10
Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of the Future Conference October 23, 2017

Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

  • Upload
    others

  • View
    5

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

Cybersecurity Strategy – Active Defense

Presented by: Jeff PackCIGRE Grid of the Future ConferenceOctober 23, 2017

Page 2: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

2

Agenda

History

Threats Change

Strategic Shift

Situational Awareness

Action Plan

Summary

Page 3: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

3

History – Risk Management

NIST Special Publication 800-39

How long does this cycle take?We need to account for the modern threat model.

Page 4: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

4

Threats Change

Dragos, Inc.

Symantec CorporationICS is becoming a major targetWe need to spend resources on the right things

Page 5: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

5

ICS• Specialized devices Powerful general hardware• Digital Relay Multi-function Protective Devices• Serial Ethernet

Strategy Shift – Active Defense

Page 6: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

6

World defined by software• Dedicated devices Virtualization• Analog CT/PT Digital merging

units

Strategy Shift – Active Defense

Page 7: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

7

Cybersecurity controls evolve• Network Monitoring Self-

defending IED and Anomaly Detection

• Authentication IED challenge-response

Strategy Shift – Active Defense

Page 8: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

8

Situational Awareness

Operational devices and data• Point boundaries• Physical characteristics

Analytics• Leverage existing analytical

tools with virtual processing and storage

• Add NSM and SIEM enhancements

• Explore predictive analytics

Courtesy BARCO

Page 9: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

9

Update threat assessment• E-ISAC, othersUpdate risk assessment• Consider dynamic change and third-party reviewPrioritize funding and resourcesCommunicate direction to staff• Utilize change management conceptsReview guidance documents

Action Plan

Page 10: Cybersecurity Strategy – Active Defensecigre-usnc.org/wp...Active-Defense_Session_3A_GOTF.pdf · Cybersecurity Strategy – Active Defense Presented by: Jeff Pack CIGRE Grid of

10

Summary

Dynamic threats - need to adapt quicklyActive Defense• Use intelligent edge devices to protect themselvesSituational Awareness• Include operational data and consider analyticsDevelop an action plan to adopt active defense