mnemonic security podcast

Prioritisation & Decision Making in Critical Infrastructure Defence

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 36:00

Joe Slowik, ATT&CK CTI Lead at MITRE, joins the latest episode of the mnemonic security podcast to share his insights on the complexities of securing critical infrastructure. With a background in cyber threat intelligence, incident response, and detection engineering, Joe discusses with Robby the challenge of defining and prioritising what's truly "critical" in a landscape where every sector claims importance.

They explore the difficulty in distributing security investments across industries and the growing need for organisations of all sizes to adopt a mindset of self-defence. Joe also addresses the potential consequences of large-scale cyberattacks, such as those by Volt Typhoon, emphasising the need for coordinated incident response and leadership during crisis scenarios. He concludes with a strong call for resilience and highlights the vital role CEOs play in ensuring organisational preparedness.

Send us Fan Mail

Critical Infrastructure Security and Resource Allocation

Speaker

From our headquarters in Oslo, Norway, and on behalf of our host, Robby Peralta, welcome to the Mnemonic Security Podcast.

Robby Peralta

Back in 2004, Pixar and Walt Disney Pictures released the Incredibles. Which is a great movie when you're 11 years old. And long story short, there's a part of the film where the incredible mom tells her incredible son that everyone is special. To which she insightfully replies, which is another way of saying that no one is. That smart ass reminds me of someone. Fast forward 2024, unfortunately in a world without superheroes, that same analogy can be used in a critical infrastructure context. You tell me which is most important. Electricity? Water? Roads, railways, airports? What about the armed forces? Police? Intelligence agencies, emergency services. Just thinking about this makes me hungry. So of course we need food too. But we probably need money to pay for the food. So maybe we need a bank then too. And they probably need their IT service partner. You get the point. If everything is critical, then nothing is. And in the face of crisis, the inevitable cyber doomsday, who is gonna get helped first? And by whom? Joe Slowik, welcome back to the podcast.

Joe Slowik

Always a pleasure being here, Robby.

Robby Peralta

The colors in the trees are changing. It's pouring rain outside, it's getting darker. So that kind of sucks. But that means it's the time of year that I get to see you in Copenhagen for the ICS conference.

Joe Slowik

This is very true. Yeah. And actually, uh not only Copenhagen, but I will be at BruCon and I will be out at the vinterfestivalen in January as well. So I will be in Oslo in January because that's a lovely time to go to Oslo.

Robby Peralta

Yeah, right. It will feel like snow. Well, awesome. I'm gonna be seeing you a bunch then. Yeah. Cool. So for uh those that haven't met you before, who's uh Joe Slowik and uh what's he up to these days?

Joe Slowik

So Joe Slowik is currently running the attack port, the CTI portion of the MITRE attack framework while also doing some critical infrastructure security research and analysis, which is I believe kind of more what we're going to talk about today, but also doing some wide-ranging information security research training. So been doing this in some form for over 15 years now, which is getting kind of scary when you think about it. Um, but uh yeah, pleasure to be here as always.

Robby Peralta

Yeah, well, uh, you're the right man for the job. I mean, if you're if you're invited back four times from the conference, that you're doing something right.

Joe Slowik

Yes.

Robby Peralta

So uh what are you talking about this year's conference?

Joe Slowik

So this year, uh it's not a very technical discussion, although it does have technical implications. But you know, there's for anyone who's seen the film The Incredibles, you might remember there is a scene of that movie where the villain says, like, if everyone is super, then no one is. Well, there's a similar analogy to critical infrastructure that if everything's critical, then is anything really critical? And really kind of trying to address head-on, how do we assess, how do we start evaluating what are the most important things to allocate resources for hardening, improving defense, and securing when there's so many things that we can call critical, uh, but we don't have the resources to possibly cover everything. And this honestly was um a thought that I've had for a while, but it really hit home with content from last year's conference where folks from the Danish security um energy sector security organization discussed an intrusion campaign targeting some uh networking equipment that had some potential overlaps with sandworm activity. Uh, that's still indeterminate, but that the activity took place is not. And in talking with the presenters on that material, identifying that there were some very tiny uh entities in Denmark that were hit through that. And it's the question of okay, can you layer on security like a thin coating across everything, or should you really only focus on the most important, the most critical items uh that are key to the country's economy or security or whatnot? And how does that balance work? And it's a tough conversation because no one wants to have it, because no one wants to be the person that tells some rural electric cooperative or something that, well, so it sucks to be you. Um you don't get support because you're small. Uh, and maybe there are ways around that too, uh, that need to be explored in greater detail, if that makes sense.

Robby Peralta

So who like today? I'm assuming like this conversation it becomes more and more relevant, but it's also brought on in Europe for like NIST 2 and stuff like that, right? Because there's actually certain uh organizations are critical to have to be able to do NIST2, I guess. Uh who decides that? And how is that? I'm not sure if you know the answer to that for Dan for Denmark and Europe, but who does that in the States?

Joe Slowik

That's a really good question. And the answer is it depends. So if you're talking the energy sector, it's a combination of FERC and NERC, uh federal energy regulatory. If you're talking water, it's the Environmental Protection Agency. If you're talking pipelines, it's the Transportation Security Agency. The same people that screen you at the airport if you're in the United States, which is a frightening thought if you think about it. Um not the same, same people, but anyway. Um so that's the other thing is that the decision making is scattered. And certainly frameworks like NIST II, um, you know, we also have things like uh, why can't I think of the name right now? The Presidential Policy Directive that was superseded by recent uh executive orders from the Biden administration that are trying to rationalize these items and centralize them more effectively. And certainly in the European context, you have the European Union that can step in and sort of knock heads together and get everyone pulling in the same direction. But there's lots of both entrenched interests within the various sectors of like, don't tell us what to do, we know what we're doing already, which is true to a certain extent, that you want the people that actually know how these operations function to be the ones deciding how to best secure them, unless they're not doing a very good job of securing them, in which case they need some stronger incentive, hence NIST. Um but there's also the question of uh you know holding people's feet to the fire, so to speak, of making sure that proper actions and proper security uh investments are being made. So yeah, like the decision making is kind of all over the place right now. And honestly, I think maybe in the States we can learn a bit from what's going on in Europe and seeing how uh the NICE directives play out, and um, because that just went into force. I'm trying to remember now. I know it's been a long time kind of people adapting to them uh and saying, like, oh, we're gonna get there. Uh, I know this is a discussion I've had with friends in Belgium as well as friends in Denmark as well, but it seems like it's been a painful process for many organizations to try to completely get into in alignment with the directive as it is currently written.

Robby Peralta

So if I just untangle what you just said, I mean, you have like critical infrastructure in the states. If it's water, it's the uh yeah, that agency. If it's uh energy, it's that agency. But someone at some point in time said that okay, you sectors are important. What about and then kind of maybe going off um on a tangent here, but I had a podcast recently with someone that uh it's called When Ransomware Hits the Ranch, right? And like the the meat producers, uh the largest meat producer in Norway, let's say that they got hit by a ransomware attack and they go down. That's critical for me, like or for people that are really into meat, right? But I would assume that they're not very critical, they're not on that, like

Joe Slowik

according to the US cybersecurity and information security agency, CISA, food is very much a critical infrastructure sector. There are over a dozen critical infrastructure sectors, which if you start getting over a dozen, again, the question becomes what's really critical at that point? Because, like you said, like, okay, I I want a steak. You want a steak, everyone wants a steak, right? Not everyone, but some people want steaks. Um that might be more of a luxury item, but if you can't get fresh food produced, shipped on the shelves of the market and so forth, that's a problem. The question is, how big of a problem is that compared to, say, electricity going down or not having clean and fresh water available coming out of the taps or other items? So a combination of both which sectors align with the highest degrees of criticality, as well as which entities within those sectors are most important. So the largest meat producer in Norway, it's probably pretty important. Um a cooperative that produces uh organic grass-fed beef or something along those lines that's located in some rural area that no one's ever heard of before? Probably not so much. Um, but it's still part of the food sector, though. So does that also mean that they are, you know, we would say for health reasons that they're beholden to the same standards and such, because we want to make sure that those steaks are good. Great A. Exactly. Uh, but does that mean we also apply the same security standards to them as well, which if we start talking about things like NIST framework and so forth? I mean, there are stipulations in terms of the size of the organization, I believe, in the NIST directives. But uh the idea being is you know, is this a one size fits most sort of endeavor, and how does that work in practice?

Robby Peralta

Interesting. So doomsday, right? Tomorrow something horrible happens and we need to allocate resources. What's that look like? Is there actually that people know what to do?

Joe Slowik

I think people think they have some idea of what to do, but no one really knows how things are going to happen. And this is something that we're seeing in the in the US certainly. So I don't know if uh all of your listeners would be familiar with there is a entity that's been linked to People's Republic of China activity called Volt Typhoon that has been top of mind for uh breaching critical infrastructure environments for a few years at this point. And it's been a very open question of like, well, if any of this ever actually happens and goes live, what do we do about it? Um, depending on where they are and what sort of effects get delivered, because it is fairly widespread. There's not a European equivalent that I'm aware of. You could link to maybe some of the Russian-related uh intrusion sets that have been acted in and around the ongoing conflicts in Ukraine and so forth. And we've certainly seen critical infrastructure intrusions, but you know, say some theoretical actor will, you know, pick a country you don't like or whatever, bad guy land or something, ends up breaching the networks of Norwegian critical infrastructure entities and starts a cascading effect that it impacts electricity, water, or the gas operations, big, big deal in Norway, food and similar items, but just, you know, hits lots of things simultaneously. How do we start prioritizing what comes online first and where restoration starts? I don't think anyone wants to answer those questions because that's not only difficult, but it's going to leave some people very unhappy when they find out that they're not as critical as maybe they thought they were. Which is the other side of this conversation is that in coming up with wide definitions of criticality when it comes to infrastructure and services, that I think we've created a false sense of like, well, if something bad happens, the government will save me, or the military will save me, or someone will be there in order to back me up when that might not be the case. And so we need to have more honest discussions about what capacity even exists to step in in these instances so that asset owners can find out precisely where they stand in terms of can I

Responsibility for Critical Infrastructure Cybersecurity

Joe Slowik

expect external support and assistance in these situations, or am I really going to be on my own and knowing that how can I then properly invest on my own to better counter and better align myself with how things might play out.

Robby Peralta

Forgot who I was talking to about this, but uh anyway, there was like an analogy where, okay, so the government obviously, if somebody comes and steals my wallet, the gov the police are supposed to help me, right? Right. Uh the government has a certain set of responsibilities that everybody's a citizen that pays taxes can just enjoy that they're there, right? Uh keep me safe. But in cyberspace, that government's really not there. Uh they want to they well they want to know about what happened, but yeah.

Joe Slowik

I mean, yes and no, but also you know, even looking at your original example, like if I if I'm wandering the streets of Oslo and I a pickpocket takes my wallet or whatever, like, okay, I can report that to the police. They're not going to take four or five officers or whatever, and it's like, okay, we have the top men assigned to your case, and you know, you're going to get your wallet. Like, no, that's not happening. You can file a police report, and maybe you'll get lucky as part of something else, but they have other things to do. Um, that is not a very high priority. Uh, and knowing that, you know, it gives us a better expectation of like, okay, I should probably like keep my wallet in my front pocket, not my back pocket, or something like that, if I'm going through certain areas and uh things along those lines, because I can't expect that it'll just be recovered by the authorities if it's taken because it's just not that important for them. And we can extend that into the cyber realm where it's like, okay, I can't just expect the authorities, whether it's in Norway, the United States, the United Kingdom, uh, or elsewhere, to step in and make things better uh in all cases, because again, resources are scarce, not everything is as important as other things, and it means that difficult choices have to be made. There's no really getting around it, and just accepting that means that we can at least make better decisions in terms of how we're defending ourselves. And that's one of the things I want to, I'm really going to touch on. You know, everyone thinks that when that they they hear the background for the discussion I'll have at industrial security conference in Copenhagen, it's like, oh, that's such doom and gloom. It's like, no, it's not. It's honest. And it at least helps us then understand like what do asset owners then need to do on their own from their own perspective to better prepare for worst-case scenario instead of just blindly hoping that you know someone else will step in and save me.

Robby Peralta

So uh I totally agree with you. Good point. I mean, uh up in the north of Norway, they probably have police officers that would love to handle uh a pickpocketing case because they don't have anything to do up there. Yeah. But uh to your point, yeah, you're right. These uh these asset owners, at least I would assume, like the large oil and gas companies in Norway, right? They they have understood that they need to have people to defend their own networks and they they have that. What do you think they actually expect? Like I would I would assume like some of these, at least the the large oil and gas operators here in Norway, like do you think they even expect anything from the government at that point? Like the security people, or do they think we have been around long enough to know that we're not gonna get shit from the government there?

Joe Slowik

I think that they've both been around long enough to understand where things reside, but also have the resources available. Like if I'm talking to an Ecuador or I'm talking to an Acrobp or something like that, you know, not only do they have, you know, a pretty good understanding of their domain, they also have money. Um, I've uh talked to individuals on the security teams from, you know, several of the major oil and gas organizations in Norway. They know what they're doing and they have things aligned in order to try to defend their networks and make sure that they can keep up and running in the face of a determined adversary. The problem really becomes when you start shifting away from you know fairly large, well-resourced organizations and get into the electric utility in some very remote area of northern Norway that also might be close to that little snippet of border that uh connects to a very interesting country. Okay, do they have resources aligned similarly with what these large oil and gas companies do to potentially operate against a well-resourced state-sponsored adversary? Probably not. So that becomes an area where we can start anticipating, like, okay, while these are discussions that I think need to be had, that um it's not just a question of what is economically or strategically most important, but also who has the ability to actually

Coordination of Critical Infrastructure Security

Joe Slowik

do this on their own effectively versus what entities are kind of left helpless uh in the face of these adversaries that genuinely need external support and maybe looking at things in that perspective as well. So that large oil and gas company, you guys are on your own. Why? Because you could probably make make it happen. If things go to complete shit, then you know there's a war going on, that's a little different. And then in that case, it's all hands on deck, and we will try to figure out how to organize resources as an entire uh society at that point to repel things. We'll hopefully never find out what that looks like. But at least for things that we're looking at now, okay, oil and gas companies, take care of your own shit because you can do it. Smaller entities or whatever that have strategic significance, probably not able to do so on their own, therefore meriting that sort of external support and investment uh because otherwise they just can't do it on their own.

Robby Peralta

Uh actually in in real life, I'm just thinking if this scenario would go down, you know, you like you have this huge oil and gas companies, they get hit, they have their own team, but they have a response retainer. So we have some of our good people over there helping them. Then it's kind of like doubled up with, you know, maybe that's a little too much for that one entity. And you have all these other entities that don't have anything and they're not going to get help because we're kind of commercially binded to help who we who actually doesn't need help from afar, kind of, you know. I can see that happening.

Joe Slowik

Well, I mean, you know, you look at the security plans that a large organization would put together, they have an incident response retainer for a reason because it's not economically feasible to have a large sort of standby security presence that hopefully doesn't have to get used very often, if at all, hence mnemonic or Mandian, well, Google Cloud or uh, you know, CrowdStrike's IR practice and you know all these other sorts of organizations out there. Where things get interesting, though, and this is sort of a separate discussion, is when you have a large-scale intrusion that impacts many entities simultaneously, mnemonic only has so many people. Very good people. I've, you know, met many mnemonic folks or whatever, and they're great, but there's only so many of them. And if multiple customers with retainers get breached simultaneously, that becomes an interesting question commercially as well. Again, separate discussion from this, but one that I think uh is getting more interesting as we start seeing certain entities get more what's a good word for this? Frisky? Um a little more um risk-averse in uh executing operations, whether we're talking a Vol Typhoon, a sandworm, or something else that if you should genuinely have multiple critical entity incidents coming up simultaneously, like a not petcha, but with even greater sort of impact scenarios, what's that that bench, that uh that roster look like, and how deep does it extend so that you're not left with organizations that thought they had an incident response retainer being told, like, we're sorry, but we have X number of customers and only Y number of responders. We'll get to you when we get to you.

Robby Peralta

Yeah, I used to say when I was competing with mnemonic, I would say, like, yeah, but you know, mnemonica has all these customers, like, what happens if there's a big big incident, like, and they're busy. But now, like, I've seen it here, uh, and I mean you've worked with a bunch of different mnemonics around the world. Uh, in in an event like this, um, I'm actually wondering because I'm not allowed to go in the war room, right? We have like this own section of the building with blocked behind doors and whatnot. If it's the same incident, isn't it sort of like you're giving a lot of the same advices, you're asking them to check the same things, uh, or how how are those incidents actually play out when it's like an

Joe Slowik

It's actually a really good question because that's also something I think, you know, going back to the critical infrastructure discussion, why, you know, another way of looking at this is in terms of high-level incident coordination and analysis, so that you're not repeating the same work over and over, but instead able to gather up information, aggregate it, and start learning from you know what happened at entity A is similar to what happened at entity B, so we can reasonably predict what an incident at entity C is going to look like to more rationally use resources at that point. Yeah, where things get interesting in that regard, and you know, we've seen this in looking at uh certain um you know widespread intrusion campaigns like a Vault Typhoon or like some of the APT-28 activity that's been going on, is there the capacity to both gather that information up and to potentially even compel organizations to share that information necessary to get that sort of wide perspective of what's going on, which gets us into another realm entirely of information analysis and information sharing among you know essentially private sector organizations and doing so for public purposes and the public good.

Robby Peralta

Yeah, interesting. Well, I think uh at least in the security world, I feel like uh we're kind of like the nice guys. I think we'd be open to sharing and whatnot. Maybe it's a little different than uh than Norway and the States in that regard.

Joe Slowik

Yeah, uh, you know, it's interesting because I'm not trying to speak ill of any entities or whatever operating in the commercial sector in information security, but if you have organizations that have an incident response practice and have like a threat intelligence practice that they make money off of, their incentive is to continue generating value for their customers and justifying why they're paying for something. And if they just start giving away information, you know, for these reasons, are they undermining their own value proposition? But in the process of trying to maintain their commercial presence, are they actively harming the ability to tackle national security issues at this point, you know, which could even extend into things like the ransomware epidemic because it's having significant impacts on the ability to operate critical infrastructure sectors these days, uh, even if that's not the intention necessarily of these entities, but it has you know significant effects that not having that information in front of decision makers that are helping to plan out and execute higher level strategy, is that limiting our ability to defend modern societies? Because company XYZ wants to make sure that they hit their numbers for Q3.

Robby Peralta

Well, money is the root of all evil. So you definitely have a point there.

Joe Slowik

Yeah. Yeah, but you know, at the same time, though, I could see a counter argument that it's like, well, government's not doing this effectively, and so we're filling, you know, the commercial energy. Are filling a gap that otherwise would not be addressed, and they can pay the salaries and invest the resources that the public sector has not. So there's a real tension there. Um, and I don't think anyone's come up with a really good way of resolving it yet. Uh, not in the States, not in Europe, as far as I can tell from it. And there are some really great government certs and similar, and there are some really great commercial organizations like a mnemonic that are out there, and balancing the tension between the missions of the two can be really interesting and how that plays out when it comes to critical infrastructure security and defense is going to be a really thorny issue to figure out uh should it become necessary to do so.

Robby Peralta

There's a movie about greed being good. So uh yeah, that's a very we have to figure that out over a beer at the conference.

Joe Slowik

Yeah, no, exactly. And you know, that's one of the arguments that's made in the States at least about this is that, like, well, you know, let the market figure out the efficiencies and the ways to do this. And again, that's all well and good until it comes to the power and water utility or whatever that's located in some part of Arkansas or whatever that also happens to serve a large military installation that has neither the budget nor resources to get any of these uh items that should they be uh essentially on their own in the face of potentially nasty adversaries because they just can't afford the market solution. So, how do we correct those market inefficiencies? I guess would be another item worth uh uh acknowledging.

Robby Peralta

And I guess uh the bigger of a country you are, the more these problems are actually apparent, I guess. Small little Norway will be okay either way, but uh by the way, all I'll just talk about, you know, Doomsay and do you believe in like these big uh public, private or like, you know, like tests, like these uh uh nationwide tests for incident readiness and stuff. Uh no one's ever like I've never had anybody on the uh on that like talked about it. Uh what do you think about those?

Joe Slowik

I think it's a very good idea. I know there's been work, especially in the electric sector, where you have things like grid X and um why am I I can't think of the name right now? I'm trying to think of like the name I can say in public, not the name or whatever that I can't say. Um but uh operations to test things in terms of grid resiliency and how to do things like restore power in the face of persistent and pretty interesting attack scenarios, uh, which is something that has been going on in the US for a few years. I think it's very valuable because it tests assumptions and shows just how certain scenarios can work out if you have a genuinely creative and knowledgeable team acting on these resources to show just what is possible and can really be effective in showing, like, oh, we didn't think about that, and oh, uh didn't realize that we might need to, you know, work around these issues or identifying things like the need for spares and uh other items that can result in you know real impacts to the resilience of critical infrastructure. Having said that, okay, we do some of that in the States. I'm roughly familiar with this going on in a few uh areas in Europe, not so much in the Nordics, though, although that could be just by ignorance, but we don't do it in all sectors. So again, you know, how what does this look like for the food sector? What does this look like for the water sector? How does that actually play out? That trying to piece together a whole of economy way of testing critical infrastructure resiliency, that's very difficult. It's also very would be very expensive, which I think is one limiter in actually doing any of this sort of activity is just uh cost in terms of time, resources, and money. Uh, but absent, you know, the same reason why we do red teething and pen penetration testing engagements, to quote the philosopher Mike Tyson, everyone has a plan until they get punched in the mouth. So the same idea applies here that yes, you have defensive plans, you have restoration plans, it's all well and good until it's actually tested by someone

Supply Chain Security and Resilience

Joe Slowik

actively poking and trying to counter what it is that you planned for.

Robby Peralta

I feel like a lot of those entities can just do a tabletop exercise with their leadership internally before uh doing it with a bunch of other different uh partners and whatnot.

Joe Slowik

And that's better than nothing for sure, but things get really interesting when you start thinking about how sector-wide interdependencies work out that, okay, say I am a water utility serving a major metropolitan area or a major urban center or something like that, and there's a power issue that lasts for more than three days. At that point, okay, maybe I haven't been impacted directly by cyber in this sense, but am I still able to perform my mission absent my reliance on reliable sources of power? And how much diesel do I have to run generators for this period of time so that I can continue that mission? What does that look like from there? And looking for other sorts of, I don't know, indirect ways that organizations could be impacted, even if they're not say directly affected by the nasty doomsday cyber effect or whatever on their own.

Robby Peralta

I guess that's one good thing about the CrowdStrike incident uh this year is that there are people are thinking about resiliency. Because I don't I I mean, I know that there's a company in Denmark that has like a I won't call them a chief resilience officer, but it's someone that is in charge of Doomsday. You know, they they they have like radios, they they it was really fun talking to them because they have all these crazy plans, right? Yeah. Very uh paranoid guy, but very fun guy to sit next to at the bar. But uh I don't think very many companies have that, you know?

Joe Slowik

No. Uh yeah, it's fun. There were way back in the day when I was in graduate school, I was taking a class with someone who worked for the US Department of Homeland Security well before CISA existed. And his job was basically what you're describing, like you know, Mr. Doomsday of trying to figure out like, well, what would be like the worst case scenario for creating a mass casualty event in the city of Chicago in the United States? That was his job, just planning that out and then figuring out like, okay, how does this work together? And he had some really interesting ideas, um, some really scary ones that I don't really want to share because I think they're still pretty relevant, cyber or otherwise. But on the one hand, like that's a really cool job. On the other hand, like talking through that, it's like we're not prepared for a lot of these things if someone was really intent on and had the resources to cause something along these lines, which gets pretty scary pretty quickly as well. Who who should be having that resilience responsibility? Uh honestly, this goes beyond cyber at this point. Cyber is a component of it, and it's an increasingly important component of it. So they need to be in the room, so to speak, and discussing this. But we're talking about fundamental issues for the continued operation and viability of an organization. So if you're talking about private organizations, this is a CEO level concern at this point. Uh so certainly there needs to be a champion for these efforts, but if that doesn't have high-level leadership attention, I would say the organization is probably not doing a very good job of trying to figure out exactly how they may they maintain their viability as an entity moving forward.

Robby Peralta

Considerations we should take regarding those left behind. Yep. What do you mean by that?

Joe Slowik

So if you're an organization that finds yourself on the wrong side of are you critical or are you not, what do we do about that? Because it seems not just callous, but almost morally indefensible to say, like, well, sucks to be you. Good luck out there in the zombie apocalypse of trying to survive. Like, that's not how we operate. So, how do we start leveraging available resources to support those organizations that unfortunately will not be priorities in these instances, but can also be completely abandoned either? And so looking for things like security hardening and advisory opportunities in advance of a potential incident to build better security posture and a more defensible security posture, or highlighting instances for reliability so that, yeah, if there's an actual incident, we might not be able to actively help you, but we can better prepare you in advance so that you're able to respond more effectively on your own. And thinking of how to make investments in that way that can pay interest over time, even if they don't result in sort of boots on the ground, people on site support in the event of an incident, and trying to stretch available resources in such a fashion to help out these sorts of entities.

Robby Peralta

I was just thinking in my head, why don't the government give tax breaks for companies investing in uh security stuff? But I guess they kind of they can write off as a business expense, but that's not enough, I guess.

Joe Slowik

Well, it's really interesting how it's played out in the US, where we have a, you know, very much a privatized power sector of sort of natural monopolies that exist. And you have controls over, you know, what power companies can charge their consumers. And you look at things like, you know, in the Western US, where they've had tons of wildfires over the last several years and such, and part of them, and many of them due to power lines that have fallen, sagged, come into contact with vegetation or whatever, that then spark the initial fire and then spreads into a wider conflagration. And so you have organizations that are trying to invest to improve these things, which means, well, that money's got to come from somewhere. Maybe that means that we can't do cyber anymore. Or if we do uh invest in cyber, that means that the end users have to start paying for more because there is a guaranteed rate of return that these organizations have negotiated in terms of their rate-paying um entities or whatever. So there's really interesting commercial aspects to this as well that limit or place interesting considerations around how organizations operating in some of these sectors can even uh prepare for these items, which is why looking to things like government support, because we're talking about critical services for everyday people at this point. Um, you know, how do we start negotiating among these conflicting interests so that, you know, the people who are providing the power can still exist because they have to make money, but they can still provide power, which everyone needs to some degree, because without that, nothing works in modern society anymore. How do we start balancing out those conflicting interests sometimes, whether it's cyber or vegetation management or um, you know, burying power lines or whatever in certain areas or implementing technologies to rapidly trip items if it detects high winds or a fault or whatever, so that you don't have an energized line sitting on the ground in a bone-dry area of California that then's gonna set tens of thousands of acres on fire. Right.

Robby Peralta

So, last question for you today, Joe. Um I was at a conference this week and they were talking about it, it was a CISO and he had a new role. It was called chief external security officer. True. And so he was basically pushing security onto his supply chain. Right? Okay. He said basically one of his plans was to sort of because we were talking about how to not leave the SMBs behind. And, you know, if you're a big company, right? Uh big bank or big energy company, I have lots of suppliers, thousands of them. Yep. If I was to push, you're familiar with CMMC, right? Yep. Pushing requirements. If you want to do business with us, you have to have this level of security. And uh, I think it was him that said that by you pushing that, you're kind of raising the the level of security in the SMBs because those are your vendors, a lot of them are your vendors. Do you buy that?

Joe Slowik

I think there's something to be said for it. Um, I think there needs to be greater enforcement mechanisms around them. And the idea definitely has validity to it, that if everyone is actually doing this correctly and as advertised, then yes, you know, the the rising tide lifts all boats, so to speak, uh, because large bank organization or even like government or military as a spender, you know, buying services requiring these steps of their suppliers means that those suppliers everyone else that deals with those suppliers benefit from the same improved security stance. Where things get interesting, um, I don't know if you for were following in the news, but there was an incident that happened, uh legal incident that took place with the research laboratory associated with Georgia Tech University in the United States. Yeah. Where, you know, it's one thing if you have a you have CMMC and you have security plans and have, you know, uh authorities to operate in similar, uh, it's one thing if you're actually implementing them, it's another thing if you're saying you're implementing them and you're not. Um, so seeing how that plays out, and I'm pretty sure they're not the only ones who are guilty of doing this to a certain extent, um, you know, that's where things can go awry, is if people sort of game the system or figure out ways to legally comply with these items and not technically comply with them. So doing so in not in the spirit of how it was in uh designed, but trying to meet the minimal uh criteria in whatever way possible at uh the minimal cost.

Robby Peralta

Yeah. And for those of you that don't know what we're talking about, it was uh it was a Georgia Tech. Anyway, so it was some university that uh bid on uh bid on doing some research or doing something and they didn't have what they said they had. And that's interesting because today it's you never get a client like I've always get those questionnaires, right? Do you guys do this? What do you do? And it goes to Messisa and we fill it out and do it. But they never really tested and they're not like coming in doing a vent test on us, you know? They're doing an audit, I guess, but that they're not. So there's uh and if they're not doing that to us, they're probably not doing that to anybody. So there isn't really no normal established practice for that sort of stuff. Testing, yeah, testing what your vendor says they actually do, right?

Joe Slowik

Right. Uh so again, it's a great idea, but there needs to be something that fills in on the accountability side to make sure that people are actually doing what they say they are.

Robby Peralta

Instead of sending out Excel sheets, uh, yes, yes, no. Yeah. I guess it's certifications are for though, I guess. That's the yeah.

Joe Slowik

Because those can't be gamed either here.

Robby Peralta

No, right. Yeah. Hate on, it's just so scary. Scary reason. Any closing uh thoughts before uh before we wrap it up? And I'll see you here in two or three weeks in uh in Belgium.

Joe Slowik

Yes. Uh no, I think we touched on just about everything. I hope it's an interesting conversation that we'll have in Copenhagen. I'm looking forward to it, and hopefully we can spark some interesting thoughts and uh considerations on the part of attendees and if you want some.

Robby Peralta

Thank you so much for time, Mr. Slowik. We'll see you soon. Sounds good, Robby. Well, that's all for today, folks. Thank you for tuning in to the Mnemonic Security Podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast @ mnemonic.no. Thank you for listening, and we'll see you next time.