Dive into the world of manufacturing cybersecurity with an insightful podcast episode featuring Ashley McGlone, a seasoned technology strategist from Tanium. Join your host, Luigi Tiano, as he engages in a riveting conversation with Ashley, unraveling the complexities of Industry 4.0, IoT, and the critical role of cybersecurity in the manufacturing landscape.
In this episode, Ashley shares his wealth of expertise, drawing on decades of experience in the tech industry, including roles at Microsoft, Toyota, and his current tenure at Tanium. The duo delves into the challenges posed by the convergence of IT and OT, exploring the unique cybersecurity concerns faced by manufacturing companies in an era of increased connectivity and automation.
Discover the significance of standards like ISA 62443 and the Purdue model in structuring cybersecurity practices for manufacturing environments. Luigi and Ashley explore the pressing need for visibility and control in OT environments, shedding light on the evolving trends and the potential risks associated with cloud integration.
As the conversation unfolds, Ashley provides valuable insights into the diverse mix of devices in manufacturing and how strategic platform partnerships can be the key to effective cybersecurity. The duo navigates the landscape of resources available for companies venturing into cybersecurity enhancements, with a special spotlight on the SANS Institute's industrial controls training.
Resources:
Watch the episode: https://youtu.be/1u6Ot5s-sXI
Ashley's LinkedIn: https://www.linkedin.com/in/ashleymcglone/
Tanium's website: https://www.tanium.com/
Luigi Tiano’s LinkedIn: https://www.linkedin.com/in/luigitiano/
Assurance IT Website: http://www.assuranceit.ca/
About Ashley McGlone:
Ashley McGlone has spent his life in IT. Between recordings of Tanium Tech Talks he enjoys advocating for customers, getting in the weeds of tech, and savoring a particular retro variety of red licorice. In his role as Technology Strategist he researches and creates vertical-specific guidance for customers to maximize their Tanium experience. He also is a megaphone for customer feedback to the Tanium product teams. As a frequent conference speaker he's always looking for opportunities to share the "Wow Tanium" experience with new audiences. Message him just to say hi or to talk Tanium and tech.
About 10 Questions to Cyber Resilience:
Twice per month, learn about how IT leaders are strengthening their cyber security practices. Every episode comprises of 10 questions that get you one step closer to cyber resilience. Subscribe to stay up-to-date with hot topics in cyber security.
About Assurance IT:
Assurance IT (www.assuranceit.ca) specializes in data protection and data privacy for the mid-market in Canada, since 2011. The Montreal-based company’s unique approach to helping customers become cyber resilient is called the PPR Methodology which stands for Prepare, Protect and Recover. Based on industry best practices, the PPR Methodology is an easier way to achieve cyber security and compliance objectives.
All right.
Luigi Tiano:Good morning everyone.
Luigi Tiano:Good day.
Luigi Tiano:Today I've got Ashley McGlone from
Luigi Tiano:Tanium with me in the podcast.
Luigi Tiano:I had the opportunity to talk
Luigi Tiano:with one of his colleagues
Luigi Tiano:a couple days ago, and we
Luigi Tiano:talked about specifically
Luigi Tiano:manufacturing and cybersecurity
Luigi Tiano:in the manufacturing field.
Luigi Tiano:So without further ado, I'm gonna
Luigi Tiano:ask Ashley to introduce himself.
Luigi Tiano:What his expertise is, where he
Luigi Tiano:is working today what he likes
Luigi Tiano:to do on a day-to-day basis.
Luigi Tiano:And then we'll start from there.
Ashley McGlone:Thanks for
Ashley McGlone:having me on the show, Luigi.
Ashley McGlone:This is a lot of fun.
Ashley McGlone:Been looking forward to it.
Ashley McGlone:Yeah.
Ashley McGlone:I'm Ashley McGlone.
Ashley McGlone:I'm a technology strategist
Ashley McGlone:in our manufacturing segment.
Ashley McGlone:So I've spent the last few
Ashley McGlone:years here in this part of my
Ashley McGlone:tenure at Tanium, focusing on
Ashley McGlone:manufacturing customers and where
Ashley McGlone:Tanium is relevant to them on
Ashley McGlone:the factory floor, helping them
Ashley McGlone:with visibility and control.
Ashley McGlone:I've been here at Tanium
Ashley McGlone:five and a half years.
Ashley McGlone:Before that, I was with
Ashley McGlone:Microsoft for about eight years.
Ashley McGlone:Before that, Toyota
Ashley McGlone:for about eight years.
Ashley McGlone:And if you go all the way
Ashley McGlone:back, I started with Commodore
Ashley McGlone:in 1982, so I've been doing
Ashley McGlone:technology for four decades now.
Luigi Tiano:Wow.
Luigi Tiano:Impressive.
Luigi Tiano:Impressive.
Luigi Tiano:I'm sure the time at Toyota
Luigi Tiano:helped build your knowledge with
Luigi Tiano:regards to manufacturing there.
Luigi Tiano:Obviously manufacturing has
Luigi Tiano:become a huge, fundamental
Luigi Tiano:piece of our ecosystem.
Luigi Tiano:It's really integral
Luigi Tiano:into everything.
Luigi Tiano:What we're seeing and more so now
Luigi Tiano:is that manufacturing companies,
Luigi Tiano:like it or not, have become huge
Luigi Tiano:attack surfaces for bad actors.
Luigi Tiano:There's so much technology
Luigi Tiano:that's being integrated
Luigi Tiano:on a day-to-day basis.
Luigi Tiano:I know you're very tactical
Luigi Tiano:in your day-to-day.
Luigi Tiano:Can you define some
Luigi Tiano:of the terms we hear?
Luigi Tiano:Some of the people listening
Luigi Tiano:to the podcast may or may
Luigi Tiano:not know what the terms are.
