CyberWire Daily - CyberWire Daily at 10: Critical infrastructure attacks over the last 10 years. [Special Edition]

Episode Date: September 20, 2026

In this Special Edition episode, Maria Varmazis⁠ and ⁠Dave Bittner⁠ from N2K Cyberwire get back together to reflect on the past decade of critical infrastructure attacks, evolving threats, and l...essons learned from incidents like the Ukraine power grid attack and Colonial Pipeline ransomware. They discuss how these events have shaped current cybersecurity practices and the importance of resilience and preparedness. Join Maria and Dave as they discuss: The critical infrastructure evolution over the past 10 years. Notable cyber attacks including the Ukraine power grid, NotPetya, and the Colonial Pipeline. The shift from traditional ransomware attacks to attacks on infrastructure. The emergence of space and satellite communications as targets. Lessons learned and the future outlook for cybersecurity resilience.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Hello there, and thank you for joining me for today's special edition. I'm Maria Varmazes, and in today's episode, I'm speaking with the host of the Cyberwire Daily, Dave Bittner. We're continuing our conversations celebrating 10 years of the Cyberwire Daily, and in today's episode we're talking about critical infrastructure attacks, and we're looking at major incidents like the Ukraine Power Grid attack and the Colonial pipeline and all the lessons that those incidents have taught the cybersecurity industry about resilience and preparedness. Here's our chat. It is my distinct honor and pleasure to once again
Starting point is 00:01:07 welcome back Dave Bittner, host of the CyberWire Daily to talk with me about the past 10 years of cybersecurity stories. Hi, Dave. Hello. It's good to be back. Yeah. We've been doing a bunch of these retrospectives over the last year. Hard to believe that there's still so much that we haven't even begun to speak about. Yeah, a lot's happened in the past 10 years, huh? Imagine. Imagine in cybersecurity. And one area that we've actually touched on quite a bit, because these things do interweave and interrelate, is critical infrastructure and the types of fascinating, scary, interesting,
Starting point is 00:01:47 all the above types of attacks we've seen on infrastructure. And honestly, your definition of infrastructure, your mileage may vary on that one. But let's think about, like, very generally, critical infrastructure around the world, what we've seen in the last 10 years, because this is an area where things have really evolved, or at least that's my impression.
Starting point is 00:02:07 I'm curious what you think about that, Dave. I think you're right. And I think sometimes it's better to be lucky than good. And I think we were just lucky in that, We were lucky, even if the world was not, that 10 years ago, when we were just getting started on this thing, it kind of coincided with a Ukraine power grid attack, which was, what, back in December 2015 or so. And so I think this was the realization of things that people had been talking about and warning about. And it was a lot of question here in the U.S. Like, was this a test run for capabilities that perhaps could come to our shores?
Starting point is 00:02:54 So I think it was a bit of a wake-up call. And just more clarification, I guess. This was Russian-linked sandworm attackers. They compromised the Ukrainian electricity distribution companies. It was what, over 200,000 customers lost their power. And my recollection is this was the first really publicly acknowledged cyber attack that caused a power outage. Yeah. And what's fascinating about that incident to me is in my previous to that incident, I remember within the cybersecurity industry,
Starting point is 00:03:33 are experts in ICS or industrial control systems. I'm going to be thrown in that acronym. a lot. The ICS experts had been saying, listen, it's inevitable. There's, there are going to be disabling attacks. We're not trying to do FUD, fear, uncertainty, and doubt. We're not trying to, to, you know, to, but we need to also be realistic that we recognize that, you know, ICS are huge targets. They're a very appealing target. And it doesn't require much sophistication to necessarily take them out, which was, you know, very unsexy for a lot of people to hear that. It's like, they're very important and very hard to defend. And, uh, not.
Starting point is 00:04:08 not a priority in the way that you would think they should be. And good luck sleeping tonight when you think about it. And then one of these days it's going to happen. And then it did. I guess and then everything changed, she said in the movie narration. Well, you had sent over a clip that reminded me that there was congressional testimony about this, you know, going far, predating all of this. There were some experts, some familiar names in, I don't know, OG hackers, right? Yeah, the Loft Crew, right?
Starting point is 00:04:45 The Loft Crew, yeah. The Loft Crew, yep. Who went to Congress and basically said, if you turned us loose on this system, yeah, we could shut it down, no problem. It wouldn't take long. It would be pretty easy to do. So the warnings go back pretty far. I think we have a clip from that. I'm informed that you think that within 30 minutes, the seven of you could make the internet unusable for the entire nation.
Starting point is 00:05:18 Is that correct? That's correct, actually, one of us with just a few packets. We've told a few agencies about this. It's kind of funny because we think that this is something that the various government agencies should be actively going after. We know the Department of Defense just at a very large... investigation into what's known as denial of service attacks against the infrastructure. In our various day jobs, we contributed a large portion of the information to that actual investigation. Much to our chagrin, the learnings from it were instantly classified, which
Starting point is 00:05:56 we were giving them largely public information. It is very trivial with the old protocols to segregate and separate the different major long-haul providers, which would then be the national access points, the metropolitan area ether sections, AT&T can't talk to MCI, can't talk to PSI net, can't talk to alternate, et cetera, et cetera, and keep it down that way as long as we really wanted to. It would definitely take a few days for people to figure out what was going on. you you state that that with regard to
Starting point is 00:06:35 commerce over the internet which is rapidly growing as we all know that the internet was not designed for it what do you mean by that the internet was designed out of the defense department's
Starting point is 00:06:49 advanced research project agency to simply have computers talk to each other this was a very laudable act and a laudable goal and I think they succeeded fantastic drastically. This was largely an academic environment with some government research organizations. It grew up, it flourished, it struck everybody by surprise, and now big businesses saying, well, let's jump on board and make some money off of this. Well, you know, this is kind of like if you've driven in Boston, you know, the streets aren't tremendously designed in a wonderful fashion
Starting point is 00:07:20 because they followed the cows around. Yeah, I mean, the loft guys were very prescient and, you know, sure it annoys them, heartbreaks them to no end that they were right. And, you know, their warnings still bear out to this day. It stinks to be a Cassandra. But it's the reality often of being in this world. And I feel like, again, this is just impressions of what I remember pre-2016 or so. I feel like there was some discussion of maybe the still extant gentleman's agreement around, we're not going to have, no one's going to really go after ICS because if they do that to us, we're going to do that to them and then it's all over for everybody. I think you're right. Yeah. And I think in the pre-Ransomware days, it was also kind of
Starting point is 00:08:07 considered off limits in the same way that hospitals were considered off limits, you know, critical infrastructure, right? Things affecting the public, non-military targets, I think you're right. There was this gentleman's agreement right up until the moment when there wasn't. And so the Russians demonstrating this capability really, it was a shift. Yeah. And I think there was also an element of security through obscurity for a lot of ICS that that's a very rarefied skill set. Not everybody understands how ICS work, not everybody wants to. A lot of people are just straight up, not interested. That village at DefCon is not as well attended as you might want it to be. Right. You know, it's, who wants to talk about sewage plants when we
Starting point is 00:08:52 could be talking about cool stuff, you know. Ooh, valves. Yeah. It's always a valve. I don't know about you, but especially during 2020, when COVID shut down the world, I remember thinking, well, all those really unsexy things are what keeps civilization going, and I appreciate them a lot more now. But yeah, I think a lot of people didn't and still don't understand how these systems work. They're very, very old, both the physical parts and then try to,
Starting point is 00:09:22 attacking on an internet-enabled thing. It's probably not necessarily going to be the newest and greatest, sitting in some plant somewhere that's not frequently updated. And that's a big part of it, that a lot of these old legacy systems that get, you know, they have service lives in the decades. So over the intervening decades, like you say, they'd had these automation components literally grafted on to many of them.
Starting point is 00:09:50 And so they weren't designed in from the outset. And that led to all sorts of vulnerabilities. Yeah, it became a security through obscurity thing for ICS until again, even then everything changed yet again. And then malware authors and adversaries started understanding how to actually speak the language of industrial control systems and actually target them specifically. And in destroyer, industrial, that's the name that comes to mind. Yeah, what do you remember about that story? I mean, it was in Destroyer, which I think was also called Crash Override, and that was just malware that had been tuned to communicate using those ICS protocols.
Starting point is 00:10:36 And so the malware could interact directly with that equipment, rather than just to breaking into the computers that were kind of adjacent to the grid, the bad guys could get in and interact with the grid directly. And so that set people back on their heels, I think. Sure did. Another thing that around that time, seismic, and we've talked about it a lot in a number of a retrospectives, is not Petya, which I don't think will immediately spring to mind
Starting point is 00:11:09 for a lot of people as an OT or industrial control or infrastructure attack, because we often just talk about it as, you know, ransomware. But it had such a huge ripple effect that it ended up, I mean, it had huge effects on infrastructure. So can you recount that story for us, Dave? Well, again, my recollection is this was an operation from Russia that was directed at Ukraine. They had compromised some Ukrainian accounting software packages, but it broke free. It escaped Ukraine, started copying itself, made its way through all sorts of multinational corporations. I think Maersk and Merck were a couple of the companies who were kind of the poster children for things going
Starting point is 00:11:56 wrong. Mersk is a global shipping company. They were disrupted. They're port operations. One of the little side stories about Maersk is that one of the reasons they were able to recover it at all is one of their domain controllers that was in Ghana happened to have been offline during the attack. Like somebody was doing routine maintenance on something.
Starting point is 00:12:22 And so as this thing spread its way through all of Maersk's infrastructure, there was this one, I picture it as this dusty device sitting in a closet somewhere, right? Somebody had thrown the circuit breaker. Unintentionally air-gapped. Right. And through pure luck, it didn't get infected when everything else did. And so they were able to build off of that remaining. domain controller to get up and running again just through sheer luck.
Starting point is 00:12:53 Yeah. Yeah. Yeah. And I'm going to issue a correction to what I said earlier real quick. Not Petch is not ransomware. We thought it was. It's not, though. So, sorry.
Starting point is 00:13:01 I should clarify that. Right. It was a destructive operation. They were, yeah, they were just looking to destroy and wipe things. That's right. But it broke out. Scorch field, right? Scorched earth.
Starting point is 00:13:12 Yeah. Yep. Yeah. And so the lesson there was that, you know, cyber weapons don't receive. expect borders. And you, like a biological weapon, right? You think you could control it, but not Petchut taught us that not necessarily so. Yeah, we got very lucky with, or not we, wasn't me personally, but Maris got very, very lucky with that one terminal in Ghana. I mean,
Starting point is 00:13:39 but you don't want your threat model to rely on luck, but that's life. I mean, it happens sometimes. It's quite amazing when that does. It's quite amazing. All right. So moving after NotPetya, we're now in, that was what, 2016? 16 or 17 or so, yeah. 16 or 17 or so. Let's see, after 2017.
Starting point is 00:14:02 Yeah, Natpeche, I think, was June 2017. Yeah. Yeah. So if we move forward a few more years. Now, again, I incorrectly had said Notpeggia's ransomware. Super wrong. At first, we thought it was and realized it was not. It's a scorched earth thing.
Starting point is 00:14:17 but ransomware does enter the picture when it comes to wreaking havoc on infrastructure, not long after, not Petia. That's probably why I'm getting a little scrambled there. Forgive me, I get my wires crossed sometimes. No, no. Yeah, and attacking ICS was, again, in my mind, classically, pre 10 years ago, a thing that maybe nation states would try to do to each other, but criminals figured out that there was money to be made.
Starting point is 00:14:47 by holding infrastructure for ransom, essentially. And I mean, that is, again, another huge shift with the entrance of ransomware into the arena when it comes to infrastructure. Yeah. Yeah, when about you remember that happening? In 2019 to 2020 or so, the ransomware crews had shifted from low-level ransomware
Starting point is 00:15:14 ransomware aimed at individuals and were going after critical infrastructure, the hospitals, emergency services, transportation, manufacturers, schools, and realizing that these were was sort of a perfect storm for the ransomware operators to take advantage of because these were underserved facilities, hospitals, schools, they're not rolling in dough when it comes to their cybersecurity teams. So perhaps they were underprotected and also have critical operations. Hospitals have to keep running, obviously. So the ransomware gangs figured out that this was a good situation for them to be able to
Starting point is 00:16:03 force payment to get things back up and running again. And it's good to remember, too, this was kind of before the double extortion model where the ransomware gang started exfiltrating lots of information to kind of blackmail companies into paying. This was back in the day when they just locked everything up and said, if you want to,
Starting point is 00:16:23 if you want the keys, send us some money. But again, another wake-up call because you would hope that things like hospitals would be off limits where lives are at stake, but they were not and continue to not be, which is kind of... Yeah. Heartbreaking.
Starting point is 00:16:42 Horrendous, truly. And ransomware making the rounds affecting infrastructure, among other systems as well, but in this context we'll focus on infrastructure. Especially in 2020, you know, nobody was at their best right then. And, you know, everybody was running a skeleton crew for obvious reasons. So, I mean, those ransomware criminals were making a killing and just taking advantage of, you know, when nobody was going to be able to exactly hone in. I mean, it's just great timing for them, awful timing for the rest of us.
Starting point is 00:17:19 You know, we were already so vulnerable. Yeah, and you sort of alluded to this, but it was blurring the lines between the cyber criminals and the national security operators, right? Like, of who's going after what and what's off limits and what responses to things. I mean, you know, my understanding is that during a time of war, hospitals are supposed to be off limits. And yet here we have ransomware operators just going after them without hesitation. Yep, yeah, the gloves certainly came off.
Starting point is 00:17:58 And then after 2020, I remember this story in the news was the attacks on the colonial pipeline, the energy pipeline. that yeah that again 2021 i think that was still a lot of us very much locked down due to you know for covid reasons um but that was alarming uh i again i remember hearing that in the news and going oh man even now we're dealing with this uh what do you remember about colonial pipeline pardon me um well i mean living on the east coast uh we were concerned about our fuel being disrupted. It did not actually hit me in Maryland, but states south of us got hit by it in particular.
Starting point is 00:18:47 One of the things that in retrospect, I think, is interesting about colonial pipeline that I think is maybe a common misunderstanding is that the darkside ransomware group, who was responsible for this, that they had shut down the pipeline operations. But it was actually Colonial Pipeline who shut down the pipeline operations because their billing operations weren't functional. So this was an attack on their business network and they felt as though they couldn't continue to operate not being able to keep track of the flow of the fuel and after the fact know who owes what to whom, right? Yeah, yeah. So I think that's an interesting nuance, right? Because we have a shutdown here that was caused by a business interruption and a company choosing to shut down the physical operations because of a business interruption.
Starting point is 00:19:53 Yeah. And do we know, do we, I mean, when we think about the, pardon me, my computer just decided right now to lock me out while we're speaking. Again, computer issues that I was mentioning. Oh my God. Oh, are you kidding me? Sorry, Dave.
Starting point is 00:20:09 This is super annoying. No problem. All right. Had to re-log on in the middle of, well, at least the mic kept going, but my computer, my screen completely locked me out. Okay, back in. I'm wondering in our retrospective, and I don't want to, I don't want to come down on anybody.
Starting point is 00:20:27 I'm just curious, do we think that that was the right move? Like, when we armed here quarterback, how colonial pipeline decided to operate, you know, closing essentially a lot of stuff down to, to regroup in the face of ransomware. Was that considered the right move? Or do we think that maybe that was too bigger reaction or is it, you know, easy for us to say now? Do we know? I think it's easy for us to say now. I think it's easy for us to second guess them now. I think in the moment, something like this hadn't happened before. And I'm sure they were worrying about all kinds of things, including liability. So they did, I'm going to say in good faith, they did the best that they could and shut down the pipelines.
Starting point is 00:21:14 But yeah, I don't know. I mean, this led to gas shortages. It led to panic buying. You know, people were filling trash bags with gasoline. I remember seeing those stories and seeing, you know, gas shortages. And there were people remembering, you know, it's like the 70s all over again. And, you know, there was a lot of panic buying, and it became this sort of contagion,
Starting point is 00:21:39 which, again, really awkward with us still being in COVID at that time. It's like, oh, great. Now we have a social contagion. But, yeah, people were hearing stories about the pipeline being shut down. Gas shortage is happening. So other fuel providers that had nothing to do with the climate, like they were getting shortages. It was this is really interesting knock-on effect
Starting point is 00:22:00 that I'm sure the attackers in this case were, very interested in seeing, oh, if we cause a disruption here, here's where else it can ripple. Look at all that damage that we can do, essentially, and all the panic that we can incur. Yeah. And it was very public-facing.
Starting point is 00:22:18 Right. But again, it was another wake-up call for the general public because we hadn't really seen something like this at this scale to be able to, because I think everybody was after what had happened in Ukraine, I think people were most worried about having the lights turned off. And it wasn't the lights got turned off. It was the fuel supply.
Starting point is 00:22:42 And that was an aha moment for a lot of people to go, oh, right, and start thinking about what are all the things that we as a civil society have come to rely on and don't even think about, but are potentially vulnerable to cyber attacks? Yeah. One of those things I know, the thing that I am certainly very dependent, on being the internet and also just the ability to communicate. Certainly is critical infrastructure. You know, you don't die without it necessarily, necessarily,
Starting point is 00:23:12 but, you know, one can in an emergency. But it's sometimes left out the whole idea of, you know, communication systems. And just a year after, colonial pipeline was everyone in space cyber's favorite story, which is the 2022 attack on the, on the Viasat satellite communications network as basically the opening salvo for Russia's invasion of Ukraine that year. Right before their invasion began, they disabled a whole bunch of satellite communicates, or the ability for the satellites to communicate, I should be more precise,
Starting point is 00:23:48 over a whole chunk of Eastern Europe and Ukraine. So it was, I mean, that one was a huge disruption, but it was very unsophisticated technically. They basically went after the ground stations by, using a hole in the, I guess a VPN. It just nobody went after a satellite. They went after like pretty basic software that just hadn't been patched,
Starting point is 00:24:11 which is a not like they didn't burn a zero day going after it. But it was still, you know, an opening salvo for an honest to God war. And, you know, Russian you, if they disabled these systems,
Starting point is 00:24:26 people wouldn't be able to communicate what was going on on the ground. And that was very, very on purpose. And I know for me, my blood ran cold with that story and the more I learn about it. And it's horrifying to think that this field that we're all in is now very much enmeshed with actual kinetic war. And for me, that's like the watershed moment in 2022. But I don't know. I don't know.
Starting point is 00:24:51 Maybe I'm being too poliana. No, I mean, but obviously of the two of us, you're the expert when it comes to things in space. So I'm curious. my impression is that before this space had kind of been considered to be an off-limits domain, or we didn't know of anyone messing with each other in space? Is that fair to say? Yeah, it was some of it was also the gentleman's agreement, I think, whether or not space is critical infrastructure as a whole discussion.
Starting point is 00:25:25 But I think for, I think, I mean, some of it was these, these satellites and in these networks were not easily accessible to an adversary via the internet. It requires a level of sophistication and, frankly, monetary investment that only a military would have access to. But now that more of this infrastructure is internet enabled and also more of us are dependent on it, it has become a much more viable target for an attacker to go after, but also a much more valuable target. So it hadn't been before. But now it is because a lot of people are wholly dependent on satellites for communication, not just the military. So it wasn't, and now it is.
Starting point is 00:26:09 And that gentleman's agreement just doesn't hold anymore. Well, and how is this evolved to where we find ourselves today, you know, with things like Starlink, you know, and the ability to enable or disable certain parts of the globe to have access? to a low-earth orbit internet connection. Yeah, it's, I mean, these civilian companies, I mean, Starlink is very heavily and meshed with the U.S. military. There's no denying that. It is still technically a civilian network, Starlink, at least.
Starting point is 00:26:46 They know that because they are being used in the field for, you know, war and military operations, they are now a legitimate target. This is, it used to be considered there's military space and their civilian space. but increasingly the two are very much an overlap. So just like the internet, I mean, it's the same. It's the pipes that everybody uses, right? So they're all legitimate targets now. So there's no guarantee that just because, you know, you're a civilian satellite doing whatever,
Starting point is 00:27:15 you might have a payload that's being used by a military that's the enemy of another one, and that makes you now a legit target to go after. So it's been interesting seeing that evolve. Again, that's like a whole different show. but admittedly, a bit of an area of interest for me. But space is critical infrastructure, so it's been very interesting seeing my little arena entering the field there in a way that, you know,
Starting point is 00:27:40 not great, but there it is. Yeah, it's a new domain. It sure is. And it's a, I mean, who doesn't want to say they hacked space? I mean, that's like a cool thing to go after, right? Unfortunately, we all depend on it a lot more than we realize. So it's a terrifying. target. In any case,
Starting point is 00:27:59 speaking of things that we wholly depend on to a terrifying degree, I feel like I talk about satellite communications, but there's terrestrial, you know, the actual telecoms that we all use day to day. And this is where I think we start talking about things like the typhoons.
Starting point is 00:28:15 Volt Typhoon, for example. Let's start with that typhoon. That is a pretty nasty threat. Walk me through that one, Dave. Well, this was U.S. agencies saying that China-linked organizations had a presence in our critical infrastructure, our critical communications infrastructure. Not just that. I mean, they were in energy organizations, transportation, water, wastewater, those sorts of things. that the Chinese had taken advantage of vulnerabilities to pre-position themselves so that in the future, if they needed the capability of disruption,
Starting point is 00:29:02 they were already in. Yeah. And we were just talking about Salt Typhoon recently. And it was just, again, that idea of I'm saving it for later. I'm embedded. You can't get rid of me so I can strike when the moment is right. And that is, oh, I mean, horrifying. Yeah, it's an interesting psychological warning, right?
Starting point is 00:29:27 You know, we are inside the house and we will strike at the time of our choosing. Those kinds of messages, sure, they put your adversary off balance, off kilter. And our military power depends on civilian infrastructure. So we're dependent on all of these sorts of things. So since then, we've seen moves to get Chinese devices out of our critical telecommunications, hardware installations. We're trying to clean all of this out. But we've been at it for a few years now. And I think we're not even halfway there.
Starting point is 00:30:13 And we've certainly spent a lot of money to try to get there. but and whenever something like this comes up I guess you have to fairly say well are we in their systems that is a very valid point I would assume that we are as well yeah I would make that assumption yeah how much of this is espionage tradecraft would you just what you would expect but we just happen to have public knowledge of this which makes everybody a little uncomfortable I don't know the answer to that, obviously. Yeah, I don't either. And admittedly, we're in the anglosphere. I don't read any dialect of Chinese, and I would not be surprised if in, you know, the Mandarin version of the cyberwire, they're talking about the same thing about the U.S. being in their systems.
Starting point is 00:31:02 Honestly, I mean, I really wouldn't be surprised. There goes my computer again. All right. It's still recording, so I'm just going to keep talking and I'll deal it later. Yeah, sorry. I'm really, really loving this. Thanks, Chris. Yeah. Please edit that part out, everybody. Please do not keep that in. You should have t-shirts made.
Starting point is 00:31:24 Just this is thanks, Chris. Yeah. Me and Jen only. It's just totally throwing me on my back foot, just trying to deal with that. Where was I on this? There was a thought I had, and I've completely lost it. Oh, of course.
Starting point is 00:31:40 I mean, just we're talking about attacks on critical infrastructure, and, I mean, just very, recently, you've been covering on the CyberWire Daily recent attacks on water infrastructure here in the U.S. by suspected Iranian cyber attackers. I mean, it's just, this is a super fresh example. And it's been fascinating, as I remember sitting in the meetings when you were talking about the day's updates. And it would be like one power, you know, one water plant has said that they've,
Starting point is 00:32:16 encountered an issue suspected to Iran the next day. Actually, there's a whole bunch of them the day after that. Actually, there's even more. And it just kind of as the days as the days on, you know, unfurl. It's snowballed. It's completely snowballed. It was so fascinating to sort of watch that happen in a scary way, but it was fascinating. Right. Well, but we have all of these water treatment plants all over our nation, all over the world. But, you know, let's just stay at home for the moment. And it's the same story we talked about with hospitals and schools. They're underfunded. They are operating kind of in a steady state with equipment that's been around for a long time. And they're running a lot of automation to do the things that they need to do with the least
Starting point is 00:33:05 amount of resources that they can. And they're vulnerable. And also, I think so many of these facilities are one-offs, you know, it's not like you go and buy, you know, go to water treatment plants are us and they're custom built for each community, you know. Yeah. Yeah, I mean, you can imagine a very well-resourced municipality, like I don't know, New York City probably has, I would imagine some very interesting, hefty capabilities, but, you know, my local Department of Public Works is two guys. So, you know, they're up against it, truly. Yeah.
Starting point is 00:33:47 Yeah, no, I have a friend whose job is just this, is keeping the water treatment plant up and running. And it's just a couple of guys, and they're responsible for the water safety, for a decent-sized community. And they do a great job, right? We generally don't worry about our water. But again, it's this shot across the bow of,
Starting point is 00:34:12 hey, we're in here, you know, think about that. I try not to, to be honest. I try not to. But, you know, we kind of have to for a living. But, you know, it's not great. I remember, I think when I first learned about that ICS, you know, that industrial control systems were vulnerable when I was, you know, brand new to this field.
Starting point is 00:34:36 And I mean, really brand new. I had no idea. I think one of the first things I did was I sat down with my parents and said, Did you know that these things could get hacked? Oh my God. And this was like 20-something years ago, forgive me. But I think I gave them a panic attack because I was all so freaking out. And so I don't want to freak people out.
Starting point is 00:34:56 But at the same time, it's all of our jobs and the jobs of our colleagues who are in the field. They have to think about these things. And it's, I mean, there's no way around it. It is pretty scary to think of these things being disabled because the consequences are pretty dire. Maria, it is a slippery slope. It's a slippery slope to becoming a prepper, let me tell you. I hear you. That cabin in the mountains, real, real, real feeling.
Starting point is 00:35:23 But knowing all of this stuff and reporting on all of this stuff has changed my own approach for my own family for our own resilience. You know, we have gone and talked about, okay, what happens if the water gets cut off? okay, what happens if the electricity gets cut off? And what happens if it's in the wintertime or it's in the summertime? You know, where could we go? How long could we stay here? What do we have? What do we need?
Starting point is 00:35:51 And so we've done some things around the edges to kind of improve how robust our response could be, trying to manage risk and say, how many days could we go, all those kinds of things that we hadn't really talked about because we hadn't really worried about it. It wasn't something that we really thought about very much, how real these things could be. But I think so many of these events have reminded us that it can happen. It can happen quickly and without warning. So you don't need to go crazy about it, but you need to have good plans in place just in case. And hopefully more people are doing that than we have. Yeah, same in my family, and I know I drive my husband insane with that kind of family risk management kind of discussion, but putting it politely.
Starting point is 00:36:49 But I think the Venn diagram of people in this world and the Infosec world and Preppers is a bit of a circle. There's a lot of crossover, yeah. There is a huge amount. And I think the first people, the first thing most of us would say is we're not being paranoid, we're being realistic. It's like, listen, we see what's going on. But maybe it's an attempt to try and feel like we have control over things that feel increasingly uncontrollable. Because for me, I just know a thing that will probably hit us out of nowhere or something I can't anticipate. And that's probably the scariest thing of all.
Starting point is 00:37:25 Yay! I don't know where to leave us at that aside from. That's a dark note. Well, I mean, so, I mean, let's wrap it up here. Let's kind of take stock. I think 10 years ago, when all this started, I think the number one thing was what happens if someone gets into the power grid? What happens if somebody turns the lights off? And it's still a concern because the power grid is not just turning the lights off. It's turning
Starting point is 00:37:52 the heat off or the air conditioning off in the increasingly warm summers that we're experiencing here. You look at places like Europe who are having dangerously hot sun. And so what happens if their power grids get stressed and people start losing their lives to heat or cold or any of those things? So that was a major concern. But now we've broadened our horizons and we see it's really all of the infrastructures, power, water, communications, health care, transportation. What happens if the trains can't run or the ports can't operate or the bridges, you know, the draw bridges can't. open and close. All of these things, the satellites shut down, all these things that we've come to rely on as parts of everyday civilization. They all need to be hardened and protected.
Starting point is 00:38:51 And fortunately, there are a lot of good people out there who are doing that hard work, and probably a lot of that hard work we will never know about. They're probably near misses that we'll never know about, and ignorance is bliss when it comes to that. But hopefully we're all a little more careful and are managing our own family's risk profiles given the knowledge that we have. That's for sure. And certainly to anyone, always to our listeners who are defenders, but especially listeners who are defenders in ICS,
Starting point is 00:39:24 we thank you for a lot of the seemingly invisible work that you do, but we greatly appreciate it. Yeah, I mean, think about companies like Dragos, companies like Nazomi networks, you know, they're out there. They have set their companies toward these tasks. And good on you. I'm glad you're out there. Very glad you're out there.
Starting point is 00:39:47 It does help me actually get sleep at night. So greatly appreciating it. Well, Dave, as always, it's been a great chat. Thank you again. And congratulations, yet again, I'll say it every time. Congratulations on a fantastic 10 years. And here is to another 10, at least, of the Cyberwire Daily. It's been a pleasure, Dave.
Starting point is 00:40:05 No, thank you. It's always a joy to be able to chat with you about these things. So I'll see you next time. See you next time. All right. Now I'm going to unlock it. Thanks for joining me. See you next time.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.