Keynote & Theme: Believe!

Dale Peterson

S4x24 - ICS Security Conference · Day 1 · Main Stage

Overview

In his compelling keynote address at S4, Dale Peterson, an industry veteran and former NSA cryptanalyst, challenged the prevailing mindset within Operational Technology (OT) security. Titled "Believe!", Peterson's talk explored the profound impact of belief—or the lack thereof—on the success and well-being of cybersecurity professionals tasked with defending critical infrastructure. He argued that the pervasive narrative of an attacker needing only one success against a defender who must be perfect is not only demoralizing but also fundamentally flawed, leading to stress and missed opportunities.

Watch on YouTube

Visual summary for Keynote & Theme: Believe! by Dale Peterson
Visual summary for Keynote & Theme: Believe! by Dale Peterson

Key moments

  1. 0:00 NSA cryptanalyst experience and the power of belief
  2. 2:00 Direct question: Believing in preventing high-consequence OT attacks
  3. 2:26 The powerful placebo effect demonstrated with acupuncture
  4. 4:00 Challenging the 'perfect' fallacy in OT security
  5. 5:48 Learning from safety: Measuring success beyond zero incidents

Keynote & Theme: Believe!

Speakers: Dale Peterson

Conference: S4

YouTube: https://www.youtube.com/watch?v=0ByTj8GTHHk

Overview

In his compelling keynote address at S4, Dale Peterson, an industry veteran and former NSA cryptanalyst, challenged the prevailing mindset within Operational Technology (OT) security. Titled "Believe!", Peterson's talk explored the profound impact of belief—or the lack thereof—on the success and well-being of cybersecurity professionals tasked with defending critical infrastructure. He argued that the pervasive narrative of an attacker needing only one success against a defender who must be perfect is not only demoralizing but also fundamentally flawed, leading to stress and missed opportunities.

Peterson leveraged his unique background in code-breaking and compelling scientific evidence, such as the placebo effect, to illustrate how deeply ingrained beliefs shape outcomes. He posited that by fostering a belief in our ability to succeed, even in the face of formidable adversaries like Volt Typhoon or Sandworm, OT security teams can become more effective and resilient. The keynote served as a critical call to action, urging the community to re-evaluate its metrics, celebrate its often-overlooked successes, and cultivate a more optimistic and sustainable approach to defending the industrial control systems that underpin modern society.

This talk is particularly significant for the OT security community, which frequently grapples with high stakes and a perceived asymmetry of advantage favoring attackers. Peterson's message offers a refreshing perspective, emphasizing psychological resilience and strategic reframing as crucial, yet often neglected, components of a robust defense strategy. By shifting focus from an unattainable ideal of perfection to a more realistic and measurable standard of success, the industry can empower its professionals and build a stronger, more confident security posture.

Background

▶ Watch: NSA cryptanalyst experience and the power of belief (0:00)

The landscape of Operational Technology (OT) security is often characterized by a pervasive sense of dread and an overwhelming burden of responsibility. For years, the mantra has been that "the attacker just has to succeed one time while the defender has to stop all attacks." This foundational belief, while seemingly rooted in the reality of cyber warfare, inadvertently cultivates a culture of perfectionism that is both unrealistic and psychologically damaging. OT security professionals, tasked with protecting critical infrastructure from potentially catastrophic cyber-physical incidents, operate under immense pressure. The constant exposure to reports of sophisticated threat actors and novel attack vectors, often presented in ominous terms, further exacerbates this stress, making it difficult for individuals to genuinely believe in their long-term success.

Dale Peterson drew parallels from his early career as a cryptanalyst at the National Security Agency (NSA). He recounted how young code breakers were progressively given harder problems. While brilliance was a common trait among them, Peterson observed a crucial differentiator: the element of belief. Those who consistently achieved breakthroughs, even on systems thought to be unbreakable, were often the ones who came to work every day believing they would succeed. In contrast, cryptanalysts who lacked this conviction often performed routine tasks without significant progress, eventually missing opportunities to crack codes simply because they didn't believe it was possible. This anecdotal evidence from a high-stakes intelligence environment underscores the historical significance of belief in overcoming complex security challenges.

