SANS Open-Source Intelligence (OSINT) Summit & Training offers immersive cyber security courses and a free Summit!


To attend this webcast, login to your SANS Account or create your Account.

This webcast has been archived. To view the webcast login into your SANS Portal Account or create an account by clicking the "Get Registered" button on the right. Once you register, you can download the presentation slides below.

Exploring the Unknown ICS Threat Landscape

  • Tuesday, April 18, 2017 at 11:00 AM EDT (2017-04-18 15:00:00 UTC)
  • Robert M. Lee, Ben Miller, Michael Assante


  • Dragos, Inc.

You can now attend the webcast using your mobile device!



ICS (in)security is hiding in plain sight. This presentation will be our first public discussion on unique research on industrial control system software, malware, and the consequences of poor operations security. Our premise for this project is the belief that there is a wealth of information surrounding Industrial Control Systems that is unrecognized by the traditional IT cybersecurity industry. We will walk through our methodology, show real-world findings and conclusions of what this means in our space.

Speaker Bios

Robert M. Lee

Robert M. Lee, a SANS certified instructor and author of ICS515 ICS Active Defense and Incident Response and FOR578 Cyber Threat Intelligence courses, is the founder and CEO of Dragos, a critical infrastructure cyber security company, where he focuses on control system traffic analysis, incident response and threat intelligence research. He has performed defense, intelligence and attack missions in various government organizations, including the establishment of a first-of-its-kind ICS/SCADA cyber threat intelligence and intrusion analysis mission. Author of SCADA and Me and a nonresident National Cyber Security Fellow at New America, focusing on critical infrastructure cyber security policy issues, Robert was named EnergySec’s 2015 Energy Sector Security Professional of the Year.

Ben Miller

Ben leads a team of analysts in performing active defense inside of ICS/SCADA networks. He is responsible for a range of services including threat hunting, incident response, penetration testing and assessments for the industrial community as well as advanced research and innovation within ICS security.

Michael Assante

Michael Assante currently manages the SANS Industrials and Infrastructure practice area and is the lead for the Industrial Control System (ICS) and Supervisory Control and Data Acquisition (SCADA) security curriculum. Previously he served as vice president and chief security officer of the North American Electric Reliability Corporation (NERC), where he oversaw industrywide implementation of cyber security standards across the continent. Before joining NERC, Mike held a number of high-level positions at Idaho National Laboratory and served as vice president and chief security officer for American Electric Power. His work in ICS security has been widely recognized.

Need Help? Visit our FAQ page or email

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.