Navigating OT Security: Insights from Rockwell Automation Rick Kaun
Transcript
Hey everyone, it's Alan Shimmel here, back on Techstrong tv. Uh, my next guest is Rick Kahn. Rick is the Global Director of Cybersecurity services, excuse me, at Rockwell Automation.
Um, I'm looking forward to hearing from Rick more about Rockwell Automation, and we're gonna be discussing Think Global, act Local. So stay tuned on this. But first, let's welcome Rick to the show.
Rick, how are you man? How are you? I'm good.
Thanks Ellen. How are you today? Good.
Welcome. Welcome. Thank you.
Welcome. Pleasure being here. Um, it's nice to have you.
So Rick, before we jump into the mm-hmm. Think Global Act local, and we even discuss Rockwell automation, I always like to give our audience a sense of who they're listening to, right? Sure.
Beyond your title, which is Global Director Cyber Services over at Rockwell Automation, give us a sense of kind of your journey and how you came to be here. Yeah, that's, uh, thank you for the opportunity. So, um, by way of background to your point, uh, I, I sort of stumbled into OT security once upon a time working for a, a small company called matcon that did a lot of loop tuning and process improvement, alarm management.
You know, we're getting more automated, we're plugging things in, can we, can we get more juice out of it? You know what I mean? And so we, we started up a consulting service that helped to try and navigate how cyber and OT would play together because we're slapping it looking things in there, but we got ot, you know, guardrails to worry about.
So anyways, I started that about 25 years ago. So over the last 25 years, I've worked for a combination of small, medium, large consultative, uh, software based whatever. Um, and seeing a lot of the same commonalities in multiple places.
Uh, I don't think we'll ever be as close to it as, as, um, as we want to be in terms of automation and function, but we're getting really close and I'm really excited in this most recent chapter for me, because I become part of Rockwell through another one of their acquisitions, um, that allows Rockwell to pivot now to that, that one trusted advisor. Um, I've never seen such a combination of both cyber and automation manufacturing, a single bench strength, and then supported by a global footprint worldwide. And it lends well to today's discussion on Think Global Act local, coming from the startup, you know, trying to help figure things out and cut through the noise to now being able to do that on a global stage with the resources of Rockwell is, is really quite exciting for me.
Excellent. Excellent. Sounds exciting.
You know, I tell you, Rick, I guess it was, was it two weeks ago, was Black hat, it seems like, I'm not sure if it was yesterday or a month ago, that's how it's been a fog since then. But, um, this year a black hat OT was out in full force, huh? Mm-hmm.
So a lot of discussions around it, A lot of water cooler kind of conference hall discussions, formal, informal, um, it's really starting to become, um, top of mind, right? Yes. In, in the broader cyber community.
It used to be a very sort of niched, you know, piece of the market. Yep. But, um, it, it really has come along.
Um, Rick, so look though we have a strong cyber community mm-hmm. OT security is, is it, you know, maybe something that not a lot of our audience, or not enough of our audience mm-hmm. They weren't a black hat, they're not familiar with it.
How would you describe OT security to them? Yeah, that's a good one to start with, you know, because if you show a vulnerability dashboard to someone with an IT perspective, they're like, what's the big deal? I see that they don't understand necessarily the nuance and the challenge to get there.
Um, and so to me, the, the, the biggest difference, there's two or three that really big that, that, uh, really differentiate and, and emphasize how much different it is. Yeah. We've got it look and stuff in that space.
We've got, you know, windows boxes and Cisco switches and all those different, you know, competitors in those spaces. Um, but there's two things that you need to add to that picture. One is that there's a third rail, if you will, in ot, and that's all of the actual OT equipment.
So, PLCs, relays, controllers, you know, things that actually manage and monitor spinning equipment, high pressure, high temperature, high volume. And, and that's, that's a, a completely different unknown. The behaviors and the communications, the, the quirks and quirks of those devices on that, in, in, uh, local area network, they look and behave and feel different.
And it needs to be able to not only understand what those are, but the second really big difference is that the, the impact of issues on that side is huge. We can't make everything Windows 11 and patch on Tuesday. We had a client that outsourced, you know, general support for a Cisco switch and network infrastructure.
They rebooted the wrong switch. Long story short, $17 million outage for a pipeline, right? Um, now that gets even more scary when you're looking at devices and systems and networks that control safety systems or things could blow up or things could explode and whatnot.
So there's, there's of course, the fact that we've got the third rail, there's the consequences. And then let's, just to make it even more interesting, uh, OT is a set and forget environment, and technology is always evolving. Like you'd said, it's been a month since Black hat.
It's like, was it yesterday? What? It's just a blur in this space when your technology, so we see Windows 98 and Server 20, you know, 2010.
I mean, it's, and, and they're tied to high value, brand recognition, big dollar, you know, big impact system. So, oh, I get it. It's, it's, I always say, if you can do OT security, right?
You're basically taking it security and tying one hand behind your back and covering one eye. Right. You know, like, we can get there, but we need to take a different path, right.
Because there's very different consequences. You know, to me it's always been analogous. Had a very good friend of mine, unfortunately he's not with us anymore, but he, he was very big in healthcare security, healthcare security.
He was a cyber through, through and through. And he always told me, you know, every hospital, every healthcare facility actually has three networks. There's the regular IT network that all our regular cybersecurity friends out here are used to.
Yep. Then there's the network that the doctors use because they're all prima don is, and they, you almost gotta give them a special network like Snowflake network, call it. Yeah.
And, uh, and let them do it. They want, because otherwise they huff and they puff and they have a hissy fit. Yep.
But then there's a third network, and that is the healthcare specific devices. Every insulin, uh, not insulin pump, every IV IV pump, the respirators that, you know, ICU patients are on the heart lung machines, the, the, the crap that keeps, you wanna talk about mission critical life or death. This is the stuff that keeps people alive while they're hopefully recuperating at, at the, or, you know, getting better at the hospital being treated.
And that is a, that's a, that's a network of a different animal. Yep. Right?
You can't afford, you can't afford outages. You need real insight. But like you said, how many of those machines are running headless windows mm-hmm.
From, you know, God knows what. Yeah. And, uh, it, it, it's a problem.
It, it's, it's, it's just a whole different set of cyber problems. Absolutely. Yep.
Than, Than the usual. Let's turn to Rockwell, if you can. Sure.
A little bit for me. Give, give, you know, I think people have heard Rockwell, they think Rockwell out, weren't they something with the space shuttle or NASA or, you know, all that good stuff. But Rockwell automation, the, the, uh, folks you're working for, tell people about 'em, Rick.
Yeah. So we're, we're 120 year old-ish, you know, manufacturing company. We are in every industry you could imagine.
We help our clients to build and man manage and make multiple products. Like, I go into some of these facilities and they look at the display case, and I'm like, wow, we got one of every one of those in my house. You know what I mean?
Uhhuh from toiletries and medical or life science to food beverage to oil and gas and energy and electricity and utilities and fresh water and wastewater. So we have a very, very deep understanding of, remember we talked that third rail, there's the real consequences in this space. Yeah.
Um, and because a lot of our stuff is getting smarter and needing help and, and whatnot, we, we get really good at networking and communication and data collection. Well, it's a really small pot to get from there to now helping to secure all that stuff. Right.
And so Rockwell has actually been selling cybersecurity solutions for about 15 years now, maybe a little longer. But again, they've done a recent, uh, evolution to go in and, and work on acquisitions for industry leaders and thought leaders in terms of our consulting bench strength. Um, some of the world class products that we're starting to bring in any security topic has to understand that we're talking about building a program.
And, and the corollary in, in, in rural Rockwell comes from and why we're so good at understanding building into the culture is it's when done right. It's just like a safety system. It's in every project we do.
It's in everything we think about every day that we come in. It's, it's how we design and make decisions. And so Rockwell has this really strong capability, not only on the manufacturing and helping with, you know, factory of the future and digitization, but how to do all that stuff securely and more importantly, safely.
At the end of the day, our mandate and security on the OT side isn't necessarily around forensics or attacking or, you know, counter attacking nation states or, or persecution or prosecution. It's defense. We need that en environment and that equipment to run the way it's supposed to and safely and expectedly.
And if something tries to take that away or we deviate from it, we gotta get back to normal pretty quick. And Rockwell has both that blend of, of that cybersecurity and how the digital components are tied together, and how you turn that into practical applications and empower people to, um, how we would then, um, uh, you know, extend those uniquely into manufacturing environ, uh, explicitly. That's, that's actually Rick, that's a great, um, you know, description of what Rockwell is and, you know, so I'm a little older than a lot of people watching this, I think.
Mm-hmm. And I remember the days of the conglomerates, right? You do too.
I'm sure. We don't have a lot of those con a lot of these conglomerates, you know, GE was the conglomerate of my generation, right. Jack Welch's ge Yeah.
And one of, one of, one of many tentacle monster that was right. They did everything and they did it well. Yeah.
Um, Rockwell's one of the few still, you know, blue chippers out there doing that, and yes, it's amazing. But I, I think you're right. A lot of folks out here maybe don't realize that they're a powerhouse in cyber.
Yeah. If you don't mind, Rick, I'd like to pivot to our, what we call our topic of discussion today, which was this whole think global act, local approach to cyber at manufacturers and critical infrastructure. Like I was talking about, the healthcare stuff, critical infrastructure operators.
It's about resiliency, which is a word we hear a lot more in security than we used to. Um, scalability, you know, as, as things go on today. So, you know, kind of global strategies to safeguard regional industrial operations, Rick mm-hmm.
Make us smart. What, what, what's going on? So the basic premise is simply that we talked earlier about some of the challenges in OT and, and the wide range in vintage and complexities of these orgs.
Now, that gets exacerbated when you look at global footprints, either because different regions have different, you know, regulatory reporting or, or what have you. Or even just within smaller facilities and, you know, contained in the geography, depending on the vintage of the prediction, particular production line or input output or warehousing, a wide range of different systems. And the challenge for OT is, like I said, we can't make everything Windows 10 or 11 and patch on Tuesday.
It also means that we can't get risk to zero. We can't patch everything and move vulnerabilities outta the system. We just, we have some legacy challenges that just won't let us do it.
So what is our secret weapon? The secret weapon is data, but not just individual lines of, you know, IP addresses matched against bones, matched against patches. It's about the context.
The context is key. So if I tell an a plant operator that he's got a critical loan on the system, he is like, well, that's nice, but you know, that's either this insert name a very important platform here, or it's inconsequential. I don't care if I lose it.
Right. That's the problem. So how do we help organizations understand their risk?
How prevalent it is? You know, how, how acute it is, right? Because again, simply knowing a critical VUL isn't enough.
Knowing where that VUL is on which system, at which facility, under what circumstances from a network or a backup or other protections. That's where the magic comes in. And so what we're seeing the leaders in this space do is they're starting with a very rich, multi-dimensional data collection, right?
So we don't just have an asset, the asset's the core of the record, but the asset, and then immediately the operational context. What is its impact? How does it work?
Is it redundant? Where is it? What production line?
Is it a safety system? Is it is whatever it is. Then we add the traditional things like vulnerabilities, threat vectors, exploits, patches, et cetera.
Then we look at what else there may be for protections. Where is it in the Purdue model? Does it have a digital twin?
Is it redundant? Does it have microsegmentation in front of it? We need to know everything about that asset.
And then corporately, this is where an IT and OT sit together. We talk about OT con it, OT convergence and specialty, you know, capabilities and a lack of cybersecurity skills. Once we have that data, you can very easily pair the manufacturing brain with the pure security brain.
And now we can say, look, of all these risks, I've got scores for every single one of my assets. Now based on what I see, I can also see globally how many places I have it right. And now we can start to build a cohesive action plan to either remediate or accept risk and provide countermeasures, but we can also decide collectively how far we need to go.
We're never gonna boil the ocean and OT and get it to zero. We're never gonna have the budget, we're never gonna have the staff. So what we need to be able to do is pivot to streamlining what we have for resources.
One global team that can look at an emerging risk or vulnerability or threat, and immediately understand where it exists in that entity, worldwide, geography by production line, whatever. And the importance of that risk and how important we need to, uh, address it, and how fast is game changing. We have clients that are looking at things that like, yeah, that's a high priority based on the fact that I've got some really critical systems with it.
Guess what? I've got some redundant file servers, domain controllers over at this site, and, and I can test it over at that site. I can burn it in on non impactful systems.
Once I know that I share that with my wide audience. All of manufacturing knows we're testing and we're getting ready. Once it's approved, they can proceed with safety.
We're seeing customers take, you know, 60, 70, 80% of their typical manual effort, which they would do prior to this concept and save that. So engineers are going back to being engineers with a three hour window instead of what used to take 10. We're not having one bulletin on a risk.
Go to multiple sites and each and every site design their own way to address it or not address it at all. Or try to engineer completely out. And you're all over the map and you're in your consistency.
This drives so much better. Uh, consistency in reporting, showing the board, showing insurers, being able to test and learn once and share results everywhere. The efficiency gains across multiple use cases are, are through the roof, and it's all predicated on contextual data.
And then an aggregated view so that we have, you know, design and build once, and then share consistently, repeatedly. Excellent. Very cool.
Yeah. Rick, people heard you say it, but you know how people are, they need sometimes to read it, see it true on it. Sure.
Work on the Rockwell automation site. Can we get some of this information? Yeah.
So the, the really cool thing is that, um, because of the recent acquisitions, we're now starting to bring in, um, you know, a cohesive, you know, rebranded, let's go to market with this, you know, combination of capabilities. And I know that we recently just re-upped a lot of our content, and it's right on the Rockwell automation, uh, dot com. There's, there's a section in there for cybersecurity.
Uh, you can see a lot of these use cases you can see by industry, by regulatory, uh, requirement. Um, you can see what your peers are doing. We have one client that is a global food and beverage manufacturer.
They went from not knowing what their asset counts are. They, they thought they had 4,000 assets, they have 20,000. They went from never patching anything or doing any updates to now proactively testing and preloading for the next outage.
They also are now proactively going to the board and saying, look, based on the obsolescence and lifecycle of a lot of these, the only way to get rid of risk is to put capital projects in place. And so, as you're looking at your funding and your return on investment, these need to be factored in so we can be a more secure, more resilient factory of the future. They've gone from reactive to proactive case studies like that are up there.
Um, references, uh, invitations to our webinars. Of course, we have our automation fair in a couple of weeks or months, I think, um, first bit of November where a lot of these peers of the people that are hopefully listening here are going to be presenting their journey from that disjointed, unknown wild west that OT used to be, to having this, this global view and the ability to, to design and deploy, you know, cohesive, uh, strategies, whether it's immediate patching and system hardening, or whether it's longer term presenting to the board for capital projects. Um, it's, it's really quite empowering.
Very cool. Excellent. You know, you mentioned a few times consolidation a, uh, and, and, uh, acquisitions and stuff.
I, I see a verve behind you up on the, I'm assuming verb ISS one of the acquisitions in Rockwell. Is that right? Yeah, actually, that's how I came to, so I, in my 25 years, I've, I've gone startup and figure out and hustle and consult and whatever, and then got picked up by a big one.
First one was Honeywell. Um, Verve was another one that came actually from our founder was an electrical engineer in the business for 30 years, just recently hung him up. Um, and he built this really cool direct response.
And it was a platform built by ot, specifically for ot. And it emerged 20 years ago in North America for, uh, in response to, um, NERC SIP regulation where we're enforcing IT standards. Sure.
In an OT environment. Fast forward today with Rockwell, we take the value and the magic of Verve with some of the, like I said, world class consultants, you know, that we've got that are able to help clients understand, well, do you need it right now or do you need it next? What do you, you know, where are you at the journey?
The, uh, the epitome is getting to that automated think global act, local visibility, uh, to be able to manage up, down, left, right insurers, board, capital budgets, regulators, et cetera. That's where we're driving and trying to help people get to. Excellent.
Hey, Rick, thanks for coming up here on text, on tv. Don't be a stranger. Okay.
Anytime you have me on, appreciate the time. All righty. Rick Conn, global Director of Cybersecurity servers at Rockwell Automation.
Uh, we'll be right back.