OT Sponsorship By Advancing Operational Priorities

Fritz Byam

S4x24 - ICS Security Conference · Day 2 · Stage 2

Overview

In a landscape increasingly defined by the convergence of Information Technology (IT) and Operational Technology (OT), the success of security initiatives often hinges less on cutting-edge technological solutions and more on the fundamental alignment of human stakeholders. Fritz Byam, President at ITS Partners, delivered a compelling talk at the S4 conference that underscored this critical, yet frequently overlooked, aspect: OT sponsorship. Byam, drawing from a rich career spanning decades in manufacturing operations and IT, argued that robust sponsorship from key operational leaders is not merely beneficial but an absolute prerequisite for achieving meaningful and sustainable OT security outcomes.

Watch on YouTube

Visual summary for OT Sponsorship By Advancing Operational Priorities by Fritz Byam
Visual summary for OT Sponsorship By Advancing Operational Priorities by Fritz Byam

Key moments

  1. 0:00 Fritz Biam's operational bias and Unilever experience
  2. 2:00 How OT reconnected him with his operational roots
  3. 2:20 The critical 'people part' of OT execution
  4. 2:40 OT sponsorship: a fact, not a hypothesis
  5. 3:05 Introducing the critical 'Operational SWOT' analysis

OT Sponsorship By Advancing Operational Priorities

Speakers: Fritz Byam

Conference: S4

YouTube: https://www.youtube.com/watch?v=apASwaOxvXw

Overview

In a landscape increasingly defined by the convergence of Information Technology (IT) and Operational Technology (OT), the success of security initiatives often hinges less on cutting-edge technological solutions and more on the fundamental alignment of human stakeholders. Fritz Byam, President at ITS Partners, delivered a compelling talk at the S4 conference that underscored this critical, yet frequently overlooked, aspect: OT sponsorship. Byam, drawing from a rich career spanning decades in manufacturing operations and IT, argued that robust sponsorship from key operational leaders is not merely beneficial but an absolute prerequisite for achieving meaningful and sustainable OT security outcomes.

Byam’s presentation challenged the prevailing, technology-centric view of OT security, redirecting focus to the intricate "people part of the equation." He posited that without deliberate efforts to bridge the historical and cultural chasm between IT and OT teams, even the most sophisticated security tools and strategies are destined to falter. The core message resonated with a fundamental truth in complex organizational environments: initiatives thrive when championed by those who understand and are invested in the underlying operational priorities. This talk serves as a vital guide for organizations struggling to translate their OT security investments into tangible improvements, emphasizing that true progress begins with understanding, influencing, and securing the active support of operational leadership.

Background

▶ Watch: Fritz Biam's operational bias and Unilever experience (0:00)

Fritz Byam's unique perspective on the challenges and opportunities within OT security is deeply rooted in his extensive professional journey. He began his career in engineering at Unilever, a global consumer products giant, working on advanced liquid packaging technologies. However, a pivotal shift to a production supervisor role, initially met with resistance, fundamentally reshaped his professional identity. He quickly developed a profound appreciation for the "urgency of the motion" and the tangible satisfaction of operational success, eventually leading Unilever's largest worldwide liquid packaging operation. This formative experience instilled in him a distinct operational bias – a deep-seated understanding of manufacturing rhythms, priorities, and the critical importance of uptime, efficiency, and safety.

Following his tenure in operations and supply chain management, Byam transitioned into IT, where he spent 25 years working on foundational workloads. This period, while removed from the direct pulse of production, provided him with invaluable insights into the intricacies of enterprise IT systems, data management, and the challenges of sustaining long-term technology initiatives. It was the emergence of Operational Technology (OT) as a distinct domain that reconnected him with his manufacturing roots. This dual expertise – a deep operational understanding combined with extensive IT experience – positioned him uniquely to observe and articulate the inherent difficulties in successfully executing OT initiatives, particularly in the realm of security.

The problem, as Byam articulates, is multifaceted. While the cybersecurity industry boasts a wealth of technological solutions and skilled professionals, these advancements often fail to translate into effective OT security programs because "none of that technology is going to work if the people part of the equation doesn't come together." OT environments are characterized by a diverse array of stakeholders, including IT professionals, operational engineers, plant managers, safety officers, and executive leadership. Historically, these groups have operated in silos, often speaking different technical languages and prioritizing different objectives. IT typically emphasizes data confidentiality, integrity, and availability, while OT's paramount concerns are personnel safety, environmental protection, continuous operation, and product quality. This divergence in priorities and lack of established collaborative frameworks create significant friction, hindering the successful implementation of security measures that are often perceived by operational teams as impediments rather than enablers. Without a concerted effort to foster collaboration and secure genuine buy-in from operational stakeholders, OT security programs risk becoming isolated, underfunded, and ultimately ineffective.

Key Findings

▶ Watch: How OT reconnected him with his operational roots (2:00)

The central thesis of Fritz Byam's talk is a declarative statement: "OT sponsorship is a key to OT success as a fact, not a hypothesis." This pronouncement underpins the entire presentation, shifting the conversation from a theoretical aspiration to a fundamental requirement for any organization serious about securing its industrial control systems and critical infrastructure. Byam asserts that the successful execution of OT initiatives, particularly those related to security, cannot be achieved through technology alone. Instead, it critically depends on the active and sustained support of key operational leaders.

Byam’s assertion is not based on abstract theory but on decades of practical experience, which he refers to as "proof points." His 25 years in IT, dedicated to foundational workloads, demonstrated the necessity of organizational alignment for any complex system to thrive. He observed that even seemingly mundane but critical tasks, such as creating and maintaining a sustainable Configuration Management Database (CMDB), require significant cross-functional cooperation and executive backing to be truly effective over time. Without such sponsorship, these foundational efforts often languish, becoming outdated and irrelevant.

The "people part of the equation" is highlighted as the most challenging, yet most impactful, aspect of OT security. Byam emphasizes that the diverse stakeholders involved in OT – from plant floor personnel to corporate IT – often lack a history of successful collaboration. Their concerns, priorities, and risk appetites can differ dramatically. For instance, an operations manager's primary concern might be preventing unscheduled downtime, while an IT security analyst might prioritize patching vulnerabilities. Without a unifying vision and a champion who can bridge these disparate viewpoints, security initiatives are likely to be met with resistance, misunderstanding, and ultimately, failure. The talk posits that effective OT sponsorship serves as this crucial bridge, translating technical security requirements into terms that resonate with operational priorities, thereby fostering a collaborative environment essential for achieving robust and sustainable security outcomes.

Technical Deep Dive

▶ Watch: The critical 'people part' of OT execution (2:20)

While Byam’s talk primarily focuses on strategic organizational alignment rather than specific technical exploits or protocols, it delves into the foundational technical workloads that underpin effective OT security and the critical role of sponsorship in their success. His experience in IT on "foundational workloads" provides a lens through which to understand the technical requirements for a resilient OT environment. One key example he cites is "creating a sustainable CMDB (Configuration Management Database), measuring it and managing it over time."

In an OT context, a CMDB is not merely an IT asset inventory; it is the bedrock of asset visibility and management for industrial control systems. A comprehensive OT CMDB would meticulously catalog all assets within the operational network, including Programmable Logic Controllers (PLCs), Distributed Control Systems (DCSs), Supervisory Control and Data Acquisition (SCADA) systems, Human-Machine Interfaces (HMIs), industrial workstations, network devices, and even specialized sensors and actuators. For each asset, a sustainable CMDB would track critical information such as:

  • Hardware and Software Details: Manufacturer, model, firmware version, operating system, application software, patch levels.
  • Network Configuration: IP address, MAC address, network segment, VLAN, firewall rules, communication protocols (e.g., Modbus, DNP3, OPC UA, EtherNet/IP).
  • Physical Location: Plant, line, cabinet, rack.
  • Ownership and Responsibility: Department, owner, maintenance schedule.
  • Criticality: Impact on safety, production, quality, and environmental factors if compromised or unavailable.
  • Dependencies: Relationships with other assets, control loops, and business processes.

The technical challenge in creating and sustaining an OT CMDB is immense. Unlike IT environments where automated discovery tools are prevalent, OT networks often contain legacy devices that are difficult to scan, proprietary protocols that are not easily interpreted, and strict uptime requirements that prohibit intrusive active scanning. Manual inventorying is time-consuming and prone to error. Therefore, achieving a "sustainable" CMDB in OT requires not only specialized tools (e.g., passive network monitoring, industrial asset discovery platforms) but also a continuous process involving collaboration between IT and OT teams for data collection, validation, and maintenance. Without strong operational sponsorship, the resources, time, and cross-functional cooperation necessary for this endeavor simply won't materialize, leaving the organization blind to its true asset posture. An outdated or incomplete CMDB directly impacts vulnerability management, incident response, compliance audits, and even basic network segmentation efforts, making it a critical security enabler.

Byam also introduces the concept of the "operational SWAT" – a SWOT analysis (Strengths, Weaknesses, Opportunities, Threats) conducted from the perspective of operational personnel. This is a critical technical and strategic exercise for bridging the IT/OT divide. Unlike a corporate SWOT, the operational SWOT is grounded in the day-to-day realities of the plant floor.

  • Strengths: What are the operational team's current capabilities? Reliable processes, skilled workforce, existing safety protocols.
  • Weaknesses: What hinders operations? Legacy equipment, lack of skilled maintenance staff, outdated documentation, frequent unplanned downtime events.
  • Opportunities: How can operations improve? Adoption of new automation, predictive maintenance, energy efficiency projects, improved data analytics.
  • Threats: What keeps operational leaders awake at night? Equipment failures, supply chain disruptions, safety incidents, quality control issues, and crucially, cyber-attacks leading to production halts or safety hazards.

Conducting an operational SWOT requires technical understanding of the plant environment, the specific processes, and the potential impact of various events. For security professionals, understanding this operational SWOT is key to framing security initiatives in terms that resonate with OT. Instead of presenting security as an abstract IT requirement, it can be framed as a solution to an operational threat (e.g., "Implementing network segmentation will reduce the risk of a cyberattack causing production downtime, addressing a key operational threat") or as an enabler of an operational opportunity (e.g., "Secure remote access enables quicker troubleshooting by expert engineers, improving uptime and efficiency"). This technical translation, facilitated by operational sponsorship, transforms security from a perceived burden into a strategic advantage, directly addressing the concerns identified in the operational SWOT.

Demo / Proof of Concept

▶ Watch: OT sponsorship: a fact, not a hypothesis (2:40)

The talk by Fritz Byam did not feature a live technical demonstration or a specific proof of concept in the traditional sense of showcasing a tool, exploit, or a working system. Instead, Byam presented his decades of experience in both operational technology and information technology, coupled with real-world observations of organizational dynamics, as the "proof points" for his central thesis regarding the critical role of OT sponsorship. His argument is built on anecdotal evidence and professional insights derived from successfully navigating complex organizational challenges in industrial environments.

Defensive Implications

▶ Watch: Introducing the critical 'Operational SWOT' analysis (3:05)

The central message of OT sponsorship carries profound defensive implications for organizations grappling with the complexities of securing their industrial environments. The primary takeaway for defenders is that technical solutions alone are insufficient; robust OT security fundamentally requires the active buy-in and championing from operational leaders. This strategic alignment directly impacts the ability to implement and sustain effective defensive measures.

Firstly, understanding and leveraging the operational bias of plant personnel is crucial. Defenders must learn to articulate security risks and proposed solutions in the language of operations. Instead of discussing CVEs and threat intelligence in abstract terms, security professionals should translate these into tangible impacts on production uptime, worker safety, product quality, and regulatory compliance. For example, rather than simply stating "we need to patch a vulnerability in the HMI," the message should be "patching this HMI vulnerability will prevent a potential remote control compromise that could lead to an unscheduled shutdown on Line 6, impacting our Q4 production targets and incurring significant financial losses." This reframing, facilitated by strong operational sponsorship, ensures that security initiatives are perceived as integral to business continuity and operational excellence, rather than as an IT overhead.

Secondly, securing sponsorship enables the allocation of necessary resources. OT security initiatives often require significant investment in specialized tools, training, and personnel. Without a champion in operations, these requests can be deprioritized or rejected by leadership focused solely on immediate production metrics. An operational leader who understands the cyber risks and their potential impact on their domain can advocate for the necessary budget, personnel, and production windows required for security deployments, such as network segmentation, asset inventory projects (like the CMDB Byam mentioned), or patching cycles. Their endorsement lends credibility and urgency to security proposals, making it easier to gain executive approval.

