Matthew Carr

When a security failure has a physical consequence.

Most security advice assumes the worst thing that can happen is losing data. In a plant the worst thing that can happen is a process that stops, an asset that breaks, or a condition that hurts somebody. That changes which controls are worth having and which ones will get you thrown out of the control room.

I have spent fifteen years in critical infrastructure and national security, much of it on the offensive side. I disclosed cyber-physical attack chains against SCADA systems in 2018 and industrial control research at DefCon two years running. That work is why I can tell you which risks deserve your budget and which ones only sound frightening.

An operational network is not an office network.

The controls that protect a corporate estate can be actively harmful on a plant floor. Anyone advising your board on operational risk needs to know why.

DimensionCorporate ITOperational technology
First priorityConfidentiality of dataSafety, then keeping the process running
Cost of downtimeDisruption and lost workLost production, sometimes an unsafe state
PatchingRoutine, often automaticScheduled around outages, sometimes blocked by the vendor
Asset lifespanThree to five yearsFifteen to thirty years
Failure modeBreach or data lossPhysical consequence
Rate of changeFast by designSlow by design, and correctly so

What I lead on in an operational environment.

Asset and network visibility

You cannot lead what you cannot see. The first question in every plant I have worked in is what is actually connected, and to what.

The IT and OT boundary

Segmentation, the conduits that cross it, and the historians, jump hosts and engineering workstations that sit on the seam. This is where most real incidents begin.

Vendor and integrator remote access

The most common route in, and the hardest to withdraw once it has been granted. It needs an owner, a review date and somebody willing to say no.

Control and safety-system separation

Oversight of the boundary between the control system and the safety-instrumented system, and of who is permitted to change it.

Supply chain and technology

The integrators, OEMs and platforms your process depends on, reviewed as the operational dependencies they are.

Incident preparedness

A plan that answers who stops the process, who talks to the regulator and who decides to run degraded, agreed before the day you need it.

Frameworks and regulation

Where you stand against IEC 62443, the NCSC Cyber Assessment Framework, NIS 2 and NIST SP 800-82, turned into decisions your board can take.

An attacker's read on your estate

I will tell you how I would go after your process, because for most of my career that is what I was paid to do.

The research behind the advice.

Published disclosures and original research, coordinated with the vendors and reported in the trade press.

2024Progress MoveIt TransferCoordinated with the vendor and reported in the trade press.
2024Zoho DeskCoordinated with Zoho. Covered alongside the MoveIt finding.
2023N-able workgroup guidelinesVendor defaults that quietly exposed managed service providers.
2018Physically hacking SCADACyber-physical attack chains against industrial control systems.
2017ICS killswitchMulti-vendor industrial control research, disclosed at DefCon.
Energy and utilitiesWater and wastewaterManufacturing and processTransport and logisticsHealthcare estatesData centres

Technical work such as penetration testing, OT assessments and architecture review stays available and I oversee it. It supports the leadership engagement and is scoped and quoted separately.

The retainer scope and fees

Bring an operational risk to the call.

Tell me what your process cannot afford to lose and I will tell you honestly whether CISO-as-a-Service is the right answer for it.

£4,950 per month. £5,000 onboarding assessment, waived on a twelve-month commitment.