From Boardrooms to Polling Places: Securing Critical Infrastructure in 2024

RSA Conference 2024 · Track Session

Overview

In this compelling talk at RSAC 2024, Nadir Israel, CTO and co-founder of Armis, illuminated the escalating dangers confronting critical infrastructure in an increasingly volatile geopolitical landscape. Israel underscored that the threats extend far beyond traditional cybercriminal activities, now squarely placing every organization, from hospitals to energy grids, on the front lines of nation-state cyber warfare. The core premise of the presentation was a stark call to action: the cybersecurity industry must fundamentally shift from a reactive "detect and respond" posture to a proactive, preemptive strategy, focusing on comprehensive attack surface management and intelligent remediation.

Watch on YouTube

Visual summary for From Boardrooms to Polling Places: Securing Critical Infrastructure in 2024
Visual summary for From Boardrooms to Polling Places: Securing Critical Infrastructure in 2024

Key moments

  1. 0:00 Introduction to critical infrastructure dangers and Armis's mission
  2. 0:50 Unique challenges of securing critical infrastructure: old and new tech
  3. 1:30 Geopolitical shifts: cyber warfare is now overt and disruptive
  4. 2:25 Nation-state threats now target every critical infrastructure organization
  5. 3:10 Evolution of attacks: from Stuxnet to Colonial Pipeline disruption
  6. 4:20 The alarming, increasing rate of critical infrastructure attacks
  7. 4:50 Why current vulnerability response (CISA KEV) is too late

From Boardrooms to Polling Places: Securing Critical Infrastructure in 2024

Speakers: Nadir Israel, CTO and co-founder, Armis

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=bFgGEUd1Zmc

Overview

In this compelling talk at RSAC 2024, Nadir Israel, CTO and co-founder of Armis, illuminated the escalating dangers confronting critical infrastructure in an increasingly volatile geopolitical landscape. Israel underscored that the threats extend far beyond traditional cybercriminal activities, now squarely placing every organization, from hospitals to energy grids, on the front lines of nation-state cyber warfare. The core premise of the presentation was a stark call to action: the cybersecurity industry must fundamentally shift from a reactive "detect and respond" posture to a proactive, preemptive strategy, focusing on comprehensive attack surface management and intelligent remediation.

Armis, a company founded eight years ago to address the foundational problem of organizations lacking a clear understanding of their assets, attack surface, and the threats they face, has evolved its mission to tackle these complex challenges head-on. Israel detailed why critical infrastructure environments are uniquely vulnerable, characterized by a perilous blend of aging operational technology (OT) never designed for internet connectivity, alongside modern, interconnected systems. This creates a massive, dynamic, and often unknown attack surface that attackers are relentlessly exploiting.

The talk emphasized that while the concept of securing critical infrastructure isn't new, the urgency and nature of the threats have dramatically intensified. Geopolitical shifts have transformed cyber warfare from clandestine intelligence operations into highly disruptive, broad-daylight campaigns. This article delves into Israel's analysis of the current threat landscape, the systemic failures of existing security paradigms, and the actionable strategies, including leveraging Artificial Intelligence (AI) and advanced early warning systems, that organizations must adopt to secure the vital systems underpinning modern society.

Background

▶ Watch: Introduction to critical infrastructure dangers and Armis's mission (0:00)

The security of critical infrastructure has always been a paramount concern, yet Nadir Israel highlighted that the problem has reached an unprecedented scale and complexity in 2024. Critical infrastructure sectors — ranging from healthcare and energy to transportation and electoral systems — share fundamental vulnerabilities despite their diverse operations. A significant portion of the technology operating within these environments was designed and built 40 or more years ago, predating the modern internet. These legacy systems were never intended to be interconnected, yet economic pressures and operational efficiencies have led to their integration with modern IT networks and the internet, creating a sprawling, heterogeneous, and inherently insecure environment. This blend of antiquated, often unpatchable, systems with cutting-edge technologies creates a massive, often opaque attack surface.

The geopolitical landscape has dramatically altered the nature of cyber threats. Israel pointed out that the days of cyber warfare being conducted "under the covers" as intelligence operations are long gone. The turning point, he suggested, was around 2017 with events like NotPetya, which demonstrated the potential for widespread, indiscriminate destruction. Since then, and particularly during the COVID-19 pandemic, attacks on critical infrastructure, such as hospitals, have become commonplace, no longer considered off-limits. Nation-state actors and their affiliated groups are now actively and openly targeting these sectors, making every organization, regardless of its perceived political neutrality, a potential frontline target. This shift means that the average CISO can no longer dismiss nation-state threats as someone else's problem.

Historical attacks underscore this evolution. Israel cited Stuxnet, a sophisticated attack from over a decade ago, as a "world-defining event" that first exposed critical infrastructure companies to the reality of dormant, persistent threats within their Operational Technology (OT) environments. While Stuxnet primarily served as a surgical, nation-state-level strike, later incidents like the Colonial Pipeline attack demonstrated a new era of "highly disruptive, no longer something that's under the covers" attacks. These modern campaigns aim for maximum disruption and financial gain, often in broad daylight. The rate of these attacks is significantly increasing, driven by geopolitical tensions, technological advancements, the proliferation of vulnerabilities, and the growing cost-effectiveness for attackers.

Compounding these challenges is the industry's predominantly reactive approach to security. Israel criticized the reliance on mechanisms like CISA KEV (Known Exploited Vulnerabilities), which he described as fundamentally too late. CISA KEV feeds, while valuable, typically report vulnerabilities after they have been weaponized and exploited in active campaigns. By the time a vulnerability is reported and security firms develop countermeasures, a weaponized exploit is already circulating "across the board." This delayed response means organizations are perpetually scrambling to limit damage, highlighting a critical need for a paradigm shift in how security is approached.

Key Findings

▶ Watch: Geopolitical shifts: cyber warfare is now overt and disruptive (1:30)

Nadir Israel's talk identified several critical findings that underscore the urgent need for a strategic overhaul in securing critical infrastructure. The central finding revolves around the inadequacy of the industry's prevailing "detection and response" model. While detection tools make organizations "feel safe" by promising to identify threats in real-time, Israel argued that this focus is misplaced, addressing symptoms rather than root causes. The reality, he asserted, is that by the time an attack reaches the "launch part" — the point where most detection tools become active — it's often "far too late" to prevent significant damage, as evidenced by incidents like the Change Healthcare attack. Such events quickly overwhelm existing security controls, leading to "infinite damage" in terms of financial loss, reputational harm, and customer trust.

A core problem highlighted is the sheer scale and complexity of the attack surface. Israel described it as "massive," "constantly changing," "ever dynamic," and possessing "multiple layers." Crucially, a significant portion of this attack surface remains unknown to organizations. While security teams might understand their core IT assets, the vast sprawl of cloud environments, IoT devices, OT systems, and third-party dependencies often creates a "black hole" of unmanaged and unmonitored exposure. This lack of visibility is a fundamental barrier to effective security.

Perhaps the most alarming finding presented was the critical disparity between the speed of exploit weaponization and the average time to remediation. Israel stated that a zero-day exploit typically becomes weaponized and actively used by threat actors within "around seven days on average." In stark contrast, the mean time to remediation (MTTR) for critical vulnerabilities within an average enterprise is a staggering "197 days." This creates a "full 190 days" window during which critical infrastructure organizations are acutely vulnerable to known, weaponized threats. This massive gap provides attackers ample time to infiltrate, establish persistence, move laterally, and achieve their objectives before defenders can even patch the initial vulnerability.

The talk further dissected the typical attacker methodology, revealing a multi-stage process that capitalizes on this remediation lag. Attackers spend "months of recon" to understand their target, followed by "months" for initial intrusion and establishing a beachhead. Lateral movement within the compromised environment can take "weeks to months," depending on the target's complexity. The actual "launch" of the attack — be it ransomware, data exfiltration, or operational disruption — often takes only "days or even less." Current security, focusing heavily on this final "launch" phase, misses the vast majority of the attacker's operational timeline, allowing them to operate with impunity for extended periods.

Ultimately, Israel's key finding is that the industry must shift from a reactive, detection-centric approach to a proactive, prevention-first strategy. He posited that "the boring basics" — knowing your assets, understanding your attack surface, and intelligently remediating vulnerabilities — are what truly keep organizations safe. If something "isn't vulnerable in the first place, it's not vulnerable," highlighting the superior effectiveness and cost-efficiency of proactive measures over post-breach detection and response.

Technical Deep Dive

▶ Watch: Nation-state threats now target every critical infrastructure organization (2:25)

The technical deep dive of the talk focused on dissecting the multifaceted problem of the attack surface and proposing a proactive, intelligent approach to its management. Israel described the attack surface not as a flat entity but as a complex, multi-layered construct. At its core, organizations might have an "innermost layer" of assets that are known, understood, and adequately secured through patching or mitigating controls. However, beyond this, the layers quickly become problematic.

The next layer comprises assets that are "known to exist" but are also "known that it's exposed" due to a lack of mitigating controls. These are typically vulnerabilities sitting in a remediation queue, awaiting action. The critical issue here is the exceptionally long mean time to remediation (MTTR), which Israel quantified at 197 days on average for critical vulnerabilities in enterprises. This extended period leaves organizations exposed to weaponized exploits that emerge within a mere seven days of discovery. This 190-day window is a significant strategic advantage for attackers.

Further out, the attack surface includes assets that are known to exist, but their exposure status is uncertain, creating challenges in prioritization. The outermost and most perilous layer consists of assets that are simply "unknown." This "black hole" encompasses a vast array of elements across networks, cloud environments, Operational Technology (OT), Internet of Things (IoT) devices, and third-party connections. This layer represents the greatest blind spot, as organizations cannot secure what they do not know exists. Israel stressed that while this unknown surface is enormous, it is "still discrete," "finite," and "quantifiable" with dedicated effort, emphasizing the importance of these "boring basics."

The talk then delved into the attacker's operational timeline to illustrate why reactive security fails. An attack typically begins with "months of recon" to gather intelligence on the target's infrastructure, vulnerabilities, and personnel. This is followed by "months" dedicated to initial intrusion, gaining a foothold, and solidifying their presence. Once inside, attackers engage in "weeks to months" of lateral movement to escalate privileges, map the internal network, and identify high-value targets. The actual "launch" of the attack — the ransomware deployment, data exfiltration, or system disruption — often takes "days or even less." The critical insight here is that most security tools and strategies are designed to detect this final "launch" phase, by which point the attacker has already spent months or weeks within the environment, often disabling security controls and achieving their objectives.

To counter this, Israel advocated for the concept of early warning systems in cybersecurity, a principle borrowed from other industries but historically underemphasized in security. The goal is to "stop certain attacks well before they even happen." This proactive stance requires not only comprehensive visibility into one's own attack surface but also intelligence about emerging threats before they become public.

A significant opportunity in this shift, according to Israel, lies in the intelligent application of Artificial Intelligence (AI), particularly Generative AI (GenAI). He argued that AI can transform "a quote-unquote dumb data set into a contextual entity," enabling the understanding of complex environmental aspects and facilitating a "great degree of automation." Historically, the security industry has been hesitant about heavy automation, fearing mistakes and preferring a "human last mile switch." However, with attacks becoming "fast, scalable, AI-driven," Israel asserted that defenders "can't afford to not use all the data at our disposal and use AI and use heavy degrees of automation." This paradigm shift in automation is crucial for moving the defensive timeline forward and providing the necessary early warning.

Demo / Proof of Concept

▶ Watch: The alarming, increasing rate of critical infrastructure attacks (4:20)

The provided transcript does not include any mention of a live demonstration or a proof of concept. The speaker focused on conceptual frameworks, statistical data, and strategic shifts required to address critical infrastructure security challenges.

Defensive Implications

▶ Watch: Why current vulnerability response (CISA KEV) is too late (4:50)

The defensive implications derived from Nadir Israel's talk are clear and demand a fundamental reorientation of cybersecurity strategy for critical infrastructure organizations. The paramount shift required is from a predominantly reactive "detection and response" model to a proactive, prevention-first approach. Defenders must prioritize the "boring basics" of security, which, when performed intelligently, are far more effective and cost-efficient than reacting to active breaches.

1. Comprehensive Attack Surface Management: The first and most critical step is to gain complete visibility into the entire attack surface. This means moving beyond known IT assets to discover, quantify, and understand every connected device and system. This includes Operational Technology (OT), Internet of Things (IoT), cloud environments, mobile devices, and all third-party and supply chain dependencies. Organizations must actively map and monitor these assets to eliminate the "black hole" of unknown exposures. This effort is foundational, as you cannot secure what you do not know you have.

2. Intelligent Vulnerability Management and Accelerated Remediation: Given the perilous gap between exploit weaponization (7 days) and average enterprise remediation time (197 days), defenders must drastically reduce their mean time to remediation (MTTR). This requires intelligent prioritization of vulnerabilities, focusing on those that are actively exploited or pose the highest risk to critical operations. Leveraging context about asset criticality, exposure, and threat intelligence can help streamline patching and mitigation efforts, ensuring that the most dangerous weaknesses are addressed well before attackers can exploit them.

3. Embrace AI and Automation: The talk strongly advocates for the strategic adoption of Artificial Intelligence (AI) and Generative AI (GenAI). Defenders must overcome historical reluctance to implement heavy automation. AI can analyze vast datasets, identify complex patterns, and provide contextual insights that human analysts cannot achieve alone. GenAI, in particular, can transform raw, "dumb data" into actionable intelligence, enabling autonomous security operations. This is essential to counter the increasing speed and scale of AI-driven attacks from adversaries, allowing defenders to "move the needle" forward in the security timeline.

4. Implement Early Warning Systems: To truly shift to a proactive stance, organizations need to develop and integrate early warning systems. This involves actively monitoring the threat landscape outside the perimeter before attacks even reach the intrusion phase. Two key methods were suggested:

  • External Honeypots: Deploying honeypots "around the world" can lure in and observe attacker techniques, tactics, and procedures (TTPs) before they are used against the organization's actual infrastructure. This provides valuable intelligence on emerging threats and attack vectors.
  • Weapon Test Tracking: Actively monitoring for attacker "weapon tests" — the pre-deployment testing of exploits — can provide crucial lead time. Israel noted that these tests often occur in specific geographic regions (e.g., Brazil, Africa) before global deployment. Gaining intelligence from these tests allows defenders to proactively prepare and mitigate threats before they are fully weaponized and unleashed.

By adopting these proactive strategies, critical infrastructure organizations can move beyond merely reacting to breaches and instead build resilient defenses that anticipate and prevent attacks, securing the vital services they provide.

Key Takeaways

  • Critical Infrastructure Under Siege: Critical infrastructure sectors face an escalating and highly disruptive threat landscape, driven by geopolitical shifts and nation-state actors, where every organization is now on the front lines, making proactive defense non-negotiable.
  • Reactive Security is Insufficient: The industry's current reactive "detection and response" model, exemplified by mechanisms like CISA KEV, is fundamentally too late; it addresses threats only after they are weaponized and actively exploited, leading to significant and often irreversible damage.
  • The Critical Remediation Gap: There is a dangerous 190-day window between the average time for a zero-day exploit to become weaponized (around 7 days) and the average enterprise's mean time to remediation (MTTR) for critical vulnerabilities (197 days), leaving critical infrastructure highly vulnerable for extended periods.
  • Proactive Attack Surface Management is Paramount: A shift to a proactive security stance is essential, focusing on comprehensive attack surface management to discover, quantify, and intelligently remediate vulnerabilities across all IT, OT, IoT, and cloud assets, including the often-overlooked "unknown" elements.
  • Leverage AI for Automation and Context: Organizations must embrace Artificial Intelligence (AI) and Generative AI (GenAI) to transform raw data into contextual intelligence, enabling heavy automation in security operations. This is crucial for matching the speed and scale of increasingly AI-driven adversary attacks.
  • Build Early Warning Systems: Implementing early warning systems, such as deploying external honeypots and actively tracking adversary "weapon test deployments" in various global regions, provides critical lead time to anticipate and mitigate threats before they impact an organization's environment.

About the Speaker(s)

Nadir Israel is the CTO and co-founder of Armis, a company established eight years ago with a foundational mission to address a critical gap in organizational security: the lack of understanding regarding their assets, attack surface, and the threats they face. Armis's initial focus was on helping organizations answer the fundamental question, "What do I have?" This core capability has since evolved, becoming particularly relevant in the complex and rapidly changing threat landscape surrounding critical infrastructure today. Israel's expertise lies in identifying systemic security challenges and developing proactive solutions to safeguard essential services.

All talks from RSA Conference 2024