The Worst ICS OT Love Story Ever Told
Mike Holcomb
DEF CON 33 · Day 1 · Main Stage
Overview
Mike Holcomb's DEF CON talk, "The Worst ICS OT Love Story Ever Told," delves into the alarming state of cybersecurity within Industrial Control Systems (ICS) and Operational Technology (OT) environments. The presentation argues that a pervasive lack of fundamental security practices, awareness, and resources has created a critical vulnerability, making it "too easy" for attackers—ranging from low-skill activists to sophisticated state-sponsored groups—to compromise essential infrastructure. Holcomb's ironic "love story" title underscores the tragic reality of how negligence and convenience have inadvertently fostered an environment ripe for exploitation, leading to potentially devastating real-world impacts.

Key moments
- 0:00 Introduction: 'Worst Love Story' and 'Hackers' movie
- 2:45 Introducing the Critical Draos OT/ICS Cybersecurity Report
- 4:15 Alarming Remote Access and Internet-Exposed SSH in OT
- 6:00 Critical Gap: Less Than 5% of OT Networks Monitored
- 6:30 Emerging Threat: Alignment Between State Actors and Activists
- 7:50 Real-World Impact: Activist Attack Causes Ireland Water Outage
The Worst ICS OT Love Story Ever Told
Speakers: Mike Holcomb
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=ruVlunKr4BY
Overview
Mike Holcomb's DEF CON talk, "The Worst ICS OT Love Story Ever Told," delves into the alarming state of cybersecurity within Industrial Control Systems (ICS) and Operational Technology (OT) environments. The presentation argues that a pervasive lack of fundamental security practices, awareness, and resources has created a critical vulnerability, making it "too easy" for attackers—ranging from low-skill activists to sophisticated state-sponsored groups—to compromise essential infrastructure. Holcomb's ironic "love story" title underscores the tragic reality of how negligence and convenience have inadvertently fostered an environment ripe for exploitation, leading to potentially devastating real-world impacts.
The talk serves as a stark warning, moving beyond theoretical threats to highlight tangible consequences, such as power blackouts and industrial explosions, directly attributable or strongly linked to cyber-attacks. Holcomb emphasizes that despite the increasing sophistication of adversaries, the vast majority of successful attacks exploit basic security gaps, not advanced zero-days. He advocates for a return to foundational cybersecurity principles, asserting that these often-overlooked measures are sufficient to defend against the full spectrum of threats targeting OT/ICS today.
This analysis is particularly crucial for anyone involved in critical infrastructure, manufacturing, and other industrial sectors, as well as cybersecurity professionals seeking to understand the unique challenges and effective defensive strategies in OT. Holcomb's insights, drawn from extensive experience and data from leading industry reports, paint a sobering picture of vulnerability but also offer a clear, actionable path forward through the disciplined application of cybersecurity fundamentals.
Background
▶ Watch: Introduction: 'Worst Love Story' and 'Hackers' movie (0:00)
Holcomb begins by drawing a compelling parallel between fictional depictions of cyber warfare and real-world OT/ICS threats. He references the 1995 movie Hackers, noting its prescient portrayal of an OT-specific attack where a protagonist remotely controls robotic arms in a TV station, and the "Da Vinci virus" designed to capsize an oil tanker. This fictional foresight, 15 years before the world knew about Stuxnet in 2010, highlights that the concepts of industrial cyber warfare have been simmering for decades.
The core of Holcomb's background analysis relies heavily on the Dragos OT/ICS Cybersecurity Year in Review report, which he describes as the "Verizon DBIR for the OT world." This report underscores several disturbing trends:
- Ransomware attacks against industrial environments are steadily increasing, a trend observed since incidents like the Colonial Pipeline attack four years prior. Dragos tracks a growing number of ransomware groups specifically targeting industrial sectors.
- Manufacturing is the number one targeted sector, primarily due to its widespread presence and often minimal security posture. Holcomb cites a client with 100 plants across North America lacking even a firewall between IT and OT, making them easy targets for ransomware infections.
- Alarmingly, 65% of environments assessed or incident-responded by Dragos exhibited unsecure remote access, making it simple for attackers to pivot into the OT network.
- Even more concerning, 45% of these environments had active SSH connections to the internet, often used for remote administration, but with unknown authorization status.
