The Case for Vertical-Specific OT Cybersecurity Solutions

Miki Shifman

S4x24 - ICS Security Conference · Day 2 · Stage 3

Overview

In the rapidly evolving landscape of operational technology (OT) cybersecurity, a paradigm shift is underway, moving beyond generalized solutions towards highly specialized, vertical-specific OT cybersecurity solutions. This talk, delivered by Miki Shifman, co-founder of Cylus, a company dedicated to rail cybersecurity, makes a compelling case for why deep industry context and data fidelity are paramount for effective protection. Shifman argues that while generic OT security solutions were a necessary evolution from IT-centric approaches, they often fall short in addressing the unique complexities and nuances of individual critical infrastructure sectors.

Watch on YouTube

Visual summary for The Case for Vertical-Specific OT Cybersecurity Solutions by Miki Shifman
Visual summary for The Case for Vertical-Specific OT Cybersecurity Solutions by Miki Shifman

Key moments

  1. 0:00 Introduction: The case for vertical OT cybersecurity solutions
  2. 1:00 Evolution: From IT to generic OT to vertical-specific security
  3. 3:10 Five key criteria defining unique industry needs
  4. 5:20 Challenge 1: Generic asset inventory becomes a spreadsheet
  5. 6:00 Challenge 2: Distinguishing 'by design' alerts from real threats
  6. 6:40 The critical twofold role of industry-specific regulations

The Case for Vertical-Specific OT Cybersecurity Solutions

Speakers: Miki Shifman

Conference: S4

YouTube: https://www.youtube.com/watch?v=Z77ay6thGj4

Overview

In the rapidly evolving landscape of operational technology (OT) cybersecurity, a paradigm shift is underway, moving beyond generalized solutions towards highly specialized, vertical-specific OT cybersecurity solutions. This talk, delivered by Miki Shifman, co-founder of Cylus, a company dedicated to rail cybersecurity, makes a compelling case for why deep industry context and data fidelity are paramount for effective protection. Shifman argues that while generic OT security solutions were a necessary evolution from IT-centric approaches, they often fall short in addressing the unique complexities and nuances of individual critical infrastructure sectors.

The presentation highlights that the common denominator among diverse OT industries is too low for a single solution to be universally effective. Instead, industries like rail, automotive, or maritime possess distinct operational characteristics, device ecosystems, regulatory frameworks, and protocol implementations that demand tailored security strategies. Shifman's insights, drawn from his experience in the rail sector, underscore that true precision in cybersecurity, leading to actionable intelligence and tangible business value, can only be achieved by deeply understanding the specific operational context of an industry. This talk is crucial for cybersecurity professionals, asset owners, and solution providers seeking to enhance the efficacy of their OT security programs.

Background

▶ Watch: Introduction: The case for vertical OT cybersecurity solutions (0:00)

The journey of cybersecurity has seen a progressive evolution, starting predominantly with Information Technology (IT) security. As the digital transformation extended into industrial environments, the inherent differences between IT and Operational Technology (OT) became glaringly apparent. IT security solutions, often designed for data confidentiality, integrity, and availability in business networks, proved inadequate for OT, where safety, availability, and real-time operations are paramount. This realization led to the emergence of generic OT security solutions, a class of tools specifically designed to address the unique challenges of industrial control systems (ICS), SCADA, and other operational technologies.

However, as Miki Shifman eloquently points out, the "hammer for which the entire world is a nail" problem persisted, albeit at a different level. While generic OT solutions were a step in the right direction, they often struggled to provide comprehensive and precise protection across the vast spectrum of OT industries. The core issue lies in the low common denominator among these diverse sectors. A solution designed to protect, for example, a power grid might not effectively secure a railway network or a maritime vessel due to fundamental differences in their operational models, inherent risks, and technological stacks.

Shifman identifies five critical criteria that define the uniqueness of an industry, necessitating a vertical-specific approach:

  1. Functional Applications: These are the core business processes that an industry performs. For rail, it's moving trains; for hospitals, it's saving lives. Understanding these functions is vital because they represent the primary targets for disruption by malicious actors.
  2. Device Profiles: Each industry utilizes a unique array of devices, often with highly specialized engineering nuances that go beyond simple protocol identification. These devices might operate on particular operating systems, custom firmware, or bespoke hardware configurations.
  3. Suppliers: Many OT industries rely on a limited set of specialized suppliers who develop proprietary equipment and systems. Protecting this equipment demands an intimate understanding of its internal workings, including specific operating systems, applications, and communication methods.
  4. Regulations and Standards: Industries are often governed by specific regulations, standards, or requirements related to safety, operations, and increasingly, cybersecurity. Compliance with these mandates often dictates the types of security solutions that can be implemented and how they must function. Examples include TSA regulations for critical infrastructure in the US or various international standards specific to rail (e.g., CENELEC EN 50128/50129 for railway signaling).
  5. Protocols: While common OT protocols exist, their implementation and interpretation can vary significantly. Merely knowing a protocol is present is insufficient; a deep understanding of its application layer, the meaning of every bit, and specific configurations within a given industry context is crucial. This deep understanding allows for accurate anomaly detection and threat identification.

Without addressing these unique characteristics, generic OT security solutions frequently lead to common pitfalls, such as incomplete asset inventories, an abundance of false positive alerts, and an inability to effectively meet industry-specific compliance requirements. This forms the foundational argument for the necessity of vertical-specific solutions that bridge the gap left by their more generalized predecessors.

Key Findings

▶ Watch: Five key criteria defining unique industry needs (3:10)

Miki Shifman's talk highlights several key findings regarding the limitations of generic OT cybersecurity solutions and the imperative for vertical specialization. The central discovery is that a lack of deep industry context fundamentally undermines the effectiveness of security measures, leading to significant operational inefficiencies and an elevated risk posture.

One of the most striking findings relates to asset discovery. While generic solutions can often identify IP addresses, operating systems, or general asset types, they frequently fail to provide the granular detail required for meaningful security. Shifman refers to such outputs as a "glorified spreadsheet" – an inventory that lists assets but lacks the crucial understanding of their business function and operational role. Without this context, it's impossible to accurately assess risk, prioritize vulnerabilities, or understand the potential impact of a compromise. Knowing what an asset is, beyond its technical specifications, is deemed crucial for subsequent business applications of security data.

Another critical finding concerns alert fidelity. Generic OT security solutions often generate a high volume of alerts that appear to indicate security incidents but are, in fact, "by design" operational events. Shifman illustrates this with the example of trains stopping. In the rail environment, there are numerous built-in safety mechanisms that can cause a train to stop, and these are not necessarily indicative of a malicious cyberattack. A system lacking specific rail context might flag every such event as a security alert, overwhelming security teams with false positives. This not only leads to alert fatigue but also diverts resources from investigating genuine threats. Distinguishing between normal operational behavior and true security anomalies requires an intimate understanding of how particular equipment and systems are supposed to work within their specific industrial context.

Finally, the talk emphasizes the dual role of regulation and the inability of generic solutions to adequately address it. Regulations act as both constraints on permissible security activities and empowerment for achieving compliance. Industries like rail, automotive, and maritime are subject to highly specific safety and cybersecurity regulations (e.g., TSA guidelines, CENELEC standards for rail). A generic solution, by its very nature, cannot be deeply attuned to the nuances of these varied regulatory landscapes. Consequently, organizations attempting to use such solutions for compliance often find themselves performing extensive manual work to bridge the gap, incurring significant operational expenditure (Opex) and failing to achieve true regulatory alignment.

In essence, Shifman's key findings underscore that precision is paramount in OT cybersecurity. This precision, which drives both security effectiveness and business value, is unattainable without a deep, vertical-specific understanding of functional applications, device profiles, suppliers, regulations, and the intricate details of protocol implementations. The opposite of this precision is a reliance on manual effort, increased costs, and an inability to focus on truly critical threats.

Technical Deep Dive

▶ Watch: Challenge 1: Generic asset inventory becomes a spreadsheet (5:20)

The core technical argument presented by Miki Shifman revolves around the necessity of context and data fidelity to achieve effective OT cybersecurity, moving beyond superficial insights provided by generic solutions. This deep dive into vertical-specific requirements touches upon asset discovery, alert correlation, and protocol analysis, using the complex rail environment as a primary illustrative example.

At the heart of a robust OT security posture is accurate asset discovery. While IT-centric and even generic OT solutions can identify basic attributes like operating systems or network types, Shifman emphasizes that this is often insufficient. For a vertical-specific solution, asset discovery must go beyond merely listing devices to understanding their business function. In a rail network, for instance, an asset isn't just a "PLC" or a "server"; it's an "interlocking controller" managing track switches, a "train detection system" ensuring safe distances, or an "onboard control unit" managing braking. This functional understanding allows for a more accurate risk assessment and prioritization of security efforts, as the impact of compromising an interlocking controller is vastly different from that of a non-critical sensor.

The challenge of alert fidelity is another critical area demanding vertical context. Generic solutions often rely on signature-based detection or generalized anomaly detection, which can struggle to differentiate between genuine security threats and normal operational events. Shifman highlights that many industrial systems are designed with inherent safety mechanisms that can trigger events resembling security incidents. For example, in rail, a train stopping might be a critical safety function, not a cyberattack. A vertical-specific solution, with its deep understanding of the system's design and operational logic, can classify these "by design" events correctly. This requires knowledge of specific equipment behaviors, expected communication patterns, and the operational states of the system. By integrating this context, the solution can significantly reduce false positives, allowing security analysts to focus on true threats.

Protocol understanding is perhaps where the technical depth of vertical solutions is most evident. Shifman argues that merely identifying the presence of a protocol (e.g., Modbus, DNP3, IEC 61850) is a shallow understanding. True insight comes from comprehending the application layer of the protocol, the meaning of every bit, and the specific configurations and commands used within a particular industry. For instance, a generic OT solution might detect a Modbus communication, but a rail-specific solution would understand the context of a particular Modbus command being sent to a specific type of signaling device, recognizing whether it's an expected operational command or an anomalous, potentially malicious, instruction that could disrupt train movements or safety systems. This level of granularity allows for the detection of subtle attacks that manipulate legitimate protocol functions in an unauthorized manner.

The rail environment serves as a powerful illustration of this complexity. Shifman breaks down the rail system into multiple layers, each with its unique operational technology:

  • Operational Control Center: The highest level, where dispatchers manage train movements across the network. This involves SCADA-like systems, human-machine interfaces (HMIs), and communication with lower layers.
  • Interlocking Level: This crucial layer includes key signaling components and train control systems. Interlockings are safety-critical systems that prevent conflicting train movements by ensuring that switches and signals are coordinated. This level often involves complex logic controllers and significant wireless communication for train control (e.g., Positive Train Control (PTC) systems in the US).
  • Field Elements: Moving further down, these are the physical assets on the tracks, such as railroad switches (points), light signals, and train detection systems (e.g., track circuits, axle counters). These elements directly interact with the physical environment and are fundamental to safe train operation.
  • Trains (Onboard Systems): The trains themselves are highly complex mobile OT environments. They contain numerous systems, including propulsion control, braking systems, door control, passenger information systems, and increasingly sophisticated onboard train control systems that communicate with wayside infrastructure. These systems are unique in their mobