contrasted gaps: common solutions in a global ot environment€¦ · contrasted gaps: common...

62
Contrasted gaps: Common Solutions in a Global OT Environment Industrial Cybersecurity Center Susana Asensio

Upload: others

Post on 02-Jun-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Contrasted gaps: Common Solutions in a Global OT Environment

Industrial Cybersecurity Center

Susana Asensio

Page 2: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Agenda

Contrasted gaps: Common Solutions in a

Global OT Environment

Initiatives to decrease these barriers

Who is CCI & Why CCI has the capacity

to detect global gaps

More remarkable contrasted gaps and

their consequences

Page 3: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

CCI

The Industrial Cybersecurity

Center

Kaspersky Industrial Cybersecurity Conference 2019

Page 4: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

+2.000 Members worldwide

Page 5: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

All actors involved in

Cybersecurity in Industrial Environments

Page 6: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Endusers

Publicbodies

Devicemanufacturers

Engineering

Integrators

Cybersecurity providers

Page 7: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

CCI Coordinators

Andrea ParadaClaudio Caracciolo

Diego Andrés Zuluaga

Fernando Guerrero

Ernesto Landa Gabriel Bergel

Hernán Vázquez Jesus Peña Jorge Abanto

Juan Carlos Gómez

Marcelo Branquinho

Mateo Martinez

Nora AlzuaSantiago Vazquez

South America

Raúl Rivera

José Torres

Patrick MillerCentre America

North America

Page 8: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Javier Cao

Jesús Mérida Joan Figueras

Susana Asensio

Marcin Dudek

José Luis Jiménez

Belén PérezDr. John McCarthy

Edorta Echave

Europe

Vicente Asensi

Óscar Bou

José Valiente

Stephen Smith

Laurent Pelud

Piotr Jasinski

Juan Miguel Pulpillo

Anton Shipulin

Asia

AyhanGücüyener

Can Demiral

Ignacio Paredes

Ayman Al-Issa

Middle East

CCI Coordinators

Page 9: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

- Forensic Analysis Expert: Javier Pagès Joan Figueras

- Industrial Hacking: Claudio Caracciolo

Ignacio Paredes Silvia Villanueva

- Critical Infrastructure: Santiago G. Gonzalez

Robert M. Lee- ICS Threat Intelligence:

Gustavo Presman

- Cybersecurity Management Systems: José Valiente Samuel Linares

- Industrial Security: Arturo Trujillo

CCI Experts

Page 10: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

CCI Experts

- Legal Compliance:Paloma Llaneza

- Industrial Systems: David Marco Hector Puyosa

- Industrial Networks: Ignacio Álvarez

- Physical Security: Miguel Merino

Eduardo Di Monte- Resilience and Continuity:

- Security and Privacy Management Systems: Carlos Asún

- Manufacturing Execution Systems: Antonio Rodríguez U.

Page 11: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

21

studies

Page 12: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

21

studies

11 countries

Page 13: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

21

studies

11

countries

+650

industrial organizations

Page 14: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

21

studies

North Americ

a

Central & South Americ

a

Europe

11

countries

+650

industrial organizations

Page 15: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Contrasted gaps

Kaspersky Industrial Cybersecurity Conference 2019

Page 16: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Contrasted

gaps

Common Solutions in a Global OT

Environment

UNAWARENESS, LACK OF TRAINING &

QUALIFICATION

INDUSTRIAL CYBERSECURITY

RESPONSIBLE

CIBERSECURITY IN NEW PROYECTS

INCIDENT INFORMATION SHARING

REGULATIONS, NORMS & STANDARDS

Page 17: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

UNAWARENESS, LACK OF TRAINING & QUALIFICATION

Page 18: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

?

ASSETS

Page 19: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

IF YOU DON’T KNOW WHAT YOU’VE GOT…

HOW CAN YOU PROTECT IT?

Page 20: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

NO

DIAGNOSIS

Page 21: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

217

organizations

Our participants

Page 22: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

33%Have not carry out a risk assessment

Page 23: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

63.500

Industrial

organizations

700.000

employees33%

Page 24: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference
Page 25: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

VULNERABILITIES

Page 26: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

30% 40% 50% 60% 70% 80% 90%

Page 27: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

20% 25% 30% 35% 40% 45%

Incident response management; 38%

Page 28: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

6% 8% 10% 12% 14% 16% 18%

Page 29: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

NO

INTEGRATION

Page 30: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

30%Have not defined an incident procedure

Page 31: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Electricity, water, oil & gas

A cyber incident response process has

been defined, implemented and tested 50%

Page 32: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Electricity, water, oil & gas

A cyber incident response

process is being defined 33%

Page 33: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Electricity, water, oil & gas

Cyber incident response is reactive 17%

Page 34: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

17%CYBER INCIDENT RESPONSE IS REACTIVE

Page 35: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

8.529Infrastructures

215.739 Employees

Page 36: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

RISK PERCEPTION

SUPPORT

REQUIREMENTS

CRITICAL CAPACITY

SUPPLY

LA

CK

OF

TR

AIN

ING

&

QU

AL

IFIC

AT

ION

Page 37: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

RISK PERCEPTION

SUPPORT

REQUIREMENTS

CRITICAL CAPACITY

SUPPLY

LA

CK

OF

TR

AIN

ING

&

QU

AL

IFIC

AT

ION

Page 38: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

0% 20% 40% 60% 80% 100%

Fairly well aware

19%

Have an average

awareness

36%

Very little

awareness

37%

I don't know

9%19% 37%

Page 39: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

RISK PERCEPTION

SUPPORT

REQUIREMENTS

CRITICAL CAPACITY

SUPPLY

LA

CK

OF

TR

AIN

ING

&

QU

AL

IFIC

AT

ION

Page 40: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

PLEASE,

work on

awareness,

training, and

qualifications

Page 41: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Kaspersky Industrial Cybersecurity Conference 2019

Page 42: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

CYBERSECURITY IN NEW PROJECTS

Page 43: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

IMPACT

• Performance

• Deployment

• Budget

EXISTANCE

• Industrial technology

• Providers

• Law orstandard

VALIDATION PROFESSIONALS

Page 44: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Design phaserequirements

Completely; 19,95%

At a basic level;

48,55%

Never; 20,34%

I don't know; 11,17%

0%

10%

20%

30%

40%

50%

60%

70%

80%

90%

100%

Page 45: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

INDUSTRIAL CYBERSECURITY RESPONSIBLE

Page 46: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

INDUSTRIAL CYBERSECURITY RESPONSIBLE

Page 47: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

COMMITMENT

CONSEQUENCES

LACK OF STRATEGIC ALIGMENT

LACK OF SUPPORT

LACK OF LEADERSHIP

WITHOUT THE INDUSTRIAL CYBERSECURITY RESPONSIBLE

Page 48: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

LEADERSHIP TEAM

RESPONSIBLE FOR BUYING

HAVE NOT DEFINED INCIDENT PROCESS

ONLY BASIC CYBERSECURITY

REQUIREMENTS IN NEW PROJECTS

HAVE NOT CARRY OUT A RISK ASSESSTEMENT

CHARACTIRIZATION

WITHOUT THE INDUSTRIAL CYBERSECURITY RESPONSIBLE

>250Emp

National

>2M$

60%

70%

80%

75%

Page 49: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

INCIDENT INFORMATION SHARING

Page 50: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

We all are in the same boat…

Kaspersky Industrial Cybersecurity Conference 2019

Incident notification systems

• Incident notification systems implemented by the states

• Teams need also to get prepare

Cybersecurity

exercises

• Attacker & Defense point

of view

• Theory and reality are not

always the same

Sharing Platform of Industrial Cybersecurity Incident Information

• Incident scenario

• Incident full characterization

• Incident treatment

• EMPOWERMENT TEAMS

Page 51: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

REGULATIONS, NORMS & STANDARDS

Page 52: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Do not startthe housefrom the roof

Page 53: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

30%DO NOT USE ANY NORMS & STANDARDS

Page 54: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

ISO 27001; 42%PERSONAL DATA

PROTECTION; 34%NONE; 30%

CRITICAL INFRASTRUCTURE

PROTECTION LAW; 16%

Page 55: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

But they are not enough

Page 56: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Proactive measuresDisinformation

&

Uncertainty

Reactive measuresControl actions based on

analisys of malicious activity

Learning algorithms

&

Model training

Anticipative measures

Page 57: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Initiatives

Kaspersky Industrial Cybersecurity Conference 2019

Page 58: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

CCI INITIATIVES

UNAWARENESS, LACK OF TRAINING & QUALIFICATION

INDUSTRIAL CYBERSECURITY

RESPONSIBLE

CIBERSECURITY IN NEW PROYECTS

INCIDENT INFORMATION

SHARING

REGULATIONS, NORMS &

STANDARDS

TECHNICAL

PLATFORM OF

INDUSTRIAL

CYBERSECURITY

REQUIREMENTS

EVENTS &

TEAMS &

INDUSTRIAL

CYBERSECURITY

SCHOOL

GUIDE &

CREDENTIALS &

INDUSTRIAL

CYBERSECURITY

SCHOOL

INDUSTRIAL

CYBERSECURITY

INCIDENT

INFORMATION

SHARING

PLATFORM

ICMS,

INDUSTRIAL

CYBERSECURITY

SCHOOL,

EUROPEAN LAW

GUIDE

Page 59: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference
Page 60: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

PLEASE,

BUILD TEAM

THAT, NEVER

FAILS

Rumba chiva bus

Page 61: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Cybersecurity grows, as it grows the team trust

Page 62: Contrasted gaps: Common Solutions in a Global OT Environment€¦ · Contrasted gaps: Common Solutions in a Global OT Environment ... Kaspersky Industrial Cybersecurity Conference

Kaspersky Industrial Cybersecurity Conference 2019

THAT’S ALL

THANK YOU

;-)

[email protected]