🟠 Our next OutofBand podcast touches on Operational Technology (OT) Security with our OT SMEs - Dominika Rusek and Alex Stavroulakis. Alex and Dominika demystify the buzzwords IT vs OT vs IoT vs IIoT which we hear a lot about in a simplified manner. We focus on OT systems and discuss the challenges faced in securing them, the skills required and how to gain experience in them without having access to the actual gear. Finally, we touch on their perception around diversity in OT Security and what can be done about it.
Curious for more? Tune In!
-- Guest Profiles --
Dominika Rusek
LinkedIn: https://www.linkedin.com/in/dominikarusek/
Alex Stavroulakis
LinkedIn: https://www.linkedin.com/in/alexstavroulakis/
-- 🎧 Listen via Podcast --
Spotify: https://open.spotify.com/show/6q7bbcQUXEn1kjbRwcsAA6?si=CxmhRZKUSxm__bJrjWi6FQ&utm_source=copy-link&dl_branch=1
Google Podcast: https://podcasts.google.com/feed/aHR0cHM6Ly9hbmNob3IuZm0vcy81ZjRlNzU3OC9wb2RjYXN0L3Jzcw
Apple Podcast: https://podcasts.apple.com/us/podcast/out-of-band/id1572330733
— References —
Here are a couple of resources shared by our guests to get you started. We hope you find them useful.
A) Reading materials:
+ Industrial Network Security book by E.Knapp - https://www.amazon.com/Industrial-Network-Security-Securing-Infrastructure/dp/0124201148
+ Hacking Exposed Industrial Control Systems by C. Bodungen - https://www.amazon.com/Hacking-Exposed-Industrial-Control-Systems/dp/1259589714
+ ICS reading list by Dragos - https://www.dragos.com/blog/industry-news/a-dragos-industrial-control-system-security-reading-list/
B) Trainings:
+ Trainings offered by Cybersecurity & Infrastructure Security Agency -https://www.cisa.gov/uscert/ics/Training-Available-Through-CISA
+ Trainings offered by SANS:
GICSP - https://www.giac.org/certifications/global-industrial-cyber-security-professional-gicsp/
GRID - https://www.sans.org/cyber-security-courses/ics-visibility-detection-response/
ICS Cybersecurity In-Depth - https://www.sans.org/cyber-security-courses/ics-cyber-security-in-depth/
+ Virtual Training Grounds - https://www.fortiphyd.com/training/
+ OpenPLC project - https://www.openplcproject.com/
C) Creating your own OT lab:
+ FactoryIO - https://factoryio.com/
+ CLICK Programmable Controllers - https://www.automationdirect.com/adc/overview/catalog/programmable_controllers/click_series_plcs/click_plcs_(stackable_micro_brick)
+ Velocio PLC’s - https://velocio.net/
D) Example ICS conferences - Defcon ICS Village, s4x22, SANS ICS Security Summits
––––––––––––––––––––––––––––––
Track: Drive — Markvard [Audio Library Release]
Music provided by Audio Library Plus
Watch: https://youtu.be/3dQDaKnyiX0
Free Download / Stream: https://alplus.io/drive
––––––––––––––––––––––––––––––