Inductive Automation’s Jason Waits on Building Scalable Security Programs Through Automation
May 28, 2024
auto_awesome
Jason Waits, CISO at Inductive Automation, discusses the role of SCADA systems in security, challenges in building scalable security programs with automation, and the impact of IT-OT convergence. He emphasizes the importance of automation in security operations, ML, and AI for efficient data analysis to enhance detection capabilities.
In SCADA systems, prioritizing reliability and uptime over security is crucial, especially in industries like pharma and data centers.
Automation in security programs enhances scalability and efficiency, focusing on detection engineering, automating responses, and proactive measures for robust operations.
Deep dives
Importance of Uptime and Reliability in ICS and SCADA
Uptime and resilience are vital in industrial control systems (ICS) and supervisory control and data acquisition (SCADA) environments, surpassing even security concerns. These critical systems, prevalent in industries like pharma, nuclear, water, and data centers, demand uninterrupted operation due to their indispensable nature. This emphasis on reliability highlights the indispensability of such systems and the necessity to prioritize continuous functionality above all else.
Transitioning to OT Environment and Automation at Scale
Adapting to operational technology (OT) environments in a software company like inductive automation involves unique challenges, such as a wider technology footprint and legacy system integration. To handle this complexity, automation is the key focus, ensuring that all processes are streamlined and scalable for future growth. By automating security measures and pre-hardening systems, the organization can efficiently manage its diverse technological landscape.
Enhancing Security Operations Through Automation and Tight Integration
Building a security program centered on automation and response integration optimizes efficiency while maintaining high security standards. The emphasis on automation extends to detection engineering, response automation, and operational alerts, streamlining security operations. By establishing a strong foundation focused on automation and proactive response measures, inductive automation enhances its ability to scale security operations effectively.
In our latest episode of Detection at Scale, Jason Waits, CISO at Inductive Automation, shares insights learned in his journey from network administration to cybersecurity and the importance of SCADA systems.
He dives into the value of automation, ML, and AI in security operations, highlighting the need for asking the right questions for efficient data analysis. Jason also discusses building a security team with a focus on detection and response, leveraging automation for faster investigations.
Topics discussed:
The role of SCADA systems in various industries and the importance of security in OT environments.
The challenges and strategies in building a security program for scale, focusing on automation and infrastructure as code.
The impact of IT-OT convergence on security issues and the need for enhanced controls and monitoring in interconnected systems.
Embracing automation in security operations, including detection engineering and automating response actions for efficiency and scalability.
Utilizing enrichment techniques for contextual data analysis and the significance of data sources for effective security investigations.
The use of ML and AI in security operations, particularly in natural language querying and data analysis for actionable insights.
Jason's advice on building a successful security team, emphasizing automation, staying informed on industry trends, and fostering collaboration with engineering teams.