Adapting Zones And Conduits – A Transformation Story

Dennis Hackney

S4x24 - ICS Security Conference · Day 3 · Stage 2

Overview

Dennis Hackney’s presentation at S4, "Adapting Zones And Conduits – A Transformation Story," delves into the complex, yet critical, endeavor of implementing and evolving foundational cybersecurity principles within vast, highly optimized industrial control system (ICS) environments. Hackney, speaking from his experience at Chevron, outlines the challenges and strategic approaches required to secure operational technology (OT) across a diverse range of sectors, including upstream, downstream, midstream, shipping, and point-of-sale operations. The talk emphasizes that while concepts like zones and conduits may seem "older," their effective application remains paramount in the face of rapidly changing threat landscapes and increasing connectivity.

Watch on YouTube

Visual summary for Adapting Zones And Conduits – A Transformation Story by Dennis Hackney
Visual summary for Adapting Zones And Conduits – A Transformation Story by Dennis Hackney

Key moments

  1. 0:00 Introduction and the broad scope of the challenge
  2. 2:00 Technology concerns and learning from past events
  3. 3:45 Using MITRE ATT&CK for threat mapping
  4. 4:20 Overcoming resistance: The 'Why change?' argument
  5. 5:00 Most exploited CVEs: The critical need for change
  6. 6:00 Critical data required for effective network segmentation
  7. 7:00 Fictional model example: Understanding system communications
  8. 7:50 Analyzing configurations, policies, and process hazard analysis

Adapting Zones And Conduits – A Transformation Story

Speakers: Dennis Hackney, Chevron

Conference: S4

YouTube: https://www.youtube.com/watch?v=tLw-F-b7cdo

Overview

Dennis Hackney’s presentation at S4, "Adapting Zones And Conduits – A Transformation Story," delves into the complex, yet critical, endeavor of implementing and evolving foundational cybersecurity principles within vast, highly optimized industrial control system (ICS) environments. Hackney, speaking from his experience at Chevron, outlines the challenges and strategic approaches required to secure operational technology (OT) across a diverse range of sectors, including upstream, downstream, midstream, shipping, and point-of-sale operations. The talk emphasizes that while concepts like zones and conduits may seem "older," their effective application remains paramount in the face of rapidly changing threat landscapes and increasing connectivity.

The presentation is not merely a theoretical discussion but a practical account of navigating the realities of securing systems that have evolved over decades, prioritizing operational efficiency and safety above all else. Hackney highlights the delicate balance of introducing cybersecurity measures without disrupting critical processes, equipment, or the "amazing people" who operate them. The core message underscores the necessity of a holistic approach that integrates security considerations deeply into operational workflows, leveraging existing safety paradigms, and fostering cross-functional collaboration between cybersecurity, operations, and safety engineering teams.

This talk is particularly significant for owner-operators and cybersecurity professionals grappling with the practical implementation of robust security architectures in complex OT environments. It offers valuable insights into overcoming common organizational hurdles, advocating for an attacker-centric perspective, and demonstrating how a well-structured approach to zones and conduits can effectively break the kill chain of a cyber attack, thereby protecting not just data, but critical physical processes and human safety.

Background

▶ Watch: Introduction and the broad scope of the challenge (0:00)

The industrial landscape Hackney describes is characterized by systems optimized over a century, where processes, equipment, and human operators function with remarkable efficiency. In these environments, technology was historically introduced as a means to enhance existing operations, not as a primary focus for security. This has led to a scenario where critical infrastructure relies on a blend of legacy and increasingly modern, connected technologies, often with an inherent vulnerability to evolving cyber threats. The challenge is compounded by the rapid introduction of wireless and ubiquitous connectivity, making traditional perimeter-based security models less effective.

Hackney emphasizes the critical importance of learning from past events and mistakes, citing instances where "the writing was on the wall," with government agencies providing warnings that were nonetheless insufficient to prevent some organizations from being caught off guard. A major contributing factor to this vulnerability is the persistent exploitation of known weaknesses. Hackney points out that despite common beliefs that existing firewalls or identity and access control mechanisms are sufficient, numerous Common Vulnerabilities and Exposures (CVEs), particularly those enabling remote code execution, continue to be released and exploited in these very devices. This reality forces a re-evaluation of security postures, moving beyond a superficial understanding of controls.

To address this complex problem, Hackney advocates for drawing on established frameworks. He specifically highlights the MITRE ATT&CK for ICS reference as a crucial tool for understanding the relationships from threat actors to mitigations and detection mechanisms. This framework provides a structured way to analyze potential attack paths and inform defensive strategies. The underlying problem, however, is often a lack of detailed understanding of network inventories, data flows, and the technical and functional requirements of the systems, which are prerequisites for effectively defining security zones and conduits. Without this foundational understanding, attempts to implement comprehensive security standards like IEC 62443 can quickly become overwhelming and lose focus.

Key Findings

▶ Watch: Using MITRE ATT&CK for threat mapping (3:45)

Dennis Hackney’s presentation reveals several key findings critical for securing complex OT environments. Firstly, the successful implementation of foundational security concepts like zones and conduits is not purely a technical endeavor but an organizational transformation. Hackney stresses that the effort "doesn't really necessarily rely on the on the security people, on the technical security people," but rather heavily depends on inputs from operations engineers and safety engineers. These stakeholders possess an intimate understanding of how systems function, how much they produce, and the critical processes that must be protected, which he estimates constitutes "probably 80% of what we're actually trying to protect." Engaging these teams is paramount, as they hold the "millions of lines of studies between causes and safeguards" that provide invaluable context for cyber risk.

Secondly, effective inventory management is identified as a non-negotiable prerequisite. Hackney argues that inventories must go beyond simple asset lists; they must be capable of mapping to topologies and providing an architectural perspective. This allows security professionals to understand interconnections, data flows, and where gaps exist, informing the definition of security requirements around devices. He notes that while technologies exist to automate inventory collection, the key is to first define how the inventory will be used.

Thirdly, linking cybersecurity efforts to existing process hazard analysis (PHA) or hazard and operability studies (HAZOP) is a powerful and often overlooked strategy. These safety-focused studies provide detailed piping and instrumentation drawings and step-by-step process descriptions, which are invaluable for identifying actual impacts and potential points where a cyber impact could occur. This integration bridges the gap between safety and security, leveraging established, highly regulated processes to inform cyber risk assessments.

Finally, Hackney emphasizes the utility of an attacker-centric approach using frameworks like MITRE ATT&CK for ICS. When faced with the overwhelming scope of securing an entire, well-orchestrated environment or the comprehensive nature of standards like IEC 62443, framing the problem from an attacker's perspective helps to "decide what I need to do to figure out what the attacker is going to actually look at and how they're going to get into the environment." This approach helps prioritize efforts and define the scope of zone and conduit implementation more effectively, ultimately aiming to "break the kill chain of a cyber attack."

Technical Deep Dive

▶ Watch: Most exploited CVEs: The critical need for change (5:00)

The technical core of Hackney's talk revolves around the practical application of zones and conduits within operational technology (OT) environments, extending beyond a simplistic network segmentation model. He defines zones not merely as "a bunch of boxes" on a diagram, but as security boundaries where everything within a given zone inherits the same security requirements. This hierarchical approach involves assigning security levels (e.g., levels 1 through 4, with 4 being the highest) to zones. When connections occur between zones of differing security levels, the conduit (the connection itself) must enforce protection mechanisms commensurate with the highest security level involved in that communication.

Hackney implicitly references the Purdue Model by noting that elements like Distributed Control Systems (DCS) represent "pretty much the bottom of our technology stack." However, he highlights that even at these foundational levels, understanding communication patterns—how devices are configured, the policies governing their interactions—is crucial, often requiring more than just active or passive network scanning; it necessitates examining existing configurations and policies. This deep understanding of communication is a prerequisite for accurately defining security boundaries and the controls necessary within conduits.

A significant driver for this renewed focus on segmentation is the pervasive threat of exploitable CVEs, particularly those granting remote code execution. Hackney points out that even seemingly secure identity and access control devices are susceptible, enabling an attacker to "do whatever you want to that device." This vulnerability necessitates a robust segmentation strategy that limits the blast radius of such compromises.

To achieve this, Hackney outlines a procedural and technical methodology:

  1. Comprehensive Inventories: These are not just lists but dynamic repositories that "map to your topologies" and provide an "architectural perspective." The inventory must be capable of providing actionable information about interconnections, allowing security teams to understand the functional dependencies and potential attack paths. He acknowledges the existence of technologies that automate inventory collection, but stresses the importance of defining how the inventory will be used before its collection.
  2. Data Flow Analysis: Understanding the intricate communication patterns between devices is critical. This involves examining configurations and policies to determine legitimate communication paths, informing the design of conduits.
  3. Integration with Safety Studies: Leveraging Process Hazard Analysis (PHA) or Hazard and Operability Studies (HAZOP) is a unique technical insight. These studies, which include detailed piping and instrumentation drawings (P&IDs), provide a rich source of information about process steps and potential failure points. By mapping cyber threats to these existing safety analyses, organizations can identify where cyber impacts could occur and understand their true operational consequences.
  4. Attacker-Centric Design: Employing MITRE ATT&CK for ICS helps in scoping the effort. Instead of attempting a monolithic security overhaul (which can be paralyzing, as with a direct deep dive into the entirety of IEC 62443), an attacker's perspective allows teams to identify the most probable and impactful attack vectors, thereby prioritizing where zones and conduits are most critically needed to "break that kill chain."

Hackney's approach is pragmatic, recognizing that while raising the security level across an entire environment might be the most secure option, it is often not the most cost-effective. Therefore, the strategy involves planning for future enhancements while making informed decisions about adding specific security devices to environments with differing security levels, always considering not just hardware costs but also support, installation, integration, and maintenance cycles.

Demo / Proof of Concept

▶ Watch: Critical data required for effective network segmentation (6:00)

The talk by Dennis Hackney did not include a live demonstration or a proof of concept. Instead, it focused on a conceptual framework, strategic considerations, and lessons learned from Chevron's ongoing journey in adapting zones and conduits within their extensive industrial environments. The presentation utilized diagrams and examples to illustrate the principles discussed, rather than showcasing a working system or attack scenario.

Defensive Implications

▶ Watch: Analyzing configurations, policies, and process hazard analysis (7:50)

Hackney's presentation offers several crucial defensive implications for organizations operating in complex OT environments:

  1. Reimagine Inventory Management: Defenders must move beyond simple asset lists. Inventories need to be architecturally driven, dynamically mapping to network topologies and detailing data flows. This allows for a granular understanding of interconnections, dependencies, and potential attack vectors. Prioritizing how the inventory will be used (e.g., for segmentation design, vulnerability management, incident response) before collection is key, potentially leveraging automation tools for efficiency.
  2. Integrate Cybersecurity with Operations and Safety: This is perhaps the most significant defensive implication. Cybersecurity cannot operate in a silo. Actively engaging operations engineers and safety engineers is non-negotiable. Their deep understanding of processes, equipment, and existing safety studies (like PHA and HAZOP) provides invaluable context for identifying critical assets, understanding potential cyber-physical impacts, and prioritizing defensive efforts. Leveraging existing safety documentation, such as piping and instrumentation drawings (P&IDs), directly informs the cyber risk assessment process.
  3. Adopt an Attacker-Centric Security Posture: Utilizing frameworks like MITRE ATT&CK for ICS is vital for scoping and prioritizing security initiatives. By understanding common threat actor tactics, techniques, and procedures (TTPs), defenders can focus on implementing controls that effectively "break the kill chain" of a cyber attack, rather than attempting to secure every possible vector simultaneously, which can be an overwhelming and inefficient approach.
  4. Implement Adaptive Zones and Conduits: The traditional concept of zones and conduits remains fundamental but requires adaptation for modern, highly connected OT environments. Defenders should meticulously define security boundaries and assign security levels (e.g., 1-4) to zones, ensuring that all assets within a zone inherit consistent security requirements. Crucially, conduits connecting zones of different security levels must enforce protection mechanisms aligned with the highest security level involved, rigorously controlling data flows and access.
  5. Challenge Assumptions about Existing Controls: The prevalence of exploitable CVEs, particularly those allowing remote code execution in devices like firewalls and identity/access controls, means defenders cannot assume that existing security infrastructure is inherently robust. Continuous vulnerability management, patching, and rigorous configuration reviews are essential to mitigate these pervasive threats.
  6. Plan for Ubiquitous Connectivity: With the rise of ubiquitous connectivity and the Internet of Things (IoT) in industrial settings, defenders must acknowledge that network boundaries are increasingly permeable and difficult to measure. Security strategies must evolve to account for this constant change, incorporating mechanisms to evaluate and secure new connections as they are introduced into the environment.
  7. Consider Total Cost of Ownership: When implementing new security devices or upgrading existing ones, defenders must evaluate not just hardware costs but also the full spectrum of expenses, including support, installation, integration, and the impact on maintenance cycles and turnaround schedules. This holistic view ensures that security investments are sustainable and align with operational realities.

By embracing these defensive implications, organizations can build more resilient and adaptable cybersecurity postures that effectively protect critical industrial processes from evolving threats.

Key Takeaways

  • Zones and conduits remain foundational: Despite being "older" concepts, their effective implementation is critical for segmenting and securing complex OT environments, especially against threats leveraging ubiquitous connectivity.
  • Collaboration is paramount: Successful OT cybersecurity hinges on deep engagement with operations engineers and safety engineers. Their process knowledge and existing safety studies (PHA, HAZOP) are indispensable for identifying cyber-physical impacts and prioritizing protective measures.
  • Inventories must be architectural: Beyond simple asset lists, comprehensive inventories must map to network topologies and data flows, providing an architectural understanding necessary for defining robust security boundaries.
  • Leverage an attacker mindset: Using frameworks like MITRE ATT&CK for ICS helps to scope complex security initiatives by focusing on how adversaries would exploit systems, enabling defenders to strategically "break the kill chain."
  • Security levels drive protection: Assigning hierarchical security levels to zones dictates the inherited security requirements within those zones and the necessary protection mechanisms for conduits connecting different security levels.
  • Ubiquitous connectivity demands continuous adaptation: The ever-increasing and often unmeasurable connectivity in OT environments necessitates an evolving security strategy that continually evaluates and secures new connections and addresses the limitations of traditional perimeter defenses.

About the Speaker(s)

Dennis Hackney is a cybersecurity professional who, at the time of this S4 conference talk, had been with Chevron for "a little bit over a year." In his role at Chevron, he was tasked with leading efforts related to zones and conduits within their extensive operational technology (OT) environments, spanning upstream, downstream, midstream, shipping, and point-of-sale operations. Hackney brings a background in compliance and defense, which informs his pragmatic approach to securing industrial systems. His experience as an "owner-operator" provides him with a deep understanding of the challenges involved in balancing security with the imperative of maintaining highly optimized and critical industrial processes.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Hackney's talk from Chevron provides a brutally honest and deeply practical account of implementing foundational cybersecurity concepts like zones and conduits within a sprawling, highly optimized industrial environment. While the concepts themselves are not new, the talk excels in detailing the organizational transformation required, the critical integration with operations and safety teams, and a pragmatic attacker-centric approach to scope and prioritize efforts. This isn't theoretical fluff; it's a valuable case study for owner-operators grappling with the immense challenge of securing critical OT.

Heather Calloway (CISO) — STRONG ACCEPT

Hackney’s talk delivers a clear, pragmatic account of securing critical OT environments, moving beyond purely technical solutions to address the organizational and governance challenges inherent in adapting foundational security concepts like zones and conduits. His emphasis on integrating cybersecurity with existing operational and safety engineering processes, leveraging frameworks like MITRE ATT&CK for ICS, and building architectural inventories provides a credible roadmap for owner-operators grappling with systemic risk and accountability in complex industrial settings. This is a strong contribution to bridging the gap between technical defense and executive action.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference