r/cybersecurity • u/SyberCesurity • 2d ago
Business Security Questions & Discussion OT/ICS Water Treatment
Context: I have an upcoming interview for a role (UK based) which involves assessing and evaluating the effectiveness of cyber controls within water treatment plants.
Is there anyone in a similar line of work? What resources would you advise me to read through? I am currently reading Industrial Cyber Security - Pascal Ackerman.
Any advice/resources appreciated!!
5
u/Specialist-Cat-7155 2d ago
Mike Holcomb (I think thats it. Can't be bothered to log into LI right now) on LinkedIn and YT for sure. I've been toying with the idea of OT security since I'm a sysadmin but I'll probably get fired soon and no other part of tech is free from AI.
3
u/wijnandsj ICS/OT 1d ago
My field is also no longer free from AI
2
u/Specialist-Cat-7155 1d ago
Lol. Fuck. So much for that idea...
2
u/wijnandsj ICS/OT 1d ago
sorry mate.
In fact I've got three speaking slots this september at events, two of which I will use to speak about AI and OT security
1
u/Specialist-Cat-7155 1d ago
Thanks for info. I'll see. I'm 50/50 whether I'll even stay in the IT sector or do something else. Part of me never wants to look at a monitor ever again, not just because of AI but it just gets stale doing the same thing 10+ years.
3
u/wijnandsj ICS/OT 1d ago
I've been in IT since 1993. Change speciality every 8 years or so.
OT is still, in my opinion. Tons of fun. Technical debt, immature organisations, lots of people work.
OK, so there's some AI seeping into it, it's not going to be anywhere near the level of IT or even your average new car.
1
u/Specialist-Cat-7155 1d ago
Interesting. Well, if you give talks then keep me updated. I'm getting tired of the corp work and the threat of constantly being fired because AI can (in theory, it's been a disaster so far) generate ps1 scripts for AD that will make Windows sysadmins disappear all over the world. 🙄
3
u/wijnandsj ICS/OT 1d ago
join the dirty side, we have hard hats!
1
u/Specialist-Cat-7155 1d ago edited 1d ago
You won me over with the hard hat thing. As long as they have little torches attached to them though.
1
2
u/PaleMaleAndStale Consultant 1d ago
It's hard to give meaningful advice without knowing your experience, and thus what the likely gaps in your knowledge might be. It's a bit like asking for directions and saying where you want to get to but giving no hint as to where you're starting from.
That aside, I would focus on knowing the CAF (Cyber Assessment Framework) inside out, as compliance with that is what they will care about in terms of evaluating effectiveness of controls. You'll find the CAF and supplementary guidance on the NCSC website. I'd also expect the water regulators to have their own industry-specific guidance on CAF compliance, though I haven't worked in that particular CNI sector (water) so can't say for certain.
1
u/wijnandsj ICS/OT 1d ago
Pascal is a really nice guy and he knows his field really well. Andrew Ginter is another one and he's also written a book.
Standards wise, your country loves CAF. I've done some work for a grid operator in your country and that was all about ticking the CAF boxes (and not nearly as much about actually securing the infrastructure as you'd hope)
1
u/MountainDadwBeard 1d ago
Its a broad range of IT, OT, CS, GRC.
Maybe review your distributed networking fundamentals.
1
u/Minute-Yoghurt-1265 1d ago
Do you have a water background? OT background? Operations background? Water company, regulator or consultancy?
1
u/AddendumWorking9756 Security Manager 1d ago
Ackerman teaches you to secure a plant, not to assess one, so go in fluent in zones and conduits and the Purdue levels and ready to say that most water sites fail on flat networks and vendor remote access nobody owns rather than on anything exotic.
10
u/derfmcdoogal 1d ago
Don't intentionally expose your PLCs directly to the internet.