https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • MSP 501 Rankings
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • MSP 501 Rankings
    • NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Channel Futures 20: Top Tech Providers
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

RSAC 2023 critical infrastructure panel

RSAC 2023: Tackling the Myriad Challenges in Securing Critical Infrastructure

  • Written by Edward Gately
  • April 25, 2023
DDoS overtakes ransomware as biggest perceived threat to critical infrastructure.

RSA CONFERENCE — In an RSAC 2023 forum Tuesday, panelists addressed the many challenges facing critical infrastructure in terms of cybersecurity, including reluctance to adopt automation.

The topic of the RSAC 2023 panel was the state of critical infrastructure security. (Channel Futures is on scene this week in San Francisco.) Panelists agreed some slight progress has been made, but organizations still have a long way to go.

Gartner predicts that by 2025, 30% of critical infrastructure organizations will experience a security breach resulting in the halting of operations, and/or mission-critical cyber-physical systems.

Panelists include:

  • Rick McElroy, VMware‘s principal security strategist.
  • Duncan Greatwood, Xage Security‘s CEO.
  • Theresa Lanowitz, AT&T Cybersecurity‘s head of evangelism.
  • Chaim Mazal, Gigamon‘s CSO.
  • Jon Check, executive director of cyber protection solutions at Raytheon Intelligence & Space.

Same Attack Patterns Over and Over

During the RSAC 2023 panel, Greatwood said there has been some progress in the last couple of years with some improved threat detection and some improved boundary protection as well.

Xage Security's Duncan Greatwood

Xage Security’s Duncan Greatwood

“But we’re still seeing the same patterns of attack over and over again: lost credentials, insecure protocols, stuff exposed on the internet, attacks spreading easily within the operation once it gets inside, as well as it being too easy to get in in the first place,” he said. “So I think the big shift that we’re seeing is much more aggressive adoption of preventative cyber in operations. And people have been using the word ‘protection’ for a few years, which kind of means absolutely everything. Every single thing you could possibly imagine doing in cyber is protective, but not everything is preventative.”

There are techniques that allow organizations to block most of the attacks that have taken place, Greatwood said. However, it hasn’t been easy for operations to adopt those techniques.

“They have tons of legacy equipment in the typical oil and gas operation,” he said. “Probably 80-95% of the equipment has no password. So that’s sort of the baseline that you’re starting from. There’s still quite a lot of opportunities within the operation to make attacks.”

RSAC 2023: DDoS Overtakes Ransomware as Greatest Concern

According to a new AT&T Cybersecurity report, organizations were most concerned about ransomware in 2022 with distributed denial of service (DDoS) coming in last. Now, DDoS is the No. 1 concern for organizations in energy and utilities, as well as manufacturing.

One of the reasons cybercriminals are gravitating to DDoS is it’s cheaper and easier than ransomware, Lanowitz said.

AT&T Cybersecurity's Theresa Lanowitz

AT&T Cybersecurity’s Theresa Lanowitz

“If I am trying to execute something along the lines of ransomware, I have to rely on somebody doing something,” she said. “Now, with this proliferation of IoT devices, which edge computing is, they’re going to attack the device and then move laterally and work with the ransomware gang if that makes sense.”

There are legacy systems that are antiquated, air-gapped systems and networks that aren’t connected and don’t ever get updated or intercommunicate with each other, Mazal said.

“So being able to create a game plan to cycle through these environments and actually implement these controls at an asset or identity level is highly problematic,” he said. “But we’re seeing that’s what the White House is actually pushing for. They’re saying that whatever perimeter defense we’ve been doing up until now is not working and not successful. So we have to start inventing these unique controls across the board, whether that means implementing a tool that’s an aggregate of data that allows you to have insight and visibility into how you go ahead and secure these systems, and you create scheduling for interconnectivity.”

There are systems that can’t be patched and updated, Mazal said.

“These things are 25 years old,” he said. “They have systems that haven’t been touched or looked at since the 80s.”

Destruction as a Service Emerges

Part of the RSAC 2023 panel focused on destruction as a service. Along with ransomware as a service (RaaS), destruction as a service is on the rise, McElroy said.

VMware's Rick McElroy

VMware’s Rick McElroy

“It looks very similar to a ransomware service,” he said. “So I create payloads. You pay me for those commodity payloads; I change them based on your target list. And then of course, I have the infrastructure to go out and facilitate payments, a help desk if people have to call and get crypto and all of that good stuff, so there’s the destruction.”

There’s no strategy for defense-in-depth against outdated systems in critical infrastructure, Mazal said.

“You can access critical infrastructure, and our weakest link is our users of this critical infrastructure,” he said. “Same that happened with Colonial Pipeline. Easily provisioning an account and forgetting to decommission that account at offboarding. We have a ton of risk associated with that.”

Zero trust is a viable option for critical infrastructure and it should be working toward that, Mazal said.

“People have confused the general market about what zero trust is,” Lanowitz said. “It’s a business issue, not a tech issue. It’s a shift in the way business is thinking.”

In addition, automation could help better secure critical infrastructure, but there’s a lot of continuing mistrust and reluctance, Check said.

“It’s a generational problem,” he said. “We need a generational shift. We don’t have the people to do it, but we’re not embracing automation so we don’t need them.”

The panel did agree the Biden administration’s executive order aimed at defending critical infrastructure is a step in the right direction. McElroy said he hopes it prompts legislation to require changes. And Mazal said he wants to learn more about specific requirements and how it translates to all organizations.

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Edward Gately or connect with him on LinkedIn.
Tags: MSPs VARs/SIs Analytics Best Practices Channel Research Cloud IoT Mobility & Wireless Regulation & Compliance Security Technologies Vertical Markets

Most Recent


  • AI and Cloud
    Generative AI and Cloud: Google, Salesforce, Bessemer, BCG Chime In
    Plus non-AI news from OVHcloud and TD Synnex. Yeah, we’re breathing a sigh of relief, too.
  • IT Nation Secure Solutions Pavilion 2023 Feature
    IT Nation Secure Images: Solutions Pavilion with ThreatLocker, SentinelOne, Cisco, Trend Micro, More
    This week's Solutions Pavilion included a record number of exhibitors.
  • Cisco's Jeetu Patel on stage at Cisco Live 2023, Cisco Webex
    Cisco Webex Gets Generative AI Boost, AT&T Network Integration
    In the meantime, AT&T is targeting SMBs with a new self-service platform.
  • Imperva partner program redesigned with 3 tiers
    Imperva Partner Program Redesigned with 3 New Tiers
    Partners can engage in one of four go-to-market strategies.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Cloud PC, desktop as a service
    Desktop as a Service Provider Dizzion Makes Inroads into the Channel
  • 2023 growth for tech advisors
    Tech Advisors Saw Staff Growth, Channel Conflict in Q1
  • Optiv Partners Get Refreshed Channel Program Based on Feedback
  • Channel Partners Conference & Expo (CP Expo) MSP Summit Logo Blue
    Channel Partners Conference Preview: Our Editors Pick 12 Must-Attend Sessions

Upcoming Events

View all

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Channel Partners Conference & Expo

March 11, 2024 - March 14, 2024

Galleries

View all

Generative AI and Cloud: Google, Salesforce, Bessemer, BCG Chime In

June 7, 2023

IT Nation Secure Images: Solutions Pavilion with ThreatLocker, SentinelOne, Cisco, Trend Micro, More

June 7, 2023

Channel Cloud Challenges Abound: Pax8, Dell, VMware, Rackspace Talk

June 7, 2023

Industry Perspectives

View all

Identity Is Increasingly Valuable – and Targeted

May 18, 2023

Gaining a Competitive Advantage through AV Managed Services

May 10, 2023

How to Build an Organization That Attracts and Retains Talent

May 1, 2023

Webinars

View all

From Problem to Profit: Mastering the Science of Selling Using Business Outcomes

May 9, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode No. 123: MartinWolf M&A Advisors, CP Expo Preview

UScellular Takes On Rivals with Partner Program Simplicity

April 21, 2023

OpenText Simplifying Deal Registration, Doubling Down on MDF

April 21, 2023

Everything-as-a-Service: CloudBlue Touts Critical Customer Transition

April 18, 2023

Twitter

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X