Group Purchasing
Group Purchasing

The Questions Critical Infrastructure Leaders Should Be Asking

Authored byTim Conway
Tim Conway

Since this year’s SANS ICS Summit in June, we’ve seen cyberattacks that targeted and disrupted over a hundred water and wastewater systems (WWS) throughout the US, threats to exposed programmable logic controllers (PLCs) across multiple industrial sectors, and new government initiatives urging us to fortify critical infrastructure. Two talks in particular have been on my mind since the summit, because they raised some of our industry’s most difficult and fruitful questions that only seem to grow more important by the day.

These pivotal talks are part of what makes the SANS ICS Summit special to each and every one of us who attends, regardless of sector, country, or experience level. I’d estimate almost half the group this year was brand new to the space, attending alongside practitioners who’ve been doing cybersecurity and ICS for over 25 years. Everyone chooses their own adventure as they attend workshops and sessions that fit their needs and job role; the summit is structured to meet attendees where they are with more hands-on workshops and talks every year, bringing the foundations to newcomers while helping organizations that are ready to mature their programs. It’s always a balance, and there are always some talks that everybody needs to hear.

The Talks: Nation-State Threats and a Simulated Catastrophe

What struck me most about these talks was hearing in absolute, plain, direct English, “This is what we’re seeing.” Both of these experts came forward on stage to tell us from experience that these threats are real, both around the world and within the US.

Brian Harrell outlined the present threats posed to critical infrastructure by nation-state adversaries. These threats are real and concrete, and they demand a shift in how we rely on government intelligence in threat hunting, how we invest in human capital, and how the highest levels of organizational leadership arrange their priorities. Thinking about future attacks, it’s also essential that we look internally, both for insider threats and for the risk that security team exhaustion could make us miss something. Brian’s expertise here comes from multiple domains, with his background starting with DHS, then with NERC as the electric reliability organization for North America, his leadership perspective with Avangrid, and now as Chief Security Officer with FirstEnergy.

Mark Bristow walked us through a high-level tabletop exercise simulating the catastrophic impact of a nationwide cyberattack on infrastructure. Five cities, five sectors, 200 participants from 70 organizations, and a multi-phase attack that showed how unprepared core infrastructure is to operate in isolation. Mutual aid may not work anymore, communication failures may lead to more damage than the attacks themselves, and we may need to consider a “civil defense mindset” to help address both our practical and public psychological preparation. Mark was formerly with DHS and CISA, and in addition to being a SANS Principal Instructor he is now the Director of the Cyber-Physical Systems Division at MITRE, which does a tremendous amount of government programs, project work, and research, almost to the degree of a national laboratory.

These are the realities. Nothing hidden, and importantly, no kind of FUD (Fear, Uncertainty, and Doubt). Brian and Mark let us know what is really happening, and not just that these are problems we’re facing, but that these are problems we’re preparing for. I think this was refreshing for a lot of practitioners in the crowd, myself included.

Understanding the Realm of What’s Possible

These talks painted an unapologetic picture of the threats to critical infrastructure, but they also both point to the essential role leaders play in guiding the steps we take to change our approach. This is a vital opportunity to unearth and challenge assumptions about ICS/OT security.

The first question I would encourage critical infrastructure leaders to ask is: Do you understand the realm of what is possible?

Consider these two common assumptions that are all too easy for organizations to make, either explicitly or implicitly:

“This could never happen to us. We’re too small.”

Unfortunately, this is not anyone’s decision to make, and it’s one of several factors that can keep you from examining how to improve your position until something bad has already happened. Both talks demonstrated how interconnected our infrastructure is, making this distinction even less meaningful.

Security and regulation can’t happen overnight, but another question you should be asking is: What can we start doing now, instead of waiting until something fails? Unregulated sectors can lean in on something like the Five ICS Cybersecurity Critical Controls. That’s something you can programmatically start doing instead of waiting around for the big bad event, to help you wait for regulation to arrive, or for adversaries to arrive.

“The worst case is an outage.”

Threat actors are misusing systems to destroy them, making them unavailable for months to years. The scenario in Mark’s tabletop exercise illustrates that the failure of these interconnected systems can mean direct, widespread threats to health and safety. This is an essential point for leaders to understand, especially when making decisions about security investments: Boards may be disapproving ICS/OT security investments without understanding the possible consequence in terms of human loss of life. Securing your IT means securing how you manage your business, but securing your OT means securing the reason your organization exists and the people you serve.

These assumptions are worth challenging across all sectors and positions. Below are some more practical, actionable questions that only you can answer about your organization:

Questions Leaders Should be Asking

  • Do you understand the systems that you’re responsible for?
    • Who is responsible for your systems? Can you name the human that understands both the risk to operations, resiliency, reliability, and safety, and also the risk from a cybersecurity perspective?
    • What is this person’s ability to communicate risks and resource needs? Does the board have access to this person?
  • Are there resources where you need them?
    • Is the person you identified in question 1 under-resourced, understaffed, or underfunded? If so, why is this the case?
    • If there are no resources, have you balanced the risks? To what degree are you conducting exercises? What happens if an attack takes place tomorrow?
  • Do you spend your resources in a way that takes the highest-impact events off the table?
    • Given your verified understanding and adequate resources, how do you prioritize what to pursue?

What Stands Between Today and ICS/OT Resiliency

Part of what Brian’s and Mark’s talks indicate is the need to shift our priorities from reaction to prevention. One of the reasons we’ve been staying reactive is the challenge of making sure the public is informed about complex systems that are very hard to explain, and this can stand in the way of finding resources. Most people don’t know the full picture of what's happening behind the switch, or behind the faucet tap, or behind the burner on your stove or your thermostat on the wall.

Customers tend to think about their utility structures on exactly two occasions: once when paying the bills, and once when there’s an outage. No customer wants to pay a penny more per kWh for power, gallon of water, or BTU of natural gas — so nobody is thinking, “Why don't we pay a little bit more to get a more resilient and a more reliable system?” This is especially true if the customer isn’t certain their money is going to infrastructure that even supports their own area. But both Brian and Mark offered sobering pictures of just how interconnected our systems are, meaning investments in every system matter, even if they’re outside the borders of your community.

“Just keep it working” means investment in the full system. What's the speed bump between us and having a secure, defensible system? It's everything. All of the sectors, all of the load, all of the customers, all of the other investment that needs to happen. Cybersecurity is just one of the many risks that need to be managed, but it is often a risk that we do not fully understand.

Tune in for the Roundtable

I’ll be discussing this new era of critical infrastructure preparedness with Brian Harrell, Mark Bristow, and Robert M. Lee in an upcoming roundtable webcast. We’ll be analyzing and expanding these ideas and more in an all new discussion that you won’t want to miss.

Join us to learn where organizations should focus their people, planning, and investments, to examine the organizational capabilities needed to prepare for prolonged disruption, and to hear practical guidance and insights to help leaders rethink preparedness priorities and build the capabilities needed for what’s next.

Register to Watch

The Questions Critical Infrastructure Leaders Should Be Asking | SANS Institute