To further solidify his argument about the power of belief, Peterson cited the well-documented placebo effect. He presented a compelling example involving acupuncture: ten German health insurance companies conducted a study with almost half a million patients suffering from lower back pain. Three out of four patients reported a marked or moderate reduction in pain after acupuncture treatments, a result superior to standard medical treatments and at a lower cost. However, a subsequent study introduced a control group that believed they were receiving acupuncture but were only lightly touched with a toothpick, without needles. The results for this "sham acupuncture" group were almost identical to those who received actual acupuncture, demonstrating that the belief in the treatment, rather than the treatment itself, was a significant driver of pain reduction for back pain, neck pain, and migraine headaches. This scientific evidence serves as a powerful metaphor for OT security: if belief can physically alter a person's experience of pain, it can certainly influence the effectiveness and morale of a security team. The challenge, Peterson highlighted, is that current narratives and metrics in OT security actively undermine this essential belief.

Key Findings

▶ Watch: Direct question: Believing in preventing high-consequence OT attacks (2:00)

Peterson's keynote distilled several critical findings that challenge conventional wisdom in OT security and propose a paradigm shift. The primary finding is the profound and often underestimated power of belief, even a false one, in shaping outcomes and human performance. Drawing from his cryptanalysis experience and the placebo effect studies, Peterson demonstrated that conviction in success is a crucial, if intangible, asset. He argued that the prevailing negative narrative in OT security—where defenders must be perfect against adversaries who only need one win—systematically erodes this vital belief among professionals.

A second key finding is that the current metrics and public discourse around OT security are counterproductive. By constantly highlighting the growing number of "ominous sounding adversaries" such as Volt Typhoon, Chernovite, and Sandworm Incontroller, and emphasizing the inevitability of failure, the industry inadvertently fosters a sense of hopelessness. Peterson contended that this focus on "almost godlike villains" and the unattainable goal of absolute perfection makes it impossible for security professionals to genuinely believe they can prevent all attacks against critical assets like computers, switches, PLCs, sensors, and actuators. This leads to chronic stress and a feeling of being perpetually behind.

Finally, Peterson's most actionable finding is the urgent need for different metrics and narratives that celebrate success rather than solely focusing on failures. He advocated for a shift away from a "perfection or bust" mentality towards a more realistic and empowering measure of efficacy. By learning from fields like safety, which tracks metrics such as the Total Recordable Incident Rate (TRIR) where a rate below three is considered "good" (not zero), OT security can begin to quantify and acknowledge its achievements. This reframing, Peterson argued, is essential to "feed the belief that we can succeed" and prevent security teams from "marking time" until the inevitable, rather than actively innovating and thriving.

Technical Deep Dive

▶ Watch: The powerful placebo effect demonstrated with acupuncture (2:26)

While Dale Peterson's keynote was not a deep dive into specific code exploits, network protocols, or architectural vulnerabilities, it presented a critical meta-technical analysis of how the perception and measurement of technical security impact actual defensive capabilities. The "technical" aspect here lies in the frameworks and mindsets that govern how we approach the technical challenges of OT security.

The talk implicitly critiques the current operational models and reporting structures within OT security, which often prioritize the identification and remediation of every single vulnerability or failed attack attempt. This approach, while seemingly thorough, contributes to the "perfection" fallacy. In a complex OT environment, characterized by a vast array of legacy systems, interconnected devices (PLCs, sensors, actuators), and intricate supply chains, achieving absolute perfection is an engineering impossibility. Latent vulnerabilities are inherent in products, human error is unavoidable, and the sheer number of interacting components creates an enormous attack surface. Therefore, the technical goal should not be zero incidents, but rather a measurable and manageable reduction in risk and impact.

Peterson highlighted the psychological impact of highly publicized, sophisticated threat groups like Volt Typhoon, Chernovite, and Sandworm Incontroller. These groups, known for their advanced persistent threat (APT) capabilities and focus on critical infrastructure, represent the apex of cyber adversary skill. While awareness of such threats is crucial for intelligence-driven defense, their constant portrayal as "almost godlike villains" can be paralyzing. Technically, understanding their tactics, techniques, and procedures (TTPs) is valuable, but the narrative often overshadows the successful defensive actions taken against them or the fact that many of their attempts are indeed thwarted.

The proposed "technical" solution lies in adopting a more nuanced approach to metrics and reporting. Instead of merely counting successful breaches or unmitigated vulnerabilities, Peterson suggested drawing inspiration from industrial safety. The Total Recordable Incident Rate (TRIR) is a widely accepted metric in safety, calculated as:

(Number of Injuries and Other Safety Incidents * 200,000) / Total Number of Hours Worked

A TRIR below three is typically considered "good" in industrial sectors, signifying a robust safety program, even though it acknowledges that incidents still occur. This metric provides a quantifiable, non-zero target that allows organizations to track progress and demonstrate program effectiveness without demanding an impossible standard. For OT security, analogous metrics could focus on:

  • Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR) for OT incidents.
  • The number of prevented high-consequence events (e.g., successful containment of an attack before physical impact).
  • The reduction in attack surface over time (e.g., patching rates, segmentation improvements).
  • The successful deployment and testing of recovery plans after simulated attacks.

These types of metrics, unlike a simple "zero incidents" goal, allow for the technical measurement of defense effectiveness, improvement over time, and the celebration of successful mitigations and incident responses. They shift the technical focus from an all-or-nothing outcome to a continuous improvement model, which is more realistic and empowering for the technical teams on the front lines. The underlying technical challenge remains complex, but the measurement of success fundamentally alters the approach to tackling it.

Demo / Proof of Concept

▶ Watch: Challenging the 'perfect' fallacy in OT security (4:00)

As a keynote address focused on the philosophical and psychological aspects of cybersecurity, Dale Peterson's "Believe!" talk did not include a technical demonstration or a proof of concept. The objective of this presentation was to provoke thought, challenge existing mindsets, and inspire a change in perspective rather than to showcase a specific tool, exploit, or defensive technology. The concepts presented, such as the power of belief and the impact of metrics, are inherently abstract and best conveyed through narrative and analogy rather than live technical demonstrations.

Defensive Implications

▶ Watch: Learning from safety: Measuring success beyond zero incidents (5:48)

The defensive implications of Dale Peterson's keynote are profound, urging OT security professionals to reconsider not just what they defend, but how they perceive and measure their defense efforts. The core message empowers defenders to move beyond a debilitating pursuit of perfection and embrace a more sustainable, belief-driven strategy.

Firstly, defenders must actively work to reframe their mindset from one of inevitable failure to one of achievable success. This involves consciously challenging the "attacker only needs one win" narrative and replacing it with an understanding that every thwarted attack, every detected intrusion, and every successful recovery is a victory that deserves recognition. Security teams should be encouraged to celebrate these successes, no matter how small, to build collective confidence and reinforce the belief that their efforts are making a tangible difference.

Secondly, a critical defensive implication is the need to adopt new, more realistic metrics for OT security. Emulating the safety industry's approach with metrics like Total Recordable Incident Rate (TRIR) provides a viable path forward. Instead of striving for an unattainable zero-incident rate, organizations should develop metrics that quantify the reduction of risk, the effectiveness of controls, and the speed of response. For example, tracking the number of high-consequence events prevented or the average Mean Time To Contain (MTTC) an incident offers a measurable benchmark for success. These metrics should be communicated clearly and consistently throughout the organization to foster a shared understanding of progress and reinforce belief in the security program's efficacy.

Thirdly, defenders should focus on building resilience and recovery capabilities as primary defensive strategies, rather than solely on prevention. Recognizing that perfection is impossible means accepting that some attacks will inevitably bypass initial defenses. Therefore, robust incident response plans, effective segmentation, immutable backups, and well-rehearsed disaster recovery procedures become paramount. Demonstrating the ability to quickly detect, contain, and recover from an attack, minimizing its impact, is a powerful form of success that directly contributes to belief in the overall security posture.

Finally, the talk implicitly advocates for a shift in threat intelligence consumption and communication. While understanding advanced adversaries like Volt Typhoon, Chernovite, and Sandworm Incontroller is crucial, the presentation of this information should be balanced. Instead of solely emphasizing their "godlike" capabilities, threat intelligence should also highlight successful defensive strategies employed against them, common points of failure for attackers, and actionable insights that empower defenders. This balanced perspective can transform threat intelligence from a source of fear into a tool for informed and confident defense planning, reinforcing the belief that even the most sophisticated threats can be managed and mitigated.

Key Takeaways

  • Belief is a Powerful Defensive Tool: A genuine conviction in one's ability to succeed, even against formidable odds, significantly enhances performance and resilience in OT security. This is supported by the speaker's NSA cryptanalysis experience and the scientific evidence of the placebo effect.
  • Perfectionism is a Detriment: The prevailing belief that "the attacker just has to succeed one time while the defender has to stop all attacks" is an unrealistic and demotivating standard that fosters stress and hinders progress.
  • Current Metrics Undermine Morale: The constant focus on "ominous sounding adversaries" like Volt Typhoon, Chernovite, and Sandworm Incontroller, combined with a lack of celebration for successes, erodes the belief of OT security professionals.
  • Adopt Realistic Success Metrics: The OT security community should learn from the safety industry's Total Recordable Incident Rate (TRIR), where "good" is a measurable rate below zero (e.g., below three), not an impossible absolute zero.
  • Celebrate Successes to Feed Belief: Actively identify, communicate, and celebrate successful defensive actions, incident preventions, and effective mitigations to build confidence and foster a positive, proactive security culture.
  • Shift Narrative and Focus: Move from a narrative of inevitable failure against "godlike villains" to one that highlights achievable progress, resilience, and the measurable impact of defensive efforts.

About the Speaker(s)

Dale Peterson is a distinguished figure in the field of Operational Technology (OT) security, known for his thought leadership and unique perspective. His career began as a cryptanalyst and code breaker with the National Security Agency (NSA), where he gained early insights into the importance of belief and perseverance in tackling complex, seemingly insurmountable challenges. This foundational experience shaped his understanding of human factors in security, which he brought to bear in his keynote address. As a prominent voice at conferences like S4, Peterson continues to influence the direction and mindset of the OT security community, urging a shift towards more empowering and effective strategies.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Dale Peterson's "Believe!" keynote at S4 delivers a crucial, much-needed psychological and strategic intervention for the OT security community. Leveraging his NSA cryptanalysis background and scientific evidence like the placebo effect, Peterson effectively dismantles the demoralizing "attacker only needs one win" narrative. He argues for a fundamental shift in mindset and metrics, urging defenders to cultivate belief in their capabilities and celebrate successes, moving away from an unattainable perfectionist ideal towards a more realistic, empowering, and sustainable defense posture. This talk provides actionable insights for leaders and practitioners to combat stress and build more…

Heather Calloway (CISO) — STRONG ACCEPT

Dale Peterson's "Believe!" keynote is a timely and essential call for a paradigm shift in how we approach and measure success in OT security. By challenging the perfectionist mindset and advocating for realistic, empowering metrics, Peterson addresses a critical, often-overlooked dimension of institutional resilience: the human element. This isn't just a feel-good talk; it's a strategic argument for fostering the belief necessary to build sustainable, effective security programs, directly impacting team performance, risk reporting, and overall business posture.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference