

Hack the Plant
Bryson Bort
Electricity. Finance. Transportation. Our water supply. In Hack the Plant, podcast host Bryson Bort looks for answers to the question: Does connecting these systems, and others, to the internet leaves us more vulnerable to attacks by our enemies? We often take these critical infrastructure systems for granted, but they’re all becoming increasingly dependent on the internet to function. From the ransomware threats of Colonial Pipeline to the failure of the Texas power grid, it is clear our interconnectivity is also a significant source of risk. Hack the Plant walks through the world of hackers working on the front lines of cyber security and public safety to protect the systems you rely upon every day.
Hack the Plant is brought to you by ICS Village and the Institute for Security and Technology.
ICS Village is a nonprofit that equips industry experts and policymakers with the tools to better defend our critical infrastructure. We educate people on critical infrastructure security with hands-on examples, not just nerd stuff. Catch us at an event near you! www.icsvillage.com.
The Institute for Security and Technology is a nonprofit think tank with the mission to bridge gaps between technology and policy leaders to help solve these emerging security problems together. Learn more at securityandtechnology.org.
Hack the Plant is brought to you by ICS Village and the Institute for Security and Technology.
ICS Village is a nonprofit that equips industry experts and policymakers with the tools to better defend our critical infrastructure. We educate people on critical infrastructure security with hands-on examples, not just nerd stuff. Catch us at an event near you! www.icsvillage.com.
The Institute for Security and Technology is a nonprofit think tank with the mission to bridge gaps between technology and policy leaders to help solve these emerging security problems together. Learn more at securityandtechnology.org.
Episodes
Mentioned books

Oct 4, 2021 • 52min
Innovation in Critical Infrastructure
“We had to go out and talk to experts and just have the conversations and then be brutally honest about what those people were telling us about the problem. In many cases, we didn't even tell them what we were thinking about doing. We would call them up and say, "How are you securing your industrial control systems today?" and just listen.” - Joshua Steinman“We really learned to go in, us. Instead of imposing what we thought the problem would be for other asset owners, really let them tell us what their problems were. So that was probably one of the biggest takeaways during the customer discovery. And it was also great to hear that a lot of people had, I would say, some similar problems across different industry verticals. And everyone knew that there needed to be some change and wanted to see change. So that was also very refreshing for me.” -Brandon ParkWhat are the biggest challenges in critical infrastructure cybersecurity? In this episode of Hack the Plant, we hear from two entrepreneurs, Joshua Steinman & Brandon Park, who just did a 7 month long customer discovery process trying to understand where the key problems are now to keep our ICS systems safe from cyber threats.Joshua Steinman is a former naval officer, ICS cybersecurity startup founder, and cybersecurity policy senior director during the Trump administration.Brandon Park formerly worked at Amazon as a Security Engineer focused on securing ICS at scale. Prior to Amazon, he supported Department of Defense and Department of Energy projects.Their conversations spanned from ICS cybersecurity experts to operators to executives at companies with large footprints in the space - and led to some surprising and unexpected insights that have led to the launch of something called Galvanick.How can this make our ICS more safe, reliable, or cyber-resilient? Join us to learn more.

Sep 6, 2021 • 29min
AI and Critical Infrastructure
When will hard infrastructure have machine learning capabilities? It might be sooner than you think. Ariel Stern, formerly an engineer in the Israeli Ministry of Defense and a civil infrastructure project manager, currently CEO of Ayyeka, which offers remote monitoring for industrial Internet of Things (IoT) systems. Ariel has a forward-looking approach to creating resilience in critical infrastructure…anticipating that we are entering a new era for critical infrastructure….from IoT data creation, management, and analysis to advanced Artificial Intelligence pattern recognition and prediction.Is this science fiction? Join us to learn how the technology that can create resilient infrastructure for tomorrow is here - today.

Jul 27, 2021 • 39min
Biden Admin's Cybersecurity Executive Order
On May 12, 2021, the Biden Administration issued an Executive Order “On Improving the Nation’s Cybersecurity.” This came in the wake of ransomware attacks drawing national attention: Solar Winds, Colonial Pipeline, and more.We take a deep dive into the Executive Order, and what it means for public and private efforts to keep our critical infrastructure safe with two attorneys and cybersecurity experts.Megan Brown is a Partner at Wiley Rein. She has deep expertise in cybersecurity and data privacy issues, working for national and global companies on cutting edge compliance and risk management. Liz Wharton the Chief of Staff at SCYTHE where she serves as a strategic advisor for the CEO and leadership team, building and maintaining cross-department relationships, crafting external initiatives, and driving day-to-day projects and tasks. Previously she was the Senior Assistant City Attorney with the City of Atlanta, where she served on the immediate incident response team for the City of Atlanta’s ransomware incident.

