CyberWire Daily - CyberWire Daily at 10: Critical infrastructure attacks over the last 10 years. [Special Edition]
Episode Date: September 20, 2026In this Special Edition episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to reflect on the past decade of critical infrastructure attacks, evolving threats, and l...essons learned from incidents like the Ukraine power grid attack and Colonial Pipeline ransomware. They discuss how these events have shaped current cybersecurity practices and the importance of resilience and preparedness. Join Maria and Dave as they discuss: The critical infrastructure evolution over the past 10 years. Notable cyber attacks including the Ukraine power grid, NotPetya, and the Colonial Pipeline. The shift from traditional ransomware attacks to attacks on infrastructure. The emergence of space and satellite communications as targets. Lessons learned and the future outlook for cybersecurity resilience.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Hello there, and thank you for joining me for today's special edition.
I'm Maria Varmazes, and in today's episode, I'm speaking with the host of the Cyberwire Daily, Dave Bittner.
We're continuing our conversations celebrating 10 years of the Cyberwire Daily,
and in today's episode we're talking about critical infrastructure attacks,
and we're looking at major incidents like the Ukraine Power Grid attack and the Colonial
pipeline and all the lessons that those incidents have taught the cybersecurity industry about
resilience and preparedness. Here's our chat. It is my distinct honor and pleasure to once again
welcome back Dave Bittner, host of the CyberWire Daily to talk with me about the past 10 years
of cybersecurity stories. Hi, Dave. Hello. It's good to be back. Yeah. We've been doing a
bunch of these retrospectives over the last year.
Hard to believe that there's still so much that we haven't even begun to speak about.
Yeah, a lot's happened in the past 10 years, huh?
Imagine. Imagine in cybersecurity.
And one area that we've actually touched on quite a bit, because these things do interweave and
interrelate, is critical infrastructure and the types of fascinating, scary, interesting,
all the above types of attacks we've seen on infrastructure.
And honestly, your definition of infrastructure,
your mileage may vary on that one.
But let's think about, like, very generally,
critical infrastructure around the world,
what we've seen in the last 10 years,
because this is an area where things have really evolved,
or at least that's my impression.
I'm curious what you think about that, Dave.
I think you're right.
And I think sometimes it's better to be lucky than good.
And I think we were just lucky in that,
We were lucky, even if the world was not, that 10 years ago, when we were just getting started on this thing, it kind of coincided with a Ukraine power grid attack, which was, what, back in December 2015 or so.
And so I think this was the realization of things that people had been talking about and warning about.
And it was a lot of question here in the U.S.
Like, was this a test run for capabilities that perhaps could come to our shores?
So I think it was a bit of a wake-up call.
And just more clarification, I guess.
This was Russian-linked sandworm attackers.
They compromised the Ukrainian electricity distribution companies.
It was what, over 200,000 customers lost their power.
And my recollection is this was the first really publicly acknowledged cyber attack that caused a power outage.
Yeah.
And what's fascinating about that incident to me is in my previous to that incident, I remember within the cybersecurity industry,
are experts in ICS or industrial control systems.
I'm going to be thrown in that acronym.
a lot. The ICS experts had been saying, listen, it's inevitable. There's, there are going to be
disabling attacks. We're not trying to do FUD, fear, uncertainty, and doubt. We're not trying to,
to, you know, to, but we need to also be realistic that we recognize that, you know, ICS are huge
targets. They're a very appealing target. And it doesn't require much sophistication to necessarily
take them out, which was, you know, very unsexy for a lot of people to hear that. It's like,
they're very important and very hard to defend. And, uh, not.
not a priority in the way that you would think they should be.
And good luck sleeping tonight when you think about it.
And then one of these days it's going to happen.
And then it did.
I guess and then everything changed, she said in the movie narration.
Well, you had sent over a clip that reminded me that there was congressional testimony about this, you know, going far, predating all of this.
There were some experts, some familiar names in, I don't know, OG hackers, right?
Yeah, the Loft Crew, right?
The Loft Crew, yeah.
The Loft Crew, yep.
Who went to Congress and basically said, if you turned us loose on this system, yeah, we could shut it down, no problem.
It wouldn't take long.
It would be pretty easy to do.
So the warnings go back pretty far.
I think we have a clip from that.
I'm informed that you think that within 30 minutes, the seven of you could make the internet unusable for the entire nation.
Is that correct?
That's correct, actually, one of us with just a few packets.
We've told a few agencies about this.
It's kind of funny because we think that this is something that the various government agencies should be actively going after.
We know the Department of Defense just at a very large...
investigation into what's known as denial of service attacks against the infrastructure.
In our various day jobs, we contributed a large portion of the information to that actual
investigation. Much to our chagrin, the learnings from it were instantly classified, which
we were giving them largely public information. It is very trivial with the old protocols to
segregate and separate the different major long-haul providers, which would then be the national
access points, the metropolitan area ether sections, AT&T can't talk to MCI, can't talk to PSI net,
can't talk to alternate, et cetera, et cetera, and keep it down that way as long as we really wanted to.
It would definitely take a few days for people to figure out what was going on.
you
you state that
that with regard to
commerce over the internet
which is rapidly
growing as we all know
that the internet was not designed
for it
what do you mean by that
the internet was designed
out of the defense department's
advanced research project agency to simply
have computers talk to each other
this was a very laudable act and a laudable
goal and I think they succeeded fantastic
drastically. This was largely an academic environment with some government research organizations.
It grew up, it flourished, it struck everybody by surprise, and now big businesses saying, well,
let's jump on board and make some money off of this. Well, you know, this is kind of like if
you've driven in Boston, you know, the streets aren't tremendously designed in a wonderful fashion
because they followed the cows around. Yeah, I mean, the loft guys were very prescient and, you know,
sure it annoys them, heartbreaks them to no end that they were right. And, you know,
their warnings still bear out to this day. It stinks to be a Cassandra. But it's the reality
often of being in this world. And I feel like, again, this is just impressions of what I remember
pre-2016 or so. I feel like there was some discussion of maybe the still extant gentleman's
agreement around, we're not going to have, no one's going to really go after ICS because if they do that to us,
we're going to do that to them and then it's all over for everybody.
I think you're right. Yeah. And I think in the pre-Ransomware days, it was also kind of
considered off limits in the same way that hospitals were considered off limits,
you know, critical infrastructure, right? Things affecting the public, non-military targets,
I think you're right. There was this gentleman's agreement right up until the moment when there
wasn't. And so the Russians demonstrating this capability really, it was a shift.
Yeah. And I think there was also an element of security through obscurity for a lot of ICS that
that's a very rarefied skill set. Not everybody understands how ICS work, not everybody wants to.
A lot of people are just straight up, not interested. That village at DefCon is not as well
attended as you might want it to be. Right. You know, it's, who wants to talk about sewage plants when we
could be talking about cool stuff, you know.
Ooh, valves.
Yeah. It's always a valve.
I don't know about you, but especially during 2020, when COVID shut down the world,
I remember thinking, well, all those really unsexy things are what keeps civilization going,
and I appreciate them a lot more now.
But yeah, I think a lot of people didn't and still don't understand how these systems work.
They're very, very old, both the physical parts and then try to,
attacking on an internet-enabled thing.
It's probably not necessarily going to be the newest and greatest,
sitting in some plant somewhere that's not frequently updated.
And that's a big part of it,
that a lot of these old legacy systems that get, you know,
they have service lives in the decades.
So over the intervening decades, like you say,
they'd had these automation components literally grafted on to many of them.
And so they weren't designed in from the outset.
And that led to all sorts of vulnerabilities.
Yeah, it became a security through obscurity thing for ICS until again, even then everything changed yet again.
And then malware authors and adversaries started understanding how to actually speak the language of industrial control systems and actually target them specifically.
And in destroyer, industrial, that's the name that comes to mind.
Yeah, what do you remember about that story?
I mean, it was in Destroyer, which I think was also called Crash Override,
and that was just malware that had been tuned to communicate using those ICS protocols.
And so the malware could interact directly with that equipment,
rather than just to breaking into the computers that were kind of adjacent to the grid,
the bad guys could get in and interact with the grid directly.
And so that set people back on their heels, I think.
Sure did.
Another thing that around that time, seismic,
and we've talked about it a lot in a number of a retrospectives,
is not Petya, which I don't think will immediately spring to mind
for a lot of people as an OT or industrial control or infrastructure attack,
because we often just talk about it as, you know, ransomware.
But it had such a huge ripple effect that it
ended up, I mean, it had huge effects on infrastructure. So can you recount that story for us, Dave?
Well, again, my recollection is this was an operation from Russia that was directed at Ukraine.
They had compromised some Ukrainian accounting software packages, but it broke free. It escaped Ukraine,
started copying itself, made its way through all sorts of multinational corporations. I think
Maersk and Merck were a couple of the companies who were kind of the poster children for things going
wrong.
Mersk is a global shipping company.
They were disrupted.
They're port operations.
One of the little side stories about Maersk is that one of the reasons they were able to recover
it at all is one of their domain controllers that was in Ghana happened to have been offline
during the attack.
Like somebody was doing routine maintenance on something.
And so as this thing spread its way through all of Maersk's infrastructure,
there was this one, I picture it as this dusty device sitting in a closet somewhere, right?
Somebody had thrown the circuit breaker.
Unintentionally air-gapped.
Right.
And through pure luck, it didn't get infected when everything else did.
And so they were able to build off of that remaining.
domain controller to get up and running again just through sheer luck.
Yeah.
Yeah.
Yeah.
And I'm going to issue a correction to what I said earlier real quick.
Not Petch is not ransomware.
We thought it was.
It's not, though.
So, sorry.
I should clarify that.
Right.
It was a destructive operation.
They were, yeah, they were just looking to destroy and wipe things.
That's right.
But it broke out.
Scorch field, right?
Scorched earth.
Yeah.
Yep.
Yeah.
And so the lesson there was that, you know,
cyber weapons don't receive.
expect borders. And you, like a biological weapon, right? You think you could control it,
but not Petchut taught us that not necessarily so. Yeah, we got very lucky with, or not we,
wasn't me personally, but Maris got very, very lucky with that one terminal in Ghana. I mean,
but you don't want your threat model to rely on luck, but that's life. I mean, it happens
sometimes. It's quite amazing when that does.
It's quite amazing.
All right.
So moving after NotPetya, we're now in, that was what, 2016?
16 or 17 or so, yeah.
16 or 17 or so.
Let's see, after 2017.
Yeah, Natpeche, I think, was June 2017.
Yeah.
Yeah.
So if we move forward a few more years.
Now, again, I incorrectly had said Notpeggia's ransomware.
Super wrong.
At first, we thought it was and realized it was not.
It's a scorched earth thing.
but ransomware does enter the picture when it comes to wreaking havoc on infrastructure,
not long after, not Petia.
That's probably why I'm getting a little scrambled there.
Forgive me, I get my wires crossed sometimes.
No, no.
Yeah, and attacking ICS was, again, in my mind, classically, pre 10 years ago,
a thing that maybe nation states would try to do to each other,
but criminals figured out that there was money to be made.
by holding infrastructure for ransom, essentially.
And I mean, that is, again, another huge shift
with the entrance of ransomware into the arena
when it comes to infrastructure.
Yeah.
Yeah, when about you remember that happening?
In 2019 to 2020 or so,
the ransomware crews had shifted from low-level ransomware
ransomware aimed at individuals and were going after critical infrastructure, the hospitals,
emergency services, transportation, manufacturers, schools, and realizing that these were
was sort of a perfect storm for the ransomware operators to take advantage of because
these were underserved facilities, hospitals, schools, they're not rolling in dough when it comes
to their cybersecurity teams.
So perhaps they were underprotected and also have critical operations.
Hospitals have to keep running, obviously.
So the ransomware gangs figured out that this was a good situation for them to be able to
force payment to get things back up and running again.
And it's good to remember, too, this was kind of before the double extortion model
where the ransomware gang started
exfiltrating lots of information
to kind of blackmail companies into paying.
This was back in the day
when they just locked everything up
and said, if you want to,
if you want the keys, send us some money.
But again, another wake-up call
because you would hope
that things like hospitals would be off limits
where lives are at stake,
but they were not and continue to not be,
which is kind of...
Yeah. Heartbreaking.
Horrendous, truly.
And ransomware making the rounds affecting infrastructure, among other systems as well,
but in this context we'll focus on infrastructure.
Especially in 2020, you know, nobody was at their best right then.
And, you know, everybody was running a skeleton crew for obvious reasons.
So, I mean, those ransomware criminals were making a killing and just taking advantage of, you know,
when nobody was going to be able to exactly hone in.
I mean, it's just great timing for them, awful timing for the rest of us.
You know, we were already so vulnerable.
Yeah, and you sort of alluded to this, but it was blurring the lines between the cyber criminals
and the national security operators, right?
Like, of who's going after what and what's off limits and what responses to things.
I mean, you know, my understanding is that during a time of war,
hospitals are supposed to be off limits.
And yet here we have ransomware operators just going after them without hesitation.
Yep, yeah, the gloves certainly came off.
And then after 2020, I remember this story in the news was the attacks on the colonial pipeline,
the energy pipeline.
that yeah that again 2021 i think that was still a lot of us very much locked down due to you know for
covid reasons um but that was alarming uh i again i remember hearing that in the news and going oh man
even now we're dealing with this uh what do you remember about colonial pipeline
pardon me um well i mean living on the east coast uh we were concerned about our
fuel being disrupted.
It did not actually hit me in Maryland, but states south of us got hit by it in particular.
One of the things that in retrospect, I think, is interesting about colonial pipeline that I think is maybe a common misunderstanding is that the darkside ransomware group, who was responsible for this, that they had shut down the pipeline operations.
But it was actually Colonial Pipeline who shut down the pipeline operations because their billing operations weren't functional.
So this was an attack on their business network and they felt as though they couldn't continue to operate not being able to keep track of the flow of the fuel and after the fact know who owes what to whom, right?
Yeah, yeah.
So I think that's an interesting nuance, right?
Because we have a shutdown here that was caused by a business interruption
and a company choosing to shut down the physical operations
because of a business interruption.
Yeah.
And do we know, do we, I mean, when we think about the,
pardon me, my computer just decided right now to lock me out
while we're speaking.
Again, computer issues that I was mentioning.
Oh my God.
Oh, are you kidding me?
Sorry, Dave.
This is super annoying.
No problem.
All right.
Had to re-log on in the middle of, well, at least the mic kept going, but my computer, my screen
completely locked me out.
Okay, back in.
I'm wondering in our retrospective, and I don't want to, I don't want to come down on
anybody.
I'm just curious, do we think that that was the right move?
Like, when we armed here quarterback, how colonial
pipeline decided to operate, you know, closing essentially a lot of stuff down to, to regroup in the
face of ransomware. Was that considered the right move? Or do we think that maybe that was too
bigger reaction or is it, you know, easy for us to say now? Do we know? I think it's easy for us to say
now. I think it's easy for us to second guess them now. I think in the moment, something like this
hadn't happened before. And I'm sure they were worrying about all kinds of things, including liability.
So they did, I'm going to say in good faith, they did the best that they could and shut down the pipelines.
But yeah, I don't know.
I mean, this led to gas shortages.
It led to panic buying.
You know, people were filling trash bags with gasoline.
I remember seeing those stories and seeing, you know, gas shortages.
And there were people remembering, you know, it's like the 70s all over again.
And, you know, there was a lot of panic buying,
and it became this sort of contagion,
which, again, really awkward with us still being in COVID at that time.
It's like, oh, great.
Now we have a social contagion.
But, yeah, people were hearing stories about the pipeline being shut down.
Gas shortage is happening.
So other fuel providers that had nothing to do with the climate,
like they were getting shortages.
It was this is really interesting knock-on effect
that I'm sure the attackers in this case were,
very interested in seeing,
oh, if we cause a disruption here,
here's where else it can ripple.
Look at all that damage that we can do, essentially,
and all the panic that we can incur.
Yeah.
And it was very public-facing.
Right.
But again, it was another wake-up call for the general public
because we hadn't really seen something like this at this scale
to be able to,
because I think everybody was after what had happened in Ukraine,
I think people were most worried about having the lights turned off.
And it wasn't the lights got turned off.
It was the fuel supply.
And that was an aha moment for a lot of people to go, oh, right, and start thinking about
what are all the things that we as a civil society have come to rely on and don't even think about,
but are potentially vulnerable to cyber attacks?
Yeah.
One of those things I know, the thing that I am certainly very dependent,
on being the internet and also just the ability to communicate.
Certainly is critical infrastructure.
You know, you don't die without it necessarily, necessarily,
but, you know, one can in an emergency.
But it's sometimes left out the whole idea of, you know, communication systems.
And just a year after, colonial pipeline was everyone in space cyber's favorite story,
which is the 2022 attack on the, on the Viasat satellite communications network
as basically the opening salvo for Russia's invasion of Ukraine that year.
Right before their invasion began,
they disabled a whole bunch of satellite communicates,
or the ability for the satellites to communicate, I should be more precise,
over a whole chunk of Eastern Europe and Ukraine.
So it was, I mean, that one was a huge disruption,
but it was very unsophisticated technically.
They basically went after the ground stations by,
using a hole in the,
I guess a VPN.
It just nobody went after a satellite.
They went after like pretty basic software that just hadn't been patched,
which is a not like they didn't burn a zero day going after it.
But it was still,
you know,
an opening salvo for an honest to God war.
And,
you know,
Russian you,
if they disabled these systems,
people wouldn't be able to communicate what was going on on the ground.
And that was very,
very on purpose.
And I know for me, my blood ran cold with that story and the more I learn about it.
And it's horrifying to think that this field that we're all in is now very much enmeshed with actual kinetic war.
And for me, that's like the watershed moment in 2022.
But I don't know.
I don't know.
Maybe I'm being too poliana.
No, I mean, but obviously of the two of us, you're the expert when it comes to things in space.
So I'm curious.
my impression is that before this space had kind of been considered to be an off-limits domain,
or we didn't know of anyone messing with each other in space?
Is that fair to say?
Yeah, it was some of it was also the gentleman's agreement, I think,
whether or not space is critical infrastructure as a whole discussion.
But I think for, I think, I mean, some of it was these,
these satellites and in these networks were not easily accessible to an adversary via the internet.
It requires a level of sophistication and, frankly, monetary investment that only a military
would have access to. But now that more of this infrastructure is internet enabled and also
more of us are dependent on it, it has become a much more viable target for an attacker to go after,
but also a much more valuable target. So it hadn't been before.
But now it is because a lot of people are wholly dependent on satellites for communication, not just the military.
So it wasn't, and now it is.
And that gentleman's agreement just doesn't hold anymore.
Well, and how is this evolved to where we find ourselves today, you know, with things like Starlink, you know,
and the ability to enable or disable certain parts of the globe to have access?
to a low-earth orbit internet connection.
Yeah, it's, I mean, these civilian companies,
I mean, Starlink is very heavily and meshed with the U.S. military.
There's no denying that.
It is still technically a civilian network, Starlink, at least.
They know that because they are being used in the field for, you know, war and military operations,
they are now a legitimate target.
This is, it used to be considered there's military space and their civilian space.
but increasingly the two are very much an overlap.
So just like the internet, I mean, it's the same.
It's the pipes that everybody uses, right?
So they're all legitimate targets now.
So there's no guarantee that just because, you know, you're a civilian satellite doing whatever,
you might have a payload that's being used by a military that's the enemy of another one,
and that makes you now a legit target to go after.
So it's been interesting seeing that evolve.
Again, that's like a whole different show.
but admittedly, a bit of an area of interest for me.
But space is critical infrastructure,
so it's been very interesting seeing my little arena
entering the field there in a way that, you know,
not great, but there it is.
Yeah, it's a new domain.
It sure is.
And it's a, I mean, who doesn't want to say they hacked space?
I mean, that's like a cool thing to go after, right?
Unfortunately, we all depend on it a lot more than we realize.
So it's a terrifying.
target. In any case,
speaking of things that we
wholly depend on to a
terrifying degree, I feel like
I talk about satellite communications, but there's
terrestrial, you know, the actual
telecoms that we all use day to day.
And this is where I think we start
talking about things like the typhoons.
Volt Typhoon, for example.
Let's start with that typhoon.
That is a pretty nasty
threat. Walk me through that one, Dave.
Well, this was U.S. agencies saying that China-linked organizations had a presence in our critical infrastructure, our critical communications infrastructure.
Not just that. I mean, they were in energy organizations, transportation, water, wastewater, those sorts of things.
that the Chinese had taken advantage of vulnerabilities to pre-position themselves
so that in the future, if they needed the capability of disruption,
they were already in.
Yeah.
And we were just talking about Salt Typhoon recently.
And it was just, again, that idea of I'm saving it for later.
I'm embedded.
You can't get rid of me so I can strike when the moment is right.
And that is, oh, I mean, horrifying.
Yeah, it's an interesting psychological warning, right?
You know, we are inside the house and we will strike at the time of our choosing.
Those kinds of messages, sure, they put your adversary off balance, off kilter.
And our military power depends on civilian infrastructure.
So we're dependent on all of these sorts of things.
So since then, we've seen moves to get Chinese devices out of our critical telecommunications, hardware installations.
We're trying to clean all of this out.
But we've been at it for a few years now.
And I think we're not even halfway there.
And we've certainly spent a lot of money to try to get there.
but and whenever something like this comes up I guess you have to fairly say well are we in their systems
that is a very valid point I would assume that we are as well yeah I would make that assumption
yeah how much of this is espionage tradecraft would you just what you would expect but we just
happen to have public knowledge of this which makes everybody a little uncomfortable I don't know
the answer to that, obviously. Yeah, I don't either. And admittedly, we're in the anglosphere.
I don't read any dialect of Chinese, and I would not be surprised if in, you know, the Mandarin
version of the cyberwire, they're talking about the same thing about the U.S. being in their systems.
Honestly, I mean, I really wouldn't be surprised.
There goes my computer again. All right. It's still recording, so I'm just going to keep talking
and I'll deal it later.
Yeah, sorry. I'm really, really loving this. Thanks, Chris.
Yeah.
Please edit that part out, everybody.
Please do not keep that in.
You should have t-shirts made.
Just this is thanks, Chris.
Yeah.
Me and Jen only.
It's just totally throwing me on my back foot,
just trying to deal with that.
Where was I on this?
There was a thought I had, and I've completely lost it.
Oh, of course.
I mean, just we're talking about attacks on critical infrastructure,
and, I mean, just very,
recently, you've been covering on the CyberWire Daily recent attacks on water infrastructure
here in the U.S. by suspected Iranian cyber attackers.
I mean, it's just, this is a super fresh example.
And it's been fascinating, as I remember sitting in the meetings when you were talking
about the day's updates.
And it would be like one power, you know, one water plant has said that they've,
encountered an issue suspected to Iran the next day. Actually, there's a whole bunch of them the day
after that. Actually, there's even more. And it just kind of as the days as the days on, you know,
unfurl. It's snowballed. It's completely snowballed. It was so fascinating to sort of watch that
happen in a scary way, but it was fascinating. Right. Well, but we have all of these water
treatment plants all over our nation, all over the world. But, you know, let's just stay at home for the
moment. And it's the same story we talked about with hospitals and schools. They're underfunded.
They are operating kind of in a steady state with equipment that's been around for a long time.
And they're running a lot of automation to do the things that they need to do with the least
amount of resources that they can. And they're vulnerable. And also, I think so many of these
facilities are one-offs, you know, it's not like you go and buy, you know, go to water treatment
plants are us and they're custom built for each community, you know. Yeah. Yeah, I mean,
you can imagine a very well-resourced municipality, like I don't know, New York City probably has,
I would imagine some very interesting, hefty capabilities, but, you know, my local Department of
Public Works is two guys.
So, you know, they're up against it, truly.
Yeah.
Yeah, no, I have a friend whose job is just this,
is keeping the water treatment plant up and running.
And it's just a couple of guys,
and they're responsible for the water safety,
for a decent-sized community.
And they do a great job, right?
We generally don't worry about our water.
But again, it's this shot across the bow of,
hey, we're in here, you know, think about that.
I try not to, to be honest.
I try not to.
But, you know, we kind of have to for a living.
But, you know, it's not great.
I remember, I think when I first learned about that ICS, you know,
that industrial control systems were vulnerable when I was, you know,
brand new to this field.
And I mean, really brand new.
I had no idea.
I think one of the first things I did was I sat down with my parents and said,
Did you know that these things could get hacked?
Oh my God.
And this was like 20-something years ago, forgive me.
But I think I gave them a panic attack because I was all so freaking out.
And so I don't want to freak people out.
But at the same time, it's all of our jobs and the jobs of our colleagues who are in the field.
They have to think about these things.
And it's, I mean, there's no way around it.
It is pretty scary to think of these things being disabled because the consequences are pretty dire.
Maria, it is a slippery slope.
It's a slippery slope to becoming a prepper, let me tell you.
I hear you.
That cabin in the mountains, real, real, real feeling.
But knowing all of this stuff and reporting on all of this stuff has changed my own approach for my own family for our own resilience.
You know, we have gone and talked about, okay, what happens if the water gets cut off?
okay, what happens if the electricity gets cut off?
And what happens if it's in the wintertime or it's in the summertime?
You know, where could we go?
How long could we stay here?
What do we have?
What do we need?
And so we've done some things around the edges to kind of improve how robust our response
could be, trying to manage risk and say, how many days could we go,
all those kinds of things that we hadn't really talked about because we hadn't really
worried about it. It wasn't something that we really thought about very much, how real these
things could be. But I think so many of these events have reminded us that it can happen. It can happen
quickly and without warning. So you don't need to go crazy about it, but you need to have good
plans in place just in case. And hopefully more people are doing that than we have.
Yeah, same in my family, and I know I drive my husband insane with that kind of family risk management kind of discussion, but putting it politely.
But I think the Venn diagram of people in this world and the Infosec world and Preppers is a bit of a circle.
There's a lot of crossover, yeah.
There is a huge amount.
And I think the first people, the first thing most of us would say is we're not being paranoid, we're being realistic.
It's like, listen, we see what's going on.
But maybe it's an attempt to try and feel like we have control over things that feel increasingly uncontrollable.
Because for me, I just know a thing that will probably hit us out of nowhere or something I can't anticipate.
And that's probably the scariest thing of all.
Yay!
I don't know where to leave us at that aside from.
That's a dark note.
Well, I mean, so, I mean, let's wrap it up here.
Let's kind of take stock.
I think 10 years ago, when all this started, I think the number one thing was what happens
if someone gets into the power grid? What happens if somebody turns the lights off?
And it's still a concern because the power grid is not just turning the lights off. It's turning
the heat off or the air conditioning off in the increasingly warm summers that we're experiencing
here. You look at places like Europe who are having dangerously hot sun.
And so what happens if their power grids get stressed and people start losing their lives to heat or cold or any of those things?
So that was a major concern.
But now we've broadened our horizons and we see it's really all of the infrastructures, power, water, communications, health care, transportation.
What happens if the trains can't run or the ports can't operate or the bridges, you know, the draw bridges can't.
open and close. All of these things, the satellites shut down, all these things that we've
come to rely on as parts of everyday civilization. They all need to be hardened and protected.
And fortunately, there are a lot of good people out there who are doing that hard work,
and probably a lot of that hard work we will never know about. They're probably near misses
that we'll never know about, and ignorance is bliss when it comes to that. But
hopefully we're all a little more careful and are managing our own family's risk profiles
given the knowledge that we have.
That's for sure.
And certainly to anyone, always to our listeners who are defenders,
but especially listeners who are defenders in ICS,
we thank you for a lot of the seemingly invisible work that you do,
but we greatly appreciate it.
Yeah, I mean, think about companies like Dragos,
companies like Nazomi networks, you know, they're out there.
They have set their companies toward these tasks.
And good on you.
I'm glad you're out there.
Very glad you're out there.
It does help me actually get sleep at night.
So greatly appreciating it.
Well, Dave, as always, it's been a great chat.
Thank you again.
And congratulations, yet again, I'll say it every time.
Congratulations on a fantastic 10 years.
And here is to another 10, at least, of the Cyberwire Daily.
It's been a pleasure, Dave.
No, thank you.
It's always a joy to be able to chat with you about these things.
So I'll see you next time.
See you next time.
All right.
Now I'm going to unlock it.
Thanks for joining me.
See you next time.
