Legal Realities of US Government OT Cybersecurity Regulation
Shari Gribbin
S4x24 - ICS Security Conference · Day 2 · Stage 2
Overview
Shari Gribbin’s talk at S4 explored the rapidly escalating and increasingly complex legal risks confronting organizations in the realm of Operational Technology (OT) cybersecurity within the United States. As a seasoned regulatory lawyer, Gribbin illuminated the profound shift from a largely self-regulated cybersecurity environment to one now heavily influenced by government mandates, legislation, and a burgeoning wave of lawsuits. Her primary objective was to equip attendees with a foundational framework to navigate this intricate legal landscape, emphasizing the critical need to integrate legal considerations into existing cyber programs and operational strategies.

Key moments
- 0:28 Introduction: Tackling rapidly expanding legal risk
- 1:25 The 'Lawyers Have Arrived': Chaos, bad law, lawsuits
- 2:09 The 'Lawyers Have Arrived': Good for advocacy, prioritizing security
- 2:43 Lessons from NERC SIP: Integrate lawyers for better regulation
- 3:45 Financial market pressure (Moody's, SEC) on cyber security
- 4:50 Proposed framework for cyber security legal risk landscape
Legal Realities of US Government OT Cybersecurity Regulation
Speakers: Shari Gribbin
Conference: S4
YouTube: https://www.youtube.com/watch?v=6vd_Vk44pTI
Overview
Shari Gribbin’s talk at S4 explored the rapidly escalating and increasingly complex legal risks confronting organizations in the realm of Operational Technology (OT) cybersecurity within the United States. As a seasoned regulatory lawyer, Gribbin illuminated the profound shift from a largely self-regulated cybersecurity environment to one now heavily influenced by government mandates, legislation, and a burgeoning wave of lawsuits. Her primary objective was to equip attendees with a foundational framework to navigate this intricate legal landscape, emphasizing the critical need to integrate legal considerations into existing cyber programs and operational strategies.
The talk underscored that the legal profession is no longer a peripheral player in cybersecurity; lawyers are now at the forefront, shaping policy and influencing corporate liability. While this shift brings challenges—such as a flood of "bad law" drafted by inexperienced legal professionals and a diversion of resources from core security functions—it also presents significant opportunities. Gribbin highlighted that strategically involving experienced legal counsel can serve as a powerful advocacy tool, helping security teams secure necessary resources and design robust programs that withstand legal scrutiny.
Crucially, Gribbin connected the burgeoning legal risks to tangible financial impacts. With major financial institutions like Moody's now factoring cybersecurity risk into shareholder value assessments, and the Securities and Exchange Commission (SEC) introducing disclosure regulations that hold C-suite executives accountable, the financial imperative for robust OT cybersecurity has never been stronger. This confluence of regulatory pressure, legal liability, and financial accountability necessitates a proactive and integrated approach, where regulatory compliance, often viewed as a burden, can be strategically leveraged as a "shield" against broader legal exposures.
Background
▶ Watch: Introduction: Tackling rapidly expanding legal risk (0:28)
For much of its history, the field of cybersecurity, particularly within Operational Technology (OT) environments, operated with minimal direct intervention from the legal sector. Security professionals often focused on technical controls, threat intelligence, and incident response, largely independent of rigorous legal frameworks. However, as Shari Gribbin articulated, "the lawyers arrived," marking a pivotal and irreversible shift in the cybersecurity landscape. This arrival is characterized by what Gribbin describes as "chaos"—a proliferation of new regulations, legislative mandates, and a significant escalation in lawsuits targeting organizations for cybersecurity failures.
A core problem stemming from this rapid influx of legal attention is the emergence of "cybersecurity lawyers" who, despite their legal background, often lack deep technical understanding or practical cybersecurity experience. This can lead to the drafting of "bad law" or contractual terms that are impractical, misaligned with operational realities, or ultimately detrimental to effective security. Such poorly conceived legal instruments not only fail to enhance security but can also divert critical resources, shifting focus from genuine security improvements to compliance with ill-fitting mandates.
Gribbin drew a significant lesson from her extensive experience in the grid sector, which has been subjected to heavy NERC Critical Infrastructure Protection (CIP) regulations for over 15 years. These regulations cover both cyber and physical security within the electric power industry. A key takeaway from this long history of regulation was that in the early stages, lawyers were often absent from the table when these critical regulations were being drafted. This omission led to significant challenges during enforcement, as the language and structure of the regulations were not optimized for legal interpretation or defensibility. The speaker emphasized that integrating legal expertise during the drafting phase can lead to more effective, enforceable, and ultimately beneficial regulations.
Beyond direct government regulation, the financial markets have also become a powerful catalyst for change. Gribbin cited a Moody's report from the previous fall, which directly informed boards and C-suites that cybersecurity risk now has a major impact on shareholder value. Concurrently, the SEC disclosure regulations have introduced a new layer of accountability for executive leadership regarding cybersecurity incidents and risk management. While these initial SEC regulations might be "a little bit soft," they represent a clear trend towards greater corporate responsibility. This financial pressure creates a "fast track" for security teams to secure funding and prioritize initiatives that were previously "screaming into the void."
The talk also highlighted the dangers of misapplying voluntary frameworks, such as those developed by NIST, in legally binding contexts. Gribbin noted a common practice where contract lawyers would "copy-paste" terms from these frameworks into product and services agreements or even insurance policies. The fundamental issue is that voluntary frameworks are designed for guidance and best practices, not as precise legal constructs for enforcement in a lawsuit. When these terms are litigated, their inherent flexibility and lack of legal specificity can become a significant liability. Furthermore, simply having a program that states, "have a plan, follow it," is a "trap." As Gribbin illustrated with the example of patching, different Subject Matter Experts (SMEs) will interpret and execute a general mandate in varying ways, leading to inconsistent application and making it incredibly difficult to prove consistent compliance in a legal challenge. This underscores the need for clarity, specificity, and rigorous internal governance, even in supposedly "voluntary" programs.
Key Findings
▶ Watch: The 'Lawyers Have Arrived': Good for advocacy, prioritizing security (2:09)
The core message from Shari Gribbin's presentation is that the era of cybersecurity operating in a legal vacuum is definitively over. The talk delineated several critical findings that underscore the current state and future trajectory of legal involvement in OT cybersecurity:
- Ubiquitous Legal Scrutiny: Lawyers are now deeply embedded in the cybersecurity landscape, with a surge in regulations, legislation, and lawsuits impacting OT environments from multiple directions. This signifies a permanent shift from voluntary guidelines to legally binding mandates.
- The Double-Edged Sword of Legal Involvement: While the influx of legal professionals can lead to "bad law" drafted by those lacking technical understanding and can divert resources, experienced legal counsel can serve as powerful advocates. They can help design robust, legally defensible security programs and influence the creation of more effective regulations.
- NERC SIP as a Precedent: The NERC CIP regulations in the grid sector offer a crucial historical lesson. Early regulations, drafted without sufficient legal input, created enforcement difficulties. Conversely, the collaborative nature of NERC's later regulatory design process, when lawyers became involved, demonstrated the potential for crafting more meaningful and enforceable standards.
- Financial Markets as a Compliance Driver: Cybersecurity risk is no longer solely an IT or OT problem; it's a significant financial risk. The Moody's report and SEC disclosure regulations directly link cyber incidents to shareholder value and executive accountability. This financial leverage is a powerful tool for security professionals to prioritize and secure resources for their initiatives.
- Inadequacy of Voluntary Frameworks in Legal Contexts: Frameworks like NIST, while valuable for best practices, are not designed as legal contracts. Copy-pasting their terms into agreements (e.g., product/services, insurance) creates unenforceable clauses and significant legal vulnerabilities during litigation. Legal constructs require specific, unambiguous language tailored for enforcement.
- The "Have a Plan, Follow It" Trap: Vague directives for security programs are insufficient for legal defense. Without precise definitions of "best practice" or consistent execution, different Subject Matter Experts (SMEs) will interpret and implement controls differently. This inconsistency makes it nearly impossible to prove due diligence or adherence to a standard in court, exposing organizations to liability.
- Regulatory Compliance as a Strategic Shield: Despite the common aversion to regulatory burdens, Gribbin argued that proactive and intelligent engagement with regulatory compliance can act as a "shield." By diligently meeting regulatory requirements, organizations can establish a strong legal defense that mitigates broader liability risks from lawsuits, contractual disputes, and shareholder actions.
These findings collectively highlight the urgent need for OT organizations to adopt a sophisticated, legally informed approach to cybersecurity, moving beyond purely technical considerations to embrace a holistic risk management strategy that integrates legal expertise from the outset.
Technical Deep Dive
▶ Watch: Lessons from NERC SIP: Integrate lawyers for better regulation (2:43)
While the talk did not delve into traditional cybersecurity "technical deep dives" involving code or specific exploits, it provided a profound "legal deep dive" into the mechanisms and structures of US government OT cybersecurity regulation and its broader legal implications. Gribbin meticulously broke down the legal risk landscape into two interconnected "lanes": direct regulation and other pervasive legal risks, offering a framework for understanding and mitigating them.
The first lane, Regulation, is characterized by a deluge of mandates emanating from various government bodies. The speaker acknowledged that this is often the most disliked lane, but also the one that can be most effectively leveraged as a defense. The primary example discussed was the NERC Critical Infrastructure Protection (CIP) regulations governing the North American electric grid. These regulations mandate specific cybersecurity and physical security controls for critical assets. Gribbin, drawing from over two decades of experience as a regulatory lawyer in this sector, described NERC as one of the most rigorous regulators, second only to the Nuclear Regulatory Commission (NRC). She highlighted that while NERC regulations are often viewed with "eye rolls" by SMEs, their development process, especially in later stages, offers a unique opportunity for collaborative design, allowing industry and legal experts to shape meaningful and enforceable standards. The crucial lesson from NERC's history was the early absence of legal counsel during regulation drafting, which led to significant enforcement challenges. This underscores the necessity of integrating legal expertise from the inception of regulatory frameworks.
The second lane encompasses "other legal risks" that often go unnoticed until an organization faces a lawsuit. These include issues arising from product and services agreements, insurance policies, and shareholder obligations. A significant problem identified here is the widespread practice of copy-pasting voluntary cybersecurity framework terms (such as those from NIST) directly into legally binding contracts. Gribbin, having personally encountered such agreements, stressed that voluntary frameworks are fundamentally different from legal constructs. They are designed for flexibility and guidance, not for the precise interpretation and enforcement required in a court of law. When these terms are integrated verbatim into contracts, they become ambiguous, open to multiple interpretations, and ultimately a "nightmare" to enforce or defend against in litigation. This often stems from contract lawyers lacking deep cybersecurity understanding.
A critical nuance within this second lane is the concept of a program that merely states, "have a plan, follow it." Gribbin termed this a "trap" for organizations. Using the example of a patching program, she illustrated that if five SMEs are asked to design or describe the "best" patching program, they will likely provide ten different answers, and those answers may change daily. Without specific, legally sound definitions and documented procedures, such a program—even if executed in good faith—becomes legally indefensible. In the event of a breach or lawsuit, it becomes incredibly difficult to prove consistent application of controls or adherence to a reasonable standard of care when interpretations vary widely. This exposes organizations to liability, particularly in the context of shareholder class action suits, where plaintiffs' lawyers can easily allege negligence or failure to protect assets, even if the security team believed they were "following the plan."
The talk also detailed the growing influence of financial market and credit institutions. Gribbin referenced a Moody's report that directly communicated to boards and C-suites about the significant impact of cybersecurity risk on shareholder value. This is further reinforced by the SEC disclosure regulations, which, although currently "a little bit soft," are evolving to hold executive leadership increasingly accountable for cybersecurity incidents and risk management. This financial pressure creates a powerful incentive for organizations to elevate cybersecurity priorities and allocate necessary resources, as failure to do so can directly impact stock prices and corporate reputation, leading to legal action from shareholders.
In essence, the "technical deep dive" revealed that effective OT cybersecurity in the current legal climate requires a sophisticated understanding of how regulatory language, contractual terms, and corporate governance intersect. It demands moving beyond a purely technical checklist approach to security and instead embedding legal foresight into every aspect of program design, implementation, and documentation. The goal is to create programs that are not only technically sound but also legally robust and defensible.
Demo / Proof of Concept
▶ Watch: Financial market pressure (Moody's, SEC) on cyber security (3:45)
Given the nature of the talk, which focused on legal and regulatory frameworks rather than technical exploits or security tools, there was no live demonstration or proof of concept presented. The speaker's objective was to provide a conceptual framework for navigating legal risks in OT cybersecurity rather than showcasing a technical solution.
Defensive Implications
▶ Watch: Proposed framework for cyber security legal risk landscape (4:50)
The insights shared by Shari Gribbin offer crucial guidance for organizations seeking to fortify their Operational Technology (OT) cybersecurity posture against escalating legal risks. Defenders must recognize that legal compliance is no longer a separate, secondary concern but an integral component of a robust security strategy.
- Integrate Legal Expertise Early and Strategically: The most significant defensive implication is the imperative to bring experienced legal counsel to the table from the very beginning. This means involving lawyers not just during incident response or after a lawsuit, but during the design of cybersecurity programs, the drafting of internal policies, and especially during the development of industry regulations. Lawyers with a deep understanding of cybersecurity and OT can help craft programs that are not only technically sound but also legally defensible, ensuring that controls are enforceable and withstand scrutiny. This proactive engagement can prevent "bad law" and ensure that regulatory requirements are practical and effective.
- Rethink "Voluntary" Programs and Governance: Organizations relying on voluntary frameworks like NIST must fundamentally re-evaluate their implementation. A voluntary program, if not backed by rigorous internal governance and compliance functions, is likely to be inconsistent and legally vulnerable. Defenders must establish clear, documented procedures, ensure consistent execution across all Subject Matter Experts (SMEs), and maintain meticulous records of compliance activities. This includes regular internal audits and clear lines of responsibility to prove due diligence in a legal context. Simply having a program is insufficient; proving its consistent and effective execution is paramount.
- Scrutinize and Customise Contractual Language: A critical defensive measure is to meticulously review and customize all product and services agreements and insurance policies. Organizations must cease the practice of blindly copy-pasting terms from general cybersecurity frameworks into legal contracts. Instead, legal teams, in conjunction with security experts, should draft specific, unambiguous contractual clauses that reflect the unique OT environment, clarify responsibilities, define acceptable risk, and are legally enforceable. This precision protects against contractual disputes and ensures that insurance coverage aligns with actual risks and liabilities.
- Define Cybersecurity Programs with Legal Specificity: General directives like "have a patching program" are a "trap." To mitigate legal risk, cybersecurity programs must be defined with sufficient specificity to minimize ambiguity and ensure consistent execution. This involves detailing patching frequencies, acceptable risk tolerances, review processes, and roles and responsibilities. While allowing for necessary operational flexibility, the underlying documentation must clearly articulate the "why" and "how" of security decisions, providing a clear audit trail and legal defense should an incident occur.
- Leverage Financial Accountability for Resource Allocation: Defenders should strategically use the newfound financial and shareholder accountability for cybersecurity (as highlighted by Moody's and SEC regulations) to advocate for increased resources and executive prioritization. By framing cybersecurity investments as a means to protect shareholder value and mitigate executive liability, security leaders can secure the funding and support needed for critical OT security initiatives. This elevates cybersecurity from a technical cost center to a critical business risk management function.
- Utilize Regulation as a "Shield": While regulatory compliance can be burdensome, organizations should view it as a strategic "shield." By diligently meeting NERC CIP or other industry-specific regulatory requirements, organizations establish a baseline of due care and demonstrate a commitment to security. This documented compliance can serve as a powerful defense against broader lawsuits, including shareholder actions, by demonstrating that the organization met or exceeded established industry standards and legal obligations. Proactive engagement with regulators can also lead to more favorable and effective regulatory outcomes.
In summary, defensive strategies in OT cybersecurity must evolve to encompass a deep understanding of legal realities. This means fostering a collaborative environment between security, legal, and executive teams to build programs that are not only technically resilient but also legally robust and financially justified.
Key Takeaways
- The legal landscape for OT cybersecurity has fundamentally shifted, characterized by an unprecedented surge in regulations, legislation, and lawsuits, making legal expertise indispensable.
- Integrating experienced legal counsel early in the design and implementation of cybersecurity programs and regulatory frameworks is crucial for creating effective, enforceable, and legally defensible controls.
- Voluntary cybersecurity frameworks, while valuable for guidance, are not suitable for direct inclusion in legal contracts; their terms must be carefully adapted and specified to ensure legal enforceability and avoid liability traps.
- Cybersecurity programs must move beyond vague mandates to include precise, documented procedures and consistent execution across all personnel to withstand legal scrutiny and prove due diligence.
- The growing focus from financial markets (e.g., Moody's report) and regulatory bodies (e.g., SEC disclosure regulations) on cybersecurity's impact on shareholder value provides a powerful lever for security professionals to advocate for resources and prioritize initiatives.
- Proactive and strategic engagement with regulatory compliance, though often perceived as a burden, can serve as a robust legal "shield" against broader liabilities arising from lawsuits and contractual disputes.
About the Speaker(s)
Shari Gribbin is a highly experienced regulatory lawyer with over 20 years in the field. Her expertise stems significantly from her work in the grid sector, where she has been intimately involved with the complex NERC Critical Infrastructure Protection (CIP) regulations governing both cyber and physical security. This extensive background provides her with a unique perspective on the practical challenges and strategic opportunities presented by cybersecurity regulation, enabling her to offer valuable insights into integrating legal considerations into operational security programs.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This session by Shari Gribbin is a critical, no-nonsense legal deep dive into the rapidly evolving landscape of OT cybersecurity regulation. It masterfully dissects the shift from a self-regulated environment to one dominated by legal mandates, financial accountability, and the severe implications for organizations. Gribbin's experience in the NERC CIP sector provides invaluable, insider perspective, offering practical strategies to integrate legal expertise, leverage financial pressures, and use compliance as a strategic shield against burgeoning liabilities. This isn't just "awareness"; it's a detailed, actionable blueprint for navigating an uncomfortable but unavoidable reality.
Heather Calloway (CISO) — MUST SEE
Shari Gribbin's talk is a critical examination of the fundamental shift in OT cybersecurity from a technical discipline to a legally entangled business risk. She clearly articulates the imperative for security leaders to integrate legal counsel strategically, leveraging financial market pressures and regulatory compliance as shields against liability. This isn't just theory; it's a practical framework for CISOs to redefine their programs, ensuring they are not only technically sound but also legally robust and defensible at the board level.