Jun 28, 2021 • 32min
ERCOT and the Texas Power Outage
In February, severe winter storms and an electricity generation failure left almost 5 million people in Texas without power, leading to hundreds of deaths, and a shortage of heat, food and water. The Electric Reliability Council of Texas (ERCOT) manages the flow of electric power to more than 26 million Texas customers. How did the massive power failure happen? What does this power outage suggest about the resilience of our critical infrastructure?Beth Garza, former director of ERCOT and senior fellow at the R Street Institute, answers these questions and more. Over the course of her 35-year career in the electric utility industry, Beth Garza has held a variety of leadership roles in generation and transmission planning, system operations, regulatory affairs and market design for both regulated and competitive entities. Further information:Watch: Shedding light on the legislative response to the Texas blackouts. Testimony: The House Committee on Science, Space and Technology hearing on "Lessons learned from the Texas blackouts: Research needs for a secure and resilient grid."

May 31, 2021 • 45min
Department of Defense Policy and ICS Security
Daryl Haegley is the Director of Cyberspace Mission Assurance and Deterrence at the Department of Defense. Daryl oversees cybersecurity efforts to secure control systems (ICS) and operational technology (OT), and focuses on bringing awareness to the ever-increasing cyber threats. He has 30 years of military, civilian and commercial consulting experience. He has successfully advocated to change laws, DoD policy and standards, and academic curricula while initiating the first comprehensive facilities related control systems cybersecurity program of its kind within the federal government."We're going to see despite investments, despite technology, we're going to see some ransomware on some of these critical infrastructure systems. And I think people are going to get hurt. Things are going to stop operating. Things are going to explode and there's going to be some serious consequences."

Apr 26, 2021 • 57min
The Congressman, The Commission, and Our Critical Infrastructure
Congressman Mike Gallagher (R-Wis.) has been instrumental in setting up the Cyberspace Solarium Commission, a bipartisan, intragovernmental body whose goal is to help create a strategic approach to defending the United States from cyber attacks of significant consequence (and for listeners of this podcast, that definitely means attacks on our critical infrastructure). Congressman Gallagher's background in the Marines, and work in the public and private sectors, gives him a unique position to help create law around the intersection of national security and cybersecurity as the two become "kitchen table issues", as he tells his constituents.

Mar 29, 2021 • 46min
On the Front Lines with Rob Lee
Rob Lee, the CEO and founder of the industrial cybersecurity company, Dragos, is a pioneer in the ICS threat intelligence and incident response community. Before Dragos, Rob served as a cyber operations officer in the U.S. Air Force tasked to the National Security Agency, helping protect industrial infrastructure - an issue that leaders around the world are now wrestling with. As he likes to put it, "The threat is worse than you realize but not as bad as you want to imagine."

Feb 22, 2021 • 42min
DoD and Critical Infrastructure
The Army Cyber Institute has been testing the cybersecurity preparedness of cities around the country in an experiment called Jack Voltaic. It is a major, multi-sector public private exercise aimed at understanding critical infrastructure dependencies on force deployment. We're joined by Lt. Col. Douglas Fletcher - chief data scientist - and Lt. Col Erica Mitchell - key resources research lead for critical infrastructure - to talk about their findings.

Jan 26, 2021 • 40min
Critical Infrastructure Protection & ICS
For today's episode, I'm joined by Dale Peterson, who is on the leading edge of helping security conscious asset owners in a range of sectors effectively manage and reduce cyber risk to their Industrial Control Systems (known as an “ICS”). ICS is a computer system that monitors or controls a physical process. They exist everywhere: power generation, water supply systems, transmission, product manufacturing. We talk today about some of the key cyber vulnerabilities in these systems, and the relationship between the government and the private sector, how CEOs and other decision makers should evaluate and deploy resources to deal with ICS cyber threats, and the importance of regulators developing metrics for improving cyber security relative to ICS systems.

Dec 28, 2020 • 35min
Critical Response for Critical Infrastructure
Megan Samford is the first woman Chief Product Security Officer in industrial control systems (ICS) manufacturing. She's spent time in both the private and public sectors, from Rockwell Automation and General Electric to serving two governors of Virginia and their offices of homeland security. She is also spearheading a project to develop a common language and framework for cyber security between governments, private sector and first responders in the space. Or, as she puts it: "I believe that every other type of responder in the world, whether you're a firefighter or a police officer, or a medic...there is a framework by which you could literally be picked up an airlifted and dropped into another organization or locality or state or government really, and you would seemingly know how to fall in line with the common framework to respond alongside your peers. But within cyber, it's very schizophrenic, it's very disparate, and it's largely based on the needs of individual companies."