Luigi Tiano:We talk about IT, we talk about
Luigi Tiano:I o T, we talk about OT, I I
Luigi Tiano:o T, maybe give us an overview
Luigi Tiano:of what all that's about.
Ashley McGlone:There's a lot
Ashley McGlone:of i's and o's and t's in there.
Ashley McGlone:Let's sort 'em out.
Ashley McGlone:So IT, that's what a
Ashley McGlone:lot of us do every day.
Ashley McGlone:That's our typical
Ashley McGlone:corporate infrastructure.
Ashley McGlone:Sometimes they like to separate it
Ashley McGlone:between the carpet and the paint
Ashley McGlone:or the carpet and the concrete.
Ashley McGlone:So the carpet is the
Ashley McGlone:office, that's IT.
Ashley McGlone:The concrete is the OT.
Ashley McGlone:That's your industrial environment.
Ashley McGlone:Operating technology is
Ashley McGlone:what that stands for.
Ashley McGlone:It could be the dials that
Ashley McGlone:turn the chlorine balance
Ashley McGlone:in a water treatment plant.
Ashley McGlone:Those types of industrial
Ashley McGlone:equipment type environments,
Ashley McGlone:that's the operating technology
Ashley McGlone:that makes the physical.
Ashley McGlone:It's a cyber physical interface
Ashley McGlone:between this technology is gonna
Ashley McGlone:control a physical process.
Ashley McGlone:That's the operating technology.
Ashley McGlone:Then IOT is internet
Ashley McGlone:of things, obviously.
Ashley McGlone:That can be anything
Ashley McGlone:from IP cameras to...
Ashley McGlone:At one customer, they had
Ashley McGlone:vulnerable Amazon Firesticks
Ashley McGlone:in their presentation
Ashley McGlone:TVs and conference rooms.
Ashley McGlone:So it could be any internet
Ashley McGlone:connected device that's not
Ashley McGlone:traditionally manageable like that.
Ashley McGlone:Then IoT and a lot of different
Ashley McGlone:verticals, like medical,
Ashley McGlone:have their own IoT flavor.
Ashley McGlone:So industrial IoT then instead
Ashley McGlone:of IoMT like medical and every
Ashley McGlone:vertical's got their own iot.
Ashley McGlone:An industrial IoT is often
Ashley McGlone:looped in with Industry 4.0,
Ashley McGlone:which is the latest revolution
Ashley McGlone:of plant floor technology,
Ashley McGlone:of which involves things like
Ashley McGlone:5G for wireless connectivity,
Ashley McGlone:especially in more rugged or
Ashley McGlone:network challenged environments.
Ashley McGlone:You've got those same IoT type
Ashley McGlone:technologies, but in the plant
Ashley McGlone:space used for manufacturing
Ashley McGlone:or industrial control purposes.
Ashley McGlone:Often, you'll see as well a gateway
Ashley McGlone:device where now the legacy devices
Ashley McGlone:that were previously not connected
Ashley McGlone:to the internet have a gateway
Ashley McGlone:to get out to cloud services.
Ashley McGlone:It's really a game changer.
Ashley McGlone:It blows my mind.
Ashley McGlone:When you think about mission
Ashley McGlone:critical plant floor systems that
Ashley McGlone:are now connected to the cloud,
Ashley McGlone:taking on that big dependency
Ashley McGlone:for another point of failure.
Ashley McGlone:So there's a lot of concern
Ashley McGlone:for a lot of traditional
Ashley McGlone:manufacturing folks.
Ashley McGlone:Do we go that path or not?
Ashley McGlone:But that's the whole gamut from
Ashley McGlone:IT, OT, Io T there you go.
Luigi Tiano:Okay.
Luigi Tiano:So you really went
Luigi Tiano:deep dive in there.
Luigi Tiano:I appreciate that.
Luigi Tiano:You mentioned Industry 4.0.
Luigi Tiano:Let me just double click on that.
Luigi Tiano:So Industry 4.0, is that a
Luigi Tiano:standard or kind of a terminology
Luigi Tiano:that we're using to augment
Luigi Tiano:or increase the efficiency or
Luigi Tiano:automation in a plant floor?
Luigi Tiano:How do you describe
Luigi Tiano:that specifically?
Ashley McGlone:Personally,
Ashley McGlone:I'm not sure that it's a
Ashley McGlone:standard necessarily, but I
Ashley McGlone:think it's a bucket phrase
Ashley McGlone:that captures a lot of that.
Ashley McGlone:I'm sure there are people
Ashley McGlone:that could go into the
Ashley McGlone:line items and explain why
Ashley McGlone:it's different than 3.0.
Ashley McGlone:That's technology, right?
Ashley McGlone:You got 1, 2, 3, 4.
Ashley McGlone:This is the latest iteration,
Ashley McGlone:which includes cloud connectivity
Ashley McGlone:on the plant floor systems.
Luigi Tiano:You mentioned
Luigi Tiano:something really important there.
Luigi Tiano:The gateway into cloud management.
Luigi Tiano:Traditional PLCs or
Luigi Tiano:traditional plant floor
Luigi Tiano:technology would typically
Luigi Tiano:not have any external access.
Luigi Tiano:And I think that gateway now,
Luigi Tiano:as much as it's creating that
Luigi Tiano:operational efficiency or
Luigi Tiano:automation and that layer of
Luigi Tiano:management, I think that's where,
Luigi Tiano:correct me if I'm wrong, is
Luigi Tiano:that where that gateway brings
Luigi Tiano:in also the security concern?
Ashley McGlone:Yes, if
Ashley McGlone:you're exposing devices to
Ashley McGlone:the internet that are on
Ashley McGlone:a plant floor, obviously
Ashley McGlone:that's gonna be a concern.
Ashley McGlone:These days, everybody knows better
Ashley McGlone:than directly exposing devices
Ashley McGlone:to the internet, I would hope.
Ashley McGlone:But even just typical Windows
Ashley McGlone:and Linux boxes that are sitting
Ashley McGlone:there beside the line controlling
Ashley McGlone:a machine in the assembly process
Ashley McGlone:of manufacturing, for example.
Ashley McGlone:Those machines are still there,
Ashley McGlone:still running old operating
Ashley McGlone:systems and still vulnerable.
Luigi Tiano:That's a good point.
Luigi Tiano:You're right.
Luigi Tiano:We often forget that.
Luigi Tiano:We put the box in the corner, it's
Luigi Tiano:got the same password for the last
Luigi Tiano:12 years, hasn't been updated or
Luigi Tiano:patched or anything like that.
Luigi Tiano:And it's kinda just
Luigi Tiano:running the old system.
Luigi Tiano:Those present obviously big
Luigi Tiano:vulnerabilities in a plant floor.
Ashley McGlone:Some people
Ashley McGlone:call that IT / OT convergence.
Ashley McGlone:Some people say, oh, that
Ashley McGlone:happened years ago, as soon as
Ashley McGlone:we put a PC on the plant floor.
Ashley McGlone:Other people say it's
Ashley McGlone:still converging.
Ashley McGlone:You've got windows and Linux
Ashley McGlone:devices typically usually on
Ashley McGlone:older flavors of the operating
Ashley McGlone:system, often not up to date,
Ashley McGlone:that are put on the controlling,
Ashley McGlone:mission critical processes,
Ashley McGlone:that are time sensitive and,
Ashley McGlone:sometimes attached to millions
Ashley McGlone:of dollars of pieces of equipment
Ashley McGlone:that are very sensitive.
Ashley McGlone:So it's not your IT
Ashley McGlone:environment at all.
Ashley McGlone:What we hear often is that, if
Ashley McGlone:you try to take IT processes
Ashley McGlone:and just copy paste into the
Ashley McGlone:OT environment, you're gonna
Ashley McGlone:break things right off the bat.
Ashley McGlone:When you think about this
Ashley McGlone:mindset change between IT and OT.
Ashley McGlone:In IT, we're concerned about
Ashley McGlone:confidentiality, integrity,
Ashley McGlone:authenticity, and the CIA triad.
Ashley McGlone:But on the plant floor, the
Ashley McGlone:number one concern is human
Ashley McGlone:safety and that trumps everything.
Ashley McGlone:So it really is a different
Ashley McGlone:place to operate technology.
Luigi Tiano:Absolutely.
Luigi Tiano:I think that's always been
Luigi Tiano:the biggest challenge.
Luigi Tiano:Like you mentioned, merging
Luigi Tiano:those two mindsets together.
Luigi Tiano:The technology is one thing,
Luigi Tiano:but the mindset is really.
Luigi Tiano:And you're right, safety
Luigi Tiano:should never be overlooked,
Luigi Tiano:a hundred percent.
Luigi Tiano:To go back to what you said,
Luigi Tiano:if anyone's ever been on a
Luigi Tiano:plant floor, you've seen that
Luigi Tiano:PC that's got Four inches of
Luigi Tiano:dust on the keyboard and four
Luigi Tiano:inches of dust on the monitor.
Luigi Tiano:And it's never been touched,
Luigi Tiano:never been clean, but it's
Luigi Tiano:just rock solid and working.
Luigi Tiano:So we don't touch it.
Luigi Tiano:Let me double click on
Luigi Tiano:the next question, which
Luigi Tiano:is all about visibility.
Luigi Tiano:We talk about a lot of
Luigi Tiano:manufacturing customers, about
Luigi Tiano:visibility and control of
Luigi Tiano:their OT environments, right?
Luigi Tiano:So what are you hearing as
Luigi Tiano:trends in that specific space?
Ashley McGlone:As much as
Ashley McGlone:we would like to think that
Ashley McGlone:this is the year, 2023 and
Ashley McGlone:everybody's all wired up, digital
Ashley McGlone:transformation's complete.
Ashley McGlone:I talk to a lot of smaller
Ashley McGlone:manufacturers and suppliers who are
Ashley McGlone:literally just now getting started.
Ashley McGlone:I've had even larger manufacturers
Ashley McGlone:tell me; if we had a ransomware
Ashley McGlone:event in the plant, we have
Ashley McGlone:a spreadsheet from five years
Ashley McGlone:ago with our asset inventory.
Ashley McGlone:And we all know that's
Ashley McGlone:just not going to work.
Ashley McGlone:Unfortunately, a lot of people
Ashley McGlone:are still just getting started.
Ashley McGlone:And I think what's happening
Ashley McGlone:is, let's say you work with
Ashley McGlone:automotive and you've got a
Ashley McGlone:top tier automotive company.
Ashley McGlone:That OEM that's supplying the
Ashley McGlone:federal government in the US.
Ashley McGlone:So now there's CMMC Cybersecurity
Ashley McGlone:Maturity Model Certification.
Ashley McGlone:It's now at 2.0 getting
Ashley McGlone:ready to be effective here
Ashley McGlone:within the next couple years.
Ashley McGlone:Then all of a sudden, now you
Ashley McGlone:find yourself maybe you're not a
Ashley McGlone:tier one supplier to that auto.
Ashley McGlone:Maybe you're a tier
Ashley McGlone:two, tier three.
Ashley McGlone:All of a sudden, depending
Ashley McGlone:on how close you are, what
Ashley McGlone:you're supplying, you could
Ashley McGlone:be susceptible to compliance
Ashley McGlone:for US federal government.
