CyberWire Daily

Encore: Active visibility into OT systems. [Control Loop]

4 snips
Dec 27, 2023
Garrett Bladow, Distinguished Engineer at Dragos, discusses active visibility into OT systems. Topics include vulnerabilities in Rockwell's Stratix routers, increasing malware attacks against IoT devices, lack of cybersecurity plan at a nuclear power plant, and Dragos' partnership with Rockwell Automation for improved ICS cybersecurity threat detection.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

OT Devices Favor Availability Over Security

  • OT devices prioritize real-time availability and reliability over authentication or encryption.
  • Garrett Bladow explains Ethernet/IP can return full device IDs but repeated queries overwhelm devices designed for control, causing failures.
ANECDOTE

No OT Systems Found Truly Air Gapped

  • Dragos has never found a genuinely air-gapped OT environment in six years of assessments.
  • Bladow recounts that simple UDP packets can disrupt devices because many protocols accept single-shot messages without sessions.
INSIGHT

OT Isolation Assumption Is Broken By IIoT

  • OT systems historically assumed isolation; modernization and IIoT have erased that assumption.
  • Bladow notes industrial IoT and wireless control mean operators often no longer control the physical wires to devices.
Get the Snipd Podcast app to discover more snips from this episode
Get the app