Unsolicited posts from an ICS/OT Professional with both GICSP and ISA 62443 Expert. GIAC Advisory and ISA member. #ICS #OT #GICSP #IEC62443

Backplane
The only time I have ever lost my luggage while flying for work. There was an oscilloscope in my checked luggage! I called the airport every day and fought with them over the phone to locate my luggage. Took a week!
1
7
316
Restoring from backups isn't necessarily going to be a free pass in the ICS/OT. Even restoring from a golden backup in a critical environment, any engineer worth their mustard is going to insist on functional testing prior to putting their license on the line. Just saying.
2
1
12
413
FYI if you purchase Seagate external drives you can use Seagates "Disk wizard" which is actually Acronis for free.
9
478
I decided a long time ago that As a policy we are not resetting SCADA passwords or MFA without both the requester and administrator being in the SCADA office together.
3
5
16
995
You are not deploying a ICS/OT specific firewall to the IT/OT boundary. There should be no ICS/OT protocols going across this boundary. If you have ICS/OT protocols going across this boundary you have bigger issues than the correct firewall.
4
17
849
I like to start my ICS/OT network switch hardening process by... Not using a Cisco switch. After selecting a purpose made industrial switch it's a piece of cake to finish off the hardening process.
2
12
1,211
Best compliment I have received in a while. I should be a ICS/OT cyber security instructor. 😅
3
1
12
836
Once again.... I can explain it to you. I can't understand it for you.
1
5
590
And this is why you should not extend centralized identity management to the ICS/OT. The consequences are far worse.
Our identity provider went down this morning. Which meant nobody could access: Slack. Email. VPN. The help desk. Our incident-management system. Or the company status page. The status page was also behind SSO. So we had successfully centralized authentication to the point where an authentication outage removed every method we had for telling employees there was an authentication outage. I spent 20 minutes walking around the office carrying a whiteboard that said: SSO IS DOWN STOP REBOOTING YOUR LAPTOP The CTO asked why we didn't have an external status page. Security reminded him they made us put the external status page behind SSO last year. We're designing a new emergency communications plan now. Current leading technology: a bigger whiteboard.
8
4
37
5,919
You don't make friends via email or Teams.
1
7
706
You can't do effective ICS/OT security from behind a desk. You have to put on some steel toes and leave the office. Visit operations. Walk down the plant(s). Get to know managers, operators and the various trades. Put eyes on the situation.
7
1
47
1,690
Why can I not setup a local AI to analyze ICS/OT syslog and network traffic using Snort IDS rules instead of using the various ICS/OT vendors?
8
2
20
2,812
🚨 PSA for the younger folks 🚨 If you are not authorized to touch SCADA you're actually not authorized to touch it. We're not fucking around.
29
13
312
58,272
Look at this shit people post on LinkedIn! This is f'n horrible!
7
2
26
1,829
Secure ICS OT retweeted
1
10
162
Just wiping old devices, tossing them and removing them from my asset inventory.
293
Had a vendor add sim cards to devices even after we said not too. We removed the sims, disconnected the cell antennas and caped the SMA ends with terminator caps.
2
18
1,125