How to Build Intelligence-Driven ICS Security

TL;DR
Industrial security should be built around lessons from real attacks, operational missions, and physical processes, not copied wholesale from enterprise IT. Gaining access to an industrial environment is only the first step toward causing physical effects, because engineering controls, safety mechanisms, system knowledge, and operational culture all shape the actual risk.
Transcript
Um, my name's Rob Lee. I'm CEO of Dragos. And what I wanna talk about today is looking at our industrial security, some of the attacks that have happened, and more importantly, the big concept that I'll, uh, sort of invoke and talk through today is this idea that we can learn a lot from the attacks, and I don't think that's very novel. But when we ... Read More
Key Insights
- • Industrial control system security is enterprise security combined with physics, because cyber activity can affect equipment, processes, safety mechanisms, and physical operations. Defenders must understand the operational mission rather than defining industrial environments only by operating systems, network protocols, or the age of their technology.
- • Industrial control systems are not simply a subset of the Internet of Things, and they are not defined exclusively by legacy serial equipment. Industrial environments can include Windows 10 human-machine interfaces and Ethernet networks, while remaining distinct because their systems support physical missions and operational processes.
- • Access to an industrial network is only the first step toward producing an operational effect. An attacker who reaches a human-machine interface may still lack the engineering knowledge needed to manipulate the process successfully, and randomly clicking controls does not guarantee disruption or destruction.
- • Physical safety mechanisms are part of industrial cyber resilience, even when they are neither Internet Protocol devices nor serial-connected assets. A relief valve, for example, can prevent an attempted pressure increase from creating the physical consequence implied by apparent control over a software interface.
- • Industrial security practices should be informed by attack evidence rather than copied directly from enterprise IT. The speaker argues that many standards, frameworks, regulations, products, and services do not yet incorporate the threat insights that began accumulating more substantially around 2014.
- • Government and private-sector intelligence requirements are different but complementary. Government efforts often prioritize identifying who conducted an intrusion, while industrial owners and private defenders need to understand how attackers entered, operated, and could be stopped through detailed intrusion analysis and lessons learned.
- • Common enterprise controls are not universally deployable in industrial environments. Endpoint agents cannot necessarily protect the automation, instrumentation, and control assets that matter most, while active scanning and vulnerability assessment can create operational concerns, including the possibility that sensitive controllers may crash.
- • Operational trust is a security requirement because past outages attributed to information technology teams can damage cooperation for decades. Even a technically safe scanning tool may be blamed when an unrelated operations problem occurs, potentially ending engineering support for future cybersecurity initiatives.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How should organizations build intelligence-driven ICS security?
Organizations should build industrial security around evidence from real intrusions, the operational mission, and the physical processes being protected. They should analyze how attackers obtain access, what knowledge attackers need to affect operations, and which engineering or safety controls limit consequences. Standards, frameworks, products, and enterprise practices should then be evaluated against those observed attack lessons instead of being copied into industrial networks without adaptation.
Q: What makes industrial cybersecurity different from enterprise IT security?
Industrial cybersecurity includes the concerns of information technology security plus physics. The systems support physical missions involving automation, instrumentation, control, and engineered processes, so a compromised computer does not by itself describe the operational consequence. Defenders must understand equipment behavior, process conditions, safety mechanisms, and resilience alongside familiar concerns such as network access, operating systems, vulnerabilities, and endpoints.
Q: Why is access to an industrial control system not automatically game over?
Access is only the first step because producing a meaningful physical effect requires knowledge of the industrial process. An attacker may reach a human-machine interface but still have no understanding of which controls to change, how the equipment will respond, or which protections will intervene. Randomly selecting interface controls therefore does not reliably produce disruption, equipment damage, or the severe consequences sometimes suggested in public reporting.
Q: How do physical safety controls reduce cyber risk in industrial systems?
Physical safety controls can prevent software commands from producing their apparent result. In the pipeline assessment described in the talk, a tester believed remote human-machine interface access could over-pressurize the system, but an engineering leader explained that a relief valve would release the pressure. The example shows why cyber assessments must account for non-IP and non-serial protections designed into the physical process.
Q: Why can enterprise security practices fail in industrial environments?
Enterprise practices can fail when they ignore operational constraints and the assets that actually control physical processes. Endpoint agents may not run on important automation, instrumentation, or control equipment. Active vulnerability scanning can also create concern because controllers may crash. Even when a tool operates safely, an unrelated operational failure may be blamed on it, damaging cooperation between engineering and information technology teams.
Q: When should active vulnerability scanning be used in an ICS network?
Active scanning should be considered only after evaluating the industrial equipment, operational risk, and relationship with the operations team. The talk warns that some controllers can crash and that technical success alone does not eliminate organizational risk. If any later operations problem is attributed to the scanning device, security personnel may lose access and trust. The decision therefore requires engineering participation rather than a blanket enterprise policy.
Q: What roles do government and private companies play in ICS threat intelligence?
Government and private organizations contribute different forms of insight. Government intelligence requirements often focus on attribution, particularly determining who conducted an intrusion. Private organizations need detailed answers about how attacks occurred because the incidents happen in their environments. Their work includes intrusion analysis, extracting practical lessons, and improving defenses. Cooperation matters, but neither side should be assumed to possess complete or magical insight.
Q: Why must operational culture be included in industrial security planning?
Operational culture determines whether security teams can deploy controls, investigate problems, and sustain cooperation with engineering personnel. The speaker describes facilities where engineers still resisted working with information technology because of a SCADA outage attributed to that group in 1995. Industrial security teams must therefore protect reliability, communicate operational risks, and build trust, since one disputed incident can influence security decisions for many years.
Summary & Key Takeaways
-
Industrial cybersecurity differs from enterprise security because industrial systems perform physical missions. The relevant environment includes information technology, automation, instrumentation, controls, engineering processes, and safety mechanisms. Assessing risk therefore requires understanding what equipment physically does, not merely identifying network access, vulnerable software, or an exposed interface.
-
Many industrial standards, frameworks, regulations, and practices were created before threat visibility began improving around 2014. The speaker argues that defenders should update their foundations with lessons from actual incidents. Private organizations are especially important because attacks occur in their environments and their operational need is understanding how intrusions happen.
-
Enterprise practices such as endpoint agents, active vulnerability scanning, and patching are not automatically wrong, but they require industrial context. Controllers can crash, important control assets may not support agents, and operational teams may distrust intrusive security tools. Effective programs must balance cybersecurity improvements with reliability, safety, engineering knowledge, and organizational cooperation.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator