Ep 83: Inside Cyber Incident Response: Military Lessons, OT Challenges & the Power of Blameless Culture | PrOTect IT All
HomeEpisodes › Episode 83
Episode 83
Episode 83 Interview

Inside Cyber Incident Response: Military Lessons, OT Challenges & the Power of Blameless Culture

Dec 1, 2025 00:55:20 with Daniel Swann
OT SecurityAIIncident ResponseRansomwareLeadership

Watch This Episode

Cyber incidents don’t just test your technology - they test your people, your processes, and your culture.

In this episode of Protect It All, host Aaron Crow sits down with Daniel Swann, Cyber Incident Commander at Rockwell Automation, to pull back the curtain on what really happens during IT and OT incidents. With decades of experience across the U.S. Air Force, enterprise environments, and industrial operations, Daniel shares lessons learned the hard way - from managing chaos in real time to building a culture where teams can learn without blame.

You’ll learn:

Whether you’re developing your first IR playbook or leading seasoned response teams, this episode delivers actionable, real-world insights that help you prepare, respond, and recover with confidence.

Tune in for battle-tested wisdom from military operations to industrial control rooms - only on Protect It All.

Key Moments: 

00:00 "Protect IT/OT Cybersecurity Podcast"

03:30 Cybersecurity: Versatility Is Key

07:52 "Balancing Bureaucracy and Flexibility"

10:20 "Practice Makes Plans Effective"

14:17 "Learning While Doing"

18:44 "Document Key Info in Incidents"

19:46 "Versatile Team Role Importance"

22:45 "Tracking Lessons with Visibility"

28:34 Proactive Reporting Encouraged

29:33 Safe Reporting Prevents Phishing Incidents

32:52 "Bridging IT and OT Safely"

37:15 Team Collaboration Enhances Outcomes

41:00 Military Preparedness and Logistics Planning

42:59 Preparing for Unlikely Scenarios

47:20 AI Threats to OT Systems

48:32 "AI's Impact on Learning and Jobs"

About the guest: 

Daniel Swann is a seasoned Cyber Incident Commander at Rockwell Automation, bringing 17+ years of IT leadership and nearly a decade of cybersecurity experience. A U.S. Air Force veteran, he has led global cyber operations, responded to major vulnerabilities like Log4J, and driven large-scale improvements in incident response and vulnerability management. Daniel is highly certified, mission-driven, and recognized for building strong, resilient security teams.

Links : 

Video of Daniel Swann with Kate Vajda, Director of Vulnerability Research and Malware Threat Research, Dragos : https://www.youtube.com/watch?v=4zotgrPk8vI

Connect with Daniel on LinkedIn : https://www.linkedin.com/in/j-daniel-swann/

Connect With Aaron Crow:

Learn more about PrOTect IT All:

To be a guest or suggest a guest/episode, please email us at [email protected]

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

00:00Protect IT/OT Cybersecurity Podcast
03:30Cybersecurity: Versatility Is Key
07:52Balancing Bureaucracy and Flexibility
10:20Practice Makes Plans Effective
14:17Learning While Doing
18:44Document Key Info in Incidents
19:46Versatile Team Role Importance
22:45Tracking Lessons with Visibility
28:34Proactive Reporting Encouraged
29:33Safe Reporting Prevents Phishing Incidents
32:52Bridging IT and OT Safely
37:15Team Collaboration Enhances Outcomes
41:00Military Preparedness and Logistics Planning
42:59Preparing for Unlikely Scenarios
47:20AI Threats to OT Systems
48:32AI's Impact on Learning and Jobs
Read the full transcript

Aaron Crow (0:0.944): Thank you for listening to another episode of the protected all podcast. Uh, I, I, again, I say this all the time, but I'm extremely thankful that, that you guys listen and that I have, uh, people that are willing to come and share their experiences, their background, their knowledge in this space, because I think as a community, we're all better by, by, know, sharing the lessons learned, the experiences, the trouble, the heartache, all the things that we've experienced over the years.

Aaron Crow (0:25.272): And we all have different stories and experiences. So with that, Daniel, why don't you introduce yourself to the audience? Let us know who you are a little bit about your background and whatever you want to share in that space.

Daniel Swann (0:35.318): Awesome. Thanks for having me, Aaron. So my name's Daniel Swan. I am the cyber incident commander at Rockwell Automation. So previous to that, when I joined the company in 2021, I worked in the product security instance response team. So I've kind of seen both sides of the coin now as far as enterprise IT and product security. So going back even further, so I've always been interested in computers. It's kind of a thing when I was a teenager.

Daniel Swann (1:5.006): And so, you know, I went to college and then did about a year at a bank and decided to join the Air Force. So I served in the Air Force, active duty for 15 and a half years. I'm still in the reserves and getting close to 20 next month. So, yeah.

Aaron Crow (1:22.672): Very cool. That's awesome. Thank you, man. That's a really cool accomplishment.

Daniel Swann (1:26.796): Yeah, thanks. So yeah, I'm looking forward to talking to everybody today. I've had some great experiences in the Air Force and then since I've been at Rockwell. And yeah, just talk about kind of why I'm here and what I look to do every day when I come to work.

Aaron Crow (1:41.294): You know, it's, it's, it's always interesting to me to hear and see whether it be people that I've hired, people that have worked for me, peers, even my own journey. you know, similar to you in that I started out in IT. I started out in technology. You know, I was interested in it as a kid. I'm probably a little older than you, but that's okay. but you know, I've been doing this a long time and all of those IT experiences have brought.

Aaron Crow (2:8.984): valuable insights into the space, you know, because technology is technology, a switch is a switch, a router is a router, know, antivirus is antivirus. Maybe I implement it differently. Maybe my process around it is different, but it's still, I need to understand routing and networking and subnetting and all of those different types of things to really be able to troubleshoot and understand. So how have you seen both, and you've even got some different experiences. from obviously IT.

Daniel Swann (2:12.280): Yeah.

Aaron Crow (2:36.228): government and working in the Air Force as well as in the OT space. Now that you're at Rockwell, how are things different? then also the follow-up to that is how are they similar and where do you see similarities across all of them as well?

Daniel Swann (2:50.702): Yeah, I think one of the things that you kind of touched on there was it's a sum of the whole experience, right? So I really do think that to be really, really good and effective at cybersecurity and, you know, OT security, you got to know a little bit about everything because I think day to day in my role, especially, I never know what I'm going to get or what I'm going to see, you know, so it's the four scum thing, you know, box of chocolates, you never know what you're going to get. It's the same thing in cybersecurity and the sense of response, especially.

Aaron Crow (3:12.868): Yep. Yep.

Daniel Swann (3:18.658): But I think as far as the comparisons between the two, I think that with the military and the Air Force specifically, my service there, there was a lot of bureaucracy that you'd have to go through to get things done. But once you got them done, it was great and you had great resources. So once you got the approval, it was go forth and conquer. And so that was always interesting to me. I had some great experiences.

Aaron Crow (3:34.992): Sure. Yep.

Daniel Swann (3:48.266): doing kind of deployable communications. That was fun because you're just kind of on your own doing your thing and getting everything taken care of. And so that's obviously pretty high IP heavy. I started my career doing satellite communications and then became a cyberspace officer after that. So I got to kind of see the backside of things as far as the transport goes and then look at more of the details of what's happening over those wires that are sending packets.

Daniel Swann (4:15.926): And then with Rockwell, it's a great company as far as collaboration goes. There's no dumb ideas. are a few times in the Air Force where I brought up something and it was like, that's great, you know, Lieutenant, but we're going to do something else, which is fine. You know, that's, that's how it rolls sometimes. But generally in Rockwell, if I bring something up, I'm going to get some, I'm going to get an audience and they're going to listen to me. And then even if we don't move forward, at least I've kind of gotten that, that, that audience. And I've been able to do some great things here.

Aaron Crow (4:32.515): Sure.

Daniel Swann (4:45.990): and just moving the ball forward for maturing things. So, so I think as far as comparing the two more bureaucracy with the air force, you know, she got to get through, but once you're through your well resource and, know, go move and the Rockwell, you always get an audience. And then after that, you know, you can move forward and kind of, and conquer. So.

Aaron Crow (5:5.496): Yeah, that's a great space to be in and talking about the, you know, the experiences from, you know, working on the, the satellite or the transportation layer of that, you know, it, it, it, it aligns with, you know, as I'm training in the past, I being training people to come in and, know, how to troubleshoot things and, you know, kind of giving feedback and guidance and training, et cetera. But it's always like, you know, I think I've said that three times this week on podcasts, but you know, you always start troubleshooting at the lowest layer of the OSI model. Like.

Daniel Swann (5:32.790): Yes, yes, yes, yeah.

Aaron Crow (5:34.148): You don't troubleshoot the application layer. If you're not, is it plugged in? You know, is the freaking cable plugged in? Like I'm not troubleshooting IP before I make sure the cable's physically plugged in. And it's so, yeah.

Daniel Swann (5:43.436): Yeah. And even when you're doing, when you're doing SATCOM, it's like, SATIC communications, sorry. your, your everything's layer one for the most part. So, you know, that was the best learning opportunity I got was the troubleshooting because you would have a whole loop of signal right from here to here. And if it didn't get from here to here, you had to go to each point test point, you know, put your spectrum analyzer up there. Is the signal getting through? If it's not, you go down here. Is it getting through? If not, you go down here.

Aaron Crow (5:51.162): Right.

Aaron Crow (6:11.524): Yep. Sure.

Daniel Swann (6:12.846): So I think it's really applicable to process control as well, know, in OT and if you got serial connections and stuff like that, you just got to start from here to here and then keep going down until you find the problem. So, so yeah, I agree. You you kind of get that like lowest level possible half split method as they called it, you know, you just kind of go from A to Z and then from Z to Y and then all down until you get to your problem. So it was really great experience.

Aaron Crow (6:36.772): But it was, yeah, it was so funny though. I would have people and they would really want to start at the, at the application or at the top or top layer. And, and I really had to beat it into their head because you're wasting time up there. Like you need to make sure the bottom layers are working. You know, is it physically getting there? Yeah. Packets getting there. Okay. Is it, is it routing? Okay. Yeah. It's doing that and work your way up instead of the opposite way. Cause the other way you could luck out and it could be in the application layer and yeah, you got there fast, but

Daniel Swann (6:48.461): Yeah.

Aaron Crow (7:5.132): In my experience, especially in OT, most of the time it's down the lower layers. Anyways, it's a fricking cable got unplugged or rat, you know, bit through a freaking fiber optic cable or something like that. You're testing the freaking firewall rule and the firewall isn't even plugged into the dang switch. So exactly.

Daniel Swann (7:12.471): Yeah.

Daniel Swann (7:20.940): Yeah, exactly. Yeah. You're like, why is my HMI not working? I'm going to troubleshoot my HMI. And then you go look and it's, you know, it's your switches even plugged in ethernet. It's not connected. And then it's.

Aaron Crow (7:28.460): Exactly. Exactly. You know, it's also funny on the, when you mentioned that the level of rigor and, the, you know, the, the bureaucracy or the paperwork and the, and the, know, the kind of minutia that it takes to get something done in the military, it's very similar in, in, you know, nuclear environments, working in nuclear power plant, things like that. There's a lot of places like that. What do you think? How do you feel about that process? Because, you know, I've been on the opposite side, you know, in extreme

Aaron Crow (7:56.933): you know, swinging the pendulum the opposite direction where there is no policies and procedures and it's the wild West. And the bad thing about that is that they don't do anything repeatedly. They don't have any consistent process or procedure. And then it's just like, well, did you do this? Well, yeah, I did it three months ago, but I haven't done it since. So how do you, I'm sure you've probably seen both sides of that coin as well. What are your feelings on extremely over process and, and, and extremely under process and where in the pendulum do you like?

Daniel Swann (8:1.102): Mm-hmm.

Daniel Swann (8:7.373): Yeah.

Daniel Swann (8:20.236): Right.

Daniel Swann (8:24.706): Yeah, I think the biggest thing to do in any instance, is to document what you're currently doing. If you don't have anything documented, then you don't really know how your organization is working. So even if you are very immature and you're like, hey, we have a spreadsheet or we're information that needs to be done. I mean, at least you know what you're doing, right? And where everything is, if you have a bad day, you've to go retrieve information.

Daniel Swann (8:54.414): So, so I think that, uh, you can definitely be over or you can be under, but, and I think there's, there's other people in the industry that have said this, but everybody's on a journey. Um, whether you're just getting started with your security journey for your organization or you're super mature and you have, you know, mountains of policies like the government would have, right. Uh, there's still things that you can improve and, um,

Daniel Swann (9:22.998): So I don't really have, I think for me, it's anytime we're gonna go somewhere new, I'm gonna check the situation out. Like what do you have documented? Are things documented? If you don't, let's go through the engineers and go through what, how are you doing things on a day to day or your network security folks or whoever, right? Let's get that on paper to see how you're doing things day to day. And then once we've got that, then we can go from there and actually talk about how we can improve what we've got. So.

Daniel Swann (9:50.834): whether it takes budget, manpower, or just training knowledge, right? That's one of things you can do. So think that's one thing the government does well generally is documentation. Now keeping it updated for any organization can be tough, especially as complex as our government is, but things are documented well. There's a good process for most things. And so if you're just starting, get what you're doing documented so that you can build off of that.

Aaron Crow (10:1.584): Yep.

Aaron Crow (10:20.037): Yeah, that's absolutely true. And having that documentation, at least something you can pull off the shelf. think that next step, and I assume, well, from the interactions I've had, think that military does this pretty well and most government agencies do, but it's actual practicing those things. So whether it be a practice exercise, a tabletop exercise, something like that is actually taking that procedure off the shelf.

Daniel Swann (10:37.719): Yeah.

Aaron Crow (10:44.473): And running through it in, a, a, in a non-volatile environment where I'm, going through the motions of does this process work? It worked great when I wrote it on paper, but let's actually practice this and say, does that make sense? And is this process realistic, at least in a, in a practice scenario? that's kind of the next thing that I see a lot of organizations struggle as they build this documentation.

Daniel Swann (10:54.115): Mm-hmm.

Aaron Crow (11:9.499): but they don't necessarily take it that next step. And maybe one person did it in his mind and his or her mind, and they built, they put it on paper, but they've never actually practiced it. not everybody, not all the players even know their role in that thing until they pull it out and start reading it. And like, wow, that's the first time I've heard of that. Okay, let me go try that.

Daniel Swann (11:21.421): Yeah.

Daniel Swann (11:27.822): Yeah, I spent a lot of time, obvious as an instant commander, doing tabletops for the different organizations and businesses within our company. And that's one thing that the military did well, exercises. One of the units I was a part of, it was a very team focused organization. So you would get there, you would get assigned to a team with your, you know, that was maintenance. So you had your maintenance, your operators and all that stuff, right?

Daniel Swann (11:56.096): And then you would go through the entire training course together, and then you would go do two exercises and then you would deploy. So you knew exactly what you were supposed to be doing with your training. And then you practice it for your first exercise. put your lessons learned in there and how you can improve it the next time. And then you do your second exercise and you're to have less lessons learned. And then you would do your mission for real and deploy, you know? So it's kind of like this, the cycle where.

Daniel Swann (12:23.758): you're building it out. And I see it the same way in a company, just like Rockwell. We have our plan, right, that we've written, obviously like any company. And then we have a tabletop simulator that we use right now, software that we can use to create new scenarios. That's the thing too, you don't wanna just do the same scenario over and over again. And then you wanna baseline that though to your instance response plan.

Daniel Swann (12:49.376): And then one of the things people don't do sometimes is they'll just create it, throw it in a closet, and then it just sits there, or a file. So you actually want to look at that and update it annually. Because things change quickly in our industry. And even annually or when a major instance happens and you have things you can take back to improve it. Because you're always going to learn something.

Aaron Crow (12:59.686): Yeah.

Aaron Crow (13:10.031): Well, yeah, I was about to say like that. That's the biggest piece, the biggest nugget, I think, after doing these for so long, I agree with you. Every time you do one, you should learn something. Cause if you're not, you're just going through the motions. Like the whole point of doing these exercises is you should get more efficient. You should find things wrong or ineffective or inefficient in your procedure, in your policy, in your process. And you should be constantly improving that thing and saying, Hey,

Daniel Swann (13:23.171): Yeah.

Aaron Crow (13:37.209): If we, if we change step one and step two, or we add a buffer or we, we add a person or whatever that, that process looks like is she constantly being better. Like the analogy always give, and we, you, we see this all the time in corporate America. We have, we have, you know, we go through, you know, fire, fire tests, right? We, the fire alarm goes off, the fake one goes off. Hey, we're going to have a fire test on a Friday and we go through the motions. We, we exit the building. We know where the muster point is. You know, we have the team, you know, the floor wardens and we're making sure everybody's clear.

Daniel Swann (13:42.338): Yeah.

Daniel Swann (13:54.690): Yeah.

Aaron Crow (14:6.853): We do this all the time. And why do we do that? It's because we don't want the first time that we're going through this process is when there's an actual fire. Cause then people panic, they don't know what to do. Then people get hurt. Then people get left behind. Like that's the type of thing. It's the same thing in cybersecurity. It's the same thing in what these tabletops are supposed to be. It's supposed to be you going through this enough and you frequently enough that when the at when something really happens,

Daniel Swann (14:14.818): Yeah.

Daniel Swann (14:29.357): Yeah.

Aaron Crow (14:32.197): Hey, I remember we've done this multiple times in a training scenario. You should think, yeah, this is my next step or I've done this before. It shouldn't be the first time you've ever done it.

Daniel Swann (14:36.579): Yeah.

Daniel Swann (14:43.394): Yeah, I think the other thing too is important that I try to do is even during an event, right? Where you're doing it for real. You always want to try to leave at least a little space to learn and capture. Cause I always capture stuff as we go after actions. Cause I don't want to wait till the end of it and look back and go, what was that that we felt like we needed to do to prevent this in the future? You know, I don't remember, right? Cause it's been, you know, however long and

Daniel Swann (15:9.804): Life's crazy and you're working until 11 o'clock at night to try to get things done. so I always try to leave a little bit of room to learn, you know, so if we have newer, newer folks on the team that we can bring in, you know, level ones, level twos, I've never seen something before. Hey, come on, you know, you can observe and because the tabletops are good and those are useful and definitely needed, but the best learning is doing it for real. Right. Unfortunately, unfortunately, right. You know, you're.

Aaron Crow (15:10.129): chaotic.

Aaron Crow (15:13.925): Yup.

Aaron Crow (15:35.281): 100%. Yep.

Daniel Swann (15:38.830): how that goes for people. And so I've been in this role long enough to where, you know, I'm very well-practiced with simulations and right with things that happen, right? So I think it's super important to leave room for growth through and improvement in learning during an actual event. If you have the ability, sometimes it may be something where you don't have the ability because of whatever reasons can happen, right? But always try to leave that if possible.

Aaron Crow (16:5.423): Yeah. I mean, I just got back from a incident response in, in the UK and you know, same thing. We're there for nine days, working odd hours, nights and, during the day and long shifts and, know, working with different teammates and members and, and, contractors. And it was just chaotic in so many ways. And to your point, like the first day or two, we didn't capture as some of the things that we wanted to. And then we're trying to.

Daniel Swann (16:25.432): Yeah.

Aaron Crow (16:34.225): you know, sit down as a group is like, Hey, what were those things that we thought we needed to make sure we remembered? And luckily as a collective, we remembered them. But then we started going forward, kind of collecting those things as we went at the end of the day, at the end of our shift or whatever. Because to your point, like again, you never, sometimes you don't know how long these things are going to go again. We were there for nine days. Um, again, different time zone. We were working different hours, odd shifts in different places that we've never been before.

Daniel Swann (16:52.652): Yeah. Yeah.

Daniel Swann (16:57.944): Yeah.

Aaron Crow (17:0.997): Like all of these things are crazy. So there has to be some kind of rigor that, that you put into this to kind of capture those things. Cause some of those nuggets are, are, are priceless. They're there. They can be the difference in, you know, making sure you close the loop and that doesn't happen again. And crap, we forgot about XYZ and now it's happened again. We didn't mention it to anybody and we should have.

Daniel Swann (17:11.597): Yeah.

Daniel Swann (17:23.096): Yeah, you never want to be in the midst of an incident and go, I feel like I've seen this before. And I feel like I was supposed to do something about this. And then when you do your, your after action to your CISO, you know, like in our case, it's like, he's going to be like, didn't we just like we did boss and we failed, right? And that's, that's situation nobody wants to be in. so that's why it's so important. And, know, during tabletops generally.

Aaron Crow (17:33.018): Right.

Aaron Crow (17:44.019): Yep, right.

Aaron Crow (17:47.953): Correct.

Daniel Swann (17:53.160): If they're facilitated at the executive level, things like that, generally you'll have a scribe that's assigned to just capture that stuff. Don't forget to do that during an incident. If you have the capability in the people to do it, right? Make sure someone is designated. Like you're the person, I need you to take the notes. Anything that we say.

Aaron Crow (18:0.209): Sure. Correct. Yeah. Yeah. Yeah.

Daniel Swann (18:12.450): We should change this, write that down. And then we'll discuss it in a formal after action post-mortem after, but during the midst of an incident, make sure someone is aware. Cause everybody else, for the most part, people are going to be jobbing out and nobody's going to think I should write this down. You know, some people may hear in there, but if you give someone the task, like, Hey, you are the person writing this stuff down, then you're going to be in a good place a week or nine days from then. Right.

Aaron Crow (18:14.117): Yep. Yeah.

Aaron Crow (18:27.729): Correct.

Aaron Crow (18:34.341): Yeah, I mean, that's a great, that yeah, absolutely. That's a great point. I think, you you, you practice, you play how you practice, right? How you do one thing is how you do all things. Right? So, you know, if you're going to have a scribe and, and, and your tabletop, you should absolutely have that. And that's a great, great example of, cause again, during that nine days, you know, the team was heads down, we were focused on the tasks that we were doing. weren't necessarily thinking about.

Daniel Swann (18:44.076): Yeah.

Daniel Swann (18:58.317): Yeah.

Aaron Crow (19:0.751): when it was going to end because we're, you know, we're putting out fires, like we're literally putting out fires and you're not necessarily thinking, well, that should be good to note for late. mean, you think it, but you're not slowing down because it's on fire, right? So you're trying to put the fire out. that's your, that's your priority, but that to your point though, if you have that designated person and maybe it's just a text message, maybe it's a team's chat, maybe it's a Slack channel, whatever your process is for that environment or for that, that incident.

Daniel Swann (19:4.504): Right.

Daniel Swann (19:14.210): Yeah. Yeah.

Daniel Swann (19:24.951): Right.

Aaron Crow (19:29.701): You know, some way to puff smoke and say, this should be remembered for later. Make sure that we take note of this. This is going on all that kind of stuff. Cause you know, there's, there's a lot of things that go on in those spaces in a very short amount of time. And there's a lot of valuable information that needs to get documented and it can't always be expected of every person. Remember every important thing and having that role that does it made a role and train your people on what to do and, and who that role is and what are the types of things that they should be.

Daniel Swann (19:53.389): Yeah.

Aaron Crow (19:56.357): you know, bringing up to the top that that's hugely powerful. That's that's a that's a great great addition to make sure. So as you're listening to this, make sure that you're thinking about that in your incident response plans, who's going to be that scribe in the in these when that incident does happen?

Daniel Swann (20:4.872): Yeah, absolutely.

Daniel Swann (20:11.150): Cause we all know that nobody can breathe until things are contained, right? I mean, that's, that's the facts of life until you get past the containment stage, nobody's breathing. So do that early right away and then make sure that person understands, you know, the importance of it. So, so you'll have that great information afterwards.

Aaron Crow (20:30.469): The great, the great thing about it. And we, we use that type of role in this as well as, is they don't have to be a super technical person. So it's not like you have to take a technical person off the bench to bring in. can literally be whomever that can take notes and, and is willing to show up and, and, and, you know, be, be part of the team, project managers, salespeople, you know, executives, managers, you know, any number of examples of scenarios of people that can be successful in that role.

Daniel Swann (20:37.985): Right.

Daniel Swann (20:54.136): Yeah.

Aaron Crow (20:58.521): It's just, need somebody that can fully focus on just that task, not the other things that they're doing to make sure that, you know, containment is done and the fires put out, et cetera. and they're working on that documentation. That's, that's a huge win. I, I think everybody should hear that. know I just said that, but everybody should hear that. It's a super important thing, especially as an extended, you know, incident happens. There's a lot of moving parts. can be 10, 20, 50, a hundred people, maybe even more.

Daniel Swann (21:15.127): Yeah.

Daniel Swann (21:25.304): Yeah.

Aaron Crow (21:26.659): at a large incident that could be and if you're not working to make sure that you're getting those nuggets from all those different people, you're going to lose things, things are going to slip through the cracks.

Daniel Swann (21:35.276): Yeah. Yeah. If you have an associate level person, an intern or rotational program person, like that's great for them because they're going to learn stuff and they're going to contribute something significant to the team. so, and that's kind of how I've done it as well. So at a rotational person and I attached him to everything that I could with the instance, you know, and he, was my eyes and ears when I was just head down into stuff. So it always works out great.

Aaron Crow (21:47.876): Absolutely.

Aaron Crow (22:3.547): So talk to me about, so we talked about that. Dude, I love that. That's a huge, a huge aha moment. What about after an incident? Let's talk about, you know, a big incident just happened. You just, know, stopped the bleeding. You know, everything's restored. Services are back up. You know, the team can now, you know, slow down. You're coming back together. What are those big important next steps to really make sure that you're?

Aaron Crow (22:28.655): capturing that stuff and documenting it and finding the ah-hahs. Like what are those big, big token items that you need to focus on during that timeframe?

Daniel Swann (22:35.437): Yeah.

Daniel Swann (22:38.498): I think one of the, one of the things that I try to do is a blameless post-mortem as they say, right? It's never constructive to blame the team or the person that, you know, unless it was, you know, complete, was malicious or like obvious, like they, bent to do it right outside of that though, blameless post-mortem. You don't want to assign the blame to a person.

Aaron Crow (22:55.887): Malicious or something, right? Yeah. Yeah.

Daniel Swann (23:7.502): you always want to try to assign it to a team, right? And it's not blame, but either way you want to assign those improvement tasks to a team because you know, it's generally not going to be on one person. It's generally going to be on the team. And even if it's not, it's their function, right? It's not the person. So I always try to start with that. And the second thing is you have to have a great way of tracking your, your lessons learned.

Daniel Swann (23:35.478): and a great way of tracking implementation and execution. Because a lot of people have, you know, a lot of times you'll have an instant, it ends, you're exhausted. Cool, we got our after action done, our blameless postmortem is done. And then the next thing we know, we're moving on to another one, because something happens again, right? If you're in a big...

Aaron Crow (23:53.583): Right. Yep.

Daniel Swann (23:56.054): You know, any business you're gonna, any big business you're gonna have that, right? So I think it's important to make sure that before you move into something else, you've got the lessons learned, you've got your notes, you've got your post-mortem report. Throw that into something where you can track it. That has visibility.

Daniel Swann (24:12.622): Throw it in your own, you know, JIRA instance or something like that where nobody else is visible. You can't assign to anybody, it's not helpful. But if you have a way to track that and give it visibility, you know that, because most of the time, you're the instance response team, you're not the person that's going to implement a new group policy change, right? That's going to fix something that you found during an investigation. So you need to be able to track it, assign it, and then maintain visibility until it's implemented.

Daniel Swann (24:41.294): So I think that's one of the things that's very important when you're talking about these lessons learned. They're precious resources that you have, that you learned out of this incident. So treat them well, like it's money, and make sure it gets invested well. So you don't just throw your money in the bank account and not track it. So same thing here. Track those things, make sure they get implemented.

Aaron Crow (24:50.939): Yeah. Yeah.

Aaron Crow (24:57.317): Yeah. Well, I also love the blameless part, you know, coming from OT, you know, it's very similar to our safety culture, right? So we, we most OT environments have a safety culture, safety zero, you know, stop when unsure, you know, they really pound it in your head. Yeah, absolutely. Right. They pound in your head. doesn't matter who it is. You can be the plant manager, can be the CEO. If they're doing something unsafe, tell them to stop.

Daniel Swann (25:9.143): Yeah.

Daniel Swann (25:15.596): Right. Knock it off. Yeah.

Aaron Crow (25:25.401): right? You know, and it's blameless, you know, self reporting, all that kind of stuff. It's not about getting any person in trouble. It's about I want you to go home the same way you came to work in a safe way with all of your fingers and toes and all the things. if I were if I give you a thing that says, Hey, you were working unsafe, it shouldn't be a punishment. It's not going to go in your your employment file that's going to be held against you come bonus time. You can't look at it that way. You want people to be able to self report and show up.

Daniel Swann (25:25.933): Yeah.

Daniel Swann (25:36.130): Yeah.

Daniel Swann (25:48.398): All right. Yeah.

Aaron Crow (25:55.407): Because if, if it's, if it's, punitive, then you're not going to report your friends. You're not going to report people that you like because you don't want it to go on there on the record. Then they're not going to like it. It's just, it's not a good environment. You're not building the environment to set up in the same way in these incidents. You don't want to be pointing a finger and say, Daniel, you messed up. It should be, how did our process fail? Daniel didn't fail. Like why, how could we make sure

Daniel Swann (26:15.501): Yeah.

Daniel Swann (26:18.028): Right.

Aaron Crow (26:21.349): That in, if this, if the same thing happened again, Daniel wouldn't have chosen or wouldn't have made the change, the same decisions and actions that he did, because I don't want it to be a Daniel problem. want it to be a process problem, a team problem, a leadership problem, because it all should roll uphill, not downhill. Like you don't want to point it at that, that bottom person that maybe clicked the button or open the valve or close the valve or did whatever the final, the straw that broke the camel's back. Because again, then nobody's going to want to share.

Daniel Swann (26:36.044): Yeah.

Daniel Swann (26:47.948): Yeah.

Aaron Crow (26:50.053): You're not going to have an open environment where people are going to feel comfortable to share the things that they saw because they're going to be afraid they're going to get in trouble or they're going to get their friend in trouble or, people are not going to like them. Like inherently that's not an environment that people are going to be open and willing to share information that you need in this scenario.

Daniel Swann (27:7.970): Yeah. And you have to build that into your culture. You know, you can't just do it when it, like when you're doing a post-mortem, like, just do it then. Yeah, we're not going to blame anybody. You got to build in your culture. It's got to be a front and center of how you communicate, how you take suggestions, criticisms, improvement, recommendations, whatever it is. If you're, if you're a leadership, then that organization. and like I said, that's how at Rockwell is, you know, there's always an audience. So, and I'm not going to.

Aaron Crow (27:15.077): Yeah. Yeah.

Daniel Swann (27:36.078): you know, get, get smashed if it's something that's dumb. it's just, okay, that's great, but it's probably not going to fit into where we're trying to move, you know, which is fine. Yeah. Yeah.

Aaron Crow (27:39.631): Right.

Aaron Crow (27:44.865): And that's okay. Yeah, that's fine. But you want people to feel comfortable to bring up an idea and, you know, not be like the little kid in the back of the room that thinks they don't want to raise their hand because they're afraid they may have may have a stupid question or the answer may be wrong. You want them to say the wrong answer because that makes it at least means that they're thinking it means least means that they're, they're bringing, they're trying to bring value again, maybe the thing that they're raising the hand about isn't going to help us today, but you want them to keep raising their hand. Cause you never know when one of those things that they raise their hand about

Daniel Swann (27:55.426): Yeah. Yeah.

Daniel Swann (28:12.536): Right.

Aaron Crow (28:14.573): It's going to be the light bulb that everybody needed. And if you beat them down by shut up, you're stupid. Then they're not going to raise their hand anymore.

Daniel Swann (28:22.358): Yeah, and aviation culture is really great at that. far as knock it off, anybody could say knock it off, you know.

Daniel Swann (28:29.566): there's a safety issue. I know in the Air Force, I'm not sure about, I don't know, civilian aviation, but in the Air Force especially, you know, it's always the option. in working in satellite communications, you had radiation hazards and stuff like that. So safety was always first with that and electricity, you know, walk out, tag out and everything. So it's super important to be direct when things like that happen, but not blaming.

Aaron Crow (28:59.001): I think that's a critical piece that most organizations are not considering when they're building out their policies and procedures and their incident response and all that kind of stuff. to double click on that, right, is if you don't have that culture, people are not going to share. They are not gonna be open. They are not gonna be forthcoming with information. They're gonna...

Aaron Crow (29:19.395): Maybe they're not going to hide information, but they're definitely not going to come come forward with it unless they're directly asked, right? It's going to be you're going to get a lot of stonewalling until you have information. But yeah, yeah, that's right. Right. You want them to be coming forward because they trust because you've shown and proven in the past that you're not going to, you know, come back on them. They trust that I can raise this and I can point this out and it's not going to get Bobby fired. It's just going to say, hey, let's fix the process so that Bobby

Daniel Swann (29:24.748): Yeah. Yeah.

Daniel Swann (29:37.312): Right.

Daniel Swann (29:45.389): Yeah.

Aaron Crow (29:48.453): that anybody in Bobby's situation wouldn't make that problem again, right? That's, and that, to your point, that goes, that takes time to build that culture. And if you don't have that culture, you need to start and there's no better time to start than now. You need to start building that culture because it's going to take that to be successful in one of these scenarios.

Daniel Swann (30:6.018): Yeah. And we've even had times where someone had realized they did something, you know, a click on official link or whatever. and then they reported it to us and, know, just, you know, not long after, right. And in that case, it's like, we won't first thing we tell them is thank you, you know, for actually.

Daniel Swann (30:24.942): You know, realizing what happened and then telling us about it. Even though we were already on the case, obviously with our tools and stuff, you still bringing it to us was important because that means you're owning it and you want it to be better next time. And so we kind of recognize that person for doing something great because that is great. If you're anybody in a plan or, you know, user on an IT environment, if you're reporting things that...

Daniel Swann (30:52.408): could lead to something not good, then you should be, you know, praised for that. Cause that is a courageous thing to do, just depending on, or wherever you are, right?

Aaron Crow (31:3.983): Yeah, absolutely. Well, and, and, know, sometimes you may report something that didn't get caught and nobody did see, and they weren't aware of. So, so you never know when you report that fishing incident that people are going to be like, that it's not an actual test and that it actually is a fishing thing and that nobody's seen it. And you're the first person that's reported it. And it could stop others from clicking the link down the road, which could cause a bigger incident or issue, whether or not you clicked it or not. So all of these things again, but this all comes back to.

Daniel Swann (31:10.850): Yeah.

Daniel Swann (31:17.635): Right.

Aaron Crow (31:33.765): you know, beating up on the idea of you have to have a culture where people, people feel safe that they can do that. And there's not going to be retribution on them, right? Yeah. I made a mistake. I clicked the link. I promise you, everybody will click a link everybody because they're so good and they're getting better. They're getting better. It's going to happen. You're going to click a link. So we need to have a culture where you want people to report, Hey, I messed up. I clicked the link. It looked real. It looked realistic.

Daniel Swann (31:39.501): Yeah.

Daniel Swann (31:42.039): Yeah.

Daniel Swann (31:48.056): Yeah, if you make it good enough, yeah, absolutely. Yeah.

Aaron Crow (32:0.973): And I didn't realize it until I clicked the link that it was not a place that I wanted to be. Please take a look at my system. Cause I don't want, I don't know if I'm impacted or not, or if I, if I have a virus or malware or whatever's on here. So take a look at that. Right. You want your people to do.

Daniel Swann (32:11.756): Yeah. The other thing too is people love, yeah. The other thing too is threat actors love to chain fish, right? So as soon as they get one person, they're going to send out blast out emails and try to get other people within your organization. So if that person's reported it and they've, they've lowered that timeframe of the possibility of that, you're going to be a lot better off.

Aaron Crow (32:20.774): Yeah.

Daniel Swann (32:36.300): because if it gets out of hand and that person is chain fishing other people and then those people get compromised, the blast radius is significantly more than if it's just the one person that maybe you're able to lock down and reset quickly.

Aaron Crow (32:36.625): 100%.

Aaron Crow (32:53.391): Yeah. I mean, and that's going to be the case in all, all different types of scenarios. It's the same thing. If I, know, I remember back in the day, working on servers, and you know, being in a, in a, in a data center and having an old school key, you know, KVM and, and one of our guys was on the wrong server. So they thought they were on, you know, server one and they were supposed to be on server two.

Daniel Swann (32:57.187): Yeah.

Daniel Swann (33:8.055): Yeah.

Aaron Crow (33:15.971): So they rebooted the wrong server. So they were, they were patching and rebooting or whatever they were doing. They did the wrong one and they rebooted it. Well, that one was production and was actually had app, you know, live users and all the things on it. And they caused an outage, but they didn't want to tell anybody because they, didn't, a, at first they didn't realize it. And then B, when they did realize that they're like, I'll just get it back up and running before anybody notices. Right. Instead of saying, oops, I reviewed the wrong server. let's, let's be proactive about this and make sure that all of our users are back up.

Daniel Swann (33:20.631): Yeah.

Daniel Swann (33:28.103): gee.

Daniel Swann (33:42.914): Yeah.

Aaron Crow (33:45.061): They didn't tell anybody because again, they didn't want to get in trouble because they had not built a culture of, you know, being safe to share. I made a mistake because we all make mistakes. Mistakes are going to happen. We want to encourage you to admit when you made a mistake and let's fix it. I'm not going to be mad at Daniel. Let's just fix the problem and then figure out a way that we can make sure it maybe doesn't happen again. So we use back again, going back in the day, we put BG info on the desktop so that it would actually have the machine name and

Daniel Swann (33:55.917): Yeah.

Daniel Swann (34:6.669): Right.

Daniel Swann (34:13.132): Yeah.

Aaron Crow (34:13.561): and which device it was on. So when we're on the screen, because it's KVM, you think you're on port one, you're on port two, but right on the desktop, it says the machine name. So it's just three ways of communication like we do and using the phonetic alphabet and three-way communication. I heard you say this, you want me to reboot that server one? Yes, please reboot server one. Okay, I'm rebooting server one. These are all tools that we use.

Daniel Swann (34:30.167): Yeah.

Aaron Crow (34:40.843): Using the military, we bring those into these industrial spaces. IT doesn't always understand or experience in those things because you don't necessarily use those in an IT space on a daily basis, but they're great processes of procedures. know, we do, pre, you know, pre-job briefs, you talked about lockout, tag outs, like these are all safety type minded environments, but it's the same thing in, these systems to make sure that we're working on the right system. We're not bringing things down.

Daniel Swann (34:43.181): Yeah.

Daniel Swann (34:58.264): Mm-hmm.

Aaron Crow (35:8.943): you know, and we're building this culture of excellence in these environments. and you're making your peer checking, like all of these things are things that, that really bridge between it, OT, military government work, et cetera, to make sure that we're doing safely, effectively, you know, we're communicating well, you know, we're not, we're not making assumptions. Like we're all on the same page of what's going to happen. Okay. I'm going to click the button now.

Daniel Swann (35:24.556): Yeah. Yeah.

Daniel Swann (35:33.154): Yeah, exactly. mean, it's two person integrity is huge in the, in the military. Right. So it even rolls to a cyber cyber actions, right. Or cyber operations where you're not going to push a config to a firewall until someone else has checked it. Right. Or ACL rolls or whatever it is. Right. You're going to, that person's got to check it before you push that. And that person has to be qualified on what they're looking at. So once again, can't be just someone that's like the, you know, the secretary, Hey, come over and take a look at this.

Aaron Crow (35:49.061): Yeah. Yep. Yep.

Aaron Crow (35:57.137): Correct.

Daniel Swann (36:2.638): You know Palo Alto rolled it make sure it's it's working before I push it So it's super super helpful to have that no matter what kind of industry you're in if it's a critical process It never hurts to have another set of eyes on it

Aaron Crow (36:2.735): Right. Please sign here.

Aaron Crow (36:17.241): Absolutely. You know, nobody's, nobody's infallible. We've all been, you know, it's late at night again, going back to the incident, right? You know, I was just in the UK for nine days. Like it's about day seven, not much sleep. You know, we're working 16 hour days. You know, we're in a, in a strange country, eating strange food, sleeping in hotels, not getting great food. You know, all these things you're going to be tired. You're going to miss things like you're

Daniel Swann (36:25.400): Yeah.

Daniel Swann (36:31.779): Yeah.

Daniel Swann (36:37.772): Yeah.

Daniel Swann (36:43.106): Yeah.

Aaron Crow (36:43.461): You're up at odd hours. drinking way too much caffeine. You're not eating great food. You're not at your house. Like all of these factors are going to impact us. We're only human. So if you don't expect that your people are going to have issues, that's where peer checking comes in. It's where, you know, using phonetic alphabet, three way communication, like double checking on all these things to make sure you don't make another mistake. Like you're already in this incident. You don't want to have another one because your people are tired and they made a simple mistake that

Daniel Swann (36:51.628): Yeah.

Daniel Swann (37:7.117): Right.

Aaron Crow (37:11.759): They probably wouldn't have made at the beginning of the shift, but it's 16 hours in, and they're just trying to go home.

Daniel Swann (37:17.708): Yeah, especially when you're talking about the longer something goes on, you're eventually going to get to point, hopefully, you know, to restoration. And if you're, if you're not up on it during restoration or recovery, you know, you could end up setting yourself to going back to step one. So there's not good backups or you didn't check the backups. Right. So yeah. So you end up, back to step one and starting all over and nobody ever wants to do that twice. Right. So.

Aaron Crow (37:34.929): Correct. Causing more damage.

Aaron Crow (37:46.021): No, no, for sure. You know, and that's, you know, I think the theme that I hear and it's funny as we started talking and as I talked to everyone, I never have an agenda on these conversations. Like I always just want to see where they go, but it's funny. Obviously your experience, it's natural that we kind of throttle down into this conversation, but it's funny. Not everybody's had the experiences that you have and been on incident responses and had that level of understanding.

Daniel Swann (37:57.538): Yeah.

Aaron Crow (38:14.917): So maybe they're writing an incident response, but they've never actually been on one. Maybe they've been in one, maybe it was a simple one. It was a short one. but there there's a lot of lessons learned that go into that, that, that, know, that are valuable. And obviously a lot of organizations are leaning on third parties, Rockwell being one of those that can help an instant response and following up, cetera. Right. But you still need to make sure that your team knows what's going on because again, as a third party coming in,

Daniel Swann (38:18.584): Yeah.

Daniel Swann (38:34.307): Yeah.

Aaron Crow (38:42.925): I only know so much because I don't know your environment. Like I'm, I'm leaning on your people to guide us on where the bodies are, where the critical systems are, what should be done, what, like obviously we know cyber security, we know instant response, we know how to, how to do those things, but we don't know the passwords. We don't know your systems. We don't know where the critical things are. And it's, we're leaning on you to be able to do that. So

Daniel Swann (38:44.566): Right.

Daniel Swann (38:56.557): Right.

Aaron Crow (39:8.201): There's just so many nuggets that go into this. I think we could talk for hours on this topic. And I think it's an important one as we see more and more incidents that are coming up in OT. think unfortunately more and more people are going to get experience in this space than probably really want to.

Daniel Swann (39:12.748): Yeah. Yeah.

Daniel Swann (39:23.505): Yeah. Yeah. I think one of the things too, that we have a team here, engineers, security engineers, analysts. And so, just because you bring in the third party too, doesn't mean they just stop. Typically our guys will keep going because they're driven like that. And so it makes it a lot better though, because in the end product, your third party will kind of give you their report.

Daniel Swann (39:52.150): And then your other folks have, have kind of made it to the end too. And so at that point, they can kind of get your notes and improve their own, their own selves, right? Or their training models and things like that. So it's really nice to have kind of both. And then like you said, my folks are going to know where, how to get access to things, right? You guys coming in, it's going to be difficult. And that always seems to be the, the tough tasks when

Daniel Swann (40:19.166): third party comes in it's like how do we get access to these logs? Number one question, right? Yeah.

Aaron Crow (40:22.225): Yeah. What are the important? Yeah, absolutely. How do I get access to the logs? How do I get access? How do I get access to the building? Like sometimes again, the place I was just at, I needed an escort and I, and we had to have a person that could get us in these spaces and are we authorized to go here and could we take tools with us? And there were all these other things that had nothing to do with the incident or, or cyber or any of that type of stuff. It was really just, I need somebody that can walk me into there because I can't get in there by myself.

Daniel Swann (40:30.240): Yeah, that too. Yeah. Yeah.

Daniel Swann (40:39.884): Yeah.

Daniel Swann (40:45.016): Yeah.

Daniel Swann (40:51.244): Yeah, yeah, exactly. Yeah, that is one of the key things. And that's why it's helpful in our situation to have an incident commander, because those are all things that I'm thinking about. All everybody else is, you know, face deep in a log. I might be thinking about, you know, we've got beginning to end for an incident. I don't know how it's going to go in the middle, but at least I know to start things off, there's going to need to be access requests, you know, that needs to be jumped on, know, building access or whatever it is has to be done.

Aaron Crow (41:3.738): Exactly.

Aaron Crow (41:12.507): Those bookends. Yep.

Aaron Crow (41:17.670): Yep.

Aaron Crow (41:20.645): Yeah. Yeah, absolutely. And there's just so many factors, especially as you start getting into a longer incident. It's one thing if it's a few hours, but you start talking about, you know, multiple teams, you talk about, you know, days, maybe even weeks of time. you know, maybe you've stopped the, the outbreak, but now you're in recovery mode and you're kind of still, you know, covering up the band aid or band aiding that the problem it's not spreading, but it's still not resolved. hasn't been squelched.

Daniel Swann (41:35.213): Yeah.

Aaron Crow (41:49.821): whatever word you want to use there. you know, there's just so many things that go into that. And, you know, sometimes you just don't have visibility on everything. Again, like depending on the environment that you're in, you may not have comms to those people throughout the day. It may be the end of the day before you can, they can puff smoke because of where they're at. You think about a renewable site in the middle of West Texas and there's no cell phone signal out there, right? They're going to go out there.

Daniel Swann (41:59.596): Yeah.

Daniel Swann (42:15.138): Yeah. Yeah.

Aaron Crow (42:18.477): And then six hours later, they're going to come back. Like you're not going to have any communications until they get back into town. Right? So there's all these types of things that you need to think about as you're building at your plan. And what's going to happen in those situations? Do they have, you know, radios or have satellite communications? Like what are the things do they need it? Or can you do without them and let them go for six hours and then come back and puff smoke? Like these are just, these are things that you, you, you need to think about that goes beyond just which are, what are my cybersecurity tools?

Daniel Swann (42:23.789): Yeah.

Aaron Crow (42:46.415): What's in my my toolkit? Because these are things that need to be considered in an above, you know, all of that. Like again, that West Texas site. How are people going to gain access? Do you have somebody that can escort him? Are they going to be able to get in the fence? What happens if it's after after hours? Is there somebody on the weekend? Like what happens if the one person has a key isn't available? What happens if he was the one that caused the like there's just so many things that come up in the scenario. It's almost a never ending set of questions and answers.

Daniel Swann (42:47.992): Yeah.

Daniel Swann (42:58.456): Mm-hmm.

Aaron Crow (43:14.882): of this, you know, choose your own adventure story that we are in incident response.

Daniel Swann (43:18.994): Yeah. Yeah. And I think that the military prepared me really well for that. Cause especially, uh, one of the roles I had was, um, deployable stuff, right? So setting up, thinking about logistics and stuff like that ahead of time, you know, when you're going, okay, if I go, if I go to this country, we're using a credit card is probably not going to work. And even if it is, it's the government. So it's not a easy process to get a credit card to be used anywhere.

Daniel Swann (43:47.266): Like, do I need to take cash? Do I need to go literally have someone go withdraw cash from the, you know, the base cashier cage and we're going to take so many dollars with us so that if we need to buy something over there on the economy, you know, we can. And so if you're going to some country you've never been to before and you do some research and realize, you know, it may not be your reliable payment system, then maybe I need to think about taking cash with me, which is, you know, just, so things like that always prepare me well to think the

Daniel Swann (44:16.266): second, third order effects and things that you may not be thinking about once you're jumping into an incident.

Aaron Crow (44:22.799): Yeah. hundred percent. What, what other things, is there anything else that comes up for anybody that maybe hasn't been in an incident before? Maybe they have an incident response plan, but maybe they haven't tested it fully. Luckily, I guess is a better way to say that. and maybe what are some of those, we've already hit some pretty powerful nuggets here. Is there anything else that stands out that you think should people should know or think about as their, as their practice, some tabletops or they're writing their incident response or they're updating it? What does that anything come up?

Daniel Swann (44:41.038): Mm-hmm.

Daniel Swann (44:51.534): Yeah, I think for, uh, practicing the tabletops, I think one of things is, I don't know, don't be afraid to get crazy with it. Uh, and one of things that it's important to do as well, especially if you're going to have maybe non IT people put on there, the maybe for more of your business side, right? You've got to kind of tell them and try to do a primer at the beginning. Like the scenario was, was created by, you know, an AI engine or

Daniel Swann (45:20.620): You know, these group of people at the company, but don't fight the process, right? Or don't fight the scenario. Sorry. Don't fight the scenario. So something sounds ridiculous to you. Don't just fight. Don't dwell on that one nugget, right? Like there's no way that would happen. You know, I remember one of the scenarios that we had to run when I was in the military was, Hey, a small aircraft is going to crash into the satellite antenna. And then.

Daniel Swann (45:50.666): how are you going to communicate with that satellite after that? You know, it's like, that would never happen. You know, we've got jets and things and all this stuff that protects us, you know, around military bases. It's like, but. And so everybody's trying to fight it. And then they're like, they say, yeah, don't care. Okay. Well, if it's a tornado, what if it's hail? You know, it could be anything, but tell me what you're going to do if that happens and actually think through that. So.

Daniel Swann (46:16.332): I think I always start with some of these details may not make sense or may not even be, you know, super realistic, but even then you're going to run through the process. You're still going to get something beneficial out of it because you're still got to run through your process. No matter if it's a tornado sharknado, whatever's, you know, hitting your building or, it's a super, you know, high tech threat actor that's jumping in your network and

Daniel Swann (46:42.870): and using his massive, important tool on your network. No matter what, you still got to follow your process to get from containment to recovery or restoration.

Aaron Crow (46:52.721): Yeah. Yeah, absolutely. And even if, even if you go through some of those scenarios and they're so far fetched, you're like, yeah, I don't think we need to include that in our incident response plan. The likelihood of that is so low, but at least just having that conversation and not making an assumption, bring it up, have a dialogue, make it, make sure everybody agrees. And then you park and lot it like, Hey, we didn't include this. It wasn't cause we didn't think about it. was just because it's so far fetched that it's not, it's not, it doesn't worth, doesn't, it's not high enough a priority to put in our list. Right. So

Daniel Swann (47:7.212): Yeah.

Aaron Crow (47:20.731): We're not, you can't solve for every, there's no way you can ever answer response plan, have a response for everything. It would be so complex and so long. It would be just be useless. So you need to, you need to obviously prioritize, but that doesn't mean you don't bring them up, right? You should have the dialogue and have the conversation because weird things happen. Like, you know, there was a sub, yeah.

Daniel Swann (47:21.069): Yeah.

Daniel Swann (47:27.043): Yeah.

Daniel Swann (47:38.702): Yeah, I was about to say, nothing ever surprises me. Nothing. It's just like, that's today, you know? Like, okay, this is crazy, but we're gonna move forward and fix it.

Aaron Crow (47:46.225): You

Aaron Crow (47:49.519): Substations get shot by, by deer rifles and drunk people run into things and, you know, helicopters land inside protected areas at nuclear power plants. Cause they're looking for real estate and think this is it. I mean, I've seen some crazy stuff happen, that you you're just like, really? Like you have your pilot's license and you landed inside a protected area at a nuclear power plant that has a no fly zone for a long ways around it. And you landed inside the protected area.

Daniel Swann (48:10.498): Yeah.

Aaron Crow (48:19.107): My gosh, here's your sign. Yeah. I don't think you have a license anymore. I think they revoke that the FAA said, not anymore.

Daniel Swann (48:20.886): Yeah, may not have the license long after that. Yeah.

Daniel Swann (48:28.866): Yeah, yeah, that's wild. But yeah, nothing ever surprises me. I never know what I'm going to face, you know, day to day, which honestly keeps it interesting. Interesting. That's why I like it, you know, so it's always spontaneous. So it's good.

Aaron Crow (48:43.835): Yeah. Yeah. Insult responses can be a lot of fun. Obviously there are a lot, they're stressful. They could be a lot of work there. They could be crazy hours, all that kind of stuff. But at the same time, it's really cool at the end of it when you take that breath and you're like, wow, we just went through this and, and this is the outcome that we got. That was, that was interesting. And you know, that was a lot of fun and yeah, my gosh, that was stressful, but man, that was really cool as well. It's it's, you get some cool, you know, war stories, around the, the, thing that you just

Daniel Swann (48:58.403): Yeah.

Aaron Crow (49:12.591): fought through together as a team.

Daniel Swann (49:13.861): Yeah, yeah, and think one of the things that I've always tried to do is to maintain perspective when I was in the military and you know, at end of the day, even if it's a stressful day, things were tough, you go, did anybody die today? No. So it's not as bad as it could get, right? So no matter what has happened that day, and I kind of, you know, learned this, like I said, through some of the

Aaron Crow (49:26.927): Right. Yeah.

Aaron Crow (49:30.427): Sure. Yep.

Daniel Swann (49:36.800): super stressful times in the military. It's like, nobody died. So yeah, that communication it's not functioning right now or so we can't communicate with someone we need to, or, you know, we, we, maybe we, we did not test our backups and we've restored and put malware back in there, but in the end we're going to get through it. Right. And, if you look at perspective, worst case scenario, you're probably going to be left to that.

Daniel Swann (50:3.342): 99 % of the time and if you're not that's just a different story altogether. So it's okay

Aaron Crow (50:7.845): Yep. Yeah. A hundred percent. So man, this has been a fun conversation. in the next, I asked everybody this question. I gave you a warmup of this, but you know, next five to 10 years, what's one thing you see come up over the rise and that's concerning and maybe another thing that's exciting.

Daniel Swann (50:26.094): Yeah. So I think one of the things that's concerning to me, and it's probably one of those things that everybody's going to kind of talk about, right? It's not just, uh, not artificial intelligence, but the embracing of that from, from threat actors. And we're talking about OT. I'm not talking about, it creates a really cool phishing email or something like that. But I think the more of these models learn the more

Daniel Swann (50:54.766): sophisticated threat actors are going to learn about OT environments. Cause one of the things that, uh, I took the grid class, right. And I got to take it through from Rob, uh, who taught it, which is great. But one of the things that he talked about was, you know, threat actors are there's OT environments can be very complicated and very different, but now where you go. So

Daniel Swann (51:20.992): If you look at the attacks that have been in the past, in the scenarios, they'll get in the environment and it takes them a bit to learn. They have to learn about how things are, are set up, learn about the process, learn about the products and stuff like that. Cause it's such a vast, you know, vast pool of knowledge that you would need to know that it takes time. And so I think with AI, once it gets well-trained on the OT or whatever it is, right. It's going to be a lot easier to learn. So,

Daniel Swann (51:50.798): And so I mess around with it just like everybody does, right? And Copilot can do a lot to help teach you things really quickly. And something that's one of the things that's concerning for me as it relates specifically to OT is what is it going to look like once resources are spent on learning things like that, right? Processes, products, and things like that, where they're not having to go to 20 different resources to find this information. They can go to one.

Aaron Crow (52:2.373): Yeah, sure.

Aaron Crow (52:17.679): Yeah, 100%.

Daniel Swann (52:19.584): And then as far as the exciting things, I've been doing a lot with AI agents and stuff like that. I think that those could be helpful for various tasks, right? But I think one thing that everybody's scared about, right, is like taking jobs and stuff like that. And so...

Daniel Swann (52:46.766): I think that when you're thinking about the agents, agentic AI, right? Things like that. It's important to think about how, what are the things that still need the human in the loop and focusing on making the human more prepared and smarter on what you're looking at. Right. So it kind of goes along with the bad side, but the good side is if you're someone who wants to learn about, you know, digital twins or something like that, or spacecraft, it's going to be a lot quicker.

Daniel Swann (53:15.200): So I'm excited about what that's going to mean for the defense side too, as far as us learning more about it. Cause I think that when I came into Rockwell, I didn't have any product experience or anything like that. So it took a while for me to get, like get, get, get up to speed on what all of our products were. And I still don't know everything obviously, because we make thousands of things, right. And software, right. But I have familiarity with most things. And so I think if I could have just sat.

Aaron Crow (53:37.136): Yeah.

Daniel Swann (53:43.886): you know, with some agentic AI that had all of our manuals and all that stuff in there and could have summarized some of that stuff for a week, it would have been a lot faster than, you know, osmosis over working on things. So, I know the token answer is AI, but honestly, it's just what it is right now. So, I think that's good and bad, right? Exciting and not exciting at the same time.

Aaron Crow (53:55.878): Right.

Aaron Crow (54:0.975): Yeah. Yeah.

Aaron Crow (54:4.795): Yeah.

Aaron Crow (54:7.247): Well, it is right. It, to your point, like the good guys can use it to, to, level up their game. The bad guys can use it to level up their game. So if, if the bad guys are going to use it and you know, they're going to, so we have to be using it because they are. so we have to be making sure that we're training our people that were, plugging it in. Obviously we've got to be intentional about it and careful, where we're plugging it in and what we're doing with it, because obviously we can add risk. there was a, there was an article today where.

Daniel Swann (54:19.992): Yeah.

Daniel Swann (54:34.947): Yeah.

Aaron Crow (54:37.253): You know, China just, there was an incident where they, did a full autonomous attack using AI agents. Right. So yeah. Yeah. It is. Yeah. But that's, that's the future, right? It's going to be, the AIs are going to be attacking us. not even, not even necessarily a human. They're going to, the APTs are going to be like, yeah, go after, you know, Daniel at Rockwell. Just don't give up until you find a way into his world. Right.

Daniel Swann (54:43.244): Yeah, through anthropic. that yesterday. Yeah, it's fascinating using MCPA, just stuff like that. So.

Daniel Swann (54:50.851): Yeah.

Daniel Swann (55:2.232): Yeah.

Aaron Crow (55:3.665): They don't sleep. They don't eat. Like it's the Terminator movie, but it's a cyber side, right? He doesn't eat. He doesn't sleep. He doesn't get tired. He just, he, just, they won't stop until they get to the result that they're looking for. That can be the future. But on the flip side, we can also use that in an offensive way where it's constantly looking for those things and protecting and doing all that type of stuff. So I agree with you a lot of times folks, his answers is that, but it's always a different perspective. So I appreciate that because it's not the same. Like it's a different why.

Daniel Swann (55:7.800): Yeah.

Daniel Swann (55:30.562): Yeah.

Aaron Crow (55:32.181): of why they're bringing up AI, why it's important to them, and what perspective they see from it from a good and bad perspective. Even though they're similar, they're all very different. So I still appreciate that. So with that, go ahead. Yeah.

Daniel Swann (55:35.117): Right.

Daniel Swann (55:41.878): Yeah, if you think about the pace that's going, what I mean, five years is an eternity when you think about the pace it's going. So. Yeah.

Aaron Crow (55:48.249): I know that's why I've almost thought about not asking the question the way that I do. I've been asking it that way since the beginning, but 10 years, multiple people were like, I have no idea in 10 years. Hell, I don't even know necessarily in five, but 10 years is way too far out to imagine. Cause we're, we're things are changing so fast in a year. It's going to be drastically different than it is today. Probably beyond what you and I can anticipate, even because it's growing exponentially, beyond what, what we can imagine. So.

Daniel Swann (55:58.178): Yeah.

Daniel Swann (56:1.996): Yeah.

Daniel Swann (56:14.563): Yeah.

Daniel Swann (56:18.062): Right. Yeah, absolutely. I think about when I was a teenager, the computer I had, know, 8086, right? It was the first computer I got. And then I went to the 486 and the thing you know, it's a one gigahertz processor. That was within like three or four years, you know? yeah, nowadays, yeah.

Aaron Crow (56:26.009): Yup. Yup.

Aaron Crow (56:32.943): And now, now we have these devices that are, you know, two terabytes and, you know, GPUs and CPUs and multiple cores and, you know, gigabit ethernet and, and directly up and down satellite, like all the things, like it's just exponentially more, you know, you got console wars where steam decks are going to be going against consoles and it's just, everything is changing some for the better, some for the, I don't know. We'll see, but

Daniel Swann (56:38.402): Yeah.

Daniel Swann (56:44.055): Yeah.

Daniel Swann (56:49.325): Yeah.

Daniel Swann (56:55.693): Yeah.

Daniel Swann (57:2.013): Yeah, yeah, so I think it's gonna be interesting. Five years is like an eternity when it comes to the way technology is moving. So it'll be cool to see.

Aaron Crow (57:9.775): Yeah, 100%. Well, also man, so any, any call to actions for anybody come see, speak, come check out a white paper, anything like that, that you want people to know about you or to reach out, et cetera.

Daniel Swann (57:22.958): Um, so, uh, I'm not speaking at S4, but I'm going be at S4. So I'd love to, you know, catch up with everybody. I love, I love the conference. It just feels like family, you know, I always see people I know there and hang out. Um, so I may have some stuff that I'm going to submit for call for papers this upcoming year. Um, so if that comes out, uh, keep an on it. Uh, it's a bit dated, but I spoke at SANS ICS in 2024. So definitely encourage you to go check that out.

Aaron Crow (57:40.635): Very cool.

Daniel Swann (57:50.754): Very interesting case we had at Rockwell for a capability that was being developed that our government partner told us about in the midst of being developed. So we were able to kind of cut that off before it was released and get everybody protected. but yeah, other than that, connect on LinkedIn and it's great talking to everybody.

Aaron Crow (58:6.449): Very cool.

Aaron Crow (58:11.524): Yeah, absolutely. Well, thank you so much. I appreciate you taking time and talking with me today. definitely come see me at S four cause I'll be there as well. So definitely grab a beer, coffee, cigar, whatever the thing is. And, and, always like putting a face to a, or in person, shaking a hand of, people that that I met with here. So again, thank you again so much for time. Great conversation. I really appreciate it. Definitely some.

Daniel Swann (58:19.501): Awesome.

Daniel Swann (58:27.084): Yeah, yeah.

Aaron Crow (58:33.839): some big nuggets that we hit in today around incident response. And I think they're hugely valuable for people to take in and, really implement in their environments and maybe even reach out if they need some questions or help. thanks again. Uh-huh.

Daniel Swann (58:43.726): Yeah, absolutely. Thanks, sir. Appreciate it.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.