ICS Risk: Strategies for Assessing Operational, Safety, Financial, and Cybersecurity Risks

Unknown

Black Hat USA 2024 · Day 1 · Briefing

Overview

This panel discussion delves into the intricate and often daunting challenges of securing Industrial Control Systems (ICS), Operational Technology (OT), and the broader Internet of Things (IoT) landscape. Featuring insights from leading experts in product security, academic research, and vulnerability discovery, the talk provides a candid assessment of the current state of cybersecurity within critical infrastructure. The speakers collectively unpack why these environments are inherently complex, the nature of vulnerabilities they face, and the significant hurdles organizations encounter in managing assets, vulnerabilities, and their supply chains.

Watch on YouTube

Visual summary for ICS Risk: Strategies for Assessing Operational, Safety, Financial, and Cybersecurity Risks by Unknown
Visual summary for ICS Risk: Strategies for Assessing Operational, Safety, Financial, and Cybersecurity Risks by Unknown

Key moments

  1. 0:00 Panelist introductions and ICS/OT industry overview
  2. 2:09 Discussing the inherent complexity of ICS/OT environments
  3. 4:05 Are OT vulnerabilities the same but harder to access?
  4. 4:54 Asset inventory and patching: The Achilles heel of OT
  5. 6:19 Strategies for mitigating ICS/OT threats and SBOM importance

ICS Risk: Strategies for Assessing Operational, Safety, Financial, and Cybersecurity Risks

Speakers: Cassie Crossley, VP Supply Chain Security & Product Security Officer, Schneider Electric; Thomas, Professor Cyber Security at St. Polten University & Founder of Lima Security; Nome, Clarity Team 82 (Vulnerability Research)

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=Ifimg-1tsLo

Overview

This panel discussion delves into the intricate and often daunting challenges of securing Industrial Control Systems (ICS), Operational Technology (OT), and the broader Internet of Things (IoT) landscape. Featuring insights from leading experts in product security, academic research, and vulnerability discovery, the talk provides a candid assessment of the current state of cybersecurity within critical infrastructure. The speakers collectively unpack why these environments are inherently complex, the nature of vulnerabilities they face, and the significant hurdles organizations encounter in managing assets, vulnerabilities, and their supply chains.

The discussion highlights the unique characteristics of ICS/OT that differentiate it from conventional IT security, such as the prevalence of legacy systems, the critical requirement for operational stability, and the increasing, often unintended, exposure of these systems to the internet. The panel underscores that while some security challenges might appear similar to those in IT, their implications in an OT context—where cyber incidents can translate to physical damage, safety hazards, or service disruptions—are far more severe. This article aims to elaborate on these critical points, offering a deep dive into the technical, operational, and strategic considerations for assessing and mitigating risks in these vital sectors.

The insights shared by Cassie Crossley from Schneider Electric, Thomas from St. Polten University and Lima Security, and Nome from Clarity Team 82 are crucial for anyone involved in securing critical infrastructure. Their collective experience, spanning from product development and supply chain management to academic research and active vulnerability hunting, offers a holistic perspective on the multifaceted risks. The conversation ultimately stresses the urgent need for robust strategies in asset inventory, vulnerability management, and supply chain security to safeguard the operational integrity and resilience of industrial environments against an evolving threat landscape.

Background

▶ Watch: Panelist introductions and ICS/OT industry overview (0:00)

The security of Industrial Control Systems (ICS) and Operational Technology (OT) has historically evolved under a very different paradigm than traditional Information Technology (IT). For decades, many OT systems operated in air-gapped environments, physically isolated from external networks, relying on physical security as their primary defense. Communication often occurred via proprietary serial connections and highly specialized, domain-specific protocols that were never designed with modern cybersecurity threats in mind. This isolation fostered a culture where operational uptime and safety took precedence, often at the expense of robust security features. The assumption was that if a system was not connected to the internet, it was inherently secure.

The problem, as articulated by the panel, is that this historical context clashes dramatically with contemporary operational demands. The drive for increased efficiency, remote monitoring, predictive maintenance, and data analytics has led to a significant IT/OT convergence. Industrial devices, once isolated, are now routinely connected to enterprise networks and, increasingly, directly to the internet. This shift has fundamentally altered the threat landscape for critical infrastructure. As Nome from Clarity Team 82 points out, the movement "from actual physical serial connections where you need to have physical access and basically touch each device to putting them in an IP network and in some cases even the exposed network of the internet" is a primary reason why OT security lags behind IT. Devices that were never intended to face external threats are now directly exposed to a global pool of attackers.

This inherent complexity of OT environments is a recurring theme. Thomas emphasizes that OT systems are characterized by their heterogeneous nature, comprising components from countless vendors, different generations of technology, and various industry-specific solutions. Unlike the relatively standardized components often found in IT, an OT environment might include devices from different eras, running on disparate operating systems, communicating via a multitude of protocols, all interacting to control a critical physical process. This creates a deeply intricate ecosystem where understanding interdependencies and potential points of failure is a monumental task.

Furthermore, the long operational lifecycles of industrial equipment exacerbate security challenges. As Cassie Crossley highlights, organizations often continue to use the same product for ten years or more, sometimes even retaining original firmware versions, despite the availability of newer, more secure generations. This practice stems from the high cost of replacement, the need for extensive re-validation, and the paramount importance of stability in operational settings. Consequently, OT environments frequently harbor a mix of cutting-edge technology alongside decades-old legacy systems, each with its own set of vulnerabilities and patch management complexities.

The challenges are compounded by a widespread deficiency in asset inventory. The panel identifies this as the "Achilles heel" of the industry. Many organizations lack a comprehensive and accurate understanding of what devices they operate, where they are located, and crucially, what firmware versions or software components they contain. Without a precise asset inventory, it becomes nearly impossible to effectively track vulnerabilities, assess exposure, or plan for mitigation and patching, leaving critical infrastructure vulnerable to known threats. The panelists argue that these foundational issues—complexity, legacy systems, internet exposure, and poor asset management—collectively explain why securing ICS/OT remains one of the hardest problems in cybersecurity today.

Key Findings

▶ Watch: Discussing the inherent complexity of ICS/OT environments (2:09)

The panel discussion crystallized several critical findings regarding the state of ICS/OT security, emphasizing the unique challenges and pervasive gaps that define this domain. These findings underscore the urgent need for a more strategic and nuanced approach to securing critical infrastructure.

Firstly, the experts unequivocally agreed that ICS/OT environments are inherently complex, and this complexity is not merely a function of inertia or slow adoption rates. As Thomas articulated, the intricate, heterogeneous nature of these systems, integrating diverse components and solutions across various sectors, makes them uniquely challenging. Cassie Crossley further elaborated, highlighting that while individual products might have a clear mission, their integration into a larger, interconnected system creates immense complexity. This inherent complexity, coupled with the tendency for organizations to maintain homogeneous product lines—continuing to buy the same models for a decade or more, often running original firmware—creates a security landscape fraught with legacy vulnerabilities.

Secondly, the panel concluded that the vulnerability landscape in OT often lags behind IT security. Nome from Clarity Team 82 specifically attributed this to the fundamental architectural shift from isolated, physical serial connections to pervasive IP networking and, alarmingly, direct internet exposure. This transition has exposed a multitude of "obvious or low-hanging fruit" vulnerabilities that were previously mitigated by physical isolation. While the "bugs are the same bugs that everybody else is facing," as Nome suggested, their accessibility and potential impact are significantly amplified when industrial devices are connected to global networks. These vulnerabilities, often rooted in insecure defaults, unpatched software, or lack of authentication in legacy protocols, become critical attack vectors.

Thirdly, a unanimous consensus emerged regarding asset inventory as the "Achilles heel" of the ICS/OT industry. Cassie Crossley pointed out that even organizations with good asset management at the device level often lack crucial details like specific firmware versions. This deficiency means that while an operator might know they have a hundred units of a particular device, they cannot ascertain which of those might be running vulnerable, outdated firmware. This lack of granular visibility paralyzes effective vulnerability management and patching efforts, leaving organizations blind to their true exposure. The panel acknowledged that this problem is not exclusive to OT, but its consequences are far more severe given the critical nature of industrial operations.

Finally, the discussion highlighted the extreme difficulty of mitigating threats and hardening OT systems. Thomas emphasized that the ease of mitigation depends heavily on the specific industry and its unique operational constraints. The panel recognized that while Software Bill of Materials (SBOMs) are crucial for understanding supply chain risks, their widespread adoption and effective utilization are still evolving. However, there was a positive note: "lots of the let's say really strong vendors in the market have had their own software bill of materials getting collected like a capability ramped up," indicating a growing recognition and investment in product security from key manufacturers. This suggests a nascent but important trend towards improved transparency and security posture within the vendor ecosystem.

Technical Deep Dive

▶ Watch: Are OT vulnerabilities the same but harder to access? (4:05)

The technical intricacies of ICS and OT environments are central to understanding their unique security challenges. These systems operate at the intersection of the cyber and physical worlds, dictating real-time processes that, if compromised, can have severe operational, safety, and environmental consequences. The panel's observations about complexity, legacy issues, and internet exposure can be deeply explored through several technical lenses.

At its core, an OT environment adheres to an architectural paradigm, often conceptualized by models like the Purdue Enterprise Reference Architecture or the ISA/IEC 62443 standard. These models segment industrial networks into distinct zones (e.g., enterprise, manufacturing, control, safety) and conduits, each with varying security requirements. Historically, the lower levels (Level 0-2, controlling physical processes) were isolated. However, the push for IT/OT convergence has blurred these lines, often connecting control systems directly to enterprise networks (Level 3-4) or even the internet.

The fundamental shift highlighted by Nome—from physical serial connections to IP networks—introduces a new array of technical vulnerabilities. Many legacy OT devices and protocols were designed for closed, trusted environments, lacking inherent security features such as authentication, encryption, or integrity checks. Protocols like Modbus/TCP, DNP3, EtherNet/IP, and older versions of OPC (OLE for Process Control) commonly transmit data in plain text, making them susceptible to eavesdropping, manipulation, and unauthorized command injection if exposed. For instance, a Modbus device, if accessible over an IP network, can be commanded by any entity on that network without authentication, potentially causing equipment damage or process disruption.

The "firmware aspect" raised by Cassie Crossley is a critical technical vulnerability. Many industrial devices, such as Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), and Human-Machine Interfaces (HMIs), rely on embedded firmware. This firmware often contains vulnerabilities that persist for years because updates are difficult, costly, or simply not performed. Technical challenges include:

  1. Lack of Secure Update Mechanisms: Older devices may not support authenticated or encrypted firmware updates, allowing attackers to potentially load malicious firmware.
  2. Proprietary Architectures: Firmware is often highly specialized for unique hardware, making analysis and patching complex.
  3. Resource Constraints: Many embedded OT devices have limited processing power and memory, precluding the implementation of modern cryptographic functions or robust security agents.
  4. Absence of Secure Boot: Without secure boot mechanisms, a device cannot cryptographically verify the integrity of its firmware before execution, leaving it open to tampering.

These factors contribute to the "same bugs that everybody else is facing" becoming uniquely dangerous in OT. A buffer overflow in a web server might lead to data compromise; in a PLC, it could lead to process manipulation, causing physical harm or equipment failure. Default credentials or hardcoded passwords, common in older OT devices, provide easy remote access for attackers once the device is network-accessible. Similarly, command injection vulnerabilities or insecure direct object references can allow unauthorized control over critical industrial functions.

The issue of asset inventory is not just an administrative problem but a profound technical one. Without automated tools capable of discovering and detailing OT assets, including their specific models, manufacturers, operating systems, running services, and crucially, their exact firmware versions and patch levels, organizations operate in the dark. Such tools often need to be passive network monitoring solutions to avoid disrupting sensitive industrial processes, which cannot tolerate active scanning. Furthermore, an effective inventory must also document the Software Bill of Materials (SBOM) for each device, detailing all third-party and open-source components, their versions, and known vulnerabilities. Generating and consuming SBOMs for deeply embedded, proprietary systems is a significant technical undertaking.

Finally, the mitigation side is technically constrained by the operational imperative. Unlike IT systems, OT systems often cannot be rebooted or patched without scheduled downtime, which can be infrequent (e.g., once a year) and costly. This necessitates technical solutions like network segmentation (using firewalls and industrial DMZs to isolate critical zones), protocol whitelisting, and potentially virtual patching at network boundaries to intercept and sanitize malicious traffic targeting known vulnerabilities in unpatchable devices. The technical challenge lies in implementing these controls without introducing latency or disrupting real-time operations, which are often sensitive to even minor network delays.

Demo / Proof of Concept

▶ Watch: Asset inventory and patching: The Achilles heel of OT (4:54)

This panel discussion focused on strategic insights and challenges in ICS/OT security rather than demonstrating specific exploits or proof-of-concept attacks. The emphasis was on a candid discussion of the industry's pervasive problems and potential solutions, drawing from the extensive experience of the panelists in vulnerability research, product security, and academic study.

Defensive Implications

▶ Watch: Strategies for mitigating ICS/OT threats and SBOM importance (6:19)

The candid discussion by the panel reveals a clear mandate for defenders in the ICS/OT space: a multi-faceted and highly specialized approach is essential to address the unique complexities and vulnerabilities of critical infrastructure. Defensive strategies must move beyond traditional IT security models to account for operational imperatives, legacy systems, and the profound impact of cyber-physical incidents.

  1. Establish a Robust Asset Inventory: This is the most foundational and critical defensive measure. Organizations must implement comprehensive asset management systems that go beyond basic device counts. This involves meticulously documenting:
  • All hardware components (PLCs, RTUs, HMIs, sensors, actuators).
  • Specific firmware versions for every device.
  • Operating system versions and patch levels for control systems (e.g., engineering workstations, SCADA servers).
  • Network connectivity, including IP addresses, protocols in use, and inter-zone communications.
  • Software Bill of Materials (SBOMs) for all software and firmware components, detailing third-party libraries and their versions.

This level of detail is paramount for identifying exposure to known vulnerabilities and prioritizing mitigation efforts. Passive network monitoring tools are often preferred for discovery in sensitive OT environments to avoid disruption.

  1. Implement Granular Network Segmentation: The shift from isolated systems to IP networks necessitates rigorous network segmentation. Defenders should architect their OT networks using principles like the Purdue Model or ISA/IEC 62443 zones and conduits. This involves creating logical and physical barriers between different operational levels (e.g., enterprise IT, manufacturing operations, control systems) and within the OT network itself (e.g., separating safety systems, critical control loops). Firewalls and industrial DMZs should enforce strict access controls, allowing only essential traffic and protocols between zones. Protocol whitelisting should be employed to permit only approved industrial protocols (e.g., Modbus, EtherNet/IP) and specific commands, blocking all others.
  1. Develop a Tailored Vulnerability Management Program: Standard IT vulnerability management processes are often incompatible with OT. Defenders must establish a program that accounts for:
  • Prioritization based on operational impact and safety: Vulnerabilities affecting critical processes or safety functions should receive immediate attention.
  • Phased patching strategies: Patches often require extensive testing in non-production environments to ensure stability before deployment. Scheduled downtime, which can be infrequent, must be utilized effectively.
  • Compensating controls and virtual patching: Where direct patching is impossible or delayed, network-level controls (e.g., IDS/IPS rules, firewall policies) can be implemented to detect and block exploitation attempts against known vulnerabilities.
  • Risk-based decision making: Accept that not all vulnerabilities can be patched immediately. Assess the risk of leaving a system unpatched in conjunction with compensating controls.
  1. Strengthen Supply Chain Security: As Cassie Crossley highlighted, supply chain security is a growing concern. Defenders should:
  • Demand SBOMs from vendors: Integrate SBOM requirements into procurement contracts to gain visibility into software components and their associated vulnerabilities.
  • Conduct vendor security assessments: Evaluate the security practices of ICS/OT vendors, including their secure development lifecycle, vulnerability disclosure policies, and support for older products.
  • Monitor vendor advisories: Stay vigilant for security advisories and patches released by manufacturers for their deployed equipment.
  1. Enhance Operational Resilience and Incident Response: Given the potential for physical impact, OT incident response plans must be distinct from IT plans.
  • Develop OT-specific incident response playbooks: These should address scenarios like PLC manipulation, sensor spoofing, and HMI compromise, focusing on maintaining safety and restoring operations.
  • Regularly test incident response plans: Conduct tabletop exercises and simulated attacks (safely, in isolated environments) to ensure teams are prepared for cyber-physical incidents.
  • Implement robust backup and recovery procedures: Ensure critical configurations, PLC programs, and historical data are regularly backed up and can be quickly restored.
  1. Foster IT/OT Collaboration and Training: Bridging the gap between IT and OT teams is crucial.
  • Cross-training initiatives: Educate IT security professionals on OT protocols and operational contexts, and train OT engineers on cybersecurity principles and best practices.
  • Establish joint teams or clear communication channels: Ensure a unified approach to security, leveraging the expertise of both domains.

By adopting these defensive implications, organizations can begin to build a more resilient and secure operational environment, capable of withstanding the complex and evolving threat landscape facing ICS and critical infrastructure.

Key Takeaways

  • Inherent Complexity: ICS/OT security is fundamentally complex due to heterogeneous environments, diverse legacy systems, and the unique convergence of physical processes with cyber controls, making it one of the hardest problems in cybersecurity.
  • Vulnerability Exposure from IT/OT Convergence: The shift from isolated, physical serial connections to widespread IP networking and internet exposure has unveiled a significant attack surface in OT, exposing "low-hanging fruit" vulnerabilities that were previously mitigated by air-gapping.
  • Asset Inventory is the "Achilles Heel": A comprehensive and accurate asset inventory, particularly tracking specific firmware versions and Software Bill of Materials (SBOMs), is critically lacking across the industry, severely hindering effective vulnerability management and risk assessment.
  • Challenging Mitigation and Patching: Patching and mitigating vulnerabilities in OT environments are exceptionally difficult due to the paramount need for operational stability, long system lifecycles, extensive validation requirements, and limited windows for downtime.
  • Growing Importance of Supply Chain Security: The increasing reliance on third-party components and software necessitates greater transparency from vendors, with a positive trend noted in some strong vendors ramping up their internal SBOM collection capabilities.
  • Multi-faceted Defensive Strategy Required: Effective defense demands a tailored approach, combining robust asset management, granular network segmentation, risk-based vulnerability management, strong supply chain security, and enhanced IT/OT collaboration and incident response planning.

About the Speaker(s)

Cassie Crossley serves as the Vice President for Supply Chain Security and Product Security Officer at Schneider Electric. Her role involves working extensively with customers and suppliers on product security assessments and comprehensive risk management strategies within the critical infrastructure and Industrial Control Systems (ICS) space. Cassie is also a recognized author, having penned an O'Reilly book on software supply chain security, highlighting her expertise in securing the foundational elements of industrial technology.

Thomas is a Professor of Cybersecurity at St. Polten University in Austria and the founder of Lima Security, a boutique OT Security Consulting company. With an impressive 20-year background in OT security, Thomas brings deep practical experience to the field. Notably, he was responsible for product security at Siemens during the infamous Stuxnet incident, a pivotal moment that significantly shaped the landscape of industrial cybersecurity. He also founded Siemens' product CERT, underscoring his pioneering work in establishing dedicated security response capabilities for industrial products.

Nome is a key member of Clarity Team 82 at Clarity, a firm dedicated to Cyber-Physical Systems (CPS) cybersecurity and protection. His primary focus is vulnerability research, where he actively investigates different OT, IoT, and IIoT devices to uncover security flaws. Nome and his team are responsible for responsibly disclosing hundreds of vulnerabilities to vendors each year, playing a crucial role in improving the security posture of widely used industrial and connected devices.

All talks from Black Hat USA 2024