OT Security Standards Wars
Kenneth Crowther
S4x24 - ICS Security Conference · Day 2 · Stage 2
Overview
In this thought-provoking S4 talk, Kenneth Crowther, Product Security Leader at Xylem, challenges the efficacy of current Operational Technology (OT) cybersecurity standards, arguing that they are not adequately securing critical infrastructure. Crowther introduces the concept of "standards wars," a phenomenon driven by fundamental market forces and the operational models of standards organizations. He posits that the relentless pursuit of "minimum viable consensus" within these bodies leads to a proliferation of fragmented, "stove-piped" standards. This fragmentation, far from enhancing security, creates immense complexity, escalates compliance costs, and ultimately leaves OT systems vulnerable.

Key moments
- 0:28 Overview effect: why cybersecurity standards fail
- 1:07 Contrasting product and information value chains
- 2:30 Multi-stakeholder systems and the rise of standards wars
- 4:05 The "minimum viable consensus" and standards proliferation
- 6:00 Chemical industry's standards wars and global harmonization
- 7:37 Proliferation of OT cybersecurity standards and challenges
OT Security Standards Wars
Speakers: Kenneth Crowther, Product Security Leader, Xylem
Conference: S4
YouTube: https://www.youtube.com/watch?v=prhV1RgsUcg
Overview
In this thought-provoking S4 talk, Kenneth Crowther, Product Security Leader at Xylem, challenges the efficacy of current Operational Technology (OT) cybersecurity standards, arguing that they are not adequately securing critical infrastructure. Crowther introduces the concept of "standards wars," a phenomenon driven by fundamental market forces and the operational models of standards organizations. He posits that the relentless pursuit of "minimum viable consensus" within these bodies leads to a proliferation of fragmented, "stove-piped" standards. This fragmentation, far from enhancing security, creates immense complexity, escalates compliance costs, and ultimately leaves OT systems vulnerable.
Crowther's presentation is a strategic analysis, urging the OT security community to adopt an "overview effect" – a holistic, systematic perspective akin to how astronauts view Earth from space. He draws a compelling parallel with the chemical industry's historical struggle with conflicting hazard labeling standards, which was eventually resolved through the United Nations' Global Harmonized Standard (GHS). This historical precedent serves as a powerful argument for a similar, harmonized approach to OT cybersecurity, emphasizing that without such a systemic shift, the current trajectory will continue to impede true security advancements.
The talk is crucial for anyone involved in OT security, from practitioners and engineers to policymakers and business leaders. It dissects the underlying economic and organizational dynamics that shape our security landscape, providing a fresh perspective on why current efforts often fall short. By understanding these systemic issues, stakeholders can better advocate for and contribute to the development of more effective, integrated, and genuinely secure OT environments.
Background
▶ Watch: Overview effect: why cybersecurity standards fail (0:28)
The genesis of "standards wars" in OT cybersecurity, as articulated by Kenneth Crowther, lies in a fundamental shift in market dynamics and the inherent operational characteristics of standards organizations. Crowther begins by illustrating the distinction between two primary value chains: the product value chain and the information value chain.
A product value chain is exemplified by companies like Xylem, which primarily manufactures physical assets such as pumps. These assets are physical, sold once, and scaling operations is resource-intensive, requiring new personnel, retooling, recalibration, and significant capital expenditure. Critically, there are no inherent network effects; selling more pumps provides the same value, and a typical product value chain is valued at approximately five times its cash flow.
In stark contrast, an information value chain revolves around data. Every physical asset generates data that can be collected, stored, and leveraged to improve decision-making. Crowther cites an example where a typical $50,000 install can save a water utility a million dollars a year, demonstrating the immense value derived from information. Information value chains are characterized by their ability to be sold repeatedly through licenses, subscriptions, and consulting fees. Despite holding no physical inventory or assets, these chains are valued at an astonishing 25 times their cash flow due to their future potential for sales and opportunities. This significant difference in valuation drives a powerful trend: the increasing push towards connected systems centered on intricate webs of information value chains. This shift also fosters multi-stakeholder systems, blurring the traditional notion of a single asset owner and creating complex, untangleable dependencies.
Standards organizations themselves operate as information value chains. They monetize a consensus expert set of expertise through licensing fees. To minimize their operational expenses (OpEx), these organizations typically recruit volunteer experts from a diverse array of backgrounds. This includes young professionals seeking resume enhancements, consultancy shops aiming to build their own information value chains around the standard, vendors ensuring feasibility, end-users needing to screen vendors, and government representatives driven by public interest.
This melting pot of diverse expertise, while valuable, often struggles to reach a swift consensus. However, the network effects inherent in information value chains demand rapid consensus. This pressure inevitably leads to a narrowing of scope, forcing the creation of a minimum viable consensus. This "minimum viable" standard, though released to address an immediate need, is inherently focused on a very specific "stovepipe." The consequence is a continuous cycle where new threats, regulations, or hazards necessitate yet another narrow standard, resulting in an uncontrolled proliferation. This places the burden squarely on individual product companies and integrators to navigate this convoluted landscape, select from dozens of disparate standards, and somehow piece together a secure environment – a task of immense and often overwhelming complexity.
Key Findings
▶ Watch: Multi-stakeholder systems and the rise of standards wars (2:30)
Crowther's central finding is that the current approach to OT cybersecurity standards has devolved into a state of "standards wars," leading to a detrimental proliferation of fragmented and often conflicting guidelines. This phenomenon is not accidental but a direct consequence of the economic forces driving modern OT systems and the inherent operational dynamics of standards organizations.
The core problem, as identified, is the creation of stove-piped standards. Each standard, born from a "minimum viable consensus" to address a specific, narrow threat or regulatory requirement, fails to provide a holistic security framework. This results in a complex and ever-growing landscape of requirements that product manufacturers and integrators must contend with. Crowther highlights his personal experience, noting that at both GE and Xylem, no single standard has been sufficient to meet the diverse requirements from integrators and customers, nor can any single standard span the spectrum from bare-metal firmware on a custom controller to large-scale, multi-component OT systems.
This fragmentation has several critical consequences:
- Increased Compliance Costs: Companies are forced to invest significant resources in understanding, implementing, and demonstrating compliance with multiple, often overlapping, standards. This administrative burden frequently outweighs the actual security benefits.
- Lack of Comprehensive Security: The stove-piped nature means that critical interdependencies or broader systemic vulnerabilities might be overlooked, as each standard focuses only on its narrow domain. This creates potential gaps in an organization's overall security posture.
- Trade Barriers: Mismatches between standards can create friction and barriers to trade, particularly in a globalized market, hindering the adoption of secure technologies.
- Complexity for Defenders: Asset owners and integrators face an overwhelming task in selecting, applying, and managing these disparate standards, making it difficult to achieve a consistently secure environment.
To illustrate the casualties of such standards wars and demonstrate a viable path forward, Crowther draws a compelling analogy to the chemical industry. In the 1970s and 80s, the rapid expansion of chemical transport across national borders led to a surge in accidents. In response, numerous standards organizations developed dozens of chemical labeling and hazard identification frameworks. This fragmented approach led to escalating compliance costs without a proportional decrease in accident rates, and it created significant trade barriers. Recognizing this critical issue, the United Nations convened a consortium in 1992 to harmonize these disparate standards. The result was the Global Harmonized Standard (GHS). While its implementation required significant investment in retraining, retooling, and reimplementation (costing millions of dollars), the GHS is now estimated to save hundreds of billions of dollars annually in compliance costs and has demonstrably improved safety and reduced accident rates.
Crowther concludes that the OT cybersecurity community is currently experiencing its own version of these standards wars. The key finding is that a similar "overview effect" – a systematic, harmonized approach – is urgently needed to move beyond the current state of fragmented standards and achieve meaningful, scalable security improvements in OT.
Technical Deep Dive
▶ Watch: The "minimum viable consensus" and standards proliferation (4:05)
While Crowther's talk does not delve into specific code vulnerabilities or network protocols in the traditional sense of a "technical deep dive," it provides a profound technical analysis of the architecture and mechanisms driving the current state of OT cybersecurity standards. The "technical" aspect here lies in understanding the underlying economic and organizational forces that shape the standards themselves, which in turn dictate the security posture of OT systems.
The core technical mechanism driving the "standards wars" is the economic model of information value chains and its interaction with the process of minimum viable consensus. Standards organizations, as information value chains, operate under specific financial incentives. Their primary product is codified expertise, which they license for revenue. Unlike physical products, information scales efficiently and benefits from network effects – the more widely a standard is adopted, the more valuable it becomes. This economic model places pressure on standards bodies to achieve consensus quickly to capitalize on market opportunities.
To minimize operational expenses (OpEx), these organizations rely heavily on volunteer contributions. The recruitment strategy targets a diverse group:
- Young Professionals: Motivated by career advancement and resume building.
- Consultancy Shops: Seeking to create derivative information value chains (e.g., training, implementation services) around the new standard.
- Vendors: Ensuring the standard is technically feasible and can be met by their products, potentially gaining a competitive edge.
- End Users: Utilizing standards to screen vendors and ensure baseline security.
- Government Representatives: Driven by public safety and regulatory interests.
This diverse volunteer base, while bringing a wealth of expertise, inherently struggles to reach a broad, comprehensive consensus rapidly. The imperative for speed, driven by the network effects inherent in information value chains, forces a pragmatic compromise: the pursuit of minimum viable consensus. This process involves narrowing the scope of the standard to the bare essentials that the diverse group can agree upon within a reasonable timeframe. The result is a highly focused, often granular standard designed to address a specific problem or regulatory gap.
The consequence of this "minimum viable consensus" is the creation of stove-piped standards. Each standard effectively becomes a silo, addressing one facet of security (e.g., network segmentation, endpoint hardening, supply chain integrity) without necessarily integrating seamlessly with others. For a product company like Xylem, which must secure systems ranging from bare-metal firmware on custom controllers to large-scale integrated OT systems comprising hundreds of components, this fragmented landscape is untenable. There is no single standard that can effectively span this entire spectrum of scale and complexity.
Furthermore, the shift towards connected systems and multi-stakeholder systems exacerbates this issue. As OT assets become increasingly interconnected and generate vast amounts of data, the traditional model of a single asset owner responsible for a contained system rapidly disappears. Security responsibilities become distributed across vendors, integrators, and multiple end-users, creating an "untangleable web" of dependencies. In such an environment, fragmented standards only add to the complexity, making it exceedingly difficult to establish clear security boundaries, enforce consistent policies, and achieve end-to-end assurance. The "technical deep dive" here is into the system design of standards creation itself, revealing how its current architecture is fundamentally ill-equipped to address the evolving and interconnected security needs of modern OT.
Demo / Proof of Concept
▶ Watch: Chemical industry's standards wars and global harmonization (6:00)
Kenneth Crowther's talk did not feature a live technical demonstration or a software-based proof of concept in the traditional sense of showcasing code, exploits, or tool functionality. Instead, his "proof of concept" was a historical and economic one: the successful resolution of "standards wars" in the chemical industry through the adoption of the Global Harmonized Standard (GHS).
Crowther vividly described the chaotic situation in the 1970s and 1980s, where the burgeoning $1.7 trillion chemical industry faced a rapid increase in accidents due to the cross-border shipping and transport of hazardous materials. In response, dozens of disparate chemical labeling and hazard identification frameworks emerged globally. This proliferation of uncoordinated standards led to several critical problems:
- Increased Compliance Costs: Companies had to navigate a labyrinth of conflicting regulations, leading to significant administrative and operational overheads.
- Elevated Accident Rates: Despite the numerous standards, the lack of a unified approach meant that safety improvements were minimal, and accidents continued to rise.
- Trade Barriers: Mismatches between national and regional standards created significant obstacles to international trade, hindering economic activity and the efficient movement of goods.
Recognizing the escalating crisis, the United Nations spearheaded an initiative in 1992 to harmonize these conflicting standards. This monumental effort aimed to create a single, globally recognized system for classifying and labeling chemicals. The resulting Global Harmonized Standard (GHS) required immense investment in its implementation. Crowther noted that it likely cost "millions of dollars to retrain, retool, and reimplement" systems and processes worldwide.
However, the long-term benefits have been staggering. Current estimates suggest that the GHS saves "hundreds of billions of dollars per year in compliance costs." More importantly, it has demonstrably improved safety and significantly reduced accident rates across the chemical industry by providing a clear, consistent, and universally understood framework for hazard communication.
This historical case serves as Crowther's compelling "proof of concept" for the "overview effect" he advocates. It demonstrates that standards wars, despite their complexity and deeply entrenched interests, can be resolved through a concerted, systematic, and harmonized international effort. The GHS illustrates that while the initial investment in harmonization can be substantial, the long-term returns in terms of reduced costs, improved safety, and streamlined operations are exponentially greater. This example directly supports his argument that a similar, unified approach is not only desirable but essential for the OT cybersecurity community to overcome its current fragmented state and achieve genuine security.
Defensive Implications
▶ Watch: Proliferation of OT cybersecurity standards and challenges (7:37)
The "standards wars" described by Kenneth Crowther have profound implications for defenders in the OT space, necessitating a shift from a reactive, compliance-focused mindset to a proactive, holistic security strategy. The current proliferation of stove-piped standards creates significant challenges and potential vulnerabilities that defenders must address.
Firstly, for product companies and integrators, the burden of navigating and implementing dozens of disparate cybersecurity standards is immense. This complexity often leads to:
- Increased overhead: Resources are diverted to compliance activities rather than direct security enhancements.
- Inconsistent security postures: It's difficult to ensure uniform security across diverse product lines or integrated systems when relying on fragmented guidelines.
- Vendor lock-in and compatibility issues: Choosing standards that align with specific vendor offerings can limit flexibility and create integration headaches.
Defenders in these roles must push for standardization within their own organizations to create internal profiles or frameworks that synthesize the most critical aspects of relevant standards into a manageable, actionable security program. They should also actively participate in standards bodies like ISA and SAE, advocating for broader scope and harmonization.
Secondly, for asset owners and operators, the fragmented standards landscape complicates the process of securing critical infrastructure. It becomes challenging to:
- Screen vendors effectively: Without a unified standard, comparing the security claims of different vendors is difficult and subjective.
- Assess overall risk: A patchwork of compliance certifications does not equate to a comprehensive understanding of an organization's actual security posture.
- Manage multi-stakeholder systems: As OT environments become more interconnected and involve multiple entities, the lack of harmonized standards makes shared responsibility models opaque and accountability difficult to enforce.
Defenders here need to prioritize risk-based security frameworks that transcend specific standard requirements. They should focus on understanding their critical assets, threat landscape, and implementing controls that deliver tangible security outcomes, rather than simply checking boxes against a long list of fragmented compliance mandates. Adopting a systematic approach to security architecture, security by design, and continuous monitoring becomes paramount.
Ultimately, Crowther's call for an "overview effect" implies that defenders must look beyond individual standards and champion a more harmonized and integrated approach at an industry level. This involves:
- Advocacy for harmonization: Supporting initiatives that aim to consolidate or align existing standards, much like the GHS did for the chemical industry.
- Focus on systematic security: Moving away from a checklist mentality towards understanding and implementing security as an integral part of the entire OT lifecycle, from design to decommissioning.
- Understanding economic drivers: Recognizing that standards bodies are information value chains can help defenders engage more strategically, influencing the scope and direction of new standards to ensure they serve broader security goals rather than narrow commercial interests.
The defensive implication is clear: simply accumulating more standards will not make OT systems more secure. Instead, a strategic, collaborative, and harmonized effort is required to transform the current "standards wars" into a unified defense strategy.
Key Takeaways
- OT Cybersecurity is in a "Standards War": The current landscape is characterized by a proliferation of fragmented, "stove-piped" standards that do not adequately secure critical infrastructure.
- Market Forces Drive Fragmentation: The economic model of information value chains, including standards organizations themselves, alongside the pursuit of minimum viable consensus to minimize operational expenses, leads to narrowly scoped standards.
- Increased Complexity and Costs: This fragmentation results in higher compliance costs for product companies and integrators, creates trade barriers, and makes it challenging for asset owners to achieve comprehensive, consistent security across their diverse OT environments.
- The "Overview Effect" is Crucial: A holistic, systematic perspective is needed to move beyond the current state of standards wars and create genuinely effective security frameworks.
- Historical Precedent for Harmonization: The Global Harmonized Standard (GHS) in the chemical industry serves as a powerful example, demonstrating that a UN-led initiative successfully consolidated dozens of conflicting standards, saving billions and significantly improving safety.
- Defenders Must Advocate for Integration: OT security professionals, product companies, and asset owners should actively participate in and advocate for the harmonization and integration of standards, focusing on overall security outcomes rather than fragmented compliance.
About the Speaker(s)
Kenneth Crowther is a Product Security Leader at Xylem, a global water technology company. His role involves navigating the complex intersection of product development and cybersecurity within the operational technology domain. Prior to his tenure at Xylem, Crowther also gained significant experience at GE, contributing to his deep understanding of industrial systems and their security challenges. His expertise lies in analyzing the broader market forces and organizational dynamics that influence the effectiveness and adoption of cybersecurity standards in critical infrastructure. Through his work, he aims to foster a more systematic and effective approach to securing OT environments.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Crowther’s talk brilliantly dissects the underlying economic and operational forces driving the chaotic "standards wars" in OT cybersecurity. He provides a novel, systemic analysis of how information value chains and the pursuit of "minimum viable consensus" by standards bodies lead to fragmented, stove-piped guidelines that ultimately fail to secure critical infrastructure. His compelling analogy to the chemical industry's successful harmonization efforts with GHS offers a clear path forward, making this a crucial and actionable critique for anyone serious about OT security.
Heather Calloway (CISO) — MUST SEE
Kenneth Crowther's talk on "OT Security Standards Wars" is a critical analysis that every CISO and board member overseeing critical infrastructure needs to hear. He incisively diagnoses the systemic failures in OT cybersecurity standards, attributing them to fundamental market forces and the operational models of standards organizations. This isn't just a problem statement; it's a strategic call to action, complete with a compelling historical precedent in the chemical industry's Global Harmonized Standard (GHS), demonstrating a clear path forward for achieving genuine, scalable security and economic benefit.