Artwork for podcast 10 Questions to Cyber Resilience
Unlocking the Secrets of Manufacturing Cybersecurity, with Tanium's Ashley McGlone
Episode 41st December 2023 • 10 Questions to Cyber Resilience • Assurance IT
00:00:00 00:27:15

Share Episode

Shownotes

Dive into the world of manufacturing cybersecurity with an insightful podcast episode featuring Ashley McGlone, a seasoned technology strategist from Tanium. Join your host, Luigi Tiano, as he engages in a riveting conversation with Ashley, unraveling the complexities of Industry 4.0, IoT, and the critical role of cybersecurity in the manufacturing landscape.

In this episode, Ashley shares his wealth of expertise, drawing on decades of experience in the tech industry, including roles at Microsoft, Toyota, and his current tenure at Tanium. The duo delves into the challenges posed by the convergence of IT and OT, exploring the unique cybersecurity concerns faced by manufacturing companies in an era of increased connectivity and automation.

Discover the significance of standards like ISA 62443 and the Purdue model in structuring cybersecurity practices for manufacturing environments. Luigi and Ashley explore the pressing need for visibility and control in OT environments, shedding light on the evolving trends and the potential risks associated with cloud integration.

As the conversation unfolds, Ashley provides valuable insights into the diverse mix of devices in manufacturing and how strategic platform partnerships can be the key to effective cybersecurity. The duo navigates the landscape of resources available for companies venturing into cybersecurity enhancements, with a special spotlight on the SANS Institute's industrial controls training.

 

Resources: 

Watch the episode: https://youtu.be/1u6Ot5s-sXI

Ashley's LinkedIn: https://www.linkedin.com/in/ashleymcglone/

Tanium's website: https://www.tanium.com/

Luigi Tiano’s LinkedIn: https://www.linkedin.com/in/luigitiano/

Assurance IT Website: http://www.assuranceit.ca/

 

 

About Ashley McGlone: 

Ashley McGlone has spent his life in IT. Between recordings of Tanium Tech Talks he enjoys advocating for customers, getting in the weeds of tech, and savoring a particular retro variety of red licorice. In his role as Technology Strategist he researches and creates vertical-specific guidance for customers to maximize their Tanium experience. He also is a megaphone for customer feedback to the Tanium product teams. As a frequent conference speaker he's always looking for opportunities to share the "Wow Tanium" experience with new audiences. Message him just to say hi or to talk Tanium and tech.


About 10 Questions to Cyber Resilience: 

Twice per month, learn about how IT leaders are strengthening their cyber security practices. Every episode comprises of 10 questions that get you one step closer to cyber resilience. Subscribe to stay up-to-date with hot topics in cyber security. 

 


About Assurance IT: 

Assurance IT (www.assuranceit.ca) specializes in data protection and data privacy for the mid-market in Canada, since 2011. The Montreal-based company’s unique approach to helping customers become cyber resilient is called the PPR Methodology which stands for Prepare, Protect and Recover. Based on industry best practices, the PPR Methodology is an easier way to achieve cyber security and compliance objectives.

Transcripts

Luigi Tiano:

All right.

Luigi Tiano:

Good morning everyone.

Luigi Tiano:

Good day.

Luigi Tiano:

Today I've got Ashley McGlone from

Luigi Tiano:

Tanium with me in the podcast.

Luigi Tiano:

I had the opportunity to talk

Luigi Tiano:

with one of his colleagues

Luigi Tiano:

a couple days ago, and we

Luigi Tiano:

talked about specifically

Luigi Tiano:

manufacturing and cybersecurity

Luigi Tiano:

in the manufacturing field.

Luigi Tiano:

So without further ado, I'm gonna

Luigi Tiano:

ask Ashley to introduce himself.

Luigi Tiano:

What his expertise is, where he

Luigi Tiano:

is working today what he likes

Luigi Tiano:

to do on a day-to-day basis.

Luigi Tiano:

And then we'll start from there.

Ashley McGlone:

Thanks for

Ashley McGlone:

having me on the show, Luigi.

Ashley McGlone:

This is a lot of fun.

Ashley McGlone:

Been looking forward to it.

Ashley McGlone:

Yeah.

Ashley McGlone:

I'm Ashley McGlone.

Ashley McGlone:

I'm a technology strategist

Ashley McGlone:

in our manufacturing segment.

Ashley McGlone:

So I've spent the last few

Ashley McGlone:

years here in this part of my

Ashley McGlone:

tenure at Tanium, focusing on

Ashley McGlone:

manufacturing customers and where

Ashley McGlone:

Tanium is relevant to them on

Ashley McGlone:

the factory floor, helping them

Ashley McGlone:

with visibility and control.

Ashley McGlone:

I've been here at Tanium

Ashley McGlone:

five and a half years.

Ashley McGlone:

Before that, I was with

Ashley McGlone:

Microsoft for about eight years.

Ashley McGlone:

Before that, Toyota

Ashley McGlone:

for about eight years.

Ashley McGlone:

And if you go all the way

Ashley McGlone:

back, I started with Commodore

Ashley McGlone:

in 1982, so I've been doing

Ashley McGlone:

technology for four decades now.

Luigi Tiano:

Wow.

Luigi Tiano:

Impressive.

Luigi Tiano:

Impressive.

Luigi Tiano:

I'm sure the time at Toyota

Luigi Tiano:

helped build your knowledge with

Luigi Tiano:

regards to manufacturing there.

Luigi Tiano:

Obviously manufacturing has

Luigi Tiano:

become a huge, fundamental

Luigi Tiano:

piece of our ecosystem.

Luigi Tiano:

It's really integral

Luigi Tiano:

into everything.

Luigi Tiano:

What we're seeing and more so now

Luigi Tiano:

is that manufacturing companies,

Luigi Tiano:

like it or not, have become huge

Luigi Tiano:

attack surfaces for bad actors.

Luigi Tiano:

There's so much technology

Luigi Tiano:

that's being integrated

Luigi Tiano:

on a day-to-day basis.

Luigi Tiano:

I know you're very tactical

Luigi Tiano:

in your day-to-day.

Luigi Tiano:

Can you define some

Luigi Tiano:

of the terms we hear?

Luigi Tiano:

Some of the people listening

Luigi Tiano:

to the podcast may or may

Luigi Tiano:

not know what the terms are.

Luigi Tiano:

We talk about IT, we talk about

Luigi Tiano:

I o T, we talk about OT, I I

Luigi Tiano:

o T, maybe give us an overview

Luigi Tiano:

of what all that's about.

Ashley McGlone:

There's a lot

Ashley McGlone:

of i's and o's and t's in there.

Ashley McGlone:

Let's sort 'em out.

Ashley McGlone:

So IT, that's what a

Ashley McGlone:

lot of us do every day.

Ashley McGlone:

That's our typical

Ashley McGlone:

corporate infrastructure.

Ashley McGlone:

Sometimes they like to separate it

Ashley McGlone:

between the carpet and the paint

Ashley McGlone:

or the carpet and the concrete.

Ashley McGlone:

So the carpet is the

Ashley McGlone:

office, that's IT.

Ashley McGlone:

The concrete is the OT.

Ashley McGlone:

That's your industrial environment.

Ashley McGlone:

Operating technology is

Ashley McGlone:

what that stands for.

Ashley McGlone:

It could be the dials that

Ashley McGlone:

turn the chlorine balance

Ashley McGlone:

in a water treatment plant.

Ashley McGlone:

Those types of industrial

Ashley McGlone:

equipment type environments,

Ashley McGlone:

that's the operating technology

Ashley McGlone:

that makes the physical.

Ashley McGlone:

It's a cyber physical interface

Ashley McGlone:

between this technology is gonna

Ashley McGlone:

control a physical process.

Ashley McGlone:

That's the operating technology.

Ashley McGlone:

Then IOT is internet

Ashley McGlone:

of things, obviously.

Ashley McGlone:

That can be anything

Ashley McGlone:

from IP cameras to...

Ashley McGlone:

At one customer, they had

Ashley McGlone:

vulnerable Amazon Firesticks

Ashley McGlone:

in their presentation

Ashley McGlone:

TVs and conference rooms.

Ashley McGlone:

So it could be any internet

Ashley McGlone:

connected device that's not

Ashley McGlone:

traditionally manageable like that.

Ashley McGlone:

Then IoT and a lot of different

Ashley McGlone:

verticals, like medical,

Ashley McGlone:

have their own IoT flavor.

Ashley McGlone:

So industrial IoT then instead

Ashley McGlone:

of IoMT like medical and every

Ashley McGlone:

vertical's got their own iot.

Ashley McGlone:

An industrial IoT is often

Ashley McGlone:

looped in with Industry 4.0,

Ashley McGlone:

which is the latest revolution

Ashley McGlone:

of plant floor technology,

Ashley McGlone:

of which involves things like

Ashley McGlone:

5G for wireless connectivity,

Ashley McGlone:

especially in more rugged or

Ashley McGlone:

network challenged environments.

Ashley McGlone:

You've got those same IoT type

Ashley McGlone:

technologies, but in the plant

Ashley McGlone:

space used for manufacturing

Ashley McGlone:

or industrial control purposes.

Ashley McGlone:

Often, you'll see as well a gateway

Ashley McGlone:

device where now the legacy devices

Ashley McGlone:

that were previously not connected

Ashley McGlone:

to the internet have a gateway

Ashley McGlone:

to get out to cloud services.

Ashley McGlone:

It's really a game changer.

Ashley McGlone:

It blows my mind.

Ashley McGlone:

When you think about mission

Ashley McGlone:

critical plant floor systems that

Ashley McGlone:

are now connected to the cloud,

Ashley McGlone:

taking on that big dependency

Ashley McGlone:

for another point of failure.

Ashley McGlone:

So there's a lot of concern

Ashley McGlone:

for a lot of traditional

Ashley McGlone:

manufacturing folks.

Ashley McGlone:

Do we go that path or not?

Ashley McGlone:

But that's the whole gamut from

Ashley McGlone:

IT, OT, Io T there you go.

Luigi Tiano:

Okay.

Luigi Tiano:

So you really went

Luigi Tiano:

deep dive in there.

Luigi Tiano:

I appreciate that.

Luigi Tiano:

You mentioned Industry 4.0.

Luigi Tiano:

Let me just double click on that.

Luigi Tiano:

So Industry 4.0, is that a

Luigi Tiano:

standard or kind of a terminology

Luigi Tiano:

that we're using to augment

Luigi Tiano:

or increase the efficiency or

Luigi Tiano:

automation in a plant floor?

Luigi Tiano:

How do you describe

Luigi Tiano:

that specifically?

Ashley McGlone:

Personally,

Ashley McGlone:

I'm not sure that it's a

Ashley McGlone:

standard necessarily, but I

Ashley McGlone:

think it's a bucket phrase

Ashley McGlone:

that captures a lot of that.

Ashley McGlone:

I'm sure there are people

Ashley McGlone:

that could go into the

Ashley McGlone:

line items and explain why

Ashley McGlone:

it's different than 3.0.

Ashley McGlone:

That's technology, right?

Ashley McGlone:

You got 1, 2, 3, 4.

Ashley McGlone:

This is the latest iteration,

Ashley McGlone:

which includes cloud connectivity

Ashley McGlone:

on the plant floor systems.

Luigi Tiano:

You mentioned

Luigi Tiano:

something really important there.

Luigi Tiano:

The gateway into cloud management.

Luigi Tiano:

Traditional PLCs or

Luigi Tiano:

traditional plant floor

Luigi Tiano:

technology would typically

Luigi Tiano:

not have any external access.

Luigi Tiano:

And I think that gateway now,

Luigi Tiano:

as much as it's creating that

Luigi Tiano:

operational efficiency or

Luigi Tiano:

automation and that layer of

Luigi Tiano:

management, I think that's where,

Luigi Tiano:

correct me if I'm wrong, is

Luigi Tiano:

that where that gateway brings

Luigi Tiano:

in also the security concern?

Ashley McGlone:

Yes, if

Ashley McGlone:

you're exposing devices to

Ashley McGlone:

the internet that are on

Ashley McGlone:

a plant floor, obviously

Ashley McGlone:

that's gonna be a concern.

Ashley McGlone:

These days, everybody knows better

Ashley McGlone:

than directly exposing devices

Ashley McGlone:

to the internet, I would hope.

Ashley McGlone:

But even just typical Windows

Ashley McGlone:

and Linux boxes that are sitting

Ashley McGlone:

there beside the line controlling

Ashley McGlone:

a machine in the assembly process

Ashley McGlone:

of manufacturing, for example.

Ashley McGlone:

Those machines are still there,

Ashley McGlone:

still running old operating

Ashley McGlone:

systems and still vulnerable.

Luigi Tiano:

That's a good point.

Luigi Tiano:

You're right.

Luigi Tiano:

We often forget that.

Luigi Tiano:

We put the box in the corner, it's

Luigi Tiano:

got the same password for the last

Luigi Tiano:

12 years, hasn't been updated or

Luigi Tiano:

patched or anything like that.

Luigi Tiano:

And it's kinda just

Luigi Tiano:

running the old system.

Luigi Tiano:

Those present obviously big

Luigi Tiano:

vulnerabilities in a plant floor.

Ashley McGlone:

Some people

Ashley McGlone:

call that IT / OT convergence.

Ashley McGlone:

Some people say, oh, that

Ashley McGlone:

happened years ago, as soon as

Ashley McGlone:

we put a PC on the plant floor.

Ashley McGlone:

Other people say it's

Ashley McGlone:

still converging.

Ashley McGlone:

You've got windows and Linux

Ashley McGlone:

devices typically usually on

Ashley McGlone:

older flavors of the operating

Ashley McGlone:

system, often not up to date,

Ashley McGlone:

that are put on the controlling,

Ashley McGlone:

mission critical processes,

Ashley McGlone:

that are time sensitive and,

Ashley McGlone:

sometimes attached to millions

Ashley McGlone:

of dollars of pieces of equipment

Ashley McGlone:

that are very sensitive.

Ashley McGlone:

So it's not your IT

Ashley McGlone:

environment at all.

Ashley McGlone:

What we hear often is that, if

Ashley McGlone:

you try to take IT processes

Ashley McGlone:

and just copy paste into the

Ashley McGlone:

OT environment, you're gonna

Ashley McGlone:

break things right off the bat.

Ashley McGlone:

When you think about this

Ashley McGlone:

mindset change between IT and OT.

Ashley McGlone:

In IT, we're concerned about

Ashley McGlone:

confidentiality, integrity,

Ashley McGlone:

authenticity, and the CIA triad.

Ashley McGlone:

But on the plant floor, the

Ashley McGlone:

number one concern is human

Ashley McGlone:

safety and that trumps everything.

Ashley McGlone:

So it really is a different

Ashley McGlone:

place to operate technology.

Luigi Tiano:

Absolutely.

Luigi Tiano:

I think that's always been

Luigi Tiano:

the biggest challenge.

Luigi Tiano:

Like you mentioned, merging

Luigi Tiano:

those two mindsets together.

Luigi Tiano:

The technology is one thing,

Luigi Tiano:

but the mindset is really.

Luigi Tiano:

And you're right, safety

Luigi Tiano:

should never be overlooked,

Luigi Tiano:

a hundred percent.

Luigi Tiano:

To go back to what you said,

Luigi Tiano:

if anyone's ever been on a

Luigi Tiano:

plant floor, you've seen that

Luigi Tiano:

PC that's got Four inches of

Luigi Tiano:

dust on the keyboard and four

Luigi Tiano:

inches of dust on the monitor.

Luigi Tiano:

And it's never been touched,

Luigi Tiano:

never been clean, but it's

Luigi Tiano:

just rock solid and working.

Luigi Tiano:

So we don't touch it.

Luigi Tiano:

Let me double click on

Luigi Tiano:

the next question, which

Luigi Tiano:

is all about visibility.

Luigi Tiano:

We talk about a lot of

Luigi Tiano:

manufacturing customers, about

Luigi Tiano:

visibility and control of

Luigi Tiano:

their OT environments, right?

Luigi Tiano:

So what are you hearing as

Luigi Tiano:

trends in that specific space?

Ashley McGlone:

As much as

Ashley McGlone:

we would like to think that

Ashley McGlone:

this is the year, 2023 and

Ashley McGlone:

everybody's all wired up, digital

Ashley McGlone:

transformation's complete.

Ashley McGlone:

I talk to a lot of smaller

Ashley McGlone:

manufacturers and suppliers who are

Ashley McGlone:

literally just now getting started.

Ashley McGlone:

I've had even larger manufacturers

Ashley McGlone:

tell me; if we had a ransomware

Ashley McGlone:

event in the plant, we have

Ashley McGlone:

a spreadsheet from five years

Ashley McGlone:

ago with our asset inventory.

Ashley McGlone:

And we all know that's

Ashley McGlone:

just not going to work.

Ashley McGlone:

Unfortunately, a lot of people

Ashley McGlone:

are still just getting started.

Ashley McGlone:

And I think what's happening

Ashley McGlone:

is, let's say you work with

Ashley McGlone:

automotive and you've got a

Ashley McGlone:

top tier automotive company.

Ashley McGlone:

That OEM that's supplying the

Ashley McGlone:

federal government in the US.

Ashley McGlone:

So now there's CMMC Cybersecurity

Ashley McGlone:

Maturity Model Certification.

Ashley McGlone:

It's now at 2.0 getting

Ashley McGlone:

ready to be effective here

Ashley McGlone:

within the next couple years.

Ashley McGlone:

Then all of a sudden, now you

Ashley McGlone:

find yourself maybe you're not a

Ashley McGlone:

tier one supplier to that auto.

Ashley McGlone:

Maybe you're a tier

Ashley McGlone:

two, tier three.

Ashley McGlone:

All of a sudden, depending

Ashley McGlone:

on how close you are, what

Ashley McGlone:

you're supplying, you could

Ashley McGlone:

be susceptible to compliance

Ashley McGlone:

for US federal government.

Ashley McGlone:

Or if you're in Europe, maybe it's

Ashley McGlone:

Tisax or NIST two or maybe it's

Ashley McGlone:

in US, the White House executive

Ashley McGlone:

orders around cybersecurity.

Ashley McGlone:

All of a sudden there's

Ashley McGlone:

this really big regulatory

Ashley McGlone:

compliance landscape.

Ashley McGlone:

Now, standards have been around

Ashley McGlone:

for years, but it's this regulatory

Ashley McGlone:

compliance that's forcing

Ashley McGlone:

people to take a look because

Ashley McGlone:

manufacturing is, unfortunately

Ashley McGlone:

increasingly in the headlines

Ashley McGlone:

with ransomware, malware and

Ashley McGlone:

ransomware malware targeted

Ashley McGlone:

at manufacturing specifically.

Ashley McGlone:

There was a headline a couple

Ashley McGlone:

years ago where there was

Ashley McGlone:

ransomware that was looking

Ashley McGlone:

at over 60 windows executables

Ashley McGlone:

running on the line side, and

Ashley McGlone:

it would kill those processes

Ashley McGlone:

before it ransomed the box.

Ashley McGlone:

So it was specifically

Ashley McGlone:

targeted manufacturing.

Ashley McGlone:

That's got a lot of people

Ashley McGlone:

concerned obviously.

Ashley McGlone:

A lot of people are just getting

Ashley McGlone:

started and they don't have the

Ashley McGlone:

basic inventory visibility into

Ashley McGlone:

what are my devices, whether

Ashley McGlone:

they're Windows, Linux, or those

Ashley McGlone:

lower tier PLC sensor type devices.

Ashley McGlone:

Visibility really is the

Ashley McGlone:

first place to start.

Ashley McGlone:

And what I find is a lot

Ashley McGlone:

of people are evaluating

Ashley McGlone:

software solutions there.

Ashley McGlone:

They're looking for things

Ashley McGlone:

that can inventory those

Ashley McGlone:

devices on the plant floor.

Ashley McGlone:

If I started naming vendors because

Ashley McGlone:

there are dozens of vendors in

Ashley McGlone:

that space now who are helping

Ashley McGlone:

to provide that visibility.

Ashley McGlone:

At the risk of going too

Ashley McGlone:

long on this answer, I'll

Ashley McGlone:

also say another big concern

Ashley McGlone:

is staffing and skillset.

Luigi Tiano:

I was gonna say that.

Luigi Tiano:

That's always been a

Luigi Tiano:

challenge in manufacturing.

Luigi Tiano:

Traditional, non IT environments.

Luigi Tiano:

It's about operations, it's

Luigi Tiano:

about efficiency, it's about

Luigi Tiano:

automation and safety, of

Luigi Tiano:

course, but technology's kind

Luigi Tiano:

of always taken a backseat,

Luigi Tiano:

and correct me if I'm wrong.

Ashley McGlone:

There's people

Ashley McGlone:

that design these processes and

Ashley McGlone:

they've used technology for years,

Ashley McGlone:

but security wasn't a concern

Ashley McGlone:

because they weren't exposed to

Ashley McGlone:

the internet, like they are now.

Ashley McGlone:

So you've got skillsets in

Ashley McGlone:

traditional industrial environments

Ashley McGlone:

that are having to either learn

Ashley McGlone:

new skills or you have IT people

Ashley McGlone:

coming in telling them what to do.

Ashley McGlone:

Then the production

Ashley McGlone:

engineering folks are

Ashley McGlone:

saying, now, wait a minute.

Ashley McGlone:

It doesn't work that way here.

Ashley McGlone:

You've got this hybridized

Ashley McGlone:

skillset between a cybersecurity

Ashley McGlone:

mindset coming into a

Ashley McGlone:

manufacturing environment.

Ashley McGlone:

So that really is a critical

Ashley McGlone:

skillset to have now is having

Ashley McGlone:

a security mind and an OT mind,

Ashley McGlone:

so you can bring those together

Ashley McGlone:

and doing it in a safe way.

Luigi Tiano:

Sounds like it's

Luigi Tiano:

not an easy skill set to find,

Luigi Tiano:

based on what I've just heard.

Ashley McGlone:

Yeah.

Ashley McGlone:

The cyber field as a whole.

Ashley McGlone:

I've heard stats, you get different

Ashley McGlone:

numbers, like millions of openings

Ashley McGlone:

that'll go unfilled, right?

Ashley McGlone:

And then when you get into niche

Ashley McGlone:

areas like this, where it's a

Ashley McGlone:

hybrid of IT and OT coming together

Ashley McGlone:

with cyber in the skillset,

Ashley McGlone:

it is a niche skillset area.

Ashley McGlone:

What a lot of companies are going

Ashley McGlone:

to end up doing because they

Ashley McGlone:

can't afford a senior person in

Ashley McGlone:

that space, cuz manufacturing

Ashley McGlone:

budgets are always tight,

Ashley McGlone:

especially when it comes to

Ashley McGlone:

staffing for something like this.

Ashley McGlone:

A lot of times you're going to

Ashley McGlone:

hire people straight out of college

Ashley McGlone:

and there's gonna be a lot of O

Ashley McGlone:

J T a lot of on-the-job training.

Ashley McGlone:

There's some resources

Ashley McGlone:

I'll talk about later that

Ashley McGlone:

can really help with that.

Luigi Tiano:

Yeah,

Luigi Tiano:

that's very good.

Luigi Tiano:

Before we move on to the next

Luigi Tiano:

question, anything else you

Luigi Tiano:

wanna say about visibility in

Luigi Tiano:

OT environments or you wanna,

Luigi Tiano:

we can circle back at the end?

Ashley McGlone:

I think

Ashley McGlone:

I'm good on there for now.

Luigi Tiano:

All right.

Luigi Tiano:

All right.

Luigi Tiano:

So you mentioned a lot of

Luigi Tiano:

companies are just getting started.

Luigi Tiano:

So if you've seen this, you've

Luigi Tiano:

obviously lived this through

Luigi Tiano:

conversations with your clients.

Luigi Tiano:

How does a company get started?

Luigi Tiano:

If you're a manufacturing

Luigi Tiano:

company, just listening to

Luigi Tiano:

this podcast at random, how

Luigi Tiano:

does the company get started?

Luigi Tiano:

Where do they look,

Luigi Tiano:

what do they do?

Ashley McGlone:

Number one,

Ashley McGlone:

you're not alone, especially if

Ashley McGlone:

you're in the smaller tier space.

Ashley McGlone:

There are a lot of bigger companies

Ashley McGlone:

who have already walked this path.

Ashley McGlone:

They've crafted best practices.

Ashley McGlone:

They put that into guidance.

Ashley McGlone:

You may have heard of the

Ashley McGlone:

Purdue model for the structuring

Ashley McGlone:

of systems in manufacturing

Ashley McGlone:

or industrial environment.

Ashley McGlone:

You take another layer to the I S

Ashley McGlone:

A I E C, more alphabet here, 6 2

Ashley McGlone:

4 43 and we'll have links in the

Ashley McGlone:

show notes for folks to this stuff.

Ashley McGlone:

But ISA 6 2 4 43 is the

Ashley McGlone:

international standard for

Ashley McGlone:

cybersecurity practices in

Ashley McGlone:

a manufacturing environment.

Ashley McGlone:

It's gonna help you

Ashley McGlone:

categorize and sort through.

Ashley McGlone:

If I'm just staring at I-beams

Ashley McGlone:

and network cables and equipment,

Ashley McGlone:

how do I make sense of this?

Ashley McGlone:

Where do I draw the lines virtually

Ashley McGlone:

for, how do I organize this

Ashley McGlone:

into an actual cyber strategy

Ashley McGlone:

for my industrial environment?

Ashley McGlone:

So it's gonna have a five

Ashley McGlone:

layer stack that goes from top

Ashley McGlone:

traditional kind of IT systems,

Ashley McGlone:

running Windows and Linux and

Ashley McGlone:

such, all the way down to those

Ashley McGlone:

lower tier devices that are

Ashley McGlone:

running some type of firmware

Ashley McGlone:

maybe that you need to monitor

Ashley McGlone:

or maybe it's just a dial that's

Ashley McGlone:

controlling something all the way

Ashley McGlone:

down the sensors and actuators.

Ashley McGlone:

They've carved that out.

Ashley McGlone:

They've identified, okay,

Ashley McGlone:

here's the vocabulary you

Ashley McGlone:

even used to talk about it.

Ashley McGlone:

I've got a security level

Ashley McGlone:

target that I want to get to.

Ashley McGlone:

Here's the security level

Ashley McGlone:

capability of what we can do today.

Ashley McGlone:

Then that gives us this

Ashley McGlone:

gap that we need to close

Ashley McGlone:

and zones and conduits.

Ashley McGlone:

Here are machines that are

Ashley McGlone:

going to be compensating

Ashley McGlone:

controls, we can't update them.

Ashley McGlone:

So they're gonna get firewalled

Ashley McGlone:

or air gaped over here.

Ashley McGlone:

That's a zone.

Ashley McGlone:

Then a conduit's that network

Ashley McGlone:

connection coming in and

Ashley McGlone:

out of there for firewall

Ashley McGlone:

connections, so to speak.

Ashley McGlone:

You've got network segmentation

Ashley McGlone:

between the carpet and the cement.

Ashley McGlone:

So between IT and OT, making

Ashley McGlone:

sure you've got the right

Ashley McGlone:

firewalls in place and if Mary

Ashley McGlone:

in accounting clicks a phishing

Ashley McGlone:

link, it doesn't take down

Ashley McGlone:

manufacturing and vice versa.

Ashley McGlone:

There's a lot here and

Ashley McGlone:

there's a lot of precedent.

Ashley McGlone:

If you're just getting started,

Ashley McGlone:

there's a lot of resources

Ashley McGlone:

available to help you.

Ashley McGlone:

There's a deep bench with

Ashley McGlone:

consulting practices and providers

Ashley McGlone:

like yourself who have done

Ashley McGlone:

work in this space, who can

Ashley McGlone:

really help people first off

Ashley McGlone:

to get oriented and that's what

Ashley McGlone:

I've noticed a lot of the calls

Ashley McGlone:

that I've had even recently is

Ashley McGlone:

just helping people understand

Ashley McGlone:

where do I take that first step?

Luigi Tiano:

Yeah and

Luigi Tiano:

these standards, I'll

Luigi Tiano:

just say numbers again.

Luigi Tiano:

So ISA i e c 6 2 4 43.

Luigi Tiano:

I think these international

Luigi Tiano:

standards force both the IT and

Luigi Tiano:

the OT folks, so you said process

Luigi Tiano:

engineer first to work together

Luigi Tiano:

and merge those processes.

Luigi Tiano:

As much as they are different, I

Luigi Tiano:

think these standards are extremely

Luigi Tiano:

important and should be adopted

Luigi Tiano:

obviously by these organizations

Luigi Tiano:

because if there's a skillset

Luigi Tiano:

gap from a process wise, this

Luigi Tiano:

forces them to work together.

Luigi Tiano:

So we're seeing this

Luigi Tiano:

across the board.

Luigi Tiano:

I'm glad you brought that up

Luigi Tiano:

because I think it's important

Luigi Tiano:

that individuals know this.

Luigi Tiano:

The standard, obviously

Luigi Tiano:

you're well-versed in it.

Luigi Tiano:

Is this something you get to

Luigi Tiano:

stamp once and then you have

Luigi Tiano:

yearly checks or do you know

Luigi Tiano:

how long this standard would

Luigi Tiano:

last within an organization?

Ashley McGlone:

In the realm

Ashley McGlone:

of regulations, compliance,

Ashley McGlone:

attestations, this is just a

Ashley McGlone:

standard that's a recommendation

Ashley McGlone:

that you should align to.

Ashley McGlone:

I would say that it's not enforced,

Ashley McGlone:

but when things like we're seeing

Ashley McGlone:

in EMEA right now with the Nist 2

Ashley McGlone:

is actually coming in and putting

Ashley McGlone:

teeth to some of this to actually

Ashley McGlone:

enforce it and putting penalties

Ashley McGlone:

there where there weren't, before.

Ashley McGlone:

For the last 20 years, ISA

Ashley McGlone:

62443 has just been a standard.

Ashley McGlone:

Hey, this is a good

Ashley McGlone:

way to think about it.

Ashley McGlone:

The design and framework

Ashley McGlone:

give the industry a common

Ashley McGlone:

vocabulary and put training

Ashley McGlone:

and resources behind it.

Ashley McGlone:

Yeah it's actually got a little

Ashley McGlone:

more legs now, with the headlines

Ashley McGlone:

over the last few years.

Luigi Tiano:

Just to touch

Luigi Tiano:

on that, when we talk about

Luigi Tiano:

regulatory compliance for us as an

Luigi Tiano:

organization, especially when we're

Luigi Tiano:

talking with clients, when you

Luigi Tiano:

abide by or conform to a specific

Luigi Tiano:

standard, you earn the right to

Luigi Tiano:

do business with more partners.

Luigi Tiano:

If you don't have the controls

Luigi Tiano:

in place, that's fine.

Luigi Tiano:

But if you want to continue to

Luigi Tiano:

conduct business with certain

Luigi Tiano:

entities, you're gonna be required

Luigi Tiano:

to show that you actually meet

Luigi Tiano:

a certain level of standards.

Luigi Tiano:

Whether it's enforced legally

Luigi Tiano:

or not, I think more and more

Luigi Tiano:

companies are just gonna abide by

Luigi Tiano:

a specific standard cause they want

Luigi Tiano:

to continue to do business or earn

Luigi Tiano:

the right with certain enterprises

Luigi Tiano:

that they once could not do that.

Ashley McGlone:

You're

Ashley McGlone:

describing supply chain risk.

Luigi Tiano:

There you go.

Ashley McGlone:

And that is top

Ashley McGlone:

of mind for everybody right now.

Ashley McGlone:

I remember when I used to work

Ashley McGlone:

for Toyota, for example, the

Ashley McGlone:

automotive seat supplier, the

Ashley McGlone:

seats would come in off the semi

Ashley McGlone:

truck in the order that cars were

Ashley McGlone:

going down the assembly line.

Ashley McGlone:

If that seat supplier then had

Ashley McGlone:

a cyber breach, even if there's

Ashley McGlone:

nothing cyber in the seat itself,

Ashley McGlone:

if they were victim to ransomware

Ashley McGlone:

and that supply paused, it would

Ashley McGlone:

pause the cars going down the line.

Ashley McGlone:

Even if you make wiring harnesses

Ashley McGlone:

that have no embedded technology.

Ashley McGlone:

If you can't supply those

Ashley McGlone:

because you've been breached,

Ashley McGlone:

you're gonna impact all

Ashley McGlone:

your supply chain partners.

Ashley McGlone:

So whether or not you think

Ashley McGlone:

it applies to you, it does.

Luigi Tiano:

Exactly.

Luigi Tiano:

Got another question here

Luigi Tiano:

about OT environments.

Luigi Tiano:

We see such a diverse

Luigi Tiano:

mix of devices.

Luigi Tiano:

How do you manage all those types

Luigi Tiano:

of devices with one solution?

Luigi Tiano:

Is it even possible?

Ashley McGlone:

It's not, no.

Ashley McGlone:

I tell you the more people I talk

Ashley McGlone:

to, whether it's partners, other

Ashley McGlone:

vendors prospects and customers

Ashley McGlone:

in this space, everybody's

Ashley McGlone:

looking for a silver bullet.

Ashley McGlone:

There is no one software solution

Ashley McGlone:

that's gonna give you that

Ashley McGlone:

ultimate visibility control

Ashley McGlone:

from one end to the other.

Ashley McGlone:

Today, it doesn't exist.

Ashley McGlone:

What you will find though,

Ashley McGlone:

is what I prefer to call

Ashley McGlone:

strategic platform partnerships.

Ashley McGlone:

Now, don't get me wrong.

Ashley McGlone:

There are some companies out there

Ashley McGlone:

that say, yeah, we do IT, and OT.

Ashley McGlone:

But you've gotta dig a little

Ashley McGlone:

deeper below the marketing

Ashley McGlone:

messaging and say, okay, what

Ashley McGlone:

exactly do you do in IT and OT?

Ashley McGlone:

Maybe you only scan for

Ashley McGlone:

vulnerabilities and that's it.

Ashley McGlone:

It doesn't stop there.

Ashley McGlone:

I need to fix those

Ashley McGlone:

vulnerabilities, right?

Ashley McGlone:

I need to enforce policy

Ashley McGlone:

on those works stations.

Ashley McGlone:

I got Windows and Linux that

Ashley McGlone:

I need to manage firewall and

Ashley McGlone:

disc encryption and things

Ashley McGlone:

like that, on the plant floor.

Ashley McGlone:

It goes beyond just a narrow

Ashley McGlone:

feature matrix to actually a broad

Ashley McGlone:

set of full manageability for

Ashley McGlone:

the plant floor from IT and OT

Ashley McGlone:

and where that convergence meets.

Ashley McGlone:

What I'm seeing today is as I

Ashley McGlone:

talk to people who are in this

Ashley McGlone:

starting process, they are actively

Ashley McGlone:

investigating vendors that do

Ashley McGlone:

like port spanning on the network.

Ashley McGlone:

There's dozens of vendors in this

Ashley McGlone:

space that'll listen and find those

Ashley McGlone:

devices passively on the network.

Ashley McGlone:

Then there's need for some

Ashley McGlone:

active scanning as well, cuz

Ashley McGlone:

some of those devices will never

Ashley McGlone:

initiate a network connection.

Ashley McGlone:

Then you've got your traditional

Ashley McGlone:

distributed control systems

Ashley McGlone:

vendors like Siemens and

Ashley McGlone:

Rockwell and Honeywell and GE.

Ashley McGlone:

I could name those for a while.

Ashley McGlone:

You've got all those

Ashley McGlone:

vendors who have their own

Ashley McGlone:

cybersecurity practices as well.

Ashley McGlone:

What I typically recommend,

Ashley McGlone:

you know what we do is helping

Ashley McGlone:

people with visibility on

Ashley McGlone:

the top tier of that model.

Ashley McGlone:

So the Windows and Linux

Ashley McGlone:

devices, we can give you all

Ashley McGlone:

the capability you need there.

Ashley McGlone:

Let's take that and use some

Ashley McGlone:

common backend like Splunk or

Ashley McGlone:

ServiceNow or Microsoft Sentinel.

Ashley McGlone:

Some type of sim source

Ashley McGlone:

solution, C M D B.

Ashley McGlone:

Let's take all that Tanium data,

Ashley McGlone:

put it in there, and then take

Ashley McGlone:

your other solutions in this space

Ashley McGlone:

that most of them are already

Ashley McGlone:

pre-wired for ServiceNow or

Ashley McGlone:

Splunk, something on the backend.

Ashley McGlone:

Then, use that backend for that

Ashley McGlone:

end-to-end visibility and control

Ashley McGlone:

for your IT OT SOC experience.

Luigi Tiano:

Interesting.

Luigi Tiano:

So what I heard was, form a

Luigi Tiano:

strategic platform of partnerships.

Luigi Tiano:

Make sure you've got a bunch

Luigi Tiano:

of partners that can then

Luigi Tiano:

fill those needs cuz there's

Luigi Tiano:

just no silver bullet.

Ashley McGlone:

So the benefit

Ashley McGlone:

there is, rather than having

Ashley McGlone:

a dozen solutions with a dozen

Ashley McGlone:

integration points in this matrix

Ashley McGlone:

of integrations, you can really

Ashley McGlone:

optimize that down to just a

Ashley McGlone:

few strategic integrations,

Ashley McGlone:

which is gonna make it easier

Ashley McGlone:

to maintain in the long term.

Luigi Tiano:

Got it.

Luigi Tiano:

Very good.

Luigi Tiano:

One last question cuz then

Luigi Tiano:

I wanna talk a little bit

Luigi Tiano:

about what you do and maybe

Luigi Tiano:

how your platform could help.

Luigi Tiano:

You've mentioned a lot of things

Luigi Tiano:

here and obviously I wanna give

Luigi Tiano:

you the time to talk about that.

Luigi Tiano:

What resources are available

Luigi Tiano:

to help companies today?

Luigi Tiano:

We talked about how

Luigi Tiano:

they get started.

Luigi Tiano:

Obviously a bunch of stuff online,

Luigi Tiano:

but what would you recommend?

Ashley McGlone:

There's

Ashley McGlone:

always the free and easy

Ashley McGlone:

Wikipedia and YouTube, right?

Ashley McGlone:

You can learn anything on

Ashley McGlone:

Wikipedia and YouTube and there's

Ashley McGlone:

a ton of open, stuff like that.

Ashley McGlone:

But if you're willing to invest,

Ashley McGlone:

even just looking at the open,

Ashley McGlone:

free resources, I would go

Ashley McGlone:

straight to the SANS Institute.

Ashley McGlone:

SANS has been around for years and

Ashley McGlone:

everybody knows them as the source

Ashley McGlone:

of trusted security training.

Ashley McGlone:

SANS has a whole program for

Ashley McGlone:

industrial controls, SANS ICS.

Ashley McGlone:

S A N S I C S.

Ashley McGlone:

Just put that in your search

Ashley McGlone:

engine and we've got some links

Ashley McGlone:

in the show notes here as well.

Luigi Tiano:

We're definitely gonna

Luigi Tiano:

share a lot of that information.

Luigi Tiano:

You sent me some stuff for

Luigi Tiano:

the show here, which is great.

Ashley McGlone:

Yeah,

Ashley McGlone:

they've got an I C S guide.

Ashley McGlone:

Industrial controls guide for

Ashley McGlone:

recommended controls to start.

Ashley McGlone:

Things about having an

Ashley McGlone:

incident response plan.

Ashley McGlone:

Sure we have one of those for

Ashley McGlone:

IT, but do you have it for

Ashley McGlone:

your industrial environment?

Ashley McGlone:

Just knowing who to call,

Ashley McGlone:

where do I get my inventory?

Ashley McGlone:

Where are all the firewalls?

Ashley McGlone:

And who's controlling those things?

Ashley McGlone:

Having that incident response

Ashley McGlone:

plan, a defensible architecture,

Ashley McGlone:

network visibility monitoring,

Ashley McGlone:

secure remote access, and then

Ashley McGlone:

even risk based vulnerability

Ashley McGlone:

management, which prioritizes

Ashley McGlone:

not just saying, here's all the

Ashley McGlone:

volumes, but here's the ones that

Ashley McGlone:

are prioritized for our equipment

Ashley McGlone:

with our environment where we

Ashley McGlone:

know that they are exposed.

Ashley McGlone:

They have a really good guide

Ashley McGlone:

that you can download for

Ashley McGlone:

free just to get started.

Ashley McGlone:

But they have a whole

Ashley McGlone:

suite of courses.

Ashley McGlone:

And I'm not compensated for

Ashley McGlone:

this either, by the way.

Ashley McGlone:

Just I've seen that they have

Ashley McGlone:

some fantastic instructors who

Ashley McGlone:

are writing, designing, living

Ashley McGlone:

this every day, getting real

Ashley McGlone:

world training out there to

Ashley McGlone:

the people that need it most.

Ashley McGlone:

Even if you're taking somebody

Ashley McGlone:

off the street without this kind

Ashley McGlone:

of background in their portfolio,

Ashley McGlone:

you can send them to these

Ashley McGlone:

classes, get them some hands

Ashley McGlone:

on with this technology and get

Ashley McGlone:

'em trained up and ready to go.

Luigi Tiano:

Even if you're not

Luigi Tiano:

getting compensated, I think you've

Luigi Tiano:

obviously demonstrated a wealth

Luigi Tiano:

of knowledge in this industry.

Luigi Tiano:

So if you're saying SANS ICS

Luigi Tiano:

is a good place to start,

Luigi Tiano:

that's where I would start.

Luigi Tiano:

Thanks for that, Ashley.

Luigi Tiano:

Before we wrap, obviously,

Luigi Tiano:

you work at Tanium.

Luigi Tiano:

I see the background there.

Luigi Tiano:

Maybe just tell us a little

Luigi Tiano:

bit about how Tanium could

Luigi Tiano:

help an organization.

Luigi Tiano:

You've shared time with

Luigi Tiano:

us and I appreciate that.

Luigi Tiano:

So I need to give you some

Luigi Tiano:

time to tell us how Tanium

Luigi Tiano:

could potentially help.

Ashley McGlone:

Sure.

Ashley McGlone:

Tanium is a real-time endpoint

Ashley McGlone:

management platform for visibility

Ashley McGlone:

and control at speed and scale,

Ashley McGlone:

all those marketing terms, right?

Ashley McGlone:

But basically what that means is

Ashley McGlone:

we have a unique architecture that

Ashley McGlone:

allows us literally in seconds to

Ashley McGlone:

get information from any system.

Ashley McGlone:

Windows, Mac, Linux, even Solaris,

Ashley McGlone:

and AIX that has an ip, it's

Ashley McGlone:

connected, it's on the network.

Ashley McGlone:

We can get that real time

Ashley McGlone:

visibility of your environment.

Ashley McGlone:

If you're wanting to know what are

Ashley McGlone:

all the machines in my working from

Ashley McGlone:

home, office area, on the plant

Ashley McGlone:

floor, as long as it's running one

Ashley McGlone:

of those OSs and it's got an ip,

Ashley McGlone:

it's got Tanium client installed,

Ashley McGlone:

then we can get you the richest

Ashley McGlone:

data you've ever seen in real time.

Ashley McGlone:

So we can scan for vulnerabilities,

Ashley McGlone:

we can patch, we can manage policy,

Ashley McGlone:

we can do threat detection and

Ashley McGlone:

response, and a whole list of

Ashley McGlone:

capabilities that gives you a very

Ashley McGlone:

wide feature matrix to manage the

Ashley McGlone:

top half of that OT stack, right?

Ashley McGlone:

Where you've got windows and

Ashley McGlone:

Linux machines out there that are

Ashley McGlone:

running what matters most to you.

Ashley McGlone:

I've had customers tell us,

Ashley McGlone:

when they put traditional

Ashley McGlone:

IT tools in there, they need

Ashley McGlone:

multiple tools to do that.

Ashley McGlone:

It's a performance hit on

Ashley McGlone:

the endpoint, but Tanium's

Ashley McGlone:

a single agent that

Ashley McGlone:

covers multiple tool sets.

Ashley McGlone:

With that platform approach then,

Ashley McGlone:

you can reduce the impact on often

Ashley McGlone:

under-resourced hardware profiles

Ashley McGlone:

on these manufacturing machines.

Ashley McGlone:

We've seen some real benefit

Ashley McGlone:

there as well as the actual

Ashley McGlone:

technology, what we're doing to

Ashley McGlone:

manage and secure that environment.

Luigi Tiano:

Fantastic.

Luigi Tiano:

So it's all about visibility and

Luigi Tiano:

knowing what you own, because

Luigi Tiano:

you can't really protect if

Luigi Tiano:

you don't know you own it.

Ashley McGlone:

Exactly.

Luigi Tiano:

I know it's

Luigi Tiano:

cliche and we say it often,

Luigi Tiano:

but it's the fundamental truth.

Luigi Tiano:

If you don't know what exists

Luigi Tiano:

on your network then, how do

Luigi Tiano:

you know how to protect it or

Luigi Tiano:

mitigate the risk on those devices.

Luigi Tiano:

Ashley, I've learned a ton.

Luigi Tiano:

I'm sure the audience

Luigi Tiano:

is gonna love this.

Luigi Tiano:

We will be sharing a lot of

Luigi Tiano:

the links that you've sent us.

Luigi Tiano:

Before we go, anything else

Luigi Tiano:

you want to add because you've

Luigi Tiano:

given us a lot of your time

Luigi Tiano:

here and a lot of information.

Luigi Tiano:

If you got nothing else, I

Luigi Tiano:

just want to thank you and say,

Luigi Tiano:

hopefully we can do this again.

Luigi Tiano:

I'll close off with that.

Ashley McGlone:

Thanks

Ashley McGlone:

for the opportunity to

Ashley McGlone:

come on the show, Luigi.

Ashley McGlone:

I just wanna offer a word

Ashley McGlone:

of encouragement because

Ashley McGlone:

typically IT and OT are

Ashley McGlone:

separate silos in the business.

Ashley McGlone:

Only a few places where they're

Ashley McGlone:

actually integrated with a

Ashley McGlone:

common vision, common governance.

Ashley McGlone:

It takes work to get

Ashley McGlone:

there and it's worth it.

Ashley McGlone:

Your business depends on it.

Ashley McGlone:

Your livelihood, your family

Ashley McGlone:

that you support with the income

Ashley McGlone:

that you make at your employer.

Ashley McGlone:

You want to keep that secure for

Ashley McGlone:

your own interest, but also for

Ashley McGlone:

the business and for all the people

Ashley McGlone:

that are served by that business.

Ashley McGlone:

It really is worth the effort

Ashley McGlone:

to spend the time and to do

Ashley McGlone:

the research and to get your

Ashley McGlone:

program started, if you don't

Ashley McGlone:

have one because security

Ashley McGlone:

is not an option here.

Luigi Tiano:

Time is now.

Luigi Tiano:

You gotta get started.

Luigi Tiano:

Ashley, it's been a pleasure.

Luigi Tiano:

Thank you very much.

Luigi Tiano:

Hope to talk to you again soon.

Ashley McGlone:

Take care.

Luigi Tiano:

Thank you.

Luigi Tiano:

Bye-bye.

Links

Chapters

Video

More from YouTube