Ashley McGlone:Or if you're in Europe, maybe it's
Ashley McGlone:Tisax or NIST two or maybe it's
Ashley McGlone:in US, the White House executive
Ashley McGlone:orders around cybersecurity.
Ashley McGlone:All of a sudden there's
Ashley McGlone:this really big regulatory
Ashley McGlone:compliance landscape.
Ashley McGlone:Now, standards have been around
Ashley McGlone:for years, but it's this regulatory
Ashley McGlone:compliance that's forcing
Ashley McGlone:people to take a look because
Ashley McGlone:manufacturing is, unfortunately
Ashley McGlone:increasingly in the headlines
Ashley McGlone:with ransomware, malware and
Ashley McGlone:ransomware malware targeted
Ashley McGlone:at manufacturing specifically.
Ashley McGlone:There was a headline a couple
Ashley McGlone:years ago where there was
Ashley McGlone:ransomware that was looking
Ashley McGlone:at over 60 windows executables
Ashley McGlone:running on the line side, and
Ashley McGlone:it would kill those processes
Ashley McGlone:before it ransomed the box.
Ashley McGlone:So it was specifically
Ashley McGlone:targeted manufacturing.
Ashley McGlone:That's got a lot of people
Ashley McGlone:concerned obviously.
Ashley McGlone:A lot of people are just getting
Ashley McGlone:started and they don't have the
Ashley McGlone:basic inventory visibility into
Ashley McGlone:what are my devices, whether
Ashley McGlone:they're Windows, Linux, or those
Ashley McGlone:lower tier PLC sensor type devices.
Ashley McGlone:Visibility really is the
Ashley McGlone:first place to start.
Ashley McGlone:And what I find is a lot
Ashley McGlone:of people are evaluating
Ashley McGlone:software solutions there.
Ashley McGlone:They're looking for things
Ashley McGlone:that can inventory those
Ashley McGlone:devices on the plant floor.
Ashley McGlone:If I started naming vendors because
Ashley McGlone:there are dozens of vendors in
Ashley McGlone:that space now who are helping
Ashley McGlone:to provide that visibility.
Ashley McGlone:At the risk of going too
Ashley McGlone:long on this answer, I'll
Ashley McGlone:also say another big concern
Ashley McGlone:is staffing and skillset.
Luigi Tiano:I was gonna say that.
Luigi Tiano:That's always been a
Luigi Tiano:challenge in manufacturing.
Luigi Tiano:Traditional, non IT environments.
Luigi Tiano:It's about operations, it's
Luigi Tiano:about efficiency, it's about
Luigi Tiano:automation and safety, of
Luigi Tiano:course, but technology's kind
Luigi Tiano:of always taken a backseat,
Luigi Tiano:and correct me if I'm wrong.
Ashley McGlone:There's people
Ashley McGlone:that design these processes and
Ashley McGlone:they've used technology for years,
Ashley McGlone:but security wasn't a concern
Ashley McGlone:because they weren't exposed to
Ashley McGlone:the internet, like they are now.
Ashley McGlone:So you've got skillsets in
Ashley McGlone:traditional industrial environments
Ashley McGlone:that are having to either learn
Ashley McGlone:new skills or you have IT people
Ashley McGlone:coming in telling them what to do.
Ashley McGlone:Then the production
Ashley McGlone:engineering folks are
Ashley McGlone:saying, now, wait a minute.
Ashley McGlone:It doesn't work that way here.
Ashley McGlone:You've got this hybridized
Ashley McGlone:skillset between a cybersecurity
Ashley McGlone:mindset coming into a
Ashley McGlone:manufacturing environment.
Ashley McGlone:So that really is a critical
Ashley McGlone:skillset to have now is having
Ashley McGlone:a security mind and an OT mind,
Ashley McGlone:so you can bring those together
Ashley McGlone:and doing it in a safe way.
Luigi Tiano:Sounds like it's
Luigi Tiano:not an easy skill set to find,
Luigi Tiano:based on what I've just heard.
Ashley McGlone:Yeah.
Ashley McGlone:The cyber field as a whole.
Ashley McGlone:I've heard stats, you get different
Ashley McGlone:numbers, like millions of openings
Ashley McGlone:that'll go unfilled, right?
Ashley McGlone:And then when you get into niche
Ashley McGlone:areas like this, where it's a
Ashley McGlone:hybrid of IT and OT coming together
Ashley McGlone:with cyber in the skillset,
Ashley McGlone:it is a niche skillset area.
Ashley McGlone:What a lot of companies are going
Ashley McGlone:to end up doing because they
Ashley McGlone:can't afford a senior person in
Ashley McGlone:that space, cuz manufacturing
Ashley McGlone:budgets are always tight,
Ashley McGlone:especially when it comes to
Ashley McGlone:staffing for something like this.
Ashley McGlone:A lot of times you're going to
Ashley McGlone:hire people straight out of college
Ashley McGlone:and there's gonna be a lot of O
Ashley McGlone:J T a lot of on-the-job training.
Ashley McGlone:There's some resources
Ashley McGlone:I'll talk about later that
Ashley McGlone:can really help with that.
Luigi Tiano:Yeah,
Luigi Tiano:that's very good.
Luigi Tiano:Before we move on to the next
Luigi Tiano:question, anything else you
Luigi Tiano:wanna say about visibility in
Luigi Tiano:OT environments or you wanna,
Luigi Tiano:we can circle back at the end?
Ashley McGlone:I think
Ashley McGlone:I'm good on there for now.
Luigi Tiano:All right.
Luigi Tiano:All right.
Luigi Tiano:So you mentioned a lot of
Luigi Tiano:companies are just getting started.
Luigi Tiano:So if you've seen this, you've
Luigi Tiano:obviously lived this through
Luigi Tiano:conversations with your clients.
Luigi Tiano:How does a company get started?
Luigi Tiano:If you're a manufacturing
Luigi Tiano:company, just listening to
Luigi Tiano:this podcast at random, how
Luigi Tiano:does the company get started?
Luigi Tiano:Where do they look,
Luigi Tiano:what do they do?
Ashley McGlone:Number one,
Ashley McGlone:you're not alone, especially if
Ashley McGlone:you're in the smaller tier space.
Ashley McGlone:There are a lot of bigger companies
Ashley McGlone:who have already walked this path.
Ashley McGlone:They've crafted best practices.
Ashley McGlone:They put that into guidance.
Ashley McGlone:You may have heard of the
Ashley McGlone:Purdue model for the structuring
Ashley McGlone:of systems in manufacturing
Ashley McGlone:or industrial environment.
Ashley McGlone:You take another layer to the I S
Ashley McGlone:A I E C, more alphabet here, 6 2
Ashley McGlone:4 43 and we'll have links in the
Ashley McGlone:show notes for folks to this stuff.
Ashley McGlone:But ISA 6 2 4 43 is the
Ashley McGlone:international standard for
Ashley McGlone:cybersecurity practices in
Ashley McGlone:a manufacturing environment.
Ashley McGlone:It's gonna help you
Ashley McGlone:categorize and sort through.
Ashley McGlone:If I'm just staring at I-beams
Ashley McGlone:and network cables and equipment,
Ashley McGlone:how do I make sense of this?
Ashley McGlone:Where do I draw the lines virtually
Ashley McGlone:for, how do I organize this
Ashley McGlone:into an actual cyber strategy
Ashley McGlone:for my industrial environment?
Ashley McGlone:So it's gonna have a five
Ashley McGlone:layer stack that goes from top
Ashley McGlone:traditional kind of IT systems,
Ashley McGlone:running Windows and Linux and
Ashley McGlone:such, all the way down to those
Ashley McGlone:lower tier devices that are
Ashley McGlone:running some type of firmware
Ashley McGlone:maybe that you need to monitor
Ashley McGlone:or maybe it's just a dial that's
Ashley McGlone:controlling something all the way
Ashley McGlone:down the sensors and actuators.
Ashley McGlone:They've carved that out.
Ashley McGlone:They've identified, okay,
Ashley McGlone:here's the vocabulary you
Ashley McGlone:even used to talk about it.
Ashley McGlone:I've got a security level
Ashley McGlone:target that I want to get to.
Ashley McGlone:Here's the security level
Ashley McGlone:capability of what we can do today.
Ashley McGlone:Then that gives us this
Ashley McGlone:gap that we need to close
Ashley McGlone:and zones and conduits.
Ashley McGlone:Here are machines that are
Ashley McGlone:going to be compensating
Ashley McGlone:controls, we can't update them.
Ashley McGlone:So they're gonna get firewalled
Ashley McGlone:or air gaped over here.
Ashley McGlone:That's a zone.
Ashley McGlone:Then a conduit's that network
Ashley McGlone:connection coming in and
Ashley McGlone:out of there for firewall
Ashley McGlone:connections, so to speak.
Ashley McGlone:You've got network segmentation
Ashley McGlone:between the carpet and the cement.
Ashley McGlone:So between IT and OT, making
Ashley McGlone:sure you've got the right
Ashley McGlone:firewalls in place and if Mary
Ashley McGlone:in accounting clicks a phishing
Ashley McGlone:link, it doesn't take down
Ashley McGlone:manufacturing and vice versa.
Ashley McGlone:There's a lot here and
Ashley McGlone:there's a lot of precedent.
Ashley McGlone:If you're just getting started,
Ashley McGlone:there's a lot of resources
Ashley McGlone:available to help you.
Ashley McGlone:There's a deep bench with
Ashley McGlone:consulting practices and providers
Ashley McGlone:like yourself who have done
Ashley McGlone:work in this space, who can
Ashley McGlone:really help people first off
Ashley McGlone:to get oriented and that's what
Ashley McGlone:I've noticed a lot of the calls
Ashley McGlone:that I've had even recently is
Ashley McGlone:just helping people understand
Ashley McGlone:where do I take that first step?
Luigi Tiano:Yeah and
Luigi Tiano:these standards, I'll
Luigi Tiano:just say numbers again.
Luigi Tiano:So ISA i e c 6 2 4 43.
Luigi Tiano:I think these international
Luigi Tiano:standards force both the IT and
Luigi Tiano:the OT folks, so you said process
Luigi Tiano:engineer first to work together
Luigi Tiano:and merge those processes.
Luigi Tiano:As much as they are different, I
Luigi Tiano:think these standards are extremely
Luigi Tiano:important and should be adopted
Luigi Tiano:obviously by these organizations
Luigi Tiano:because if there's a skillset
Luigi Tiano:gap from a process wise, this
Luigi Tiano:forces them to work together.
Luigi Tiano:So we're seeing this
Luigi Tiano:across the board.
Luigi Tiano:I'm glad you brought that up
Luigi Tiano:because I think it's important
Luigi Tiano:that individuals know this.
Luigi Tiano:The standard, obviously
Luigi Tiano:you're well-versed in it.
Luigi Tiano:Is this something you get to
Luigi Tiano:stamp once and then you have
Luigi Tiano:yearly checks or do you know
Luigi Tiano:how long this standard would
Luigi Tiano:last within an organization?
Ashley McGlone:In the realm
Ashley McGlone:of regulations, compliance,
Ashley McGlone:attestations, this is just a
Ashley McGlone:standard that's a recommendation
Ashley McGlone:that you should align to.
Ashley McGlone:I would say that it's not enforced,
Ashley McGlone:but when things like we're seeing
Ashley McGlone:in EMEA right now with the Nist 2
Ashley McGlone:is actually coming in and putting
Ashley McGlone:teeth to some of this to actually
Ashley McGlone:enforce it and putting penalties
Ashley McGlone:there where there weren't, before.
Ashley McGlone:For the last 20 years, ISA
Ashley McGlone:62443 has just been a standard.
Ashley McGlone:Hey, this is a good
Ashley McGlone:way to think about it.
Ashley McGlone:The design and framework
Ashley McGlone:give the industry a common
Ashley McGlone:vocabulary and put training
Ashley McGlone:and resources behind it.
Ashley McGlone:Yeah it's actually got a little
Ashley McGlone:more legs now, with the headlines
Ashley McGlone:over the last few years.
Luigi Tiano:Just to touch
Luigi Tiano:on that, when we talk about
Luigi Tiano:regulatory compliance for us as an
Luigi Tiano:organization, especially when we're
Luigi Tiano:talking with clients, when you
Luigi Tiano:abide by or conform to a specific
Luigi Tiano:standard, you earn the right to
Luigi Tiano:do business with more partners.
Luigi Tiano:If you don't have the controls
Luigi Tiano:in place, that's fine.
Luigi Tiano:But if you want to continue to
Luigi Tiano:conduct business with certain
Luigi Tiano:entities, you're gonna be required
Luigi Tiano:to show that you actually meet
Luigi Tiano:a certain level of standards.
Luigi Tiano:Whether it's enforced legally
Luigi Tiano:or not, I think more and more
Luigi Tiano:companies are just gonna abide by
Luigi Tiano:a specific standard cause they want
Luigi Tiano:to continue to do business or earn
Luigi Tiano:the right with certain enterprises
Luigi Tiano:that they once could not do that.
Ashley McGlone:You're
Ashley McGlone:describing supply chain risk.
Luigi Tiano:There you go.
Ashley McGlone:And that is top
Ashley McGlone:of mind for everybody right now.
Ashley McGlone:I remember when I used to work
Ashley McGlone:for Toyota, for example, the
Ashley McGlone:automotive seat supplier, the
Ashley McGlone:seats would come in off the semi
Ashley McGlone:truck in the order that cars were
Ashley McGlone:going down the assembly line.
Ashley McGlone:If that seat supplier then had
Ashley McGlone:a cyber breach, even if there's
Ashley McGlone:nothing cyber in the seat itself,
Ashley McGlone:if they were victim to ransomware
Ashley McGlone:and that supply paused, it would
Ashley McGlone:pause the cars going down the line.
Ashley McGlone:Even if you make wiring harnesses
Ashley McGlone:that have no embedded technology.
Ashley McGlone:If you can't supply those
Ashley McGlone:because you've been breached,
Ashley McGlone:you're gonna impact all
Ashley McGlone:your supply chain partners.
Ashley McGlone:So whether or not you think
Ashley McGlone:it applies to you, it does.
Luigi Tiano:Exactly.
Luigi Tiano:Got another question here
Luigi Tiano:about OT environments.
Luigi Tiano:We see such a diverse
Luigi Tiano:mix of devices.
Luigi Tiano:How do you manage all those types
Luigi Tiano:of devices with one solution?
Luigi Tiano:Is it even possible?
Ashley McGlone:It's not, no.
Ashley McGlone:I tell you the more people I talk
Ashley McGlone:to, whether it's partners, other
Ashley McGlone:vendors prospects and customers
Ashley McGlone:in this space, everybody's
Ashley McGlone:looking for a silver bullet.
Ashley McGlone:There is no one software solution
Ashley McGlone:that's gonna give you that
Ashley McGlone:ultimate visibility control
Ashley McGlone:from one end to the other.
Ashley McGlone:Today, it doesn't exist.
Ashley McGlone:What you will find though,
Ashley McGlone:is what I prefer to call
Ashley McGlone:strategic platform partnerships.
Ashley McGlone:Now, don't get me wrong.
Ashley McGlone:There are some companies out there
Ashley McGlone:that say, yeah, we do IT, and OT.
Ashley McGlone:But you've gotta dig a little
Ashley McGlone:deeper below the marketing
Ashley McGlone:messaging and say, okay, what
Ashley McGlone:exactly do you do in IT and OT?
Ashley McGlone:Maybe you only scan for
Ashley McGlone:vulnerabilities and that's it.
Ashley McGlone:It doesn't stop there.
Ashley McGlone:I need to fix those
Ashley McGlone:vulnerabilities, right?
Ashley McGlone:I need to enforce policy
Ashley McGlone:on those works stations.
Ashley McGlone:I got Windows and Linux that
Ashley McGlone:I need to manage firewall and
Ashley McGlone:disc encryption and things
Ashley McGlone:like that, on the plant floor.
Ashley McGlone:It goes beyond just a narrow
Ashley McGlone:feature matrix to actually a broad
Ashley McGlone:set of full manageability for
Ashley McGlone:the plant floor from IT and OT
Ashley McGlone:and where that convergence meets.
Ashley McGlone:What I'm seeing today is as I
Ashley McGlone:talk to people who are in this
Ashley McGlone:starting process, they are actively
Ashley McGlone:investigating vendors that do
Ashley McGlone:like port spanning on the network.
Ashley McGlone:There's dozens of vendors in this
Ashley McGlone:space that'll listen and find those
Ashley McGlone:devices passively on the network.
Ashley McGlone:Then there's need for some
Ashley McGlone:active scanning as well, cuz
Ashley McGlone:some of those devices will never
Ashley McGlone:initiate a network connection.
Ashley McGlone:Then you've got your traditional
Ashley McGlone:distributed control systems
Ashley McGlone:vendors like Siemens and
Ashley McGlone:Rockwell and Honeywell and GE.
Ashley McGlone:I could name those for a while.
Ashley McGlone:You've got all those
Ashley McGlone:vendors who have their own
Ashley McGlone:cybersecurity practices as well.
Ashley McGlone:What I typically recommend,
Ashley McGlone:you know what we do is helping
Ashley McGlone:people with visibility on
Ashley McGlone:the top tier of that model.
Ashley McGlone:So the Windows and Linux
Ashley McGlone:devices, we can give you all
Ashley McGlone:the capability you need there.
Ashley McGlone:Let's take that and use some
Ashley McGlone:common backend like Splunk or
Ashley McGlone:ServiceNow or Microsoft Sentinel.
Ashley McGlone:Some type of sim source
Ashley McGlone:solution, C M D B.
Ashley McGlone:Let's take all that Tanium data,
Ashley McGlone:put it in there, and then take
Ashley McGlone:your other solutions in this space
Ashley McGlone:that most of them are already
Ashley McGlone:pre-wired for ServiceNow or
Ashley McGlone:Splunk, something on the backend.
Ashley McGlone:Then, use that backend for that
Ashley McGlone:end-to-end visibility and control
Ashley McGlone:for your IT OT SOC experience.
Luigi Tiano:Interesting.
Luigi Tiano:So what I heard was, form a
Luigi Tiano:strategic platform of partnerships.
Luigi Tiano:Make sure you've got a bunch
Luigi Tiano:of partners that can then
Luigi Tiano:fill those needs cuz there's
Luigi Tiano:just no silver bullet.
Ashley McGlone:So the benefit
Ashley McGlone:there is, rather than having
Ashley McGlone:a dozen solutions with a dozen
Ashley McGlone:integration points in this matrix
Ashley McGlone:of integrations, you can really
Ashley McGlone:optimize that down to just a
Ashley McGlone:few strategic integrations,
Ashley McGlone:which is gonna make it easier
Ashley McGlone:to maintain in the long term.
Luigi Tiano:Got it.
Luigi Tiano:Very good.
Luigi Tiano:One last question cuz then
Luigi Tiano:I wanna talk a little bit
Luigi Tiano:about what you do and maybe
Luigi Tiano:how your platform could help.
Luigi Tiano:You've mentioned a lot of things
Luigi Tiano:here and obviously I wanna give
Luigi Tiano:you the time to talk about that.
Luigi Tiano:What resources are available
Luigi Tiano:to help companies today?
Luigi Tiano:We talked about how
Luigi Tiano:they get started.
Luigi Tiano:Obviously a bunch of stuff online,
Luigi Tiano:but what would you recommend?
Ashley McGlone:There's
Ashley McGlone:always the free and easy
Ashley McGlone:Wikipedia and YouTube, right?
Ashley McGlone:You can learn anything on
Ashley McGlone:Wikipedia and YouTube and there's
Ashley McGlone:a ton of open, stuff like that.
Ashley McGlone:But if you're willing to invest,
Ashley McGlone:even just looking at the open,
Ashley McGlone:free resources, I would go
Ashley McGlone:straight to the SANS Institute.
Ashley McGlone:SANS has been around for years and
Ashley McGlone:everybody knows them as the source
Ashley McGlone:of trusted security training.
Ashley McGlone:SANS has a whole program for
Ashley McGlone:industrial controls, SANS ICS.
Ashley McGlone:S A N S I C S.
Ashley McGlone:Just put that in your search
Ashley McGlone:engine and we've got some links
Ashley McGlone:in the show notes here as well.
Luigi Tiano:We're definitely gonna
Luigi Tiano:share a lot of that information.
Luigi Tiano:You sent me some stuff for
Luigi Tiano:the show here, which is great.
Ashley McGlone:Yeah,
Ashley McGlone:they've got an I C S guide.
Ashley McGlone:Industrial controls guide for
Ashley McGlone:recommended controls to start.
Ashley McGlone:Things about having an
Ashley McGlone:incident response plan.
Ashley McGlone:Sure we have one of those for
Ashley McGlone:IT, but do you have it for
Ashley McGlone:your industrial environment?
Ashley McGlone:Just knowing who to call,
Ashley McGlone:where do I get my inventory?
Ashley McGlone:Where are all the firewalls?
Ashley McGlone:And who's controlling those things?
Ashley McGlone:Having that incident response
Ashley McGlone:plan, a defensible architecture,
Ashley McGlone:network visibility monitoring,
Ashley McGlone:secure remote access, and then
Ashley McGlone:even risk based vulnerability
Ashley McGlone:management, which prioritizes
Ashley McGlone:not just saying, here's all the
Ashley McGlone:volumes, but here's the ones that
Ashley McGlone:are prioritized for our equipment
Ashley McGlone:with our environment where we
Ashley McGlone:know that they are exposed.
Ashley McGlone:They have a really good guide
Ashley McGlone:that you can download for
Ashley McGlone:free just to get started.
Ashley McGlone:But they have a whole
Ashley McGlone:suite of courses.
Ashley McGlone:And I'm not compensated for
Ashley McGlone:this either, by the way.
Ashley McGlone:Just I've seen that they have
Ashley McGlone:some fantastic instructors who
Ashley McGlone:are writing, designing, living
Ashley McGlone:this every day, getting real
Ashley McGlone:world training out there to
Ashley McGlone:the people that need it most.
Ashley McGlone:Even if you're taking somebody
Ashley McGlone:off the street without this kind
Ashley McGlone:of background in their portfolio,
Ashley McGlone:you can send them to these
Ashley McGlone:classes, get them some hands
Ashley McGlone:on with this technology and get
Ashley McGlone:'em trained up and ready to go.
Luigi Tiano:Even if you're not
Luigi Tiano:getting compensated, I think you've
Luigi Tiano:obviously demonstrated a wealth
Luigi Tiano:of knowledge in this industry.
Luigi Tiano:So if you're saying SANS ICS
Luigi Tiano:is a good place to start,
Luigi Tiano:that's where I would start.
Luigi Tiano:Thanks for that, Ashley.
Luigi Tiano:Before we wrap, obviously,
Luigi Tiano:you work at Tanium.
Luigi Tiano:I see the background there.
Luigi Tiano:Maybe just tell us a little
Luigi Tiano:bit about how Tanium could
Luigi Tiano:help an organization.
Luigi Tiano:You've shared time with
Luigi Tiano:us and I appreciate that.
Luigi Tiano:So I need to give you some
Luigi Tiano:time to tell us how Tanium
Luigi Tiano:could potentially help.
Ashley McGlone:Sure.
Ashley McGlone:Tanium is a real-time endpoint
Ashley McGlone:management platform for visibility
Ashley McGlone:and control at speed and scale,
Ashley McGlone:all those marketing terms, right?
Ashley McGlone:But basically what that means is
Ashley McGlone:we have a unique architecture that
Ashley McGlone:allows us literally in seconds to
Ashley McGlone:get information from any system.
Ashley McGlone:Windows, Mac, Linux, even Solaris,
Ashley McGlone:and AIX that has an ip, it's
Ashley McGlone:connected, it's on the network.
Ashley McGlone:We can get that real time
Ashley McGlone:visibility of your environment.
Ashley McGlone:If you're wanting to know what are
Ashley McGlone:all the machines in my working from
Ashley McGlone:home, office area, on the plant
Ashley McGlone:floor, as long as it's running one
Ashley McGlone:of those OSs and it's got an ip,
Ashley McGlone:it's got Tanium client installed,
Ashley McGlone:then we can get you the richest
Ashley McGlone:data you've ever seen in real time.
Ashley McGlone:So we can scan for vulnerabilities,
Ashley McGlone:we can patch, we can manage policy,
Ashley McGlone:we can do threat detection and
Ashley McGlone:response, and a whole list of
Ashley McGlone:capabilities that gives you a very
Ashley McGlone:wide feature matrix to manage the
Ashley McGlone:top half of that OT stack, right?
Ashley McGlone:Where you've got windows and
Ashley McGlone:Linux machines out there that are
Ashley McGlone:running what matters most to you.
Ashley McGlone:I've had customers tell us,
Ashley McGlone:when they put traditional
Ashley McGlone:IT tools in there, they need
Ashley McGlone:multiple tools to do that.
Ashley McGlone:It's a performance hit on
Ashley McGlone:the endpoint, but Tanium's
Ashley McGlone:a single agent that
Ashley McGlone:covers multiple tool sets.
Ashley McGlone:With that platform approach then,
Ashley McGlone:you can reduce the impact on often
Ashley McGlone:under-resourced hardware profiles
Ashley McGlone:on these manufacturing machines.
Ashley McGlone:We've seen some real benefit
Ashley McGlone:there as well as the actual
Ashley McGlone:technology, what we're doing to
Ashley McGlone:manage and secure that environment.
Luigi Tiano:Fantastic.
Luigi Tiano:So it's all about visibility and
Luigi Tiano:knowing what you own, because
Luigi Tiano:you can't really protect if
Luigi Tiano:you don't know you own it.
Ashley McGlone:Exactly.
Luigi Tiano:I know it's
Luigi Tiano:cliche and we say it often,
Luigi Tiano:but it's the fundamental truth.
Luigi Tiano:If you don't know what exists
Luigi Tiano:on your network then, how do
Luigi Tiano:you know how to protect it or
Luigi Tiano:mitigate the risk on those devices.
Luigi Tiano:Ashley, I've learned a ton.
Luigi Tiano:I'm sure the audience
Luigi Tiano:is gonna love this.
Luigi Tiano:We will be sharing a lot of
Luigi Tiano:the links that you've sent us.
Luigi Tiano:Before we go, anything else
Luigi Tiano:you want to add because you've
Luigi Tiano:given us a lot of your time
Luigi Tiano:here and a lot of information.
Luigi Tiano:If you got nothing else, I
Luigi Tiano:just want to thank you and say,
Luigi Tiano:hopefully we can do this again.
Luigi Tiano:I'll close off with that.
Ashley McGlone:Thanks
Ashley McGlone:for the opportunity to
Ashley McGlone:come on the show, Luigi.
Ashley McGlone:I just wanna offer a word
Ashley McGlone:of encouragement because
Ashley McGlone:typically IT and OT are
Ashley McGlone:separate silos in the business.
Ashley McGlone:Only a few places where they're
Ashley McGlone:actually integrated with a
Ashley McGlone:common vision, common governance.
Ashley McGlone:It takes work to get
Ashley McGlone:there and it's worth it.
Ashley McGlone:Your business depends on it.
Ashley McGlone:Your livelihood, your family
Ashley McGlone:that you support with the income
Ashley McGlone:that you make at your employer.
Ashley McGlone:You want to keep that secure for
Ashley McGlone:your own interest, but also for
Ashley McGlone:the business and for all the people
Ashley McGlone:that are served by that business.
Ashley McGlone:It really is worth the effort
Ashley McGlone:to spend the time and to do
Ashley McGlone:the research and to get your
Ashley McGlone:program started, if you don't
Ashley McGlone:have one because security
Ashley McGlone:is not an option here.
Luigi Tiano:Time is now.
Luigi Tiano:You gotta get started.
Luigi Tiano:Ashley, it's been a pleasure.
Luigi Tiano:Thank you very much.
Luigi Tiano:Hope to talk to you again soon.
Ashley McGlone:Take care.
Luigi Tiano:Thank you.
Luigi Tiano:Bye-bye.