Manufacturing Lessons Learned, Lessons Taught

Tim Chase

DEF CON 32 Creator Stage · Day 1 · Creator Stage

Overview

Tim Chase's DEF CON 32 talk, "Manufacturing Lessons Learned, Lessons Taught," delves into the unique cybersecurity challenges faced by the manufacturing sector. As a veteran of Information Sharing and Analysis Centers (ISACs), Chase provides an insider's perspective on an industry often misunderstood in its complexity and interconnectedness. He argues that manufacturing, unlike other seemingly discrete verticals, functions as a horizontal modality, underpinning nearly every other industry. This fundamental characteristic makes generalizations difficult yet crucial for understanding its security posture.

Watch on YouTube

Visual summary for Manufacturing Lessons Learned, Lessons Taught by Tim Chase
Visual summary for Manufacturing Lessons Learned, Lessons Taught by Tim Chase

Key moments

  1. 0:48 Manufacturing: Not a Vertical, but a Horizontal Modality
  2. 1:30 The Good News: Manufacturers Excel at Their Core Business
  3. 3:20 Profit-Driven Focus: How Manufacturers Prioritize Production
  4. 4:10 The Bad News: Why Manufacturers Neglect Cybersecurity
  5. 5:10 Ransomware's Attraction to the Manufacturing Sector
  6. 5:50 ERP Systems: IT Compromise Leading to OT Downtime
  7. 6:40 Targeting Mid-Level Enterprises: The Ransomware Sweet Spot

Manufacturing Lessons Learned, Lessons Taught

Speakers: Tim Chase

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=fqFKbDib8CY

Overview

Tim Chase's DEF CON 32 talk, "Manufacturing Lessons Learned, Lessons Taught," delves into the unique cybersecurity challenges faced by the manufacturing sector. As a veteran of Information Sharing and Analysis Centers (ISACs), Chase provides an insider's perspective on an industry often misunderstood in its complexity and interconnectedness. He argues that manufacturing, unlike other seemingly discrete verticals, functions as a horizontal modality, underpinning nearly every other industry. This fundamental characteristic makes generalizations difficult yet crucial for understanding its security posture.

The presentation highlights a stark paradox: manufacturers are exceptionally adept at their core business – producing goods efficiently and rapidly – but notoriously deficient in cybersecurity. This deficiency, rooted in a profit-and-production-driven mindset that often sidelines security investments, has led to an escalating crisis, particularly with the proliferation of ransomware. Chase’s talk serves as a critical examination of how this vital sector has been forced to confront its vulnerabilities, learn painful lessons, and begin to adapt its approach to an increasingly hostile digital landscape.

Background

▶ Watch: Manufacturing: Not a Vertical, but a Horizontal Modality (0:48)

Manufacturing has historically been at the forefront of technological innovation, with major epochs of human history often defined by advancements in production capabilities. From harnessing water and steam power to the widespread adoption of electricity and, more recently, digital automation, manufacturers have consistently embraced or even created technologies to improve efficiency, speed, and output. This relentless pursuit of optimization is driven by a core production and profit-motivated framework: the desire to produce "as many widgets as possible, as fast as possible, for the lowest unit cost per widget." This framework, while making manufacturers exceptionally good at what they do, inadvertently creates a blind spot for cybersecurity.

The problem, as Chase articulates, is that "cybersecurity doesn't make widgets." Consequently, when resource allocation decisions are made within this production-centric paradigm, security initiatives often lose out. This chronic under-resourcing has left the manufacturing sector acutely vulnerable, especially as its attack surface expands exponentially with increasing digitization and integration. The consequences of this neglect are now "coming home to roost," with cyberattacks posing significant threats to operational continuity and financial stability. The most prominent of these threats is ransomware, which has found a particularly fertile ground within the manufacturing industry.

Key Findings

▶ Watch: Profit-Driven Focus: How Manufacturers Prioritize Production (3:20)

Tim Chase identifies several critical reasons why ransomware operators specifically target manufacturers, making them a "sweet spot" for cybercriminals:

  1. Flat and Poorly Segmented Networks: Manufacturing networks are typically characterized by a lack of segmentation, meaning that a compromise in one area can quickly spread across the entire infrastructure. This flat architecture provides attackers with easy lateral movement once initial access is gained.
  2. Reliance on Enterprise Resource Planning (ERP) Systems: Many manufacturers heavily depend on centralized ERP systems that are accessed by personnel across the entire organization, from sales and front office staff to plant floor operators. These systems often connect the Information Technology (IT) environment directly to the Operational Technology (OT) environment, blurring traditional boundaries. As Chase explains, this reliance means that even an IT-only intrusion can have direct and devastating OT effects, halting production because critical orders or manufacturing files cannot be generated or accessed. This explains why many SEC 8K disclosures, while only referencing IT compromise, often correspond to significant operational downtime.
  3. Prompt Ransom Payments: Because a halt in production directly impacts their profit-driven model, manufacturers are often compelled to pay ransoms quickly to restore operations. This makes them attractive targets for ransomware groups who prioritize rapid monetization.
  4. Mid-Level Enterprise Sweet Spot: Ransomware operators often target mid-sized manufacturers. These organizations are typically large enough to afford a "decent-sized ransom" but often lack the sophisticated enterprise-grade security solutions and dedicated cybersecurity teams found in larger corporations. This combination makes them both profitable and relatively easier to exploit.

The data underscores this alarming trend. The Global Resilience Federation (GRF.org), where Chase's organization is a part, tracks ransomware incidents by scraping dark web leak sites. Their analysis, encompassing four years of data, reveals that manufacturing is by far the most targeted industry. Roughly two-thirds to three-quarters of all ransomware incidents are focused on manufacturers. This intense targeting has, paradoxically, forced many manufacturers to confront their security shortcomings and begin making more informed decisions, learning "lessons of the bad decisions they were making to start making good decisions."

Technical Deep Dive

▶ Watch: The Bad News: Why Manufacturers Neglect Cybersecurity (4:10)

Chase challenges conventional wisdom regarding IT/OT convergence in the manufacturing sector. He asserts that for the most part, this term "really doesn't apply to manufacturing." The reason is fundamental: "you can't converge something that was never separated." Unlike other critical infrastructures where IT and OT networks were historically air-gapped or distinct, many manufacturing networks were never meaningfully separated, either physically or logically. They simply evolved as a single, sprawling network used for both administrative functions (like email) and plant floor operations. This inherent lack of segregation means that the concept of "converging" distinct domains is often a misnomer in manufacturing contexts.

A significant trend observed by Chase is that manufacturing networks are becoming "less industrial" – not in terms of the endpoints or processes, but in their underlying network infrastructure. While the industrial nodes at the end of the line will still perform an industrial process and may utilize proprietary protocols, the networks connecting these nodes are transitioning from older, serial-based systems to more IP-centric networks. This shift is driven by the demands of modern technologies, particularly the integration of cloud-based infrastructure and AI/Machine Learning (ML) enablement. The sheer volume and speed of data required to transit these networks for advanced analytics and automation cannot be accommodated by simple serial connections.

To facilitate this transition while accommodating legacy equipment, manufacturers frequently employ converters or dongles. These devices bridge the gap between older industrial protocols, such as Modbus running over a serial connection, and modern IP networks. This allows existing machinery to remain operational within a more contemporary network architecture. While these converters enable necessary modernization and data flow, they also introduce new points of vulnerability and complexity, as they effectively translate between two distinct communication paradigms, potentially exposing legacy systems to new types of network-based attacks. The move towards IP-centric networks on the plant floor, potentially spanning multiple production facilities, represents a fundamental architectural change with profound implications for network security and monitoring.

Demo / Proof of Concept

▶ Watch: ERP Systems: IT Compromise Leading to OT Downtime (5:50)

The presentation focused on strategic insights and observations from the manufacturing sector's security landscape rather than a live demonstration of tools or exploits. No specific proof of concept or demo was detailed during the talk.

Defensive Implications

▶ Watch: Targeting Mid-Level Enterprises: The Ransomware Sweet Spot (6:40)

Given the unique challenges and vulnerabilities highlighted, manufacturing organizations must fundamentally re-evaluate their cybersecurity strategies. The "lessons learned" from pervasive ransomware attacks demand a shift from reactive measures to proactive, security-by-design principles.

First and foremost, the pervasive issue of flat networks must be addressed through robust network segmentation. Implementing zero-trust architectures and micro-segmentation can limit lateral movement for attackers, confining breaches to smaller, isolated zones. This involves creating logical or physical barriers between different operational areas, critical assets, and IT systems, thereby reducing the blast radius of any compromise.

Secondly, the deep reliance on ERP systems necessitates enhanced security controls around these critical applications. This includes strict access controls based on the principle of least privilege, multi-factor authentication for all users (especially those accessing from the plant floor), and continuous monitoring for anomalous activity within the ERP environment. Furthermore, organizations should explore architectural patterns that minimize direct connectivity between IT-managed ERP systems and critical OT processes, perhaps employing data diodes or one-way communication channels where feasible, to prevent IT compromises from directly impacting production.

Manufacturers must also internalize that cybersecurity is no longer a cost center but an essential enabler of continuous production and profitability. This requires a cultural shift at the executive level, prioritizing security investments comparable to other operational expenditures. Adequate resourcing for security teams, including training, tools, and personnel, is crucial. Developing and regularly testing incident response plans, particularly for ransomware scenarios, can significantly reduce downtime and recovery costs.

Finally, understanding the transition towards IP-centric networks in OT environments is paramount. Defenders must apply IT security best practices to these increasingly digitized industrial networks, including vulnerability management, patch management (where possible and safe for OT), network intrusion detection, and endpoint protection. The use of serial-to-IP converters, while enabling modernization, introduces new attack vectors that require specific attention, such as securing the converters themselves and monitoring the traffic that flows through them for malicious patterns. Organizations should also leverage threat intelligence from sources like the Global Resilience Federation (GRF.org) to stay informed about the latest ransomware tactics targeting their sector.

Key Takeaways

  • Manufacturing is a unique, interconnected horizontal: It underpins nearly all other industries, making its security vulnerabilities far-reaching.
  • Production-driven mindset hinders cybersecurity: The focus on efficiency and cost reduction often leads to chronic under-resourcing of cybersecurity, as it doesn't directly "make widgets."
  • Ransomware disproportionately targets manufacturing: Due to flat networks, reliance on ERP systems, willingness to pay, and the "mid-level enterprise" sweet spot, manufacturing accounts for 66-75% of all ransomware incidents.
  • IT/OT convergence is a misnomer for many: Manufacturing networks were often never truly separated, meaning the challenge isn't convergence but securing inherently integrated, often flat, environments.
  • Industrial networks are becoming IP-centric: The drive for cloud and AI integration is pushing manufacturing networks from serial to IP-based, demanding modern IT security practices in OT.
  • Proactive security is non-negotiable: Manufacturers must prioritize network segmentation, secure ERP systems, invest adequately in security, and adapt to the evolving IP-based OT landscape to survive and thrive.

About the Speaker(s)

Tim Chase is an experienced professional in critical infrastructure security, having dedicated over a decade to supporting vital sectors. His expertise primarily stems from his work within Information Sharing and Analysis Centers (ISACs) and Information Sharing and Analysis Organizations (ISAOs), where he has contributed to sector-specific information sharing initiatives. For the past two and a half years, Chase has been leading the manufacturing ISAC, gaining deep insights into the unique operational and cybersecurity challenges faced by this critical industry. His background provides him with a comprehensive understanding of the interplay between technological advancements, business drivers, and the evolving threat landscape in industrial environments.

All talks from DEF CON 32 Creator Stage