- A critical systemic failure is the severe lack of visibility: less than 5% of global OT organizations actively monitor their networks. Furthermore, Holcomb estimates that roughly half of those who do are performing "a really bad job" at it. This lack of monitoring means that many attacks go undetected or unattributed.
Holcomb then pivots to discuss the evolving threat landscape, specifically the alignment between state actors and activists. Traditionally, activists (e.g., the Iranian Cyber Avengers) are numerous and highly visible, often aiming to make a point with low technical impact (e.g., defacing HMIs or causing minor outages like the two-day water loss for 160 people in Ireland). State adversaries, on the other hand, are fewer but inflict high impact, as exemplified by the Sandworm group's blackouts in Ukraine in 2015 and 2016, affecting hundreds of thousands in sub-zero temperatures. The worrying trend identified by Dragos is the convergence of these groups, such as the Cyber Army of Russia Reborn aligning with state adversaries like Sandworm, merging the activists' visibility with state actors' destructive capabilities. This convergence blurs attribution and elevates the potential impact of attacks, making geopolitical considerations increasingly difficult to separate from incident response.
Key Findings
▶ Watch: Alarming Remote Access and Internet-Exposed SSH in OT (4:15)
The central and most impactful finding of Holcomb's talk is his assertion that "we're making it too easy for attackers in OT/ICS today." This isn't due to insurmountable technical challenges or the sheer power of advanced persistent threats (APTs), but rather a systemic failure in basic security hygiene. The reasons for this widespread vulnerability are multifaceted:
- Pervasive Lack of Awareness and Education: Many organizations, especially smaller utilities, co-ops, farms, and manufacturing facilities, simply don't understand the unique risks and best practices for OT cybersecurity.
- Severe Lack of Resources: Unlike large oil companies that can invest heavily, the vast majority of OT organizations lack dedicated IT or OT cybersecurity personnel, let alone comprehensive security programs. This resource scarcity directly contributes to the prevalence of unsecure remote access and unmonitored networks.
- The Power of Fundamentals: Contrary to popular belief, Holcomb argues that mastering the fundamentals of OT cybersecurity is sufficient to defend against the entire spectrum of threats—from low-skill activists and sophisticated ransomware operators to the most advanced state adversaries. He even states that it's "actually easier to secure OT environments than it is IT" by focusing on these basics.
- Real-World Impact is Underestimated: Holcomb passionately stresses that even "low impact" incidents, like a two-day water outage for 160 people or heating loss for 600 apartment buildings, have significant real-world consequences for those affected. He challenges the complacency that arises from geographical distance, warning that these impacts "are going to come here, too."
- Circumstantial Evidence of Cyber-Induced Catastrophe: The talk presents a compelling, albeit circumstantial, case for a cyber-induced explosion at a US petrochemical facility. The incident occurred after six weeks of persistent attacks by Sandworm, and the CEO attributed the explosion to a tripped Safety Instrumented System (SIS)—precisely the target of the original Tricus incident attributed to Sandworm. The lack of network evidence was explained by the organization being among the 95% not monitoring their networks, highlighting how a lack of visibility can obscure the true cause of incidents.
In essence, the "worst love story" is the industry's continued embrace of convenience and cost-cutting over essential security, leading to an environment where predictable, preventable attacks are commonplace and increasingly impactful.
Technical Deep Dive
▶ Watch: Critical Gap: Less Than 5% of OT Networks Monitored (6:00)
Holcomb provides concrete examples of how easily OT environments can be compromised, focusing on the simplicity of the attack vectors and the widespread presence of vulnerable systems.
A key illustration is the Frosty Goop malware. This seemingly unsophisticated piece of code, capable of being recreated using ChatGPT in "30 seconds or less," was used to shut off heating for 600 apartment buildings in Ukraine during winter, causing a two-day outage in sub-zero temperatures. Frosty Goop is classified as ICS-specific malware because it directly targets the control systems governing the heating infrastructure.
The specific control systems targeted were manufactured by Enko. Holcomb demonstrates how these vulnerable devices can be readily identified using search engines like Shodan. By simply typing "enko" into Shodan, one can find a list of exposed controllers, including many in Ukraine. These controllers often expose port 23 (Telnet), a common IT port, and more critically, port 502 (Modbus).
Modbus is highlighted as the most commonly used protocol in OT environments. Its critical vulnerability, and the reason attackers favor it, is its unauthenticated nature. This means that an attacker connecting to a Modbus port is not prompted for a username or password, effectively gaining "full administrative control" to read and write to the device's registers. These registers store values that dictate how the controller operates, allowing an attacker to directly manipulate industrial processes. Holcomb shows a screenshot of an Enko controller's command-line interface, accessible via Telnet, and explains how Modbus allows direct manipulation of inputs and outputs without needing to traverse the Telnet menu or authentication (which only seems to apply to resetting or configuring ports).
Holcomb also demonstrated his own recreation of Frosty Goop, which he dubbed Snow Crash, built in Python with the aid of ChatGPT. This tool showcases the ease with which an attacker can connect to an IP address and use Modbus commands to read and change register values, thereby controlling the targeted industrial equipment.
The discussion of Safety Instrumented Systems (SIS) further underscores the potential for catastrophic technical impact. Holcomb recounts the Sandworm attack on a petrochemical facility in the Middle East in 2017, where the group had "a dozen ways... to create an explosion." He then ties this to a more recent, last year's incident in the United States involving another petrochemical facility. After six weeks of Sandworm attacks, an explosion occurred. The CEO attributed it to the plant's SIS tripping, which is the failsafe backup system. The critical point is that SIS was the primary target in the original Tricus incident, strongly suggesting a cyber-physical attack. However, due to the facility being among the 95% that do not monitor their networks, "no evidence on the network" was found, illustrating how fundamental security gaps mask the true nature of sophisticated attacks.
In a Q&A segment, Holcomb addresses hardware security, acknowledging that vendors like Siemens are making strides in finding vulnerabilities and offering bug bounties. However, he emphasizes that many vulnerabilities stem from the inherent insecurity of legacy protocols like Modbus, which was developed over 30 years ago when cybersecurity was not a consideration. The slow adoption of newer, more secure protocols, combined with the fact that most OT environments are 5 to 30+ years old, means these fundamental protocol-level vulnerabilities will persist for a long time.
Demo / Proof of Concept
▶ Watch: Emerging Threat: Alignment Between State Actors and Activists (6:30)
While Holcomb did not perform a live, real-time "demo" in the traditional sense, he effectively presented a compelling proof of concept through his discussion and visual aids.
The core demonstration revolved around the ease of recreating and deploying malware like Frosty Goop. Holcomb explicitly stated that he built his own version, named Snow Crash, using Python and ChatGPT in minutes. He described how this tool could connect to an IP address and facilitate reading and writing to devices running the Modbus protocol, allowing for the manipulation of registers that control industrial operations. This directly illustrated how simple, readily available tools can be used to develop functional ICS-specific malware.
Furthermore, Holcomb showcased how readily vulnerable Enko controllers could be identified on the internet. He displayed a screenshot from Shodan, demonstrating that a simple search for "enko" reveals numerous exposed devices, many of which were located in Ukraine. He pointed out the open port 23 (Telnet) and port 502 (Modbus) on these devices, emphasizing the direct access attackers could gain. He also included a screenshot of the Enko controller's menu, accessible via Telnet, to provide context for the type of system being targeted.
By explaining how his Snow Crash tool, like Frosty Goop, interacts with the unauthenticated Modbus protocol to directly manipulate device registers, Holcomb provided a clear, step-by-step conceptual demonstration of the attack vector without needing to execute live code. This effectively highlighted the low barrier to entry for exploiting these critical vulnerabilities.
Defensive Implications
▶ Watch: Real-World Impact: Activist Attack Causes Ireland Water Outage (7:50)
Holcomb's talk provides a clear, actionable roadmap for defenders, emphasizing that the most effective defense against the full spectrum of OT/ICS threats lies in mastering cybersecurity fundamentals. He asserts that these basic "blocking and tackling" measures are sufficient to protect against activists, ransomware operators, and even advanced state adversaries.
The five critical fundamentals he outlines are:
- Backup and Recovery: Recognizing that compromise is a matter of "when" not "if," robust backup and recovery plans are paramount. This ensures business continuity and minimizes downtime, especially in OT environments where safety incidents or physical harm could result from prolonged outages.
- Asset Management: Knowing precisely what assets exist within the OT environment is foundational. This includes understanding their purpose, location, and connectivity, which is essential for identifying vulnerabilities and prioritizing defensive efforts.
- Secure Network Architecture: Holcomb stresses this as the starting point and the "number one way to reduce your risk." Implementing a firewall between IT and OT networks is crucial, as the vast majority of attacks originate from the IT side. He clarifies that this is not an "OT versus IT" stance but a necessity for collaboration and holistic organizational protection.
- Incident Response: Organizations must be prepared for a compromise. This involves having a well-defined incident response plan, trained personnel, and the tools necessary to detect, contain, eradicate, and recover from an attack effectively.
- Continuous Vulnerability Management: Regularly identifying and addressing security gaps is vital. This proactive approach ensures that the organization is continually improving its security posture and reducing its attack surface, striving to be "more secure today than we were yesterday."
Beyond these five fundamentals, Holcomb implicitly advocates for increased network security monitoring, acknowledging its importance despite resource constraints for many organizations. The anecdote of the petrochemical explosion with "no evidence on the network" directly underscores the critical need for monitoring to detect intrusions and understand attack vectors.
Addressing the root causes of vulnerability, Holcomb highlights the need to overcome the lack of awareness, education, and resources prevalent in many OT organizations. While large enterprises might invest heavily, smaller entities like local water utilities and co-ops struggle. The message is clear: even with limited resources, focusing on the outlined fundamentals will drastically reduce risk. The talk ultimately empowers defenders by reframing the challenge not as an arms race against sophisticated attackers, but as a consistent application of well-understood security principles.
Key Takeaways
- OT/ICS environments are alarmingly vulnerable due to fundamental security neglect: A significant percentage of industrial organizations suffer from unsecure remote access (65%), active internet-facing SSH connections (45%), and a severe lack of network monitoring (less than 5%).
- Basic cybersecurity fundamentals are highly effective against all threat actors: Implementing robust backup and recovery, asset management, secure network architecture (IT/OT segmentation), incident response, and continuous vulnerability management can defend against activists, ransomware, and state-sponsored groups.
- Unauthenticated legacy protocols like Modbus pose critical risks: Widespread use of protocols designed without security in mind, such as Modbus on port 502, allows attackers to gain full administrative control over devices without any authentication, as demonstrated by the Frosty Goop malware.
- The convergence of activist and state-sponsored groups escalates the threat landscape: The collaboration between groups like the Cyber Army of Russia Reborn and Sandworm combines the visibility and frequency of activist attacks with the high-impact capabilities of state adversaries, leading to more dangerous outcomes.
- Real-world physical impact on critical infrastructure is a growing and underappreciated concern: Incidents like the heating shutdown in Ukraine via Enko controllers or the circumstantial evidence of a cyber-induced explosion at a US petrochemical facility (potentially by Sandworm targeting SIS) underscore the severe human and economic consequences of OT cyberattacks.
- Lack of network visibility masks the true cause of incidents: The fact that 95% of OT organizations do not monitor their networks means that many cyber-attacks, even those with significant physical consequences, go undetected or cannot be definitively attributed, hindering effective response and prevention.
About the Speaker(s)
Mike Holcomb is a seasoned expert in OT/ICS cybersecurity, known for his practical approach and extensive experience as a longtime incident responder. He is deeply committed to raising awareness and improving education in the field, actively sharing his knowledge through various platforms. Holcomb maintains a strong presence on LinkedIn and provides over 50 hours of free OT cybersecurity courses on YouTube, aiming to bridge the knowledge gap for organizations with limited resources. In his day job, he works with major oil companies like Shell and Ramos, helping them build robust cybersecurity programs. His insights are informed by direct experience with state adversaries making runs at his customers and his participation in prominent industry events, including the S4 conference.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Holcomb is a credible practitioner delivering a well-structured OT awareness talk with real data and a reproducible-in-minutes PoC that lands the 'low barrier to entry' point cleanly. The Dragos stat stack, the Frosty Goop recreation, and the Sandworm-SIS-explosion thread are the genuine highlights, but this is fundamentally an education and awareness session — not novel research — and it lands squarely in 'solid conference filler' territory rather than anything that advances the field.
Heather Calloway (CISO) — SOLID
Holcomb delivers a credible, grounded warning about OT/ICS security failure — the data is real, the examples are concrete, and the fundamentals message is correct. But the talk stays in awareness mode and never reaches the institutional accountability or governance framing that would make it land differently in a boardroom than it does at DEF CON.