Priority Is In The Eye Of The Asset Owner
Danielle Jablanski
S4x24 - ICS Security Conference · Day 1 · Stage 2
Overview
In the critical and often chaotic realm of operational technology (OT) cybersecurity, a fundamental challenge persists: how to effectively prioritize security efforts when nearly everything is deemed "critical." Danielle Jablanski, in her compelling S4x24 talk, addresses this pervasive dilemma head-on, asserting that true prioritization stems not from top-down mandates or generalized assessments, but from the nuanced perspective of the asset owner themselves. Her presentation introduces a structured methodology, the STAR (Situation, Task, Action, Result) foundation, designed to empower asset owners to articulate their specific cyber-physical risks and, in doing so, unlock meaningful security prioritization.

Key moments
- 0:00 Introduction and talk structure
- 0:50 Two Truths and a Lie: Setting the stage
- 2:09 The situation: When everything is critical, nothing is
- 3:45 The task: Defining and prioritizing OT incidents
- 4:45 The action: Addressing preparedness and data gaps
- 6:17 Key takeaway: Priority is in the eye of the asset owner
- 6:53 Introducing the standardized priority score
Priority Is In The Eye Of The Asset Owner
Speakers: Danielle Jablanski
Conference: S4
YouTube: https://www.youtube.com/watch?v=gPcwLA4SRFs
Overview
In the critical and often chaotic realm of operational technology (OT) cybersecurity, a fundamental challenge persists: how to effectively prioritize security efforts when nearly everything is deemed "critical." Danielle Jablanski, in her compelling S4x24 talk, addresses this pervasive dilemma head-on, asserting that true prioritization stems not from top-down mandates or generalized assessments, but from the nuanced perspective of the asset owner themselves. Her presentation introduces a structured methodology, the STAR (Situation, Task, Action, Result) foundation, designed to empower asset owners to articulate their specific cyber-physical risks and, in doing so, unlock meaningful security prioritization.
Jablanski's work, informed by an exercise with the Water ISAC, highlights the inherent subjectivity of cybersecurity in OT environments and the pitfalls of applying uniform standards to diverse, heterogeneous systems. The talk dissects the limitations of current approaches, where broad designations of "systemically critical" assets paradoxically hinder effective risk management by making everything a priority, thus rendering nothing truly prioritized. This article delves into her proposed framework, its practical application, and the profound implications for defenders grappling with the complexities of securing critical infrastructure.
The significance of this perspective cannot be overstated. As the threat landscape evolves and the interconnectedness of IT and OT systems grows, the ability to pinpoint and address the most impactful risks becomes paramount. Jablanski's methodology offers a beacon for organizations struggling to move beyond compliance checklists and generic security solutions, providing a pathway to actionable intelligence that resonates deeply with those directly responsible for operational continuity and safety. By shifting the locus of prioritization to the asset owner, the industry can foster more targeted, efficient, and ultimately, more resilient cybersecurity postures.
Background
▶ Watch: Introduction and talk structure (0:00)
The foundational premise of Jablanski's talk rests on a critical observation: the current state of critical infrastructure security is plagued by a lack of effective prioritization, largely due to an overwhelming and often unhelpful designation of assets as "systemically critical." While the understanding that hardware and software underpin vital services—from civil society and business to transportation, food, and medical systems—is universal, this broad understanding fails to provide actionable guidance for security teams. The speaker aptly points out that "if everything is critical, then we can't prioritize what's critical," a sentiment echoed by many in the industry.
This problem is compounded by what Jablanski identifies as "double standards" within the cybersecurity landscape. Organizations with substantial resources can invest heavily in multiple solutions, assessments, and compliance checks, often creating a false sense of security or at least a documented one. Conversely, organizations with fewer resources, despite often being less prepared, may face proportionally higher risks without the means to address them comprehensively. This disparity highlights a systemic issue where the ability to "check boxes" often overshadows genuine risk reduction. A core lie, as Jablanski puts it, is the notion that heterogeneous systems equate to homogeneous risks. This is demonstrably false in OT environments, where diverse control systems, SCADA networks, and intermediary IT-OT systems each present unique vulnerabilities and operational contexts.
Furthermore, the industry struggles with fundamental definitions. What constitutes an OT incident? Does it have to be intentional, or can it be the manifestation of unintentional consequences, like the highly publicized Colonial Pipeline incident? Must attacks specifically target process control systems or SCADA, or do incidents impacting intermediary systems also qualify? The role of various actors—criminal groups, nation-states, or even benign insiders causing accidental cascading impacts—further blurs the lines. Without clear, agreed-upon definitions, it becomes exceedingly difficult to classify, respond to, and ultimately prioritize threats effectively.
A significant gap exists between traditional engineering disciplines and modern cybersecurity. While fields like process control are adept at fault-tolerant system design, capable of identifying and mitigating single points of failure, the cybersecurity domain often struggles to map these engineering principles directly to cyber risks. This inability to "pinpoint or illuminate that gap" prevents asset owners from understanding where to focus their limited resources. The challenge, therefore, is not merely identifying critical assets, but developing a methodology that allows for a nuanced, asset-owner-centric prioritization of cyber-physical risks, acknowledging the inherent subjectivity of cybersecurity itself.
Key Findings
▶ Watch: The situation: When everything is critical, nothing is (2:09)
The central and most impactful finding of Danielle Jablanski's presentation is that priority is in the eye of the asset owner. This assertion fundamentally shifts the paradigm from external mandates, government directives, or vendor-driven solutions to the operational realities and specific risk tolerance of the organizations directly responsible for critical infrastructure. While governments and solution providers offer valuable insights and tools, they cannot dictate the nuanced, real-world prioritization that an asset owner must undertake to secure their unique environment. This subjectivity of cybersecurity, where absolute security is unattainable, necessitates a personalized approach to risk management.
A crucial discovery, described by Jablanski as an almost "accidental" outcome of her methodology, is the development of the Standardized Priority Score. This score emerges from the application of her framework, providing a quantifiable means for leaders, governments, ISACs, and jurisdictions to prioritize individual facilities and asset owners. It bridges the gap between the asset owner's subjective understanding of their risks and the broader need for aggregated, actionable intelligence at regional or national levels. The score allows for a comparative understanding of risk without imposing a generic "critical" label on everything.
The insights gleaned from the tabletop exercise conducted with the Water ISAC further reinforced these findings. The exercise demonstrated the practical utility of empowering asset owners to identify and articulate their specific cyber-physical scenarios that could lead to severe outcomes, such as public panic or overwhelming local response capacity. This hands-on application validated the methodology's ability to extract genuine, actionable priorities directly from the operational experts, highlighting scenarios that might otherwise be overlooked by generalized risk assessments. The exercise underscored that effective prioritization is not about creating a perfect target list, but about enabling asset owners to understand and communicate their most pressing vulnerabilities and potential impacts.
Technical Deep Dive
▶ Watch: The task: Defining and prioritizing OT incidents (3:45)
Jablanski's methodology for achieving asset-owner-centric prioritization is structured around the STAR (Situation, Task, Action, Result) foundation, a framework commonly used for structured problem-solving and communication. Applied to the complex domain of OT cybersecurity, STAR provides a systematic way to dissect the prioritization challenge and derive actionable insights.
Situation: The prevailing situation is characterized by an abundance of systemically critical hardware and software that underpins essential services. While the dire consequences of disruption—ranging from mass casualties and evacuations to economic ripple effects within hours or weeks—are well understood, this generalized understanding fails to inform specific prioritization. Designations of national security significance or the acknowledgment of widespread compromise as a "bad scenario" do not provide the necessary granularity. The core problem here is that the sheer volume of "critical" assets dilutes the meaning of criticality itself, making effective prioritization impossible.
Task: The fundamental task is the urgent need to prioritize. This involves addressing several critical definitional and analytical gaps. Firstly, what precisely constitutes an OT incident? The speaker challenges the narrow view, questioning whether incidents must be intentional or if unintentional consequences (like Colonial Pipeline) qualify. Similarly, must attacks target specific process control systems or SCADA, or do impacts on intermediary IT systems that affect OT also count? The nature of the actor—be it a nation-state, criminal group, or even an accidental insider—further complicates this definition. Beyond definitions, the task involves bridging the gap between established engineering practices like fault-tolerant system design and the cybersecurity domain. Engineers are adept at designing systems that tolerate faults, but the industry is "very bad at mapping the two" to pinpoint cyber weaknesses and illuminate what an asset owner should focus on or fund.
Action: The proposed action to achieve prioritization is multifaceted, rooted in the principle that preparedness equals tolerance, which leads to readiness and ultimately resilience. This action phase involves actively seeking answers to questions currently lacking comprehensive data. A primary challenge is determining the "highest concentration of control systems in use" and identifying where systems are "most homogeneously deployed," not just nationally but globally. There is currently no comprehensive inventory for this. While some sectors might offer clearer insights, a broad understanding remains elusive, hindering the crucial gap analysis between fault tolerance and cyber security. Further, asset owners need to be able to map component failures to their specific security concerns, potentially leveraging frameworks like MITRE ATT&CK. However, this is often a labor-intensive, manual process requiring highly skilled personnel. The critical insight here is that these technical mappings alone do not identify the most vulnerable asset owner or the most likely target. Instead, the action focuses on enabling an asset owner to articulate their specific cyber-physical scenarios that could lead to severe outcomes, such as public panic and the overwhelming of local response capacities. This articulation is the foundation of their subjective but accurate prioritization.
Result: While not explicitly detailed as a separate "Result" section in the transcript's STAR breakdown, the ultimate result of this methodology, as highlighted in the "Key Findings," is the Standardized Priority Score. This score emerges from the asset owner's ability to effectively identify and communicate their most severe cyber-physical risks using the STAR framework. It provides a structured, quantifiable output that allows for comparison and aggregated understanding across different facilities and jurisdictions, moving beyond the "everything is critical" dilemma. This score empowers governments, ISACs, and other stakeholders to support asset owners more effectively by understanding their unique risk profiles, rather than imposing generic security mandates.
The "Technical Deep Dive" here is not about specific code or protocols, but about the technicality of the methodology itself – the structured thinking, the definitional challenges, and the analytical gaps that the STAR framework aims to fill. It’s about leveraging a systematic approach to extract actionable intelligence from the complex, subjective reality of OT cybersecurity.
Demo / Proof of Concept
▶ Watch: Key takeaway: Priority is in the eye of the asset owner (6:17)
While the talk did not feature a live, interactive demonstration of software or tools, Danielle Jablanski explicitly referred to a practical application of her methodology as a tabletop exercise conducted with the Water ISAC. This exercise served as the real-world proof of concept for her framework.
The tabletop exercise was carried out virtually in the fall, involving members of the Water ISAC community. Jablanski expressed gratitude to Jen Walker for allowing her to implement and test her methodology within that organization. The purpose of this exercise was to apply the STAR foundation in a collaborative setting, enabling participating asset owners to walk through the process of identifying their specific cyber-physical scenarios and articulating their unique security priorities.
Through this exercise, the methodology demonstrated its ability to help asset owners move beyond generic critical infrastructure concerns to pinpoint scenarios that could genuinely lead to "public panic" and "overwhelm their local response capacity." It validated the core premise that priority is indeed in the eye of the asset owner, as the exercise allowed them to surface and prioritize risks based on their intimate operational knowledge. The success of this tabletop exercise was instrumental in revealing the potential for the Standardized Priority Score—an outcome that emerged almost incidentally from the application of the framework, providing a quantifiable measure of these subjectively identified priorities. This practical engagement underscored the viability and efficacy of Jablanski's approach in translating abstract security challenges into concrete, actionable insights for critical infrastructure operators.
Defensive Implications
▶ Watch: Introducing the standardized priority score (6:53)
The implications of Danielle Jablanski's work for defenders in the OT space are profound and necessitate a re-evaluation of current security strategies. Primarily, defenders must internalize and operationalize the principle that priority is in the eye of the asset owner. This means moving away from a purely compliance-driven or externally dictated security posture and empowering internal teams with the frameworks to define their own most critical risks.
Firstly, organizations should adopt structured methodologies, such as the STAR foundation, to systematically identify and articulate their unique cyber-physical scenarios. This involves engaging operational staff, engineers, and IT/OT security personnel in a collaborative process to define the "Situation," "Task," "Action," and expected "Result" for their specific environment. By doing so, they can move beyond generic threats to focus on those that would genuinely cause severe impact, such as mass casualties, evacuations, or overwhelming local response capabilities.
Secondly, defenders need to actively refine their understanding and definition of an OT incident. This includes broadening the scope beyond intentional attacks on SCADA systems to encompass unintentional consequences, incidents impacting intermediary IT systems that affect OT, and the full spectrum of potential actors, including insiders. Clearer, more nuanced definitions will enable more accurate risk assessments and more effective incident response planning.
Thirdly, the industry must address the gap in mapping traditional fault-tolerant system design to cybersecurity concerns. Defenders should invest in tools and processes that allow them to thoroughly map component failures to specific security vulnerabilities and potential attack paths, potentially leveraging and extending frameworks like MITRE ATT&CK for ICS. This requires a deeper integration of engineering principles with cybersecurity expertise.
Furthermore, the concept of a Standardized Priority Score offers a valuable mechanism for internal and external communication. Internally, it can help allocate limited resources more effectively by providing a quantifiable basis for investment decisions. Externally, it can facilitate more meaningful dialogue with regulators, ISACs, and government bodies, allowing asset owners to convey their specific needs and concerns in a standardized format, fostering better support and collaboration. Rather than relying on a "perfect target list" that doesn't exist, defenders can proactively communicate their most pressing vulnerabilities.
Finally, organizations must acknowledge the inherent subjectivity of cybersecurity and the reality of heterogeneous systems not equating to homogeneous risks. This calls for tailored security solutions and strategies that respect the unique operational context of each OT environment, rather than attempting to apply one-size-fits-all approaches. Training and empowering asset owners to articulate their unique risks will lead to more resilient and defensible critical infrastructure.
Key Takeaways
- Prioritization in OT security is fundamentally flawed: The designation of "systemically critical" for nearly all infrastructure means "nothing is truly prioritized," hindering effective risk management.
- "Priority is in the eye of the asset owner": Effective cybersecurity prioritization must originate from the unique operational context and risk tolerance of the asset owner, not from external mandates or generic assessments.
- The STAR methodology offers a structured approach: The Situation, Task, Action, Result framework provides a systematic way for asset owners to identify, articulate, and understand their specific cyber-physical risks.
- Defining an "OT Incident" is crucial: The industry needs clearer, more inclusive definitions of OT incidents, encompassing intentional and unintentional events, various attack vectors, and diverse threat actors.
- The "Standardized Priority Score" is a powerful outcome: This accidental but vital output of the methodology enables quantifiable comparison and aggregation of asset owner priorities, facilitating better resource allocation and communication with broader stakeholders.
- Cybersecurity in OT is subjective and context-dependent: Recognizing that heterogeneous systems do not equate to homogeneous risks requires tailored security strategies that empower asset owners to address their unique vulnerabilities.
About the Speaker(s)
Danielle Jablanski is a prominent figure in the field of operational technology (OT) cybersecurity, known for her work in critical infrastructure security and risk management. She is affiliated with Nazo Networks, a company focused on securing critical infrastructure. Jablanski is recognized for her practical, methodology-driven approach to complex cybersecurity challenges, as demonstrated by her development of the STAR foundation for prioritization. Her engagement with organizations like the Water ISAC (Information Sharing and Analysis Center) highlights her commitment to fostering collaboration and applying innovative solutions directly within the critical infrastructure community. She specifically acknowledged Jen Walker of the Water ISAC for her support in applying her methodology.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This talk by Danielle Jablanski cuts through the usual platitudes surrounding critical infrastructure security by asserting that true prioritization must come from the asset owner, not top-down mandates. Her STAR methodology, validated through a Water ISAC exercise, provides a structured, no-bullshit framework for organizations to define their unique cyber-physical risks. This isn't just another 'awareness' session; it's a practical, actionable approach to a pervasive and poorly addressed problem, offering a quantifiable 'Standardized Priority Score' that could genuinely shift how we secure vital systems.
Heather Calloway (CISO) — MUST SEE
Danielle Jablanski's talk masterfully dissects a fundamental flaw in critical infrastructure security: the paradox that if everything is deemed critical, nothing truly is. Her proposed STAR methodology and the resulting Standardized Priority Score offer a direct, actionable path for asset owners to articulate their unique cyber-physical risks, fundamentally shifting prioritization from top-down mandates to genuine, context-driven accountability. This work is essential for any leader grappling with resource allocation and risk ownership in complex operational environments, providing a framework for clear decision-making where it is most desperately needed.