Plumbing and Cybersecurity: Basically The Same
Colin Dunn
S4x24 - ICS Security Conference · Day 2 · Stage 3
Overview
In a compelling and highly relatable presentation at S4, Colin Dunn, CEO of Fend, drew an insightful parallel between the often-underappreciated world of plumbing and the critical realm of Operational Technology (OT) cybersecurity. Titled "Plumbing and Cybersecurity: Basically The Same," the talk aimed to demystify complex OT cyber challenges and solutions by framing them within the universally understood context of managing physical flows, preventing leaks, and limiting damage. Dunn argued that by communicating the intricacies of OT cybersecurity through this analogy, practitioners can better articulate the importance of their work to non-technical stakeholders, secure necessary budgets, and ultimately foster more resilient industrial systems.

Key moments
- 0:00 Introduction: Plumbing and cybersecurity are basically the same
- 0:40 Feeling of a cyber attack vs. plumbing emergency
- 3:00 OT cyber professionals deal with 'classic' legacy systems
- 4:10 Unsung heroes: When you do things right, nobody notices
- 5:00 Called in only for new builds or major emergencies
- 5:40 Budgeting challenges: OT cyber as a project, not recurring
- 6:15 Shared objectives: Maintain flow, prevent blockages, no clogs
Plumbing and Cybersecurity: Basically The Same
Speakers: Colin Dunn, CEO, Fend
Conference: S4
YouTube: https://www.youtube.com/watch?v=aYzY3y4zjJM
Overview
In a compelling and highly relatable presentation at S4, Colin Dunn, CEO of Fend, drew an insightful parallel between the often-underappreciated world of plumbing and the critical realm of Operational Technology (OT) cybersecurity. Titled "Plumbing and Cybersecurity: Basically The Same," the talk aimed to demystify complex OT cyber challenges and solutions by framing them within the universally understood context of managing physical flows, preventing leaks, and limiting damage. Dunn argued that by communicating the intricacies of OT cybersecurity through this analogy, practitioners can better articulate the importance of their work to non-technical stakeholders, secure necessary budgets, and ultimately foster more resilient industrial systems.
Dunn, a mechanical engineer with prior plumbing experience, leveraged his unique perspective to highlight fundamental similarities in objectives, tools, and consequences between the two disciplines. The talk emphasized that, much like well-maintained plumbing, effective OT cybersecurity often operates silently in the background, only gaining attention when catastrophic failures occur. This perspective is crucial for shifting the perception of OT cyber from a reactive, project-based expense to a proactive, ongoing investment in infrastructure resilience and operational continuity, addressing a significant challenge in securing critical infrastructure.
Background
▶ Watch: Introduction: Plumbing and cybersecurity are basically the same (0:00)
The core premise of Dunn's talk addresses a pervasive problem in the cybersecurity industry, particularly within the OT domain: the difficulty in effectively communicating the value and necessity of cybersecurity efforts to those outside the immediate technical sphere. While OT cybersecurity professionals understand their work in terms of "protecting the mission," ensuring "clean energy and water," or "saving the world," these high-level objectives often fail to resonate with budget committees or even general management in a practical, actionable way. The talk posits that a more grounded, relatable analogy is needed to bridge this communication gap.
Dunn painted a vivid picture of the typical experience during a cyber attack, mirroring it with a plumbing emergency: initial confusion, gradual realization of a problem, hoping it will disappear, spreading damage, accidental worsening of the situation during remediation, and finally, a slow recovery and cleanup. This shared emotional and operational trajectory underscores how profoundly similar the impact of failures can be, regardless of whether the medium is water or data. Furthermore, the public and management often react similarly to both crises: expressing sympathy but expecting the "expert" to clean up the "mess."
A significant challenge highlighted is the "behind the scenes" nature of successful cybersecurity. Like expertly installed plumbing hidden behind drywall, effective OT cyber measures are often invisible. "When you do things right, people won't be sure you've done anything at all," Dunn quoted, encapsulating the paradox of cybersecurity success. This invisibility contributes to the undervaluation of proactive security. Plumbers, Dunn noted, are typically called in at two distinct times: during new construction (often late in the design process, expected to make everything work) or decades later, when a major catastrophe strikes. This mirrors the OT cybersecurity landscape, where security is often an afterthought during system design or only addressed in crisis mode after a breach.
Compounding this issue is the budgeting paradigm for OT cybersecurity. Unlike IT departments, which often allocate a recurring percentage (e.g., 10%) of their annual budget to cybersecurity, OT security is frequently treated as a capital project. It's often tied to major plant shutdowns or upgrades, making it an "on-again, off-again" expense rather than a continuous investment. This "deferred maintenance" approach leaves critical infrastructure vulnerable and makes it challenging to implement sustained security improvements. Many OT systems are also "classics"—cutting-edge decades ago, but now harder to work with, presenting unique challenges for security integration and maintenance.
Key Findings
▶ Watch: OT cyber professionals deal with 'classic' legacy systems (3:00)
The central finding of Colin Dunn's presentation is that the operational objectives, challenges, and even the tools used in plumbing and OT cybersecurity are fundamentally analogous. This powerful comparison offers a fresh lens through which to understand and address the complexities of securing industrial control systems. Dunn identified three core, shared objectives:
- Maintain Flow: In plumbing, this means ensuring water or other fluids reach their intended destination without interruption. In OT cybersecurity, it translates to guaranteeing the continuous and correct flow of data and commands essential for industrial processes. Blockages or "clogs" in either system lead to expensive infrastructure becoming non-functional.
- Prevent Leaks: For plumbing, leaks lead to wasted resources and structural damage. In cybersecurity, this directly maps to preventing data exfiltration or unauthorized access to sensitive operational information. Undetected leaks, whether physical or digital, can cause significant, long-term damage that only becomes apparent months or years later, often with far greater repair costs.
- Limit Damage: Both disciplines strive to design systems that minimize the impact of a failure. A burst pipe should ideally not flood an entire building, just as a cyber breach should not compromise an entire industrial plant. This objective underscores the importance of segmentation and containment strategies.
Beyond objectives, the talk highlighted shared tool categories. Filters in plumbing, which keep unwanted debris out of the system, are directly analogous to firewalls in cybersecurity, which control network traffic and block malicious content. Similarly, leak detection systems, which pinpoint the source of a physical leak, find their cyber counterpart in Intrusion Detection Systems (IDS). Both are designed to identify problems early, enabling more cost-effective and timely remediation before minor issues escalate into major disasters.
The most significant contribution of the analogy is its illumination of Consequence-Driven Cyber-Informed Engineering (CCE). Dunn argued that CCE, a methodology focused on understanding and mitigating the physical consequences of cyber attacks, is not solely the domain of cybersecurity specialists but represents sound engineering practice. By integrating security considerations into the fundamental design of physical systems, inspired by plumbing principles, organizations can build in resilience that is inherently more robust than purely digital defenses. This involves asking critical questions early in the design phase, such as whether a connection is truly necessary, if data flow can be unidirectional, and what physical modifications can limit potential cyber-physical impact.
Technical Deep Dive
▶ Watch: Unsung heroes: When you do things right, nobody notices (4:10)
The technical depth of Dunn's argument lies in translating the intuitive principles of plumbing into concrete OT cybersecurity strategies, particularly through the lens of Consequence-Driven Cyber-Informed Engineering (CCE).
Shared Objectives and Tools in Detail:
- Maintaining Flow: In OT, this involves ensuring the uninterrupted operation of industrial processes. A Distributed Control System (DCS) needs to continuously communicate with Programmable Logic Controllers (PLCs), which in turn control physical actuators. Any disruption, whether a network outage or a malicious command injection, constitutes a "blockage" that can halt production, damage equipment, or endanger safety. Just as a clogged drain renders a plumbing system useless, a compromised control network can render an industrial plant inert.
- Preventing Leaks: On the OT network, this means safeguarding proprietary process data, operational parameters, and potentially sensitive intellectual property. An attacker exfiltrating control logic or sensor readings could gain critical insights for future attacks or industrial espionage. In a physical plumbing system, a hidden leak behind a wall can lead to mold, structural damage, and eventual collapse. Similarly, an undetected persistent threat in an OT network can slowly exfiltrate data or establish footholds for a future, more damaging attack, remaining hidden for "months if not years later."
- Limiting Damage: This principle is where the plumbing analogy truly shines for CCE. In IT, damage limitation often revolves around network segmentation, Zero Trust architectures, and robust access controls. While these are vital, OT offers additional avenues for mitigation. Dunn highlighted that OT system designers have the opportunity to question fundamental architectural choices: "Do I really need to connect these two systems? Does this need to be a one-way flow of data? Is two-way what we need?" These questions lead to design decisions that can physically constrain the impact of a cyber incident.
Applying CCE through Plumbing Principles:
Dunn provided compelling examples of how physical engineering decisions, inspired by plumbing, can inherently limit cyber-physical consequences:
- Pump Sizing in Chemical Plants: In one scenario, engineers intentionally installed a smaller pump in a chemical processing system—a pump "that could just barely keep up with the job it needed to do." The rationale was that even if an attacker gained full control of this pump and forced it to run a dangerous chemical continuously, the limited capacity of the pump would prevent the accumulation of enough hazardous material to cause significant harm. This is a direct application of CCE: modifying the physical system design to be "basically immune" to a specific cyber attack vector, rather than relying solely on digital defenses. This kind of "good engineering design" involves collaboration across engineering disciplines, not just cyber specialists.
- Washer and Dryer Placement: The seemingly mundane decision of where to install a washer and dryer offers a clear illustration of physical consequence limitation. Placing these appliances in a bedroom, though convenient, carries a high risk of catastrophic flooding to lower floors if a hose bursts. Conversely, installing them in a basement physically limits the potential damage because "you can't flow back upstairs." This is a procedural decision that leverages gravity to contain potential failures, effectively creating a physical blast radius limitation.
- The Quarter-Inch Line Analogy: Dunn further elaborated on this concept with the "quarter inch line" that fills a toilet tank. While it serves its purpose, its small diameter inherently limits the amount of water that can flow out if it breaks, compared to a "big, one inch commercial line." This illustrates the principle of designing components to have minimal individual impact, even if compromised. In an OT context, this could translate to limiting the bandwidth or throughput of critical communication channels, or using smaller, isolated control loops for highly sensitive processes, thereby containing the potential physical damage from a single point of failure or compromise.
These examples underscore that CCE is about proactively embedding resilience into the physical and logical architecture of industrial systems, recognizing that physical constraints can be the most robust form of defense against cyber-physical attacks. It requires a holistic view where traditional engineering expertise converges with cybersecurity insights to create systems that are not just digitally secure, but physically safe.
Demo / Proof of Concept
▶ Watch: Budgeting challenges: OT cyber as a project, not recurring (5:40)
The presentation "Plumbing and Cybersecurity: Basically The Same" was a conceptual talk focused on drawing analogies and discussing principles rather than demonstrating specific tools or exploits. As such, no live demo or technical proof of concept was presented during Colin Dunn's session. The power of the talk lay in its illustrative examples and framework for understanding OT cybersecurity through a relatable lens.
Defensive Implications
▶ Watch: Shared objectives: Maintain flow, prevent blockages, no clogs (6:15)
The plumbing analogy and the emphasis on Consequence-Driven Cyber-Informed Engineering (CCE) provide several critical defensive implications for OT cybersecurity practitioners and organizational leaders:
- Prioritize CCE in Design and Operations: Defenders must advocate for and integrate CCE principles from the earliest stages of system design and throughout the operational lifecycle. This means moving beyond purely digital defenses to consider how physical system architecture can inherently limit the impact of cyber attacks. Engineers, operators, and cybersecurity teams must collaborate to identify critical physical consequences and design systems to mitigate them, as exemplified by the pump sizing and washer/dryer placement scenarios.
- Shift to a Proactive, Maintenance-Oriented Budgeting Model: The "deferred maintenance" approach to OT cybersecurity is unsustainable. Organizations need to transition from project-based funding for OT cyber upgrades to a recurring budget model, similar to IT. This ensures continuous investment in security controls, regular maintenance of systems (like "changing filters" for firewalls), and ongoing monitoring (like "leak detection" with IDS). This shift recognizes that cybersecurity is an ongoing operational expense, not a one-time project.
- Leverage Physical Limitations as Robust Controls: Defenders should actively seek opportunities to implement physical controls that limit the impact of cyber incidents. This includes network segmentation, but also considering physical isolation, one-way data flows (data diodes), and even reducing the capacity or potential output of critical components where safety or damage limitation is paramount. The "quarter-inch line" principle encourages designing systems with inherent limitations on potential damage.
- Enhance Cross-Functional Communication and Collaboration: The analogy provides a powerful tool for cybersecurity professionals to communicate the importance of their work to non-technical engineering, operations, and management teams. By framing cyber risks and mitigations in terms of "flow," "leaks," and "damage limitation," it becomes easier to gain buy-in, foster shared understanding, and encourage collaborative problem-solving across departments. This helps break down silos and ensures that security is seen as a collective responsibility, not just the cyber team's burden.
- Focus on Early Detection and Visibility: Just as plumbing leak detectors save significant repair costs, robust Intrusion Detection Systems (IDS) and continuous monitoring are crucial for identifying cyber anomalies in OT environments early. Investing in tools and processes that provide deep visibility into OT network traffic and system behavior can help pinpoint problems quickly, preventing minor issues from escalating into widespread damage.
- Recognize the "Invisible" Success of Good Security: While challenging, defenders should strive to articulate the value of preventing incidents. Highlighting near-misses, successful threat detections, and the continuous, uninterrupted operation of critical infrastructure due to proactive security measures can help elevate the perception of OT cyber work from being "behind the scenes" to being an indispensable enabler of the mission.
By adopting these defensive strategies, organizations can build more resilient OT environments that are better equipped to withstand the evolving threat landscape, ultimately safeguarding critical infrastructure and public safety.
Key Takeaways
- Plumbing as a Universal Analogy: The principles of plumbing—maintaining flow, preventing leaks, and limiting damage—offer an intuitive and universally understood framework for explaining complex OT cybersecurity challenges and solutions to diverse audiences.
- The "Invisible" Nature of Success: Like well-functioning plumbing, effective OT cybersecurity often operates unnoticed until a failure occurs. This makes it challenging to communicate its value and secure adequate resources.
- Budgeting for Resilience: OT cybersecurity requires a shift from project-based, reactive funding to a recurring, proactive maintenance budget, similar to IT, to address deferred maintenance and ensure continuous protection.
- Consequence-Driven Cyber-Informed Engineering (CCE) is Paramount: Integrating cybersecurity considerations into the fundamental physical and architectural design of OT systems is crucial. By leveraging physical limitations and engineering choices, organizations can inherently reduce the potential impact of cyber attacks.
- Physical Controls as Robust Defenses: Strategic physical design decisions, such as limiting pump capacities, careful placement of equipment, or using smaller flow lines, can provide more resilient and effective damage limitation than purely digital defenses.
- Cross-Functional Collaboration is Key: Effective OT cybersecurity demands collaboration between cybersecurity professionals, mechanical engineers, operators, and management, using shared language (like the plumbing analogy) to build a collective understanding and responsibility for system security and safety.
About the Speaker(s)
Colin Dunn is the CEO of Fend, a company focused on securing industrial control systems. With a background as a mechanical engineer, Dunn brings a unique perspective to the field of cybersecurity. His professional journey includes practical experience in plumbing, which he leverages to draw insightful and relatable analogies for complex OT cybersecurity concepts. His expertise lies in bridging the gap between traditional engineering disciplines and the evolving demands of industrial cybersecurity.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Dunn's presentation, while from a vendor, uses a surprisingly effective and clear analogy between plumbing and OT cybersecurity to demystify complex concepts. It delivers genuine value by translating critical defense principles, particularly Consequence-Driven Cyber-Informed Engineering (CCE), into a universally understood framework. The talk provides actionable insights for communication, budgeting, and system design, making it a substantive contribution despite its origin, demonstrating how physical engineering can limit cyber-physical impact.
Heather Calloway (CISO) — STRONG ACCEPT
Colin Dunn's talk, "Plumbing and Cybersecurity: Basically The Same," offers a compelling and highly effective analogy for communicating complex Operational Technology (OT) cybersecurity challenges to non-technical stakeholders, including boards and executive leadership. By framing OT security in terms of maintaining flow, preventing leaks, and limiting damage, the presentation provides a critical lens for understanding business risk, advocating for proactive investment, and implementing Consequence-Driven Cyber-Informed Engineering (CCE) to build institutional resilience.