Asset Owners As The Last Mile Of Cybersecurity

Matt Tompkins

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

In this insightful talk from S4, Matt Tompkins introduces a compelling analogy, arguing that industrial cybersecurity has reached its own "last mile problem," mirroring challenges once faced by the logistics industry. While government agencies, original equipment manufacturers (OEMs), Industrial Control Systems (ICS) vendors, cybersecurity providers, and system integrators have made significant strides in developing and delivering cybersecurity products, services, and guidance, the effective deployment and implementation of these solutions at the asset owner level remain persistently difficult. This talk posits that these localized, often accepted "costs of doing business" or "one-off" problems are, in fact, systemic issues that, when viewed through the lens of a collective "last mile," become solvable and worthy of strategic investment.

Watch on YouTube

Visual summary for Asset Owners As The Last Mile Of Cybersecurity by Matt Tompkins
Visual summary for Asset Owners As The Last Mile Of Cybersecurity by Matt Tompkins

Key moments

  1. 0:00 Defining industrial cybersecurity's 'last mile problem'.
  2. 2:00 How the logistics industry solved its last mile problem.
  3. 4:00 Significant advancements in government industrial cybersecurity initiatives.
  4. 6:00 Rapid expansion and specialization of the ICS cybersecurity vendor market.
  5. 7:00 Unpacking the familiar challenges faced by asset owners.
  6. 7:40 A new perspective for making asset owner problems solvable.

Asset Owners As The Last Mile Of Cybersecurity

Speakers: Matt Tompkins

Conference: S4

YouTube: https://www.youtube.com/watch?v=LNy3d6TNJCg

Overview

In this insightful talk from S4, Matt Tompkins introduces a compelling analogy, arguing that industrial cybersecurity has reached its own "last mile problem," mirroring challenges once faced by the logistics industry. While government agencies, original equipment manufacturers (OEMs), Industrial Control Systems (ICS) vendors, cybersecurity providers, and system integrators have made significant strides in developing and delivering cybersecurity products, services, and guidance, the effective deployment and implementation of these solutions at the asset owner level remain persistently difficult. This talk posits that these localized, often accepted "costs of doing business" or "one-off" problems are, in fact, systemic issues that, when viewed through the lens of a collective "last mile," become solvable and worthy of strategic investment.

Tompkins, drawing from his background which includes engagement with the intelligence community on infrastructure cybersecurity, highlights the critical disconnect between the sophisticated "central flow" of cybersecurity development and the challenging realities of individual operational technology (OT) environments. He challenges the industrial cybersecurity community to adopt a new perspective, one that aggregates these seemingly disparate asset owner challenges into a single, addressable problem, much as the logistics industry did with physical goods delivery. This reframing is crucial for unlocking novel solutions and ensuring that the advancements in cybersecurity truly reach and protect the critical infrastructure they are designed for.

Background

▶ Watch: Defining industrial cybersecurity's 'last mile problem'. (0:00)

The concept of the "last mile problem" originated in the build-out of network utilities like electricity and telecommunications, where connecting to individual users presented the most challenging business case due to the high cost per user. Later, logistics professionals encountered their own last mile problem during the peak of globalization. As the central flow of goods from overseas factories, through cargo ships, ports, and domestic shipping networks became increasingly efficient and cost-effective, the final leg of delivery to individual recipients remained fraught with inefficiencies, high costs, and localized challenges. These issues were often considered intractable or too specific to warrant large-scale solutions.

A pivotal development in overcoming the logistics last mile problem was the standardization of the shipping container, detailed in Mark Levinson's book "The Box." The 20-foot equivalent unit (TEU) became a standard metric, enabling massive improvements in cargo shipping capabilities from the 1950s onwards. However, despite these advancements, a greater proportion of time and expense in end-to-end shipping shifted to the final, "last mile" delivery. It was the aggregated perspective, recognizing these varied problems as a single, overarching last mile issue, that convinced stakeholders to invest in solutions. This led to innovations like delivery lockers (addressing "porch pirates" and unmarked addresses), route automation for efficiency, and the emergence of local delivery companies specializing in specific geographic or logistical challenges.

Industrial cybersecurity, Tompkins argues, now faces a similar predicament. Over the past two decades, there has been a significant surge in the capabilities and effectiveness of the "central flow" of cybersecurity provisions.

Government Efforts:

Government initiatives have taken a substantial leap forward. Key milestones include:

  • The creation of ICS-CERT (Industrial Control Systems Cyber Emergency Response Team) over 20 years ago, alongside the establishment of the ICS Joint Working Group. While the ICS Joint Working Group and ICS-CERT have seen structural changes (with ICS-CERT now integrated into CISA), their initial formation marked a significant commitment to critical infrastructure security.
  • The establishment of CISA (Cybersecurity and Infrastructure Security Agency) in 2018, which further consolidated and amplified private sector engagement.
  • The NSA Cybersecurity Collaboration Center, demonstrating a commitment to broader information sharing and partnership.
  • Watershed moments in information sharing, such as the declassification in 2021 of 10 years of Chinese activity targeting pipelines, and the subsequent Shields Up campaign, which provided critical intelligence and guidance to asset owners.
  • The growth in international government efforts, evidenced by an expanding list of products, seals, and advisories.

Vendor Space Maturity:

The vendor ecosystem has grown even more capable and specialized.

  • The website Industrial Cyber publishes a buyer's guide that serves as a census of the market, which in its latest version, categorized the industrial cybersecurity market into 16 primary categories and 85 specialized subcategories of products and services. This illustrates the depth and breadth of available solutions.
  • The growth of conferences like S4, from just 40 attendees in 2007 to over 1100 today, further underscores the maturity and community engagement within the industrial cybersecurity sector.

Despite this robust central development, asset owners continue to grapple with persistent, familiar challenges in deploying and integrating cybersecurity measures. These problems are often seen as unavoidable costs or too niche for scalable solutions, mirroring the pre-solution phase of the logistics last mile.

Key Findings

▶ Watch: Significant advancements in government industrial cybersecurity initiatives. (4:00)

The central and most critical finding of Matt Tompkins' talk is that the myriad, often localized, and seemingly intractable problems faced by industrial asset owners in implementing cybersecurity are not isolated incidents but rather constitute a collective "last mile problem" for the entire industrial cybersecurity ecosystem. This is not a finding of new vulnerabilities or attack vectors, but a conceptual breakthrough in how we approach the existing, well-understood difficulties of securing operational technology (OT).

Tompkins argues that just as logisticians transformed their understanding of delivery inefficiencies, the industrial cybersecurity community needs to reframe its perspective. By aggregating these individual deployment frictions – which are "mostly familiar to most of you" (the audience) – into a single, overarching challenge, they transition from being accepted as unavoidable costs or specialized one-offs to becoming solvable and worth solving at scale. This shift in perspective is the game-changer. It enables a strategic, holistic approach to problems that have long stymied effective security outcomes, despite the significant advancements in upstream government guidance, vendor offerings, and industry capabilities. The core contribution is identifying the need for this perceptual shift to unlock investment and innovation in the crucial final stage of cybersecurity delivery.

Technical Deep Dive

▶ Watch: Rapid expansion and specialization of the ICS cybersecurity vendor market. (6:00)

While this talk is conceptual and does not delve into specific exploits, vulnerabilities, or code, the "technical deep dive" section here focuses on the nature of the systemic and operational challenges that define the "last mile" for asset owners in industrial cybersecurity. These are the underlying friction points that prevent the effective application of cybersecurity principles and products in real-world OT environments.

The challenges faced by asset owners, though not explicitly enumerated in the talk, are widely recognized within the ICS community. They can be broadly categorized as:

  1. Legacy Systems and Lifecycles: Many critical industrial systems were designed decades ago, long before modern cybersecurity threats were prevalent. These systems often run on outdated operating systems (e.g., Windows NT, XP) or proprietary hardware and software that cannot be easily patched, updated, or replaced without significant operational disruption or cost. Their operational lifecycles are typically much longer than IT systems, meaning security updates are infrequent or non-existent, and traditional IT security tools are incompatible.
  1. Operational Constraints and Priorities: The primary goal of OT systems is availability, safety, and reliability, often above all else. Any cybersecurity measure that introduces perceived risk to these operational imperatives—such as potential downtime for patching, network latency, or system instability—is met with significant resistance. This creates a challenging environment for implementing security controls that might be standard in IT.
  1. Unique Network Architectures: Many OT networks are flat, lack segmentation, or employ proprietary protocols that are not well-understood by IT security teams. While "air-gapping" has been a traditional security measure, increasing convergence with IT networks and the need for remote access have blurred these lines, introducing new attack surfaces. However, even genuinely isolated systems present challenges for patching, monitoring, and incident response, as traditional network-based security tools cannot be easily deployed.
  1. Lack of Specialized Talent: There is a significant shortage of cybersecurity professionals with deep understanding of both IT security principles and the nuances of industrial control systems, process engineering, and operational contexts. Asset owners often have small teams, or even single individuals, responsible for both operations and security, lacking the specialized training or resources to effectively manage complex OT cybersecurity programs.
  1. Budgetary and Resource Limitations: Cybersecurity investments in OT often compete with other operational priorities, and demonstrating a clear return on investment (ROI) can be difficult. Many asset owners, particularly smaller utilities or manufacturers, operate on tight budgets, making it challenging to afford expensive tools, specialized consultants, or extensive training programs.
  1. Vendor Lock-in and Proprietary Solutions: ICS environments are frequently characterized by vendor lock-in, where specific hardware and software from a single vendor are deeply integrated. This can limit choices for security solutions and make interoperability a significant hurdle. Vendors may also be hesitant to allow third-party security tools to touch their proprietary systems, citing warranty or support concerns.
  1. Data Visibility and Monitoring: Gaining adequate visibility into OT network traffic, device configurations, and process data is often difficult. Traditional IT security tools for logging, monitoring, and intrusion detection may not understand OT protocols (e.g., Modbus, DNP3, OPC UA) or generate relevant alerts for operational anomalies. This lack of visibility hinders threat detection and incident response capabilities.

These "familiar" problems collectively represent the "friction and challenges and hurdles" that make the last mile of industrial cybersecurity so difficult. They are not merely technical issues but deeply intertwined with operational, cultural, and economic factors. The talk's premise is that by reframing these as components of a single, systemic "last mile" problem, the industry can begin to develop comprehensive, scalable solutions that address these multifaceted barriers rather than treating each as an isolated, unresolvable obstacle. This might involve developing specialized "last mile" tools that are OT-native, fostering regional ICS cybersecurity expertise, or creating standardized frameworks for secure deployment that account for operational realities.

Demo / Proof of Concept

▶ Watch: Unpacking the familiar challenges faced by asset owners. (7:00)

This presentation was a conceptual and analytical talk focused on reframing a persistent challenge within industrial cybersecurity. As such, it did not include a live demonstration or a technical proof of concept. The speaker's objective was to introduce a new perspective on existing problems rather than showcase specific tools, vulnerabilities, or exploits.

Defensive Implications

▶ Watch: A new perspective for making asset owner problems solvable. (7:40)

The "last mile" perspective offered by Matt Tompkins carries significant defensive implications for all stakeholders in the industrial cybersecurity ecosystem: asset owners, government agencies, and cybersecurity vendors/integrators. Moving forward, a concerted effort to bridge this gap is essential for truly securing critical infrastructure.

For Asset Owners:

  • Acknowledge Systemic Issues: Instead of viewing their unique challenges as isolated or unavoidable, asset owners should recognize them as part of a larger, solvable "last mile problem." This shifts the mindset from resignation to proactive problem-solving.
  • Demand Tailored Solutions: Asset owners should advocate for cybersecurity products and services that are specifically designed for the operational realities of their OT environments, rather than attempting to shoehorn IT solutions. This includes solutions that prioritize uptime, integrate with legacy systems, and require minimal operational disruption.
  • Invest in Localized Expertise: Similar to how logistics saw the rise of local delivery companies, asset owners should seek out or cultivate specialized, regional ICS cybersecurity integrators and service providers who understand their specific industry, regulatory landscape, and operational context.
  • Share Experiences (Anonymously if Necessary): By sharing the common pain points and successful workarounds, asset owners can help the broader community identify patterns and develop scalable solutions for the last mile.

For Government Agencies:

  • Shift from Guidance to Implementation Support: Government efforts should evolve beyond merely issuing advisories and best practices to actively facilitating their practical implementation. This could involve funding pilot programs, developing deployment playbooks, or offering incentives for adopting last-mile solutions.
  • Foster "Local Delivery" Ecosystems: Agencies like CISA and NSA should consider initiatives to support the growth of specialized regional ICS cybersecurity firms and training programs that can address the unique needs of diverse asset owners. This includes developing standardized certifications for such service providers.
  • Standardize Deployment Frameworks: While operational environments vary, governments can work with industry to develop flexible frameworks or common architectures for secure deployment that account for the last mile challenges, rather than one-size-fits-all mandates.
  • Improve Actionable Intelligence: Continue to declassify and share actionable intelligence, but also focus on making that intelligence digestible and directly applicable for asset owners with limited resources. The declassification of Chinese activity targeting pipelines and the Shields Up campaign were positive steps in this direction.

For Vendors and Integrators:

  • Innovate for the "Last Mile": Cybersecurity vendors should focus R&D on developing solutions that are inherently easier to deploy, configure, and manage in complex, often constrained, OT environments. This means prioritizing ease of integration, low overhead, and compatibility with legacy systems.
  • Specialize and Localize: Integrators should consider specializing in particular industries or geographic regions, becoming the "local delivery companies" of industrial cybersecurity. Understanding the unique regulatory, operational, and cultural nuances of these specific niches will be key.
  • Focus on Usability and Operational Impact: Products must be designed with the operator in mind, minimizing disruption to critical processes and providing clear, actionable insights without requiring extensive security expertise from OT personnel.
  • Collaborate on Interoperability: Work towards greater interoperability between different vendor solutions to reduce the burden on asset owners struggling with disparate systems and vendor lock-in.

Ultimately, addressing the "last mile problem" requires a collective shift in perspective and a renewed commitment to solving the practical, on-the-ground challenges faced by asset owners. By recognizing these issues as a systemic problem, the industrial cybersecurity community can unlock innovative solutions that ensure robust security truly reaches the critical infrastructure it aims to protect.

Key Takeaways

  • Industrial cybersecurity faces a "last mile problem," analogous to the challenges in logistics, where efficient central efforts struggle with difficult, localized deployment.
  • Despite significant advancements in government initiatives (e.g., CISA, NSA Cybersecurity Collaboration Center, declassification of Chinese pipeline activity) and a robust vendor market (e.g., Industrial Cyber's 85 subcategories), effective cybersecurity implementation at the asset owner level remains challenging.
  • The key finding is that viewing these disparate, familiar problems faced by asset owners as a collective "last mile problem" transforms them from intractable one-offs into solvable, scalable challenges.
  • Solutions for the industrial cybersecurity last mile will likely mirror logistics innovations, requiring specialized, localized approaches, potentially involving regional integrators, tailored technologies, and simplified deployment strategies.
  • A new perspective and strategic investment are crucial to bridge the gap between advanced cybersecurity offerings and their practical, effective deployment across diverse critical infrastructure environments.
  • All stakeholders—asset owners, government agencies, and vendors—must collaborate to acknowledge, understand, and develop targeted solutions for these persistent last mile challenges.

About the Speaker(s)

Matt Tompkins is a speaker with a background that positions him uniquely to discuss systemic challenges in critical infrastructure cybersecurity. Coming from an "agency of lawyers," his perspective likely incorporates policy, regulatory, and strategic considerations alongside technical understanding. He has experience engaging with an intelligence community audience, where he was asked to speak on how intelligence collectors and analysts can better support infrastructure cybersecurity. This suggests a role focused on the intersection of national security, intelligence, and the practical implementation of cybersecurity measures within critical sectors. His insights are geared towards understanding and solving large-scale, persistent problems that affect the security posture of the nation's vital assets.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Tompkins delivers a sharp, strategic reframing of the persistent challenges faced by asset owners in industrial cybersecurity, labeling it the 'last mile problem.' While the individual issues are familiar, aggregating them under this conceptual umbrella is a clever move. It shifts the conversation from isolated, intractable problems to a collective, solvable strategic challenge, which is precisely the kind of signal this industry needs to drive real investment and innovation in practical deployment.

Heather Calloway (CISO) — MUST SEE

Matt Tompkins's S4 talk masterfully reframes the persistent challenges faced by industrial asset owners in implementing cybersecurity as a systemic "last mile problem." This conceptual breakthrough, drawing a powerful analogy to logistics, moves these issues from being seen as intractable, localized failures to solvable, scalable challenges worthy of strategic investment. It provides critical clarity for CISOs and executive leaders seeking to understand and address the fundamental disconnect between security development and operational deployment in critical infrastructure, offering a new lens for governance and accountability.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference