talk-data.com talk-data.com

A

Speaker

Andrew Ginter

2

talks

VP Industrial Security Waterfall Security Solutions

Andrew Ginter is the VP Industrial Security at Waterfall Security Solutions. Before Waterfall, he spent 30 years leading the development of control system products, IT/OT middleware products and the world's first industrial SIEM. Andrew is the author of two books: SCADA Security - What's broken and how to fix it, and Secure Operations Technology. He is a co-author of the Industrial Internet Security Framework, co-host of the Industrial Security Podcast, a lecturer at the Industrial Security Institute and a frequent contributor to industrial security standards and best-practice guidance.

Bio from: (CS)²AI Online™ Replay: Managing OT Cyber Risk

Filter by Event / Source

Talks & appearances

2 activities · Newest first

Search activities →

In this webinar, we explore common OT cyber risk fallacies and powerful new approaches to physical & analog / 'unhackable' mitigations for OT cyber risk, including: Security PHA Review (SPR), Consequence-Driven Cyber-Informed Engineering (CCE), Secure Operations Technology (SEC-OT), and manual fall-backs. We finish by looking at organizational resistance to robust security measures, such as confusing detection with prevention, statistics with prediction, and 'reverse lottery' ROI. The session discusses how the risk landscape is evolving and how the world's most secure industrial sites manage OT cyber risk.

There is no consensus as to how to manage OT cyber risk, so when serious incidents occur, it is vitally important that we have a defensible rationale in place for our choices. But - what does a defensible OT security program look like?\n\nIn this webinar, we start with common OT cyber risk fallacies, such as insurance does not keep the lights on and cyber catastrophes are not like hurricanes. We explore powerful new approaches to physical & analog / \"unhackable\" mitigations for OT cyber risk, including: Security PHA Review (SPR), Consequence-Driven Cyber-Informed Engineering (CCE), Secure Operations Technology (SEC-OT), and manual fall-backs. We finish by looking at organizational resistance to robust security measures, such as confusing detection with prevention, statistics with prediction, and \"reverse lottery\" ROI.\nSo while the risk landscape continues to worsen, simple and powerful approaches to managing OT cyber risk are emerging. Join us to explore approaches to security that the world's most secure industrial sites already use routinely.