Cyber Ranges Help Municipalities Defend Critical Infrastructure
Critical Infrastructure Cybersecurity Needs Practical Training
Critical infrastructure cybersecurity is becoming more urgent as municipalities face more connected operational systems and more aggressive threat actors. In this Techstrong TV interview, Mike Vizard talks with Lee Rossey, CTO and co-founder of SimSpace, about why cities and local agencies need realistic ways to prepare for attacks on power, water, transportation and other essential services.
Rossey explains that many municipal teams are responsible for keeping vital systems running, but they may not have deep cybersecurity expertise. Water treatment facilities, power systems and other operational technology environments are increasingly networked. That creates new risk for communities that depend on them every day.
Cyber Ranges Create a Safe Proving Ground
SimSpace builds cyber ranges that recreate realistic environments for training, testing and rehearsal. These ranges can model power systems, enterprise networks, electrical subsystems and other operational environments without putting live services at risk.
That matters because critical infrastructure cybersecurity requires more than awareness. Teams need practice responding to realistic attacks. Cyber ranges give operators a place to rehearse decisions, test tools and evaluate how quickly they can recover when adversaries attempt to disrupt services.
Municipalities Face a Resource Gap
The conversation also highlights the challenge facing cities and local agencies. Many municipalities have enough budget to connect systems, but not enough funding or staff to secure every asset. Cyber Florida’s work with municipalities is one example of how states can help provide training and resources.
Rossey notes that adversaries have been probing operational technology for years. Some are building footholds quietly, while others may be more willing to demonstrate disruptive capability. That makes preparation essential, even when attacks have not yet caused catastrophic outages.
AI and OT Security Raise the Stakes
AI may help defenders respond faster, but it also introduces new questions about how tools are tested before they are trusted. Critical infrastructure cybersecurity teams need safe environments where AI capabilities, security controls and response plans can be validated before they touch production systems.
For technology leaders, the takeaway is clear. Air gaps are no longer a realistic strategy for many operational environments. Communities need training, realistic testing and faster response playbooks so they can keep essential services running during cyber incidents.
Transcript
Hey guys, thanks for the throw. We're here with Lee Rossi, who's the CTO for SimSpace, and we're having a little chat about, well, what is it going to take to secure our critical infrastructure as we get more cyber attacks from places like Iran? And it turns out that SimSpace is working with Cyber Florida to help some of the municipalities down there.
Lee, welcome to the show. Well, thank you. So walk us through what's going on here, because it seems like a lot of these critical infrastructure projects or waterworks or whatever they happen to be, are owned and operated by municipalities who may or may not have a whole lot of cybersecurity expertise.
Well, that's exactly it. A: They have an important job, which is to make sure that power's flowing, water is moving, water treatment is actually doing its thing. And honestly, I'm not saying this to criticize them.
They're not always cybersecurity savvy and expertise because expertise is in other areas. So the challenge is a lot of these systems that we rely on are getting more networked. They are becoming vulnerable to cybersecurity attacks.
And then how does, for example, the city of Tampa or Orlando or any municipality deal with the fact that they may be attacked, and how do they respond quickly to counter it? In other words, if I'm in a city, I happen to be in Boston right now, I don't really appreciate the power going out in the middle of a storm or anything bad. So, what can be done at the privately held agents...
Sorry, at the privately held company, the agencies, the city, to rapidly respond and recover from some attacks like that? And what is your role as a company in this equation? What are you guys doing here to advance that goal?
Yeah. So we build what we call cyber ranges. It's very realistic, hyper-realistic environments that you can use for training of operators or testing of technologies.
So think of it as almost like a proving ground. A range is an environment that you can actually recreate, for example, that power company or recreate that electrical subsystems or an enterprise network, have realistic attacks modeling, in your case, this would be the Iranians or the Russians, Chinese, and see how well the teams can react, respond for that. Or the technology, especially with a lot of new AI advancements, how does AI potentially help with that?
But it's the safe environment to be able to train, rehearse, and test out new capabilities. Are the threats coming out of places like Iran becoming more sophisticated? What's the issue here?
Because I think adversaries have been poking around critical infrastructure for as long as I remember. So what's changing here? Yeah.
It's actually yes and no. So I think the Russians, the Chinese, they've been poking at, they've been doing OT or critical infrastructure for many years. And I think what they're doing is burrowing themselves into our infrastructure.
So they're not disrupting things. They're making this so they have nice, good footholds in all of our places. The Chinese are pretty good.
The Russians are good. The Russians are demonstrating those against Ukraine. The Iranians are interesting.
They're not, in my mind, as capable, but they're more aggressive. They're more aggressive because of the war going on right now in the Middle East. So how can they inflict some pain back home?
And I have two examples that we've recently done. One of them was a training event with a lot of regional militaries from the Middle East. And the attack scenario that we put together in a range was, for example, the Iranians taking over the camera systems that are networked together.
So now every camera that you're seeing around a building, around a light pole or an airport, they are networked. So they were using it to basically get into the cameras and use it effectively as what we call an ISR platform, intelligence, surveillance, reconnaissance. Get into the cameras, see what's happening, look at a building, use it for targeting, use it for damage assessments and throughout.
So we did an event like that. But the Iranians are also postured to be going into our water treatment and power. I think the difference there is they're actually doing something to show that they can get in and create disruption.
None of these are catastrophic yet, where they're taking the city down for weeks or event. I think they're demonstrations that they get in and do things. So you're right.
People have been getting in there all the time. The question is: Is there anything notable that is really taken down and having a meaningful impact? And the quick answer is not really.
All right. Is there a simple solution? " Heck, most of them have been around long before the internet ever came along.
So why are we connecting them to the internet in the first place? Yeah, that horse is out of the barn years ago. So they used to be isolated, they used to be separate, and now they're all networked.
And the reality of the world today is all of these traditionally isolated systems-- By the way, whether you're a power plant or a manufacturing facility or making cars, they're all networked. And they're networked for various reasons. One of them, honestly, is COVID.
During COVID, a lot of remote access was starting to get put in there because people couldn't go to the facilities, do the updates, do the maintenance. So A, for remote access, B, leveraging AI, remote updates, it gives you a lot of insight. So I think the reality today and going forward is these networks are increasingly interconnected.
So the OT or infrastructure world is much more connected to the IT side, and now we need to make sure that our defenses, our monitoring, our responses can cover them. There's exceptions. Nuclear facilities are probably still going to be isolated for a while for pretty good reasons.
But mainly for cost and economic reasons, and the vendors. Most of these vendors require internet access to some degree to support a remote. The days of isolation are pretty much over.
As you look at all of this, here's the issue in my mind is the municipalities, I think they have just enough money to connect something to the internet, but they don't have any money to secure these things, and they don't have the expertise to do it if they had it. Yeah. So who's ultimately going to have to be responsible for this?
Because, well, it may seem like a water system is maybe a local issue, but if it gets crippled, everybody in that town is probably going to pick up and move somewhere else and then stress out the systems elsewhere, right? It is. And I think you're right.
With infinite money and time, of course, everything can be showed up. But there's a practical reality of every municipality having limited budgets. And as much as you may want to say, "I'm going to increase the rates to the end users because I'm going to apply security," they're regulated.
It doesn't work that well. I think like anything, you have to be able to deal with whatever it is and rapidly respond. And this is where I like the event that was just done in Tampa.
So the question was: How does a city like Tampa deal with a cyberattack against the infrastructure and work across the agencies to be able to respond? And the scenario here was, okay, hurricanes happen all the time in Florida. We prepare for that.
People know how to actually respond in terms of the police, the coordination, the telephony, and all that kind of stuff. And it's not like there's infinite money for hurricanes, but the city gets together and has worked it through over the various years of how do we rapidly respond and coordinate. " So we brought together about 200 operators as a mix of the power utility company, the regulatory agencies, the FBI, CISA, some of the CENTCOM, some of the military units happen to be in Tampa as well.
So a combination of the military, the mayor's office, the other ones, and how would they all react to this? And I think it's a combination of, I'm going to call it strategic and tactical. Strategic is think tabletops.
What would we do if this happened? And how do we coordinate? But then there was also an element of creating the replica or representative version of those network for the operatives.
So the operatives are sitting there dealing with the attack, coordinating with the leadership for tabletop, and trying to make those real-time decisions. I don't think we're going to say that everything is 100% secure. I don't think that's practical.
The question is: How can you rapidly respond to an attack that's going through? No different, honestly, if a hurricane is hitting a city, you're not going to say a city's going to be invaluable. There's going to be nothing wrong happening with a hurricane blasting through Florida or something else.
It's going to happen. The question is: How do you quickly marshal the resources, respond, and minimize any kind of damage in terms of lives and others? So we've also been kicking this conversation around for a long time.
Some would say we've been kicking it down the road. There's numerous various bills that go through Congress, and now they get debated, but nothing seems to fundamentally change. So are we just waiting for some sort of cataclysmic event before everybody gets a little more serious?
Or what's your assessment of what's going on here? Yes. In my mind, yeah.
So we've been kicking it around. Nobody really takes it seriously. In my mind, the US really reacts when something bad happens, and then once something bad happens, then we all kind of get around to it and do it.
But you're right. For like the last two decades, people have been trying to pass through legislation for cybersecurity, for just critical infrastructure. And at various points, it's always knocked back because of one reason or another, and it's just not perceived as being impactful enough.
I do think that when something bad happens, we get our stuff together and take action. Until there's something meaningful, I don't see it fundamentally changing. Is part of the issue that we're so busy fighting elsewhere that we don't have enough time to think about these other issues because, well, this year it's all about software vulnerabilities and not critical infrastructure?
I don't think so. I think it's just where do we want to put the focus and what do we perceive as being potentially damaging? To your point, Mythos, Daybreak, the vulnerabilities that are coming out and the cheating on those vulnerabilities from the AI models, very impressive.
And every large enterprise is very much focused on that. Interestingly, what that's also doing is finding all kinds of vulnerabilities in critical infrastructure. So it's accelerating a problem on the infrastructure.
So it wasn't solved before, and now it's worse. I will say that notable clients like militaries and others are really thinking about, okay, shoot, a lot of our weapons systems are... And this is true in general.
A weapons system is a floating power plant, if you will, for a ship. So there's this combination of OT applies to them, and how do we shore things up and fight through that? It is becoming more and more of an issue in terms of the vulnerability and the ability to use AI to disrupt these events and disrupt these systems to take advantage of it.
But there's also opportunities, for AI from a cybersecurity standpoint to be able to help with the defensive side. I do like that example of the Iranians literally using every camera that's out there at the ports, at the natural gas facilities, at the airports, quote-unquote, "hacking into those cameras" and using it as essentially a sophisticated intelligence reconnaissance. So those cameras were never meant to be a foreign nation used to spy on that facility and literally use it to be able to see, "I threw a missile at it.
" That used to cost a lot of money if you think about nation-states are putting up satellites and recon and predators. Now people are just hacking into these cameras and using it for targeting and damage assessments. And I don't know if that's still enough of a wake-up call, though.
I think it's people taking advantage of it, but it doesn't move the needle in terms of the US really taking it seriously. Do you think as we go forward, modern warfare seems to be driven by drones, so- Yeah ... will someday an attack on some sort of critical infrastructure be coordinated based on what the drones are informed by on this camera that's watching the critical infrastructure?
I see no reason why not. More and more systems are getting interconnected, that data's getting aggregated more powerful, and going through. But I don't mean to sound doom and gloomy.
There's real opportunities here for the defensive side. So the nice thing about these critical infrastructure environments, the traffic is very regular. The traffic is very deterministic in terms of what it's supposed to be.
It's not like if you think about an enterprise network, you have people browsing the web, doing social media, doing all kinds of random things. These, critically, it's very specified protocols, very specified traffic patterns. So what I'm trying to say is it's easy to spot differences in the patterns of life.
That's what the AI is really good at. So once you learn what the normal traffic patterns are, the defensive AI systems are quick at being able to identify something as a problem, and thereby being able to alert that something funny is going on. So in other words, it shouldn't take months or years for...
So let me say it this way. The longer somebody's in your network, the more potential damage they can do. So if you can detect anomalous activities within hours, days, weeks, the likelihood that somebody can take advantage of footholds that are in your network to do damage is way minimized.
So back to my examples about the Russians and the Chinese perhaps being all over infrastructure. At some point, there's a command and control. At some point, there's a means by which they're getting in and out.
Those traffic patterns should be very easy to spot if you start looking for deviations from what is normal. So there's an opportunity here to not only... I'm not saying that you're going to secure everything.
There's the opportunity to detect if something funny is happening because of the type of networks to potentially help you eradicate footholds that other nations have put in your infrastructure. We've also been somewhat conditioned to keep track of vulnerability severities. Yeah.
And I wonder if that's become obsolete because the bad guys have AI tools now, and they can chain together all kinds of low-level vulnerabilities to create something more lethal that could probably take out something. They're not quite obsolete. Keep the defenses up a little bit for the low-hanging fruit, the script kiddies, but yeah, a lot less relevant.
So everything about CVEs or vulnerabilities and keeping up with specific signatures for actors becoming less meaningful every day. And the reason why I say that is if AI, from an offensive perspective, if an adversary can use AI to increase the speed... By the way, the fundamentals of cybersecurity haven't changed.
What AI is doing is accelerating the rate at which you can find the vulnerabilities, get in the network, move around, do your thing, and get out and overwhelmed. So speed and volume are two things that are very much to the advantage of the attacker. And that's why I think the specific vulnerabilities are not as critical because they can be discovered, but the fundamentals of shoring things up, ladder movement, detections, kind of finding these things, are still valid to be able to actually respond.
What am I supposed to do as a cybersecurity professional to kind of get the local townspeople to better understand this issue? Do I just show up at the local town meeting and raise my hand and start asking questions of the town council? What am I doing here?
Actually, that's not a bad idea. From that perspective, raising the awareness and what are you doing about cybersecurity? What are you doing to protect me, given the thing that's in the news?
I will say that the people-- So I think that's a good one. The other ones, and again, I want to give credit to the state of Florida because they have started providing resources to the municipalities for training. So as an example, here are some cybersecurity courses you can take.
Here are some facilities that you can go to to learn more. Here are some assets you can learn to use. So these are state-funded initiatives to take the burden off the municipalities to improve their ability to respond to cybersecurity.
So the state of Florida, I'm going to get the number slightly wrong. I think they put in about 10 million plus dollars a year for the townships, for the agencies to improve their ability to detect cybersecurity. So money's actually been allocated.
Now the question is, are they taking advantage of it? Are they learning? Are they improving?
And what we're trying to show here is, A, how do you improve your readiness, but then B, how do you coordinate across others? I'll also say something like, I'm using the state of Florida as an example just because we've been working with them. There's always this balance between, say, the larger cities, Orlando, Tampa, Miami, that have people dedicated to this.
But like in any state, there's also going to be some small little townships in the middle of the state that may have three people and maybe the police department, the sheriff is also the IT guy, also the cybersecurity. " So there's a balance, but I would say that there is a statewide resource they're trying to apply to that. So step one is provide the resources, take advantage of them, and make your way.
So I think they're getting a lot better. Unfortunately, I can't speak for many of the other states for what they're doing, but I know that Florida, as an example, is doing a decent amount there. All right, folks.
Well, you heard it here. The good news is more resources are being made available, and I'm assuming you probably have to fill out a lot of forms in triplicate. But, if you do that, maybe we can protect our critical infrastructure, and hopefully it won't be something we've got to learn the hard way.
Hey, Lee, thanks for being on the show. Thank you so much. All right, and back to you guys in the studio.