S4 Closing Panel
S4x24 - ICS Security Conference · Day 3 · Main Stage
Overview
This S4 Closing Panel delved into the pressing issues and critical blind spots within the Industrial Control Systems (ICS) security community. Featuring insights from prominent figures like Ralph Langner, Megan Samford, and moderated by Zach Tudor, the discussion critically examined the prevailing narratives, investment priorities, and practical challenges faced by organizations securing operational technology (OT) environments. The panelists challenged the community to re-evaluate its focus, arguing that an overemphasis on theoretical, high-consequence cyber-physical attacks detracts from addressing the more prevalent and actionable threat of opportunistic, low-profile incidents.

Key moments
- 0:00 Ralph Langner: Are we missing the real problems?
- 2:00 Shift focus from catastrophic to opportunistic attacks
- 3:45 Actionable security: Tone down scare tactics for real use
- 4:30 Zach Tudor: Low adoption of available secure products
- 6:00 Megan Samford: Prioritize security features over detection
- 7:20 Ralph Langner: Underfunding forces prioritization in OT security
S4 Closing Panel
Speakers: Zach Tudor, Megan Samford, Ralph Langner
Conference: S4
YouTube: https://www.youtube.com/watch?v=twJRjRlD1ac
Overview
This S4 Closing Panel delved into the pressing issues and critical blind spots within the Industrial Control Systems (ICS) security community. Featuring insights from prominent figures like Ralph Langner, Megan Samford, and moderated by Zach Tudor, the discussion critically examined the prevailing narratives, investment priorities, and practical challenges faced by organizations securing operational technology (OT) environments. The panelists challenged the community to re-evaluate its focus, arguing that an overemphasis on theoretical, high-consequence cyber-physical attacks detracts from addressing the more prevalent and actionable threat of opportunistic, low-profile incidents.
The talk highlighted a significant disconnect between the perceived "cyber war" scenarios frequently discussed and the reality of attacks seen in the wild, which are often financially motivated or opportunistic. This divergence, the panelists contended, leads to misallocated resources, a lack of actionable advice for practitioners, and a general skepticism from those responsible for funding OT security initiatives. The conversation underscored the urgent need for a shift towards practical risk management, the adoption of inherently secure products, and a more realistic approach to prioritizing defensive investments given perennial budget constraints.
Background
▶ Watch: Ralph Langner: Are we missing the real problems? (0:00)
For years, the ICS security community has been largely shaped by a narrative centered around high-profile cyber-physical attacks, often invoking scenarios of catastrophic infrastructure disruption or state-sponsored digital warfare. Ralph Langner, a seasoned expert in the field and one of the panelists, acknowledged his own contributions to this narrative, recalling past presentations where he detailed how a cyber attack could, for instance, "blow up a nuclear power plant" (04:00). This focus, while effective in raising initial awareness and securing early funding for the nascent field, has created a paradigm where the most dramatic and theoretical threats often overshadow more mundane but equally impactful realities.
The panelists observed a fortunate absence of such predicted catastrophic attacks in recent times, leading to a dangerous complacency where some might conclude the "problem solved," thereby questioning the continued investment in OT security (02:00). This perception is exacerbated by the fact that many discussions at conferences, while valuable, often revolve around topics like Software Bills of Materials (SBoMs) or theoretical vulnerabilities rather than concrete, high-impact cyber-physical incidents. Simultaneously, the panel noted a rise in low-profile opportunistic attacks, exemplified by pervasive ransomware campaigns or specific incidents like the Oldsmar, Florida water treatment plant event, which, while having a cyber-physical angle, was characterized as opportunistic rather than a sophisticated state-level operation (02:00-04:00). This disparity between narrative and reality forms the foundational problem the panel sought to address.
Further compounding the issue is the slow adoption of available security technologies. Zach Tudor pointed out that while vendors like Schneider Electric (with whom Langner is now associated) have developed secure versions of critical industrial protocols, such as Modbus Secure (or Secure Modbus) utilizing TLS certificates, and secure options for Ethernet IP, their uptake by the customer base remains "really low" (04:00, 08:00). This indicates a gap not just in technology availability, but in market demand, procurement practices, or perhaps a lack of perceived urgency among asset owners. Megan Samford highlighted another critical imbalance: an "obsession" within government, vendors, and media with detection and threat intelligence, often at the expense of focusing on security features within products and systems themselves (06:00). This suggests a reactive security posture dominating the discourse, rather than a proactive approach embedded in design.
Underpinning all these challenges is the persistent issue of underfunding in OT security. Ralph Langner emphatically stated that "we're totally underfunded," forcing difficult choices (08:00). He criticized the community's "incapability of prioritization" when it comes to foundational concepts, often resorting to the "we have to do both" trope, which is simply not feasible given budget realities (08:00-10:00). This background sets the stage for a discussion on how to realign the community's efforts and investments to achieve more impactful and realistic security outcomes.
Key Findings
▶ Watch: Actionable security: Tone down scare tactics for real use (3:45)
The S4 Closing Panel delivered several critical findings that challenge the conventional wisdom and current practices within the ICS security domain:
- Misalignment of Threat Narratives and Reality: The most significant finding is the stark contrast between the community's prevalent narrative of sophisticated, high-profile cyber-physical attacks and the actual landscape of observed incidents. While the former are often discussed, the latter are dominated by low-profile, opportunistic attacks like ransomware and incidents such as the Oldsmar water plant event. This disparity leads to skepticism among stakeholders and a perception that security professionals are "bullshitting them anyway" to secure funding (04:00). The panel argued that this narrative needs to be "toned down" to be more actionable and relatable.
- Low Adoption of Secure Industrial Protocols: Despite vendors making strides in developing secure versions of foundational industrial protocols, their adoption remains alarmingly low. Specific examples cited include Modbus Secure (or Secure Modbus) which incorporates TLS certificate-based solutions, and secure implementations for Ethernet IP (04:00, 08:00). This indicates a market failure where the availability of secure products does not automatically translate into their widespread use, pointing to issues beyond just vendor capability.
- Prioritization Paralysis Due to Underfunding: The ICS security community struggles profoundly with prioritization. Faced with limited budgets, there's a tendency to default to a "we have to do both" mentality rather than making strategic, risk-based choices (08:00-10:00). Ralph Langner stressed that underfunding is the "biggest requirement" for OT security success, and without the luxury of abundant resources, choices must be made, otherwise, managers will make them, potentially suboptimally.
- Overemphasis on Detection and Threat Intelligence: Megan Samford identified a significant imbalance in focus, noting that "so much attention from the government from vendors from the media on detection and threat intel" (06:00). She argued that what's not being talked about sufficiently are security features within products and systems. This highlights a reactive, post-compromise security mindset dominating the industry, rather than a proactive, preventative approach rooted in secure design and engineering.
- Lack of Clear Procurement Language for Security Features: A major barrier to driving the adoption of more secure products is the difficulty for procurement departments to articulate clear, consistent security requirements. Samford suggested that it's "not easy for them in many cases to decipher what am I really asking for and is there a simple way to ask for it?" (06:00). This leads to a market where vendors aren't sufficiently incentivized to build inherently more secure products, as the demand signal from purchasers is weak or ambiguous.
Technical Deep Dive
▶ Watch: Zach Tudor: Low adoption of available secure products (4:30)
The panel discussion, while high-level, touched upon several key technical areas and concepts critical to ICS security. The core of the technical discussion revolved around the nature of cyber-physical attacks, the security of industrial protocols, and the intrinsic security features of OT products.
Firstly, the distinction between attack types was a recurring theme. The "high-profile cyber-physical attacks" often discussed are characterized by their potentially catastrophic impact, targeting critical infrastructure with sophisticated, often nation-state-level capabilities. Ralph Langner's previous talks, where he described how to "blow up a nuclear power plant with a cyber attack" (04:00), exemplify this category. These attacks often involve deep knowledge of Operational Technology (OT) processes, Programmable Logic Controllers (PLCs), and specialized industrial protocols, aiming for physical destruction or disruption. The technical complexity required for such attacks is immense, typically involving reconnaissance, vulnerability exploitation (often zero-days), and precision manipulation of industrial processes to achieve specific physical outcomes.
In contrast, the panel emphasized the growing prevalence of low-profile opportunistic attacks. These are less about targeted destruction and more about widespread disruption or financial gain. Ransomware is the prime example, often entering OT networks via IT-OT convergence points or less secure administrative networks, then propagating to impact production systems by encrypting Human-Machine Interfaces (HMIs), engineering workstations, or even directly halting processes. The Oldsmar water treatment plant incident was cited as a cyber-physical attack, but one that was "opportunistic" (02:00-04:00). Technically, this involved an attacker gaining remote access to a supervisory control system (likely via a compromised remote access tool or weak credentials) and attempting to alter chemical levels. While the potential for harm was high, the attack vector and methodology were not indicative of a highly sophisticated, bespoke nation-state operation but rather exploited common vulnerabilities. The technical implication is that many OT environments are vulnerable to less advanced, more generalized cyber threats due to poor segmentation, weak access controls, and unpatched systems.
A significant technical point raised was the issue of secure industrial protocols. Zach Tudor specifically mentioned Modbus Secure (or Secure Modbus) and secure options for Ethernet IP (04:00, 08:00).
- Modbus is one of the oldest and most widely used serial communication protocols in industrial automation. Its original design lacked inherent security features like authentication or encryption. Modbus Secure implementations address this by encapsulating Modbus traffic within a secure transport layer, most commonly Transport Layer Security (TLS). This means that communication between Modbus devices (e.g., PLCs, RTUs, SCADA systems) is encrypted, authenticated using TLS certificates, and integrity-protected, preventing eavesdropping, tampering, and unauthorized command injection.
- Ethernet IP is another widely adopted industrial protocol, extending standard Ethernet to control applications. Similar to Modbus, its original specification did not prioritize security. Secure options for Ethernet IP involve implementing security measures at various layers, often incorporating TLS or other cryptographic mechanisms for authentication and encryption of control plane and data plane communications. This ensures that commands sent over Ethernet IP are legitimate and have not been altered in transit.
The technical challenge here isn't the absence of these secure protocols, but the low pickup or adoption rate by asset owners. This suggests a failure to migrate from legacy, insecure protocol implementations to their secure counterparts, leaving industrial networks exposed to basic network attacks.
Finally, the panel advocated for a shift in focus from merely addressing vulnerabilities to prioritizing security features within products and systems (06:00). This represents a move towards Security by Design principles. Instead of patching vulnerabilities reactively, the emphasis is on building products with inherent security capabilities from the ground up. This includes features such as:
- Secure boot mechanisms to ensure firmware integrity.
- Hardware Root of Trust (HRoT) for cryptographic operations and identity.
- Robust authentication and authorization mechanisms for device access and control.
- Encrypted storage for sensitive configuration data.
- Secure update mechanisms to prevent tampering during firmware upgrades.
- Granular access controls at the device and application level.
- Tamper detection capabilities.
The call for procurement to "just ask for security level two" (06:00) implies a desire for a standardized, higher baseline of these integrated security features, likely referencing established frameworks like IEC 62443 which defines security levels (SL) for industrial automation and control systems. Achieving a higher security level means that products would intrinsically offer greater resilience against a broader range of threats, reducing reliance on external security overlays or reactive vulnerability management. The technical implication is a push for vendors to design and certify products to higher security standards, making them more defensible out-of-the-box.
Demo / Proof of Concept
▶ Watch: Megan Samford: Prioritize security features over detection (6:00)
This session was a closing panel discussion and did not feature any live demonstrations or proof-of-concept (PoC) exploits. The panelists engaged in a high-level strategic discussion about the state and future direction of ICS security.
Defensive Implications
▶ Watch: Ralph Langner: Underfunding forces prioritization in OT security (7:20)
The insights from the S4 Closing Panel carry significant defensive implications for organizations operating in the OT/ICS space, urging a re-evaluation of current strategies and investments:
- Realign Threat Prioritization: Defenders must shift their focus from purely theoretical, catastrophic cyber-physical attacks to the more immediate and pervasive threat of low-profile opportunistic attacks like ransomware and supply chain disruptions. This means prioritizing defenses against common attack vectors such as phishing, unpatched systems, weak credentials, and insecure remote access, which are frequently exploited in opportunistic campaigns. Resources should be allocated to address "low-hanging fruit" vulnerabilities that are most likely to be exploited (04:00).
- Embrace Risk Management as a Core Competency: Cyber professionals in OT need to function as risk managers, not just incident responders or patch administrators. This entails actively identifying, assessing, and prioritizing risks based on their likelihood and impact, then making strategic investment decisions that genuinely reduce vulnerability or enhance resilience (04:00, 08:00). This means moving beyond simply "doing what they like" to focusing on what provides the most security uplift for the available budget.
- Drive Adoption of Secure Products and Protocols: The low uptake of secure industrial protocols like Modbus Secure and secure Ethernet IP is a critical vulnerability. Defenders must actively seek out and implement these secure alternatives where available. This might involve upgrading legacy equipment, configuring existing devices for secure communication, or demanding secure options from vendors during procurement. The onus is on asset owners to create market demand for these features.
- Demand Built-in Security Features, Not Just Vulnerability Management: Rather than an exclusive focus on reactive vulnerability patching and threat intelligence, defenders should prioritize the procurement of products and systems with robust, built-in security features (06:00). This requires a proactive approach, integrating security requirements into the entire lifecycle, from design to deployment. Procurement departments need to be educated and empowered to articulate clear, concise security requirements, potentially using simplified asks like "security level two" to drive vendors towards higher security baselines.
- Strategic Budget Allocation and Prioritization: Acknowledge the reality of underfunding in OT security (08:00). This necessitates rigorous prioritization. Organizations cannot afford to "do both" everything and must make tough choices about where to invest their limited resources for maximum impact. This might mean focusing on fundamental controls like network segmentation, robust access controls, and secure configurations before investing heavily in advanced detection technologies that may not address the most likely threats.
- Move Beyond Detection-Centric Security: While detection and threat intelligence are important components of a comprehensive security program, they should not overshadow foundational prevention and resilience efforts. Defenders should ensure a balanced approach, investing in hardening systems, implementing secure architectures, and building resilient recovery capabilities, in addition to monitoring for threats.
- Educate and Empower Procurement: To foster a market for inherently secure products, security teams must collaborate closely with procurement. Providing clear, simplified security requirements that can be easily integrated into purchasing processes will empower procurement teams to select more secure options and send a stronger signal to vendors. This could involve developing internal "security level" definitions or leveraging existing industry standards.
By adopting these defensive implications, organizations can move towards a more realistic, actionable, and effective OT security posture that addresses the most probable threats within the constraints of real-world budgets and operational environments.
Key Takeaways
- The prevailing ICS security narrative needs a significant shift from theoretical, catastrophic cyber-physical attacks to focusing on the more common and actionable threat of opportunistic, low-profile incidents like ransomware and specific industrial compromises.
- Underfunding is a critical constraint in OT security, necessitating aggressive and realistic prioritization of defensive investments, moving beyond the often-unfeasible "we have to do both" mentality.
- Despite their availability, the adoption rates of secure industrial protocols such as Modbus Secure (with TLS certificates) and secure Ethernet IP remain critically low, leaving many OT environments exposed to basic network attacks.
- The industry and government must shift focus from an overemphasis on detection and threat intelligence towards prioritizing and demanding robust security features built into products and systems from the ground up, promoting a Security by Design approach.
- Procurement departments require clearer, simpler ways to articulate security requirements (e.g., "security level two") to effectively drive market demand for inherently more secure OT products.
- Cyber professionals in the OT space must embrace a risk management mindset, prioritizing security efforts that genuinely reduce vulnerability or increase resilience, rather than simply pursuing activities they prefer or that align with outdated narratives.
About the Speaker(s)
- Zach Tudor: Served as the moderator for the S4 Closing Panel. While specific titles or affiliations were not detailed in the transcript, his role in guiding the discussion and posing pointed questions indicates a deep expertise and leadership within the ICS security community.
- Megan Samford: A panelist who contributed significantly to the discussion, particularly in highlighting the imbalance between the focus on detection/threat intelligence versus intrinsic product security features. Her insights suggest a strong background in vendor security, product development, and advocating for a more proactive security stance.
- Ralph Langner: A highly respected and long-standing expert in ICS security, known for his seminal work on the Stuxnet analysis and his past warnings about high-consequence cyber-physical attacks. During the panel, he critically reflected on these past narratives and advocated for a shift towards addressing more prevalent opportunistic threats. The transcript notes his current affiliation with Schneider Electric (04:00), indicating his continued involvement in industrial cybersecurity from a vendor perspective. He was welcomed back to the panel after missing the previous year, underscoring his significant presence and influence at S4.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This S4 Closing Panel is a rare and essential piece of honest discourse in the ICS security community. It brutally dismantles the prevailing, often overblown, narratives around cyber-physical attacks, calling out the community's collective 'bullshit' and its inability to prioritize. Led by a legend like Ralph Langner, who even critiques his own past contributions, the panel delivers a direct, actionable call to arms: focus on real, opportunistic threats, demand inherently secure products, and make hard choices with limited budgets. This isn't just a discussion; it's a much-needed strategic intervention that should redefine how we approach OT security.
Heather Calloway (CISO) — STRONG ACCEPT
The S4 Closing Panel offers a sharp, necessary critique of the ICS security community's misaligned priorities, accurately diagnosing the disconnect between prevalent "cyber war" narratives and the reality of opportunistic threats. It directly addresses the systemic underfunding and prioritization paralysis that plague OT security programs, compelling leaders to re-evaluate how resources are allocated and how security is demanded in procurement. This discussion is highly relevant for any CISO grappling with real-world risk, accountability, and the imperative to build resilient operational environments.