Cyber Security Weekly Podcast

Episode 305 - Cyber security is more than just IT incidents


Listen Later

Joseph Weiss (www.controlglobal.com/unfettered (http://www.controlglobal.com/unfettered)) is an industry expert on control systems and electronic security of control systems, with more than 40 years of experience in the energy industry. Mr. Weiss spent more than 14 years at the Electric Power Research Institute (EPRI), the first 5 years managing the Nuclear Instrumentation and Diagnostics Program. He was responsible for developing many utility industry security primers and implementation guidelines.In this podcast, he shares his insights on Industrial Control System risks, from an engineer’s perspective.  By highlighting differences in concepts (such as Purdue versus OSI, Zero trust versus 100 percent trust), he explains how a control engineer’s focus on actual devices (such as sensors) is critical to safely managing control system risks. For example, while data sent from devices could be manipulated by malicious actions such as hacking, there are other threats that are yet to of focus in cybersecurity discussions. These include deliberately compromised hardware at source and hardware “drift”.  He urges the need for a paradigm shift from “cyber physical” to “physical cyber” in managing control system risks, where attention is to be paid to physical risks, supported by cyber risk management. This is what he calls “go back to the future”, to manage control system risks by engineers monitoring process anomalies, of which network is part. Mr. Weiss serves as a member of numerous organizations related to control system security. He is also an invited speaker at many industry and vendor user group security conferences, has chaired numerous panel sessions on control system security, and is often quoted throughout the industry. He has published over 80 papers on instrumentation, controls, and diagnostics including chapters on cyber security for Electric Power Substations Engineering and Securing Water and Wastewater Systems. He coauthored Cyber Security Policy Guidebook and authored Protecting Industrial Control Systems from Electronic Threats. In February 2016, Mr. Weiss gave the keynote to the National Academy of Science, Engineering, and Medicine on control system cyber security. Mr. Weiss has conducted SCADA, substation, nuclear and fossil plant control system, and water systems vulnerability and risk assessments and conducted short courses on control system security. The risk assessments include utility-scale solar farms and wind turbines. He has amassed a database of almost 12 million actual control system cyber incidents. He was a member of Transportation Safety Board Committee on Cyber Security for Mass Transit. He was a subject matter expert to the International Atomic Energy Agency on nuclear plant control system cyber security. Mr. Weiss has received numerous industry awards, including the EPRI Presidents Award (2002) and is an ISA Fellow, Managing Director of ISA Fossil Plant Standards, ISA Nuclear Plant Standards, ISA Industrial Automation and Control System Security (ISA99), a Ponemon Institute Fellow, and an IEEE Senior Member. He has been identified as a Smart Grid Pioneer by Smart Grid Today. He is a Voting Member of the TC65 TAG and a US Expert to TC65 WG10, Security for industrial process measurement and control – network and system security and IEC TC45A Nuclear Plant Cyber Security. Mr. Weiss was featured in Richard Clarke and RP Eddy’s book- Warning – Finding Cassandras to Stop Catastrophes. He has patents on instrumentation, control systems, and OT networks.
...more
View all episodesView all episodes
Download on the App Store

Cyber Security Weekly PodcastBy MySecurity Media

  • 3.9
  • 3.9
  • 3.9
  • 3.9
  • 3.9

3.9

19 ratings


More shows like Cyber Security Weekly Podcast

View all
Pop Culture Happy Hour by NPR

Pop Culture Happy Hour

11,585 Listeners

Global News Podcast by BBC World Service

Global News Podcast

7,707 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,654 Listeners

Risky Business by Risky Business Media

Risky Business

372 Listeners

Security Weekly News (Audio) by Security Weekly Productions

Security Weekly News (Audio)

33 Listeners

The Daily by The New York Times

The Daily

113,075 Listeners

Up First from NPR by NPR

Up First from NPR

56,825 Listeners

The Indicator from Planet Money by NPR

The Indicator from Planet Money

9,563 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

178 Listeners

If You're Listening by ABC

If You're Listening

329 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Huberman Lab by Scicomm Media

Huberman Lab

29,300 Listeners

The Fin by Australian Financial Review

The Fin

24 Listeners