The Risk and Reward of Distributed Industrial Control
Joe Slowik
DEF CON 32 Creator Stage · Day 1 · Creator Stage

Key moments
- 0:00 Introduction: Challenging the 'air gap' myth in ICS
- 2:00 Necessity of distributed operations for modern infrastructure
- 3:20 Radical shift to wireless connectivity (5G, SatCom) for ICS
- 4:00 How distributed operations dramatically expand the attack surface
- 4:50 New risks from vendor remote monitoring and integration
- 5:30 Overview of modern industrial connectivity options
- 6:00 Adversaries exploiting the dramatically changed attack surface
The Risk and Reward of Distributed Industrial Control
Speakers: Joe Slowik
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=13o-MQtANpo
Overview
Joe Slowik’s DEF CON 32 talk, "The Risk and Reward of Distributed Industrial Control," offers a critical examination of the profound transformation occurring within Industrial Control Systems (ICS) and Operational Technology (OT) environments. Slowik, a leading expert at the MITRE Corporation specializing in critical infrastructure research and a key contributor to the ATT&CK framework, argues that the long-held paradigm of air-gapped industrial networks is largely a relic of the past. Modern infrastructure demands, driven by operational necessity and technological advancement, have ushered in an era of highly interconnected and geographically dispersed control systems.
This fundamental shift, while enabling the efficient and widespread deployment of vital assets like wind farms, pipelines, and remote mining operations, simultaneously introduces a significantly expanded attack surface. Slowik posits that adversaries are no longer confined to the traditional, multi-stage approach of breaching enterprise IT networks before attempting lateral movement into OT. Instead, the pervasive connectivity of distributed industrial control systems offers new, direct avenues for malicious actors to interact with and potentially disrupt critical infrastructure, bypassing established defensive layers.
This article will delve into the core arguments presented by Slowik, exploring the historical context of ICS connectivity, the technological and operational drivers behind distributed systems, the specific mechanisms through which the attack surface has expanded, and the critical implications for cybersecurity defenders. It aims to provide a comprehensive understanding of the complex interplay between the rewards of distributed control and the inherent risks that now define the security landscape of global critical infrastructure.
Background
▶ Watch: Introduction: Challenging the 'air gap' myth in ICS (0:00)
The historical perception of Industrial Control Systems (ICS) has long been characterized by the concept of the air gap—a complete physical and logical isolation separating sensitive plant networks from external, internet-connected environments. In this traditional model, operations and control were co-located, meaning operators and the physical equipment they managed resided at the same physical site, with network boundaries aligning with facility perimeters. While this model still exists in niche, highly sensitive sectors like nuclear generation, Slowik asserts it is no longer representative of the majority of contemporary industrial operations.
The move away from the air gap is not merely a technological trend but an operational imperative. Modern critical infrastructure projects are increasingly vast and geographically dispersed. Examples include extensive wind farms scattered across wide areas, thousands of miles of pipelines requiring continuous monitoring, ambitious mining operations in remote locations, and complex offshore oil and gas exploration platforms. Manning every single compressor station, wind turbine, or remote facility with on-site personnel is economically unfeasible and logistically impractical. Consequently, remote operations control, monitoring, and maintenance have become indispensable, transforming from optional cost-saving measures into fundamental necessities for the very existence and efficient functioning of these vital assets.
While centralized management of geographically distributed systems is not entirely novel—Energy Management Systems (EMS) and Transmission Management Systems (TMS) have long managed electric grids, sometimes even through analog means—the current era signifies a "radicalization" of how this connectivity is achieved. The shift has moved beyond traditional hardline connectivity like dedicated fiber optic cables or Plain Old Telephone Systems (POTS). Instead, there is an accelerating reliance on an increasingly wireless ecosystem, utilizing technologies such as satellite communications, 5G, and 4G networks. This transition introduces entirely new security repercussions, as the communication pathways are no longer physically confined and are exposed to different types of vulnerabilities and attack vectors, fundamentally reshaping the security posture of critical infrastructure. This evolution is driven by the confluence of economic efficiencies, technological advancements, and the inherent demands of operating modern, complex infrastructure.
Key Findings
▶ Watch: Radical shift to wireless connectivity (5G, SatCom) for ICS (3:20)
Joe Slowik’s presentation highlights several critical findings that redefine the cybersecurity landscape for industrial control systems in the era of distributed operations. The most salient discovery is the dramatic expansion of the attack surface, fundamentally altering how adversaries can target and compromise vital industrial assets.
Firstly, Slowik emphasizes the transition to "always online" industrial systems, which effectively broadens the scope of potential attack vectors beyond traditional IT or business networks. Historically, an adversary's path to an industrial environment involved a multi-stage process: breaching an external enterprise network, then executing several lateral movement hops to penetrate the internal, supposedly air-gapped, operational network. However, with distributed operations, this intricate journey is increasingly circumvented. Adversaries may now achieve direct access to critical assets, either through vulnerabilities in wireless communication mechanisms (like satellite or cellular networks) or by compromising the networking infrastructure that facilitates connectivity to the broader environment. This direct access significantly streamlines initial exploitation and payload delivery, making industrial assets more immediately vulnerable.
Secondly, the talk identifies the pervasive integration of vendor management and monitoring systems as a significant and growing attack vector. Slowik cites the GE Atlanta data highway, used for managing generating assets, as a prime example of a broader industry trend. This trend sees industrial vendors deeply integrated into their customers' environments for various purposes, including preventative maintenance, remote management, big data analytics for product development, and even licensing and use monitoring. While these integrations offer undeniable operational benefits and support, they introduce a substantial supply chain risk. A compromise within a vendor's systems could provide an adversary with a direct, trusted conduit into numerous customer ICS environments, potentially enabling widespread disruption or data exfiltration without the need for individual targeting.
Finally, Slowik underscores that the adoption of technologies such as distributed satellite communication networks and 5G/4G terrestrial mesh networks creates a landscape of distributed, overlapping communications. While these networks enhance efficiency and reliability through redundancy and fail-safes, they also introduce a multitude of potential touch points for adversaries. Every wired and wireless link, every node in a mesh network, and every ground communication center becomes a potential entry point. The intricate nature of these multi-device networks, and the ability to manipulate the directionality of communication within them, presents new challenges for defenders attempting to establish effective segmentation and control over their industrial environments. Collectively, these factors contribute to a significantly more exposed and complex industrial control ecosystem.
Technical Deep Dive
▶ Watch: How distributed operations dramatically expand the attack surface (4:00)
The technical evolution of industrial control systems, as detailed by Joe Slowik, is characterized by a fundamental shift in communication infrastructure, moving from isolated, hardwired connections to a complex, interconnected, and predominantly wireless ecosystem. This transformation underpins the "risk and reward" dynamic discussed in the talk.
Historically, ICS environments relied on a limited set of communication technologies that, while less flexible, offered a degree of inherent security through physical isolation. These included the Plain Old Telephone System (POTS), often used for low-bandwidth telemetry or dial-up remote access, and dedicated fiber optic lines, which provided high bandwidth and robust physical security for specific point-to-point connections. These methods required physical access or specialized tapping techniques to compromise, making them relatively secure against remote, cyber-only attacks.
The modern landscape, however, is defined by the widespread adoption of wireless and satellite technologies. Cellular modems, though not new, are increasingly deployed to connect remote industrial assets over commercial mobile networks, such as 4G and rapidly emerging 5G infrastructure. More significantly, satellite systems are seeing increased adoption, providing connectivity to geographically isolated operations like offshore oil rigs or remote mining sites. This involves communications bouncing from a remote asset to an overhead satellite and then down to a ground communication center, creating expansive wide-area networks. Slowik notes that recent advancements, including the expansion of satellite constellations, have dramatically increased the available bandwidth for these systems, overcoming the previous limitations of older Vsat (Very Small Aperture Terminal) systems, which were often bandwidth-constrained.
The emergence of 5G and other advanced wireless technologies further complicates this environment, facilitating the creation of dynamic mesh networks. These networks consist of multiple devices that can communicate with each other in various configurations, offering redundancy and flexibility. However, this multi-path, multi-device communication introduces a complex topology where controlling the directionality of communication and preventing unauthorized access or interception becomes a significant challenge. Each wireless link, whether satellite, cellular, or local mesh, represents a new touch point for an adversary, extending the traditional wired network perimeter into the electromagnetic spectrum.
Beyond mere connectivity, these diverse communication methods enable a critical suite of operational functions that are essential for modern distributed infrastructure:
- Remote Access and Maintenance: This allows engineers and technicians to diagnose, configure, and repair equipment from a central location, reducing the need for costly and time-consuming on-site visits to widely dispersed assets.
- Remote Control and Operations: Centralized control rooms can directly manipulate industrial processes, such as adjusting the flow rates in a pipeline, managing turbine speeds in a wind farm, or controlling pumps in a water treatment facility, ensuring efficient and responsive operations.
- Telemetry and Health Checks: Continuous collection of operational data—including parameters like pressure, temperature, vibration, and flow rates—is crucial for monitoring asset health, predicting potential failures, and optimizing performance. This data is vital for maintaining system integrity and preventing costly downtime.
- Licensing and Use Monitoring: From a commercial perspective, vendors often utilize remote connectivity to monitor how their equipment is being used, ensuring compliance with contractual agreements and facilitating usage-based billing or support.
- System of Systems Coordination: For large-scale infrastructure, remote connectivity enables the synchronized management of multiple disparate facilities. Examples include maintaining frequency and phase stability across an entire electric power grid or ensuring consistent pressurization along the entire length of a pipeline network to facilitate product delivery.
The integration of these diverse communication technologies and operational requirements into an "always online" architecture fundamentally changes the security posture of ICS. The traditional model of perimeter defense and deep segmentation within a physically confined facility is no longer adequate. Instead, a comprehensive security strategy must now account for the security of every link, every device, and every third-party dependency across a highly distributed, often wireless, and increasingly cloud-connected network.
Demo / Proof of Concept
▶ Watch: Overview of modern industrial connectivity options (5:30)
The presentation "The Risk and Reward of Distributed Industrial Control" by Joe Slowik was primarily analytical, focusing on the identification and characterization of the evolving threat landscape for industrial control systems. The talk did not include a live demonstration or a detailed proof of concept showcasing specific vulnerabilities, exploits, or attack chains. Instead, Slowik's objective was to illuminate the theoretical and practical implications of increased connectivity in ICS environments and the resulting expansion of the attack surface.
Defensive Implications
▶ Watch: Adversaries exploiting the dramatically changed attack surface (6:00)
The transition to distributed and interconnected industrial control systems presents a complex and evolving challenge for cybersecurity defenders. Joe Slowik explicitly states that the idea of "turning back the clock" by re-implementing strict air gaps is unrealistic, prohibitively expensive, and fundamentally incompatible with the operational necessities of modern critical infrastructure. Therefore, defenders must embrace a proactive and adaptive defensive strategy that acknowledges the inherent "always online" nature of these systems.
A paramount implication for defenders is the urgent need to comprehensively re-evaluate and secure the expanded attack surface. This requires a meticulous inventory and understanding of all communication links, both wired and, crucially, wireless, that connect industrial assets. Defenders must identify every potential touch point—from satellite ground stations and cellular modems to 5G/4G mesh network devices—and implement robust security controls across them. This includes mandating strong authentication, robust encryption, and integrity checks for all data traversing these wireless networks. Given the unique characteristics of wireless communication, defenders must also consider threats such as signal interception, jamming, and the deployment of rogue access points, which were less prominent in traditional wired environments.
Vendor dependencies emerge as a critical area requiring heightened defensive scrutiny. The widespread integration of vendor remote management, monitoring, and maintenance systems, exemplified by the GE Atlanta data highway, means that the security posture of third-party providers directly impacts the resilience of the asset owner's Operational Technology (OT) environment. Defenders must establish stringent supply chain security requirements, including regular security audits of vendors, contractual obligations for secure development practices, and clear, granular protocols for remote access. Implementing zero-trust principles for vendor access, with strict access controls, multi-factor authentication, and continuous monitoring of vendor activities within the OT network, is no longer optional but essential.
Furthermore, the increasing trend of connecting industrial assets, or components thereof, to cloud-based instances introduces novel segmentation and security challenges. Traditional network segmentation models, historically based on physical boundaries, are insufficient when parts of the control system reside in a distributed cloud environment. Defenders must adopt cloud security best practices, focusing on robust identity and access management, secure configuration of cloud resources, and continuous monitoring for anomalous activity within cloud-connected OT components. The concept of segmentation needs to evolve to encompass logical boundaries across hybrid IT/OT/cloud environments, potentially leveraging technologies like data diodes where one-way data flow is acceptable to limit inbound connectivity and reduce risk.
Finally, defenders must prioritize situational awareness across this complex, distributed landscape. This includes continuous monitoring for network anomalies, unauthorized devices, and unusual communication patterns across all wired and wireless links. The ability to detect and respond to threats that bypass traditional IT perimeters and directly target OT assets is paramount. This necessitates specialized OT security monitoring solutions capable of understanding industrial protocols and detecting threats specific to control systems, integrated with broader enterprise security operations to provide a holistic view of the overall threat landscape. The overarching goal is not to eliminate connectivity, which is now an operational necessity, but to manage and secure it effectively, thereby reducing the likelihood and potential impact of successful attacks on critical infrastructure.
Key Takeaways
- The Air Gap is Largely Obsolete: The traditional notion of air-gapped industrial networks is no longer representative of most modern critical infrastructure, which is increasingly interconnected and "always online."
- Operational Necessity Drives Connectivity: Distributed operations for critical infrastructure like wind farms, pipelines, and remote mining sites necessitate remote control, monitoring, and maintenance, making extensive connectivity a fundamental requirement, not just a cost-saving measure.
- Expanded Attack Surface: The shift to wireless communication (satellite, 5G, 4G) and pervasive vendor remote access dramatically expands the attack surface, allowing adversaries to potentially bypass traditional IT network perimeters and directly target OT assets.
- Vendor Integration as a Major Risk: The widespread integration of vendor systems for monitoring, maintenance, and data analytics (e.g., GE Atlanta data highway) introduces significant supply chain security risks, creating direct conduits for potential adversary access.
- Wireless Ecosystem Challenges: Reliance on diverse wireless technologies creates complex mesh networks with multiple touch points, demanding advanced security strategies for signal integrity, authentication, and access control.
- "Turning Back the Clock" is Not Feasible: Re-implementing air gaps is impractical and expensive. Defenders must focus on securing the expanded, always-online environment through robust wireless security, vendor risk management, cloud security best practices, and enhanced situational awareness.
About the Speaker(s)
Joe Slowik is a distinguished figure in the field of cybersecurity, particularly within the domain of critical infrastructure and industrial control systems. He currently holds a significant role at the MITRE Corporation, where he is involved in leading functions within the renowned ATT&CK framework and conducting extensive research focused on critical infrastructure security. Slowik's expertise is deeply rooted in understanding the complex interplay between technology, operations, and security risks in vital industrial environments. His work at MITRE and previous experience (which he modestly downplays in the talk) positions him as a leading voice in deciphering the evolving threats to global critical infrastructure.