I help security engineering grow up. CTO @admeritia, research @HSUHamburg, leader @securePLC, board member @SuK_Community, @ISA_Interchange & @KDW_NRW. Blog 👇

Germany
If we understand (ICS) security by design as integrating security into an existing engineering workflow, I expected us to end up with.....some new kind of workflow. Well...we didn't. Here's a first intro to our security by design decisions approach. link.medium.com/Xb2aJi5Lprb
4
11
Sarah Fluchs retweeted
The 3rd edition of the Operational Technology Cybersecurity Expert Panel (OTCEP) Forum will be held from 22 to 23 August 2023. Stay tuned for registration details!
2
3
1
996
Sarah Fluchs retweeted
"You will always be lacking something... youre already more technical than you think, it doesn't take a dozen stickers on your laptop" Great advice from Sarah Fluchs @admeritia
2
5
583
Sarah Fluchs retweeted
What is considered a 'High Consequence Event' should be a management decision, and engineers should work towards avoiding them. - Sarah Fluchs of @admeritia at #S4x23
1
5
495
Sarah Fluchs retweeted
"You're a human in #ics. Don't feel like you need to be over technical to compensate, don't feel like you need you be all soft skills." @SarahFluchs offers great advice! @admeritia
1
3
318
Finally at @S4xNews #S4x23 again this year! I'm already starting to feel Miami vibes 🌴.
3
17
999
Excellent additions for your reading lists 🤓
My brother is getting into cyber security coming from some IT experience in the military a few years back. He's looking for Audible recommendations. I already sent him Sandworm and The Art of Attack. What else would you recommend for learning while commuting?
326
Sarah Fluchs retweeted
Also...🇩🇪
1
1
246
Sarah Fluchs retweeted
From a @SarahFluchs comment, whenever anyone asks why something is a certain way in ICS I'm just going to tap on this sticker...😂
3
2
10
689
Everyone wants #SecurityByDesign...but what does that mean? And how do you do it? Full research paper at ResearchGate: researchgate.net/publication… IEEE Xplore: ieeexplore.ieee.org/document…
1
4
7
717
Sarah Fluchs retweeted
One of my fav 🎙 podcasts 🎙 of the year: @SarahFluchs of the @securePLC coding practices list. okt.to/XcmE9n @Claroty
2
3
Yes, so much to be thankful for in the OT community indeed! Thanks for the shoutout @ron_fab.
Shoutz to @INL @andybochman & #SarahFreeman @NRECANews @digitalbond @SarahFluchs / @ControlsCyber @insaneforensics / @dan_gunter So thankful for you and the community in 2022 and beyond!
1
hi #cybersec bubble, welche cybersec Frauen* sollte man in DE unbedingt auf dem Schirm haben? Lasst mir mal Eure Empfehlungen als reply da, mit u ohne twitter bzw mastodon handle! #followerpower
13
7
36
Germany removed the president of Federal Office for Information Security @BSI_Bund: Here's what you need to know. #cyberclown More importantly, we need to talk about hype mechanisms that turn critical infrastructure security into a political battle term. medium.com/@fluchsfriction/c…
1
1
Inhaltlich ist zu #Cyberclown alles gesagt. Aber nun, da "Security kritischer Infrastrukturen" zum politischen Kampfbegriff wird, müssen wir darüber reden, wie wir öffentlich über Cybersecurity reden: medium.com/@fluchsfriction/c…
15 years ago my PhD advisor taught me One Weird Trick for editing your own writing. Edit **back to front**, paragraph by paragraph. I still use it and it still surprises me how well it works. When I get my students to do it, it often blows their minds. Try it!
752
10,074
89,041
Sarah Fluchs retweeted
🎙 @SarahFluchs, CTO @admeritia, joins the Aperture podcast to discuss the Top 20 Secure PLC Coding Practices list, how engineers are using it to improve PLC security, and more! @Mike_Mimoso Listen: okt.to/XcmE9n Download the list @securePLC: okt.to/p0EFP2
12
20
Sarah Fluchs retweeted
How Bezos makes decisions: Is it a one-way or two-way door? One-way = can't reverse so make them slowly and carefully Two-way = reversible so make them fast Most big companies die by using the slow one-way door process for a two-way decision. (2015)
7
36
272
Top20 now have an interactive dashboard!🥳 You know you have an active community around @securePLC when one of its members (Dan Ricci) reaches out saying "hey, I know a better way of viewing the Top 20 than in a pdf doc" - and already has it implemented. plc-security.com
2
5
16
This was fun. @Mike_Mimoso asked some tough questions so you can hear me thinking aloud 🙈
Been looking forward to publishing this podcast for a while: An excellent conversation with @SarahFluchs as we revisit the @securePLC coding practices list one year in. Check it out here: claroty.com/resources/podcas…
4
Sarah Fluchs retweeted
Been looking forward to publishing this podcast for a while: An excellent conversation with @SarahFluchs as we revisit the @securePLC coding practices list one year in. Check it out here: claroty.com/resources/podcas…
1
4