And that's another challenge, right? Many times you get to a business justification, it's like, just says what the rule does. It's like, don't need that to tell me that I can read the configuration and know that. Why are we doing that is the question. And so we, a lot of effort into facilitating that.

Aaron Crow (35:19.629): That's right.

Scott Rosenberger (35:24.908): And then we realized that we had very little visibility as to what is actually happening. And are we okay? Is anything bad happening? We didn't have the ability to answer that. we deployed Dragos and we've spent a lot of time working very closely with them. And I'm just excited about some of the stuff that we're doing there to be able to look at our environment and know that we're okay, that bad things that they know about. I'd say, my vision on that is to...

Scott Rosenberger (35:51.778): take their intelligence that they're looking at the threats to our sector, specifically industrial controls about threat actors and what they're doing. And not only, my comment is that today, Dragos for us is looking to the right of boom, right? Has anything bad happened? I want to get to the left of boom, right? What are the things that I can do to protect that? Cybersecurity posture drift is one of those.

Aaron Crow (36:12.963): Right, right.

Scott Rosenberger (36:20.172): But so taking that posture that I have, combining it with their intelligence and saying, is my configuration vulnerable due to these new threats that haven't happened, but hey, threat actors are not doing this thing that you actually allow in your environment. And I should take an action against that to prevent something bad from happening. So I'm excited about where that's headed and the views that we'll get to that.

Aaron Crow (36:45.911): Yeah. And you talk about how doing the basics and I talk about that a lot as well. And in, in OT and especially in critical infrastructure and power generation, but in a lot of different verticals with this, sometimes most of the time, almost all of the time, those basics are the most important thing, right? How many people have an accurate asset inventory? Is it ever a hundred percent? Probably no. but are you, are you closer to that? I mean, I walk into places and it's

Aaron Crow (37:14.831): 10%, it's 0%. They have no idea what's in their environment, right? They 100 % lean and trust on their vendor to provide all that. I don't know, go ask the control vendor, right? I have no idea. The operations folks know how to fix things and they know where the things are, but they don't understand the risks in the environment. I can't remember how many times we had a triple five system or some system that's sitting on the corner. Don't touch it. Don't look at it, don't open the cabinet.

Aaron Crow (37:43.395): just leave it alone because if it breaks, don't know how to fix it and we'll have to bring the unit down, right? It was that kind of thing. And in the beginning, was, we had to just kind of work around those things. But as we started building that trust, we were able to say, hey, you know, all the cybersecurity stuff that we're doing and the firewalls and all the things, those are great. But if this one system is so temperamental and sensitive that you can't touch it with that, or even open the door without potentially tripping a unit, that's a problem. look.

Scott Rosenberger (38:6.190): We'll

Aaron Crow (38:10.307): how can we fix those things and starting to ask those questions and make people look at it a little bit differently? Like, hey, this should be something we should be looking at beyond the cybersecurity perspective, the reliability of the unit. Cause at the end of the day, you work for a power company. Those power plants are the asset. They are the critical thing that produces revenue that makes, it's why you have a job. It's why everybody, it's why my lights turn on. And remembering that, cause I know you coming from IT and many times these other companies as well, these IT companies,

Aaron Crow (38:39.883): organizations will have a much larger budget than the OT side. And to me, it's always boggled my mind how that can be when the OT side is the thing that drives the business. It's the thing that drives the revenue. You know, back in the day when I, when, we worked together, I think we had what's, think I had a team of six people and the IT team had hundreds.

Scott Rosenberger (39:3.438): Mm-hmm.

Aaron Crow (39:3.523): You know, they had entire teams for servers and entire teams for networking, entire teams for firewall application teams, you know, all those types of things. And we had six guys that did everything from, end to end from firewalls down to, you know, VMware and everything in between and all the way down to the layer, the, networking layer. So it's just always been funny to me or not funny, but you know, we, we don't want to belittle the fact or, or, or, or light the fact that the things that you're doing, they sound basic.

Aaron Crow (39:32.591): I'm doing air quotes if you're just listening, but they are hugely impactful. And the thing that can make the difference between having a secure and understanding where your environment is, you're never gonna have a secure environment. You're never done, but you're gonna have a better understanding of where the risks are. How do I put that protective shell around the things that I can't patch or I can't update? I wanna disable Telnet, I wanna disable.

Aaron Crow (39:55.459): you know, RDP to this XP machine that's in the corner that I can't touch, but I need to protect it somehow. So where are those dangerous things and how do we protect around those things with other controls that I may do differently than I would do in an IT?

Scott Rosenberger (40:7.500): Yeah, for sure. I'm very blessed that we have a great team, very talented folks that have put things together that are helping to build this program and maintain it. So we've got people that support power plants and the trust that they've built with those plants is instrumental to our ability to continue to move forward. A central team that just the technology skills that they have to be able to pull these things together has just been

Scott Rosenberger (40:37.590): hugely beneficial and you I think Just just the You know, I'd mentioned something like was gonna was gonna comment on a camera what it was at the moment You might take that part out but

Scott Rosenberger (40:59.692): Golly. It was good too.

Aaron Crow (41:4.550): Was it talking about the, um, let's see. I don't remember what we were saying either now. I've marked it though, so we can cut this part out.

Scott Rosenberger (41:18.357): How can I jump back into this?

Aaron Crow (41:22.009): So where is, so we're doing all the basic things. You're doing the blocking and tackling, you're figuring out the assets, you're figuring out the things where you're not. So you mentioned, you know, whether it's antivirus or screw mode access or whatever, and finding those places that you're not, you're trying to be able to have metrics. And that's another thing I know you were pushing for in the beginning and we just didn't have. Like we started building the piping and the framework around being able to get the data. But even back then, I remember

Aaron Crow (41:51.725): We were such a small team and we were doing so much implementation and deployment. We didn't have time to actually look at the, Hey, what did all the stuff we just turned on? What did we find? Like some of the times I remember the very first we were at a Martin Lake and we were, we had just turned on all the monitoring and things. And like within five minutes, there was a system that was just blinking and having a problem. And it was a Cisco switch and it was a redundant pair.

Aaron Crow (42:17.601): and they didn't know it, but one of the pair was bad and it was down and nobody knew it. And it was just sitting there screaming. And we went, we went over to it and there was a zip tie. And I tell the story a lot, but you'll, you'll remember this. There was a zip tie in the fan in the back of the power supply. So we went and removed the zip tie. It, the fan started speeding up. The temperature came down and the switch spun back up again. So they had redundancy designed into their system.

Aaron Crow (42:43.887): but they had a false sense of security because they thought it was redundant, but they didn't realize that one of the systems was down because nobody was monitoring and watching it. And that gets back to what you're talking about is how do I know where my good is and how do I measure this, make sure that this is my standard, this is my baseline and my criteria and measure against the 100%, not just the 70 % where I have antivirus installed and ignore the 30 % that it's not.

Scott Rosenberger (43:9.708): Right. I think it's a lot of it you're talking about there is like operationally impacting elements that are technology based. And that's a big piece of what we're trying to accomplish as well, whether it's through the collection of logs from systems or performance data from systems. You commented on your plants being in a degraded state. They just don't know it. They need that second failure. And then they find out, I was in a degraded state. Now I'm offline.

Scott Rosenberger (43:36.206): to what anything that we can do to tell them to create awareness for redundancy that has an issue, a memory leak on a machine, a machine is rebooting over and over and over again that they're either maybe not knowing or not knowing what to do about. That's another possibility. Same thing, think, with looking, using monitoring tools to, and this has both a cybersecurity and an operational aspect of behaviors of systems.

Scott Rosenberger (44:5.066): in the environment of things like I should have DC syncs occurring in my domain. And if they stop, that's a problem waiting to happen. Things like our vulnerability scanners talking to the assets. It's supposed to run on a frequency. It's supposed to include X number of assets. And if something changes, we want to know about that. So there's both aspects of the health and

Scott Rosenberger (44:32.792): capability of the things that we're trying to accomplish, as well as the plant systems themselves, and anything we can do to provide information on things that will impact operations or security is going to be a benefit. And so we're really looking for those opportunities to do that as well. And sometimes we're waiting for technology to catch pace with us. But that definitely is something that we target.

Aaron Crow (44:57.443): Are you finding that your business owners, so the plant managers and the control system engineers, as well as technology and the executives that you're speaking with, are they more understanding and open to doing things different? Because again, I know back when we were doing this in the beginning, was, well, we've never had an impact in 40 years. This has been the way that we've always done it. I don't want to do it a different way. Or the control vendors were pushing back. I know we had to really push on.

Aaron Crow (45:26.031): all of the vendors, Foxboro, Emerson, GE, Schneider, like all of those guys would say, well, this is how we do it. And the same thing you mentioned with the SSA architecture. like, well, we want to do it this way because we support all of our customers. And we finally got to a place where we're pushing on all of our vendors and saying, I don't care. This is our site. We're the ones that are stuck with it. And we're going to do it to fit ours because we don't want to have 37 different antivirus solutions and 27 different, you know, patching solutions. want to be able to support this.

Aaron Crow (45:54.445): with a small team. And so we have to be able to figure out a way to pull this stuff together. And we, that's why we forced GE and Emerson and Schneider and Foxboro to all do it on our tech stack. And they just had their VMs running in our space. They didn't like it at first, but it was like, well, there's no reason we couldn't do this. We're just not going to buy your hundred thousand dollar data, data, excuse me, domain controller, because it's just a domain controller. I don't need you. I don't need a, you know, Emerson or Foxboro badged.

Aaron Crow (46:23.661): Domain controller. I'll just spin it up for you and you can put your GPOs on it. We'll be good.

Scott Rosenberger (46:29.378): Yeah, in fact, you mentioned a couple of things there just to talk through. One is working with the vendors, right? I think that has been a really important thing because these vendors now all have cybersecurity teams, right? And so there's an avenue into, and think about their situation. They have to be able to create a solution that if I don't have anything and I want something, they can sell it to me. As well as, you know, we really need the flexibility of

Scott Rosenberger (46:56.684): you're coming into our cybersecurity program. We've seen that a lot in the renewable space where much of the renewable stuff prior to it getting to utility scale was in really small implementations and they had to come up with models including cloud-based models. And we're not doing that. I don't care if that's the way you want to do it. That doesn't fit into our security model and we're mining a lot of it. So please let's work together to get that changed.

Scott Rosenberger (47:23.404): And we had a couple of road bumps in the very beginning of that, but that we've had a lot of really good success with including the cybersecurity requirements element as part of, that's really an important piece, because now it's part of the contract of we have written a set of requirements for how we're going to do business, including preferred solutions as part of that. Because I mean, there are some times where the solution we prefer is one that's

Scott Rosenberger (47:49.496): For some reason, not doable. so there's flexibility that has to occur. But we are trying to drive towards standardization. One of the other things that you talked about was around inventory and folks sometimes not knowing. Most of the main control system vendors have methods of collecting data about their systems. I think that the challenge that you find, I think, at a power plant is that's really good. Same thing with they have for services to patch.

Aaron Crow (48:18.287): Mm-hmm.

Scott Rosenberger (48:18.382): That's great if that was just the whole thing. It's just not the whole thing, right? Typically, oftentimes there are multiple controls vendors, sometimes up to three, turbine controls, boiler controls, and at a combined cycle, sometimes there's a steam turbine that has a different controls vendor on it. And then you have ancillary components that are part of a water plant or other components of conveyor systems in a coal plant.

Aaron Crow (48:33.913): Mm-hmm.

Scott Rosenberger (48:45.874): that were bought with the equipment that it's managing. oftentimes there's not a purview over all of that. So that's where I think we've helped to think about, I can remember the back of we used to try to, had to come up with terminology so that we could talk to plants. Getting back to, I said, you'd tell somebody DCS and they would think, that's my other system. It's like a plant control, anything at your site that has something to do with.

Scott Rosenberger (49:15.416): controlling megawatts or making megawatts is something we want to be thinking about. How is it going to be protected? And so our processes have been really thinking about holistically pulling that information in, which I think for a generation plant, unless you have one control system that does everything, which for us has been incredibly rare, I don't even think it exists. It's that bringing together of that disparate data.

Scott Rosenberger (49:45.047): to get the bigger picture.

Aaron Crow (49:48.419): How hard has it been? I know the other problem that we had, and again, this was probably back from the beginning, because again, OT, the term didn't even exist. But I know a lot of the problems that we had, not problems, but difficulties that we had as we're building out our team, or we're having those conversations, whether it's people, hiring the right people and finding people that had the skillsets that you're looking for. And we were successful in that. We had some that didn't work out great, and we had some really awesome ones that we trained and came up. And many of them had...

Aaron Crow (50:17.127): zero experience in OT or never been to a power plant before and all that type of stuff. But we found a way to train people and to your point before, I know we talked about all business of people business, but that leadership side of this is also finding people that fit in with your team. They may not have the exact technical skillset, but if they have the right questioning attitude, they have the right mindset for troubleshooting and just an understanding of technology,

Aaron Crow (50:44.931): we can teach them the rest, right? And, you know, look at, you know, some of the operators or, you know, plant engineers that we brought on that had zero real technology background, that's super intelligent, super capable, but they had that wow factor that we didn't have, and that was the trust from the plant. So when we took Danny with us to Martin Lake, they let us in the door, whereas, you know, I remember at Big Brown, we ordered them pizza and they wouldn't even let us eat in the break room, right? They made us eat out in the electronics room and the rest of the team ate in there.

Aaron Crow (51:14.369): an absolute outsider until they needed us. And that's a whole nother story, but you know, it's, it's that, you know, finding the right team that can fit in this space. And some of them may come from IT or whatever, but how has that gotten better or how has that been as far as finding the right resources for your team as it's grown?

Scott Rosenberger (51:32.280): Well, resources finding people is, I think, always going to be difficult. And oftentimes, you're not finding the perfect person with the perfect background. But we've had great success. I think we've built a very skilled team that, especially the folks that are supporting our plans directly, there's just a ton of trust that's been developed. And I think it has to do with the perspective that I don't have some objective.

Scott Rosenberger (52:1.560): to do something that's driven by somebody else to you, right? We're really trying to help you. We want to help you in whatever way we can help you, right? If it's operational information, I think you had asked that perspective also about the leadership's perspective and about cybersecurity. And I would say, generally speaking, I think everyone believes that there is risk that we need to protect. They just look at their own personal lives and you start seeing, you know, I'm...

Scott Rosenberger (52:31.456): always trying to help people think about a password manager. Think about some of the really bad practices that people in their own personal lives without exposure, they'll use the same password over and over again and it's a bad password and not use multifactor authentication when it's available. And just the step that using a password manager in their personal life is like, I just want to help you to be secure because bad stuff is happening. I people are seeing that there's truth in that.

Scott Rosenberger (53:0.342): And so we have, I think, good support to do. We have always had the approach that operations is what's important. We don't want to impact operations either. It's all of our bottom lines that's impacted if we cause a problem. So we want to be really careful about that. And we've had some road bumps along the way, and we've learned lessons from that, which is what we need to do, and have put processes in place that

Scott Rosenberger (53:28.074): ensure effective communication, you know, so that people, it's like, I tell people, like, there are times when we're doing something kind of in the periphery, like, we might be on your street or even doing something in your front yard. But there are, when we're working the control system, like we're in your living room in your kitchen, and we don't just walk into people's kitchens and just start, you know, taking the sink apart, right? We like, hey, this is now a good time, should we come back later? And so those kinds of conversations occur.

Scott Rosenberger (53:57.890): Because that trust is critical. mean, we looked at the possibility of outsourcing. We've had contractors that have worked for us. In our environment, badge colors are different based on contractor. It never mattered what color your badge was. It is your perspective and understanding of what the impact that you're going to have on the system and how you communicate and how you understand what's going to happen and what could happen and what we're doing to protect that.

Aaron Crow (54:10.755): Mm-hmm.

Scott Rosenberger (54:25.838): That part has been really good. have people from many diverse backgrounds, people from IT backgrounds. We've got INZ techs that are on the team. so that part has been people without, well, I guess they've always had at least typically an IT background. But we've been able to train them in our processes. And you talked about without saying it, but HPI, the questioning attitude, three-way communication, there's a ton of

Scott Rosenberger (54:54.904): create tools which the business uses specifically around safety to ensure, or not guess it, and nuclear uses a lot as well, not just around safety but in operations, phonetic alphabet to ensure that we're communicating effectively. And I think as people come up to speed in those tools that are available and understands that unlike what you might see in an IT data center, like you said earlier,

Scott Rosenberger (55:23.096): We don't just reboot computers, right? Especially not remotely, but even when you're in their house, you ask permission and you think, it okay if I take whatever action?

Aaron Crow (55:36.615): And that's been big, know, no matter where I've been, and especially in Power and Generation, you know, we're doing pre-job briefs. We're talking about the work before we're doing it. We're making sure everybody knows, you know, obviously we don't always necessarily need like a lock-out, tag-out environment, but we're still having those conversations because we just never know where we may impact things, right? So we're really cautious about, to your point, I remember that conversation and us telling that to myself and the rest of the team as well as like,

Aaron Crow (56:4.047): You don't just walk into somebody's house and open up their fridge and sit down on their table and eat their, you know, their take me to their turkey dinner. Like who are you? Why are you in my living room and why are you eating my food and why are your feet on my desk or my table? Right. That that's a, that'll get you shot in Texas. Uh, yeah. So, um, yeah, it's, it's, it's been, it's been an amazing things to see. Obviously I saw it at Vistra and I've had the benefit to be able to see it at other, other industries and, but especially across power.

Aaron Crow (56:32.077): and how similar it is, right? And how it's the same, no matter what the company is, it's very similar. I still think that Vistray is, and I'm sure I'm just biased because I was there at the beginning, but I definitely think that you guys are very far advanced in the space, even though you're doing basic things. I think a lot of people are not doing those. And I'm proud to say, know, sign my name on that thing from way back when and excited to see you're still there and pushing the envelope forward.

Aaron Crow (56:59.405): That's that's what we want is we want to push this industry forward because I want my lights to work when I turn the light switch on, right? I still live in Texas and are caught. So this is it's important to me.

Scott Rosenberger (57:9.934): I mean, our experience together, the decade you were here, I mean, that was the foundational times in moving this thing forward. know, a couple of things I think that I use these words all the time. In fact, I have team members that have made me a plaque and then other 3D printed things with these words on it, because it's, I look back at my years of experience and this is the thing that I'm driving towards, alignment, engagement.

Scott Rosenberger (57:38.286): and standardization in our environment, or multiple plants. It's easy for a person to walk into an environment and say, oh, I think we should do it this way. And I think we should do it this way. we have a procedure in two different implementations. like, in the world, that happened. And alignment, I think I've talked a little bit about that with the drafting team. But even in team meetings, I'm always looking for feedback loops that ask, hey, we're talking about this topic. Are we saying the same thing? Are we aligned? These are just the three.

Scott Rosenberger (58:7.906): moniker words that I use all the time, which drives a lot of what we are trying to accomplish.

Aaron Crow (58:13.773): Yeah, that's awesome. That those are all good things. So last question and then I'll get to the wrap up. But if you were obviously you've had a great team, you've had you've had all this experience over these years in this space. I have a lot of people that are coming to me and ask, you know, they're looking to get in the industry. Maybe they're looking maybe they're in IT and they want to get into OT or maybe they're still in college. Like what are some of the things that you would focus on if you were at the beginning of your career trying to get into OT?

Aaron Crow (58:41.588): And what are the right things, some of the things that they could be looking at focusing on to either earn that skill set or find that first job that could get them into this exciting space of OT cybersecurity.

Scott Rosenberger (58:55.768): Yeah, that's a great question. You know, I think when I look at people coming in, I think you have tools in your tool belt, right? So you have skills and abilities thinking about networking or working with servers or Linux or applications. Networking is a key, right? I think everybody needs to understand how just some basic networking. But your ability to build technical skills are a start at how

Scott Rosenberger (59:27.407): how you, I think, could enter into this environment. There are things about industrial controls that are unique. I mean, if you have that experience, that's awesome. But if you don't, we can certainly teach and expose you to those things and those processes. some core, as you just said, questioning attitude. Somebody that takes everything at face value and believes everything that is presented to them, it's going to be really problematic because not everything you see

Scott Rosenberger (59:54.542): That doesn't really make sense. I'm not sure if that's true. Think about systems. I think about generation might be a little bit unique in that we have a ton of dual-homed systems, right? So when you look at your network, you see all of these IP addresses. And you're just like, hey, we've got thousands of that. It's like we've got less than that, right? And you have to have a questioning attitude about that. You just can't believe that we have 14,000 IP addresses or whatever the number is.

Scott Rosenberger (60:25.155): and realize when it makes sense and when it doesn't make sense. So there's an aspect of that that I think that's a hard thing to be, I'm not sure if you can learn that, right? Maybe you can unlearn it, but a lot of people just have it innately. But a basis of technical skills and understanding how things work, when I think about how I made the transition, I had to shift from like, what does a firewall do? What are the capabilities that a firewall has?

Scott Rosenberger (60:52.472): How can I use those things? I'm not a hands-on configure the firewall expert, but I have a lot of good concepts. So if you're starting an industry, you might need to be like, get a home network. Go buy some technology. Do some virtualization. Learn the concepts and some of the technical capabilities. There's a lot of resources that I don't know what the thing is. You could probably figure out, get some support from Google on how to accomplish a technical task.

Scott Rosenberger (61:20.962): But putting that stuff all together is going to be an important piece to that.

Aaron Crow (61:26.371): Yeah, hundred percent, man. That that's awesome. Thank you for that. So last question, and, I appreciate your time here today. Next five to 10 years. What's something, one thing you see come up over the horizon. That's exciting. good, positive, whatever, whatever spin you want to say on that. And maybe the other side is what's one thing that could be concerning that if we, really need to get in front of before it become an issue.

Scott Rosenberger (61:49.570): Well, I'm sure a lot of people would say this, and I see that you've had it on your podcast. You think about what the impact of AI is going to be in the world, right? And in our industry, I'm always challenged by, we live in a pretty exact environment, And hallucinations from an AI world or actions that are taken by it, I'm interested in how can we gain

Scott Rosenberger (62:19.212): value from that, but still maintain management over the risk of things there as well. I think that could be on both sides. As you heard me say, my focus is on except for where we're not and trying to get into that because it's that Swiss cheese model of all those little things that we're not doing. I hadn't really mentioned this when we were talking, but as we start thinking about risk management, we're looking at like patching. There's a lot of systems that

Scott Rosenberger (62:47.534): that are out there and lot of vulnerabilities that might exist, but I'm looking at those ones that are accessible, those ones that can be used against me. And something buried in my network without a pathway out is less risk to me. with the resources that we have, we want to focus on the things that are most important. know, certainly a very skilled adversary, zero days getting into the environment, just think about some of the things that have happened in history of effects that have been undertaken by a nation.

Scott Rosenberger (63:17.122): That's a concern. We've never had a grid-wide blackout. We've had brownouts, but never a blackout. And the recovery of that, it's, while we practice it, it's never happened. And my concern is that could be really impactful to the world. That's what gives me purpose and why I'm doing what I'm doing. As you've mentioned, you live in Texas. I want to protect our way of life, the things that we...

Scott Rosenberger (63:45.026): we expect because this electricity is key just as other critical infrastructures are to making that stuff keep keeping things working.

Aaron Crow (63:54.795): Absolutely, that's awesome. Thank you man. It's it's been a pleasure. I appreciate you coming on. It's it's been nostalgic for me. You know again, I really look back at my time and at Vistra and appreciate all the things. And again, I know we had our disagreements and all the things all the way, but it was always just about the work and and I think that was one of things that we connected on the whole time is we were both passionate about and we both want to get to the same place. We may have a different idea of how we get there, but the end goal was always the same for us, which.

Aaron Crow (64:23.681): is why I think we connected and we were able to work through those differentiating, know, the differing opinions or the approaches because at the end of the day, we both wanted the same outcome and we're both passionate about it. We both had our ideas and things, but that was always true for both of us from my perspective. So, yeah.

Scott Rosenberger (64:38.776): We ended up in a great place. I think a lot of great work was done. And as time flew by, it was great to think back to some of the places that we've been a lot of good times.

Aaron Crow (64:47.151): Yep. Yep. Yeah, I might. My youngest was one when I started working there and I and my my or my oldest was one and my youngest was born and conceived in that time period. Not to be gross, but in that time period of that outage year. So, you know, when we went to the doctor, we're like, well, it had to have been this weekend or it wasn't me as a joke, obviously. But, you know, because that was the only time I saw my wife in about two months on either side.

Scott Rosenberger (65:16.462): That's crazy. Yeah, I was back then, and I did a lot of times at plants.

Aaron Crow (65:19.917): Yeah, we were six to nine months on the road in Foxboro doing FATs and in Colorado doing FATs and then side acceptance tests and then outage for three months doing, you know, the control system upgrades and all the things. So it was a lot of fun and a lot of good work. But, you know, I learned so much during that time. It was like drinking from a fire hose. But, you know, it was, it was amazing. And you can't, you can't buy that experience. There's no course, there's no college degree. You can go and get that amount of experience in that short amount of time anywhere. So it was, it's priceless. So.

Aaron Crow (65:49.771): I appreciate it. Had a great time with it and always look back positively for that. So well, thanks, Scott. I appreciate it,

Scott Rosenberger (65:54.894): It was great. I? Yeah, take care.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.