ICS 101

Bryson Bort, Tom VanNorman

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

In "ICS 101," Bryson Bort and Tom VanNorman, co-founders of the ICS Village, deliver a foundational talk aimed at demystifying Industrial Control Systems (ICS) for the broader security community. The presentation serves as an essential primer, distinguishing the unique operational priorities and security challenges of ICS environments from conventional Information Technology (IT) systems. They highlight that while IT focuses on Confidentiality, Integrity, and Availability (CIA), ICS prioritizes resilience, availability, and critically, health, life, and safety. This fundamental difference dictates vastly different approaches to design, maintenance, and security.

Watch on YouTube

Visual summary for ICS 101 by Bryson Bort, Tom VanNorman
Visual summary for ICS 101 by Bryson Bort, Tom VanNorman

Key moments

  1. 0:00 Introduction to ICS and key differences from IT
  2. 2:00 Why ICS security is different: health, life, and safety
  3. 4:00 The unique physical effect of industrial control systems
  4. 4:19 Understanding the Purdue Model and the "air gap" myth
  5. 5:08 Difficulties in building an ICS lab and where to start
  6. 6:16 Practical ICS security advice: segmentation and asset detection

ICS 101

Speakers: Bryson Bort, Founder of Scythe, Founder of Grim, Co-founder of ICS Village; Tom VanNorman, Co-founder of ICS Village, Senior VP at Grim

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=s_w7fxESt-o

Overview

In "ICS 101," Bryson Bort and Tom VanNorman, co-founders of the ICS Village, deliver a foundational talk aimed at demystifying Industrial Control Systems (ICS) for the broader security community. The presentation serves as an essential primer, distinguishing the unique operational priorities and security challenges of ICS environments from conventional Information Technology (IT) systems. They highlight that while IT focuses on Confidentiality, Integrity, and Availability (CIA), ICS prioritizes resilience, availability, and critically, health, life, and safety. This fundamental difference dictates vastly different approaches to design, maintenance, and security.

The speakers address the common perception that ICS is an impenetrable, highly specialized domain, arguing instead that its core components are often older, simpler, and offer tangible physical feedback loops that can aid learning. They emphasize the difficulty for newcomers to acquire hands-on experience due to the specialized nature of hardware, software licensing, and connectivity requirements. To bridge this gap, Bort and VanNorman passionately advocate for the ICS Village, an initiative designed to provide accessible, safe, and realistic environments for security professionals to learn about and experiment with real-world ICS components without impacting production systems.

This talk is crucial for anyone looking to understand the unique landscape of Operational Technology (OT) security. It provides not only an architectural overview but also practical advice on how to get started in the field, build personal labs, and implement foundational defensive strategies. By challenging the notion of an unbridgeable "air gap" and focusing on practical, actionable security measures like segmentation and asset detection, Bort and VanNorman empower the audience to engage with and contribute to the vital mission of securing critical infrastructure.

Background

▶ Watch: Introduction to ICS and key differences from IT (0:00)

The landscape of Industrial Control Systems (ICS) represents a stark contrast to the familiar world of Information Technology (IT), a distinction that forms the bedrock of this talk. Historically, ICS environments—encompassing systems like Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and Distributed Control Systems (DCS)—were designed for longevity, reliability, and physical process control, often operating in isolation. Unlike IT systems, which are routinely patched, upgraded, and replaced every few years, ICS components can remain operational for decades. This legacy creates a unique set of challenges, including reliance on outdated operating systems, proprietary protocols, and hardware that is difficult to update or replace.

The core philosophical difference lies in their respective security principles. IT security traditionally adheres to the triad of Confidentiality, Integrity, and Availability (CIA). In contrast, ICS prioritizes resilience and availability above all else, with the ultimate goal of ensuring health, life, and safety. As the speakers vividly illustrate, an IT system failure might result in a "bad day" or financial loss, but an ICS failure—such as a grid turning off or a water plant ceasing operation—can have catastrophic consequences, including loss of life, environmental pollution, or widespread infrastructure disruption. This inherent criticality means that processes cannot simply be "turned off" for patching or security updates without careful planning and significant risk.

A key conceptual framework for understanding ICS architecture is the Purdue Model for Control Hierarchy. This model provides a nominal enterprise architecture that segments ICS networks into distinct levels, from the enterprise IT systems (Level 5) down to the physical process control (Level 0). While the model suggests a hierarchical and segmented structure, often implying an "air gap" between IT and OT networks, Bort and VanNorman unequivocally state that "an air gap is not an air gap." They assert that in virtually all real-world scenarios, including highly sensitive environments like nuclear power plants, IT and OT systems inevitably communicate, driven by operational needs for data exchange, remote management, and business integration. This connectivity, while necessary, introduces significant vectors for cyber threats that exploit the traditional security weaknesses of OT.

The challenge of learning about ICS is another critical background element. Unlike IT, where one can easily acquire hardware, software, and training resources, gaining hands-on experience with real ICS components is notoriously difficult. Components are expensive, often require specialized licenses, proprietary cables, and specific engineering software that is not readily available to individuals. This creates a barrier to entry for security professionals interested in transitioning into or specializing in OT security, perpetuating the mystique and perceived complexity of the field. The ICS Village was co-founded precisely to address this gap, providing an accessible environment to experiment with real industrial hardware and bridge the knowledge divide.

Key Findings

▶ Watch: The unique physical effect of industrial control systems (4:00)

The talk "ICS 101" delivers several crucial findings that reframe the understanding of Industrial Control Systems (ICS) security for a broader audience, emphasizing both its unique challenges and its accessible aspects.

Firstly, a paramount finding is the fundamental divergence in security priorities between IT (Information Technology) and OT (Operational Technology). While IT focuses on Confidentiality, Integrity, and Availability (CIA), ICS environments are primarily driven by resilience, availability, and critically, the imperative of health, life, and safety. This means that traditional IT security practices, such as frequent patching or system shutdowns, are often impractical or even dangerous in an OT context. The direct physical consequences of an ICS failure—ranging from power outages to contaminated water supplies—underscore the unique risk profile and the need for tailored security strategies that prioritize operational continuity and safety above all else.

Secondly, the speakers highlight the tangible nature of ICS operations and learning. Unlike abstract data loss or shell access in IT, ICS interactions result in a physical effect in the real world. As Bort explains, "The lights go off, the light bulb goes on." This immediate, observable feedback loop makes learning about ICS potentially easier and more intuitive for hands-on learners, as actions directly manifest in physical changes rather than purely digital ones. This "physical feedback loop" is presented as an advantage for understanding system behavior and the impact of security interventions.

Thirdly, the talk unequivocally debunks the myth of the "air gap" in modern ICS environments. Despite common assumptions or theoretical models like the Purdue Model suggesting strict segmentation, Bort and VanNorman assert that "your IT will always talk to your OT." They emphasize that operational necessities, data exchange, and remote management invariably lead to connections between IT and OT networks, even in highly secure facilities. This finding is critical because it means that IT-borne threats can and often do propagate into OT networks, necessitating a holistic and integrated security approach rather than relying on assumed isolation.

Finally, the talk identifies core, impactful defensive strategies that are often overlooked in the pursuit of advanced security solutions. While acknowledging the complexity of ICS security, the speakers distill the most critical actions into three foundational areas: segmentation, asset detection, and basic authentication. They argue that mastering these fundamental controls provides a disproportionately high return on investment in securing OT networks. By knowing what devices are on the network, segmenting them effectively, and implementing even basic authentication, organizations can significantly improve their security posture against many common threats, making ICS security "not as hard as it sounds."

Technical Deep Dive

▶ Watch: Understanding the Purdue Model and the "air gap" myth (4:19)

The technical underpinnings of Industrial Control Systems (ICS) form a crucial part of this talk, distinguishing them from conventional Information Technology (IT). At its core, an ICS is a factory automation system, often involving Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and Distributed Control Systems (DCS). PLCs are ruggedized, industrial computers that automate specific processes, receiving input from sensors and sending commands to actuators (e.g., motors, valves). HMIs provide operators with a graphical interface to monitor and control these processes, while DCS are larger, more complex systems used to control entire plants or processes.

A key architectural concept discussed is the Purdue Model for Control Hierarchy, which provides a structured approach to segmenting industrial networks. This model typically defines five levels:

  • Level 5: Enterprise IT – Business planning and logistics systems.
  • Level 4: Manufacturing Operations – Manufacturing operations systems.
  • Level 3: Operations Management – Plant-wide control and supervision.
  • Level 2: Process Control – Direct control of the physical process (e.g., HMIs, controllers).
  • Level 1: Basic Control – PLCs and other controllers.
  • Level 0: Physical Process – Sensors and actuators directly interacting with the physical world.

The speakers highlight the theoretical "air gap" often depicted between Level 3 and Level 4 (or even between IT and OT entirely), but critically underscore that in practice, this air gap rarely exists in its purest form. Data flow, remote access, and business integration necessitate connections, creating pathways for threats.

The fundamental difference in design philosophy is paramount. ICS components are built for longevity, often running for 20-30 years, contrasting sharply with IT's rapid refresh cycles. This means ICS environments frequently contain legacy hardware and software, including older operating systems that are no longer supported or patched. The emphasis is on resilience and availability—the ability to keep critical processes running continuously, even in degraded states. Patching, a cornerstone of IT security, becomes a complex and risky endeavor in OT, as downtime can lead to significant operational disruption, safety hazards, or environmental damage. Testing patches in a non-production environment is critical, a process that requires dedicated lab infrastructure mirroring the production system.

Learning about these systems presents unique technical hurdles. While simulators and virtualized environments (like OpenPLC or Raspberry Pi-based solutions) exist, the speakers assert that "they just don't work the same" as real industrial hardware. True understanding, especially for practitioners, requires interaction with actual devices. However, acquiring real ICS components, such as an Allen Bradley controller, from platforms like eBay, is only the first step. These devices often come without essential components: proprietary cables, specific engineering software licenses, and configuration files, making them difficult to set up and operate for individuals. The cost and complexity of obtaining these ancillary necessities create a significant barrier to entry for building a personal lab.

The physical nature of ICS also offers a unique learning advantage. Unlike IT, where security incidents might manifest as abstract data corruption or unauthorized access, an ICS attack often has a direct, observable physical effect. This immediate feedback—a light turning on, a pump stopping, a simulated water supply being "poisoned" in a lab—provides a tangible understanding of impact and system behavior, which can be highly beneficial for training and incident response. This direct correlation between digital actions and physical outcomes is a defining characteristic of OT security.

Demo / Proof of Concept

▶ Watch: Difficulties in building an ICS lab and where to start (5:08)

While the talk itself does not feature a live, in-session technical demonstration or a traditional Proof of Concept (PoC) execution, the entire presentation acts as a compelling call to action and an introduction to the ICS Village, which functions as the ultimate hands-on learning and demonstration environment. The speakers, Bryson Bort and Tom VanNorman, are co-founders of the ICS Village, and they continually refer to it as the primary means for attendees to gain practical experience.

The ICS Village, located at the conference, serves as a dynamic, interactive "demo" of real-world industrial control systems. Here, participants are encouraged to engage directly with live, operational ICS components. The core concept is to provide a safe, non-production environment where individuals can "fuck up shit together" without fear of real-world consequences. This means attendees can:

  • Interact with Real Hardware: Unlike virtualized or simulated environments, the ICS Village utilizes actual Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and other industrial equipment sourced from vendors, donations, or even eBay. This ensures that the learning experience is authentic and reflects the behavior and quirks of systems found in critical infrastructure.
  • Experience Physical Effects: A central tenet of the ICS Village's approach is the tangible nature of ICS. Participants can observe direct physical changes resulting from their interactions, such as lights turning on or off, pumps starting or stopping, or even "poisoning a fake water supply." This immediate physical feedback reinforces understanding of how digital commands translate into real-world industrial processes.
  • Test Patches and Configurations: The Village provides an environment where new patches, security configurations, or network segmentation strategies can be tested on realistic systems before being considered for production deployment. This addresses a critical need in OT, where directly patching production systems is often too risky.
  • Learn About Vulnerabilities: Participants can explore common vulnerabilities in ICS, understand how they manifest, and witness the impact of exploits in a controlled setting. This hands-on exposure is invaluable for developing defensive strategies.

The speakers highlight the difficulty of building personal ICS labs due to licensing, proprietary cables, and specialized software. The ICS Village directly addresses this barrier by providing a fully equipped, ready-to-use environment. It functions as a collective "proof of concept" for the idea that hands-on learning with real industrial equipment is not only possible but essential for developing competent OT security professionals. By offering a space to "get some hands-on experience," the ICS Village demonstrates how the theoretical concepts discussed in the talk—like the Purdue Model, the physical feedback loop, and the challenges of legacy systems—play out in practice.

Defensive Implications

▶ Watch: Practical ICS security advice: segmentation and asset detection (6:16)

The defensive implications derived from "ICS 101" are pragmatic and foundational, emphasizing that effective Operational Technology (OT) security often begins with basic, well-executed controls rather than complex, cutting-edge solutions. The speakers, Bryson Bort and Tom VanNorman, distill their recommendations into three core pillars: segmentation, asset detection, and basic authentication.

1. Segmentation: This is presented as the most critical defensive measure. Recognizing that the mythical "air gap" between IT (Information Technology) and OT (Operational Technology) rarely exists, robust network segmentation becomes paramount. This involves logically dividing the OT network into smaller, isolated zones based on function, criticality, or trust levels, using firewalls, VLANs, and other network controls. The goal is to limit the lateral movement of an adversary, containing breaches to smaller segments and preventing them from reaching critical control systems. For instance, isolating Programmable Logic Controllers (PLCs) from Human-Machine Interfaces (HMIs), or segmenting different processes within a plant, can significantly reduce the attack surface and impact of a compromise. This approach acknowledges the reality that IT and OT systems will inevitably communicate, but seeks to control and monitor those communication pathways rigorously.

2. Asset Detection (Knowing What's on Your Network): Before any effective security measures can be implemented, organizations must have a comprehensive understanding of every device connected to their OT network. This includes not just major components like PLCs and HMIs, but also smaller, often overlooked devices, network switches, and any transient connections. The speakers implicitly stress the importance of an accurate and up-to-date asset inventory. Without knowing what assets exist, their function, their vulnerabilities, and their communication patterns, it's impossible to properly segment, monitor, or protect them. This foundational step is often neglected but is vital for establishing a baseline understanding of the environment and identifying unauthorized or rogue devices.

3. Basic Authentication: While acknowledging the historical reality of "admin/admin" default credentials in deeply segmented and physically secured industrial environments (like a nuclear plant "seven layers down" behind guard gates and guns), the speakers advocate for implementing stronger authentication, especially on gateway devices or systems that are more exposed. They highlight the balance required: while rapid access to control systems might be necessary in an emergency to "turn that thing off or on," this does not justify weak authentication on all devices. For internet-facing or less physically protected components, strong, complex passwords are essential. The underlying message is to apply a risk-based approach to authentication: the closer a device is to the outside world or the IT network, the stronger its authentication should be.

Beyond these three pillars, the talk implicitly reinforces several other defensive considerations:

  • Testing in Non-Production Environments: The emphasis on the ICS Village as a place to "see if our patches work" underscores the critical need for robust test environments that mirror production systems. Never patch production directly without thorough testing.
  • Physical Security: While not explicitly detailed as a cyber defense, the mention of "guard gates and guns" in high-security facilities reminds us that physical security remains a foundational layer of defense for OT, especially for systems with weak logical controls.
  • Understanding Unique OT Principles: Defenders must internalize the core health, life, and safety principles of OT. Security solutions must be evaluated not just for their cyber efficacy but for their potential impact on operational continuity and safety. Any security measure that jeopardizes availability or resilience is counterproductive in an OT context.

In essence, the defensive implications from "ICS 101" advocate for a back-to-basics approach, focusing on fundamental cyber hygiene tailored to the unique operational realities and priorities of industrial control systems.

Key Takeaways

  • ICS Priorities Differ Fundamentally from IT: Unlike IT's focus on Confidentiality, Integrity, and Availability (CIA), ICS prioritizes resilience, availability, and critically, health, life, and safety. Security strategies must align with these core operational imperatives.
  • The "Air Gap" is a Myth: Despite theoretical models, IT and OT networks are almost always connected in real-world industrial environments due to operational necessities. Defenders must assume connectivity and plan security accordingly.
  • Physical Feedback Aids Learning: Interacting with ICS provides tangible, physical effects, making the learning process more intuitive and impactful compared to abstract IT concepts. This direct feedback can accelerate understanding of system behavior and security implications.
  • Hands-on Experience is Crucial but Challenging: Gaining practical experience with real ICS hardware is essential for effective OT security, but acquiring and setting up personal labs is difficult due to proprietary components, licenses, and cables. Initiatives like the ICS Village are vital for bridging this gap.
  • Foundational Security is Paramount: Effective ICS defense hinges on mastering three core principles: robust segmentation of the network, comprehensive asset detection (knowing every device on your network), and implementing basic, context-appropriate authentication.
  • Test Before Production: Due to the critical nature of OT systems, all patches, configurations, and security changes must be thoroughly tested in non-production environments that accurately simulate the operational system before deployment.

About the Speaker(s)

Bryson Bort is a prominent figure in the cybersecurity community, known for his deep expertise in industrial control systems and critical infrastructure security. He is the founder of Scythe, a company focused on adversary emulation, and Grim, a cybersecurity consulting firm. Crucially, Bryson is also a co-founder of the ICS Village, an initiative dedicated to providing hands-on learning experiences for securing industrial control systems. His work highlights the importance of practical, real-world engagement with OT environments to develop effective defensive strategies.

Tom VanNorman is a co-founder of the ICS Village alongside Bryson Bort, demonstrating his commitment to advancing education and practical skills in industrial control system security. He also serves as a Senior Vice President at Grim, where he contributes his extensive experience to cybersecurity challenges. Tom's contributions emphasize the need for accessible, hands-on training to demystify OT security and empower professionals to protect critical infrastructure effectively.

All talks from DEF CON 32 Creator Stage