Thirdly, sponsorship fosters cross-functional collaboration, which is essential for effective OT defense. Many OT security tasks, such as incident response, vulnerability management, and secure system design, require close cooperation between IT and OT teams. An operational sponsor can bridge the cultural and communication gaps between these groups, facilitating joint workshops, training sessions, and integrated processes. For instance, developing an OT incident response plan requires input from both IT security analysts (who understand cyberattack methodologies) and operational engineers (who understand the physical processes and safety protocols). A sponsor can ensure that both perspectives are heard, respected, and integrated into a cohesive, actionable plan.

Finally, the concept of the "operational SWAT" provides a powerful framework for defenders to proactively identify and address risks in a way that aligns with operational priorities. By conducting a SWOT analysis from the operational perspective, defenders can uncover the true pain points and critical concerns of the plant floor. This insight allows them to strategically position security solutions as direct remedies to operational weaknesses or threats, or as enablers for operational opportunities. For example, if "unplanned downtime due to equipment failure" is a key operational weakness, defenders can propose security monitoring solutions that also provide insights into system health, effectively merging security and reliability goals. This proactive alignment, driven by operational sponsorship, transforms security from a reactive burden into a proactive component of operational resilience and strategic advantage.

Key Takeaways

  • OT sponsorship is non-negotiable for success: Active support from operational leaders is a fundamental requirement, not an optional bonus, for effective OT security programs.
  • The "people part" is paramount: Bridging the historical and cultural divide between IT and OT stakeholders is more critical than technology alone.
  • Frame security in operational terms: Translate technical security risks and solutions into language that resonates with operational priorities like safety, uptime, quality, and efficiency.
  • Foundational workloads require sponsorship: Initiatives like establishing and maintaining a sustainable CMDB for OT assets demand cross-functional collaboration and leadership buy-in.
  • Leverage the "operational SWOT": Understand and address operational strengths, weaknesses, opportunities, and threats to strategically align security initiatives with core business objectives.
  • Sponsorship drives resource allocation: Operational champions can advocate for the necessary budget, personnel, and production windows required for robust OT security deployments.

About the Speaker(s)

Fritz Byam is the President at ITS Partners, bringing a unique and deeply practical perspective to the field of Operational Technology (OT) security. His career began in engineering at Unilever, where he specialized in liquid packaging technologies. A pivotal shift into a production supervisor role instilled in him a profound "operational bias," leading him to eventually manage Unilever's largest worldwide liquid packaging operation. This extensive background in manufacturing operations provided him with an intimate understanding of industrial processes, the critical importance of uptime, safety protocols, and the unique challenges of the plant floor.

After a period in supply chain planning, Byam transitioned into Information Technology (IT), where he spent 25 years focusing on foundational workloads. This experience equipped him with a comprehensive understanding of enterprise IT systems, data management, and the complexities of sustaining technology initiatives over time. The emergence of OT as a distinct domain reconnected him with his manufacturing roots, allowing him to bridge the gap between his operational expertise and his IT knowledge. His combined experience gives him a unique vantage point to help organizations achieve quality outcomes from their OT programs by emphasizing the crucial role of human factors and strategic alignment.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Byam's talk cuts through the usual noise surrounding OT security to address a critical, often-overlooked truth: without genuine operational sponsorship, even the best technology will fail. Drawing on decades in manufacturing operations and IT, he articulates the 'operational bias' and provides actionable strategies like the 'operational SWOT' to bridge the IT/OT divide. This isn't a deep technical dive, but it's a brutally honest and practical guide for anyone struggling to implement real security in industrial environments by securing the necessary buy-in from those who actually keep the lights on.

Heather Calloway (CISO) — STRONG ACCEPT

Fritz Byam's S4 talk on OT sponsorship is a vital reminder that effective security in operational technology environments is fundamentally a leadership and organizational challenge, not merely a technical one. He compellingly argues that genuine buy-in and active championship from operational leaders are absolute prerequisites for any meaningful and sustainable OT security program. This presentation offers crucial guidance for security leaders on how to bridge the historical IT/OT divide by framing security in terms of direct operational priorities, thereby securing the necessary resources and collaboration for success.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference