An Interview with Andy Greenberg - Author of Sandworm
Release Date: 03/18/2020
Unsolicited Response Podcast
info_outline S4x24 Closing PanelUnsolicited Response Podcast
info_outline Q1: ICS Security In ReviewUnsolicited Response Podcast
Emma Stewart joins Dale to discuss the 3 big OT & ICS security stories from the first quarter. They end by giving their win, fail and prediction for Q1.
info_outline S4x24 PreviewUnsolicited Response Podcast
info_outline Predictions AnalyzedUnsolicited Response Podcast
In this solosode episode Dale reviews the status of his three predictions from the Q1, 2 and 3 quarter in review episodes and answers a listener question.
info_outline Q4 ICS Security Quarter In ReviewUnsolicited Response Podcast
info_outline CISA Attack Surface Scanning ServiceUnsolicited Response Podcast
Dale is joined by Steve Pozza, CISA Section Chief of Operational Resilience, and Tom Millar, CISA Branch Chief of Resilience, to discuss some of CISA's security services for asset owners. They discuss: The Internet accessible attack surface enumeration and vulnerability scanning surface. Asset owners can buy products or services to do this. Why is the government doing this? What CISA is doing with this attack surface data? How is CISA measuring the success of this service offering? Other broadly available services and tools, the cybersecurity performance goals (CPG assessment) ~500 done in...
info_outline Engineering-Grade OT Security with Andrew GinterUnsolicited Response Podcast
Andrew Ginter published his third book this year: . Dale interviews Andrew on the book including: Who was the target reader that Andrew wrote the book for? Do (should) professional engineers lose their licenses for poor and dangerous cybersecurity design and deployments? The use of the term engineering grade, and how he defines it. Unhackable protection and safety controls as a major part of engineering grade. Unidirectional (one-way) network devices as the only security control listed as engineering grade. Is one-way from the enterprise network to the OT network engineering grade? Given the...
info_outline Asset Inventory, Lawyers, and AIUnsolicited Response Podcast
This week is a Dale Peterson solosode. Updates and Announcements Dale provides updates about S4x24 ticket sales and announces the Women In ICS Security program and sponsor package. Main Topics Asset Inventory in Cybersecurity: Dale challenges the common security mantra "You can't protect what you don't know," using examples from both physical and cyber domains. He notes many of the comments on this week's article missed the main point, and he gives hints on the next two asset inventory articles. Legal and Regulatory Issues in Cybersecurity: Dale emphasizes the importance of domain expertise...
info_outline Is The Purdue Model Dead (E)Unsolicited Response Podcast
info_outlineIn this episode Dale Peterson interviews Sandworm author and Wired Senior Writer Andy Greenberg on the S4x20 Main Stage. They focus on the ICS issues in the story.
The discussion includes:
- What led Andy to write this book?
- What response did people he interviewed want to these Sandworm attack? Did he think any of these proposed responses would be effective?
- Should NATO Articles 4 and 5 been triggered in any of these European cyber attacks?
- Interviews with Obama and Trump officials on cyber norms to agree not to do things like attack critical infrastructure. (They didn't want to do this; they wanted to have the option to do it.)
- The USG concept of defending forward.
- False flags used in Sandworm attacks, and the future of false flags and misleading attribution.
- Besides Sandworm, who were the villains in the book?
- Why did he go and how scared was Andy when he went to Russia to see the building where Sandworm worked?