Asset and network visibility
You cannot lead what you cannot see. The first question in every plant I have worked in is what is actually connected, and to what.
Most security advice assumes the worst thing that can happen is losing data. In a plant the worst thing that can happen is a process that stops, an asset that breaks, or a condition that hurts somebody. That changes which controls are worth having and which ones will get you thrown out of the control room.
I have spent fifteen years in critical infrastructure and national security, much of it on the offensive side. I disclosed cyber-physical attack chains against SCADA systems in 2018 and industrial control research at DefCon two years running. That work is why I can tell you which risks deserve your budget and which ones only sound frightening.
The controls that protect a corporate estate can be actively harmful on a plant floor. Anyone advising your board on operational risk needs to know why.
| Dimension | Corporate IT | Operational technology |
|---|---|---|
| First priority | Confidentiality of data | Safety, then keeping the process running |
| Cost of downtime | Disruption and lost work | Lost production, sometimes an unsafe state |
| Patching | Routine, often automatic | Scheduled around outages, sometimes blocked by the vendor |
| Asset lifespan | Three to five years | Fifteen to thirty years |
| Failure mode | Breach or data loss | Physical consequence |
| Rate of change | Fast by design | Slow by design, and correctly so |
You cannot lead what you cannot see. The first question in every plant I have worked in is what is actually connected, and to what.
Segmentation, the conduits that cross it, and the historians, jump hosts and engineering workstations that sit on the seam. This is where most real incidents begin.
The most common route in, and the hardest to withdraw once it has been granted. It needs an owner, a review date and somebody willing to say no.
Oversight of the boundary between the control system and the safety-instrumented system, and of who is permitted to change it.
The integrators, OEMs and platforms your process depends on, reviewed as the operational dependencies they are.
A plan that answers who stops the process, who talks to the regulator and who decides to run degraded, agreed before the day you need it.
Where you stand against IEC 62443, the NCSC Cyber Assessment Framework, NIS 2 and NIST SP 800-82, turned into decisions your board can take.
I will tell you how I would go after your process, because for most of my career that is what I was paid to do.
Published disclosures and original research, coordinated with the vendors and reported in the trade press.
| 2024 | Progress MoveIt Transfer | Coordinated with the vendor and reported in the trade press. |
| 2024 | Zoho Desk | Coordinated with Zoho. Covered alongside the MoveIt finding. |
| 2023 | N-able workgroup guidelines | Vendor defaults that quietly exposed managed service providers. |
| 2018 | Physically hacking SCADA | Cyber-physical attack chains against industrial control systems. |
| 2017 | ICS killswitch | Multi-vendor industrial control research, disclosed at DefCon. |
Technical work such as penetration testing, OT assessments and architecture review stays available and I oversee it. It supports the leadership engagement and is scoped and quoted separately.
Tell me what your process cannot afford to lose and I will tell you honestly whether CISO-as-a-Service is the right answer for it.
£4,950 per month. £5,000 onboarding assessment, waived on a twelve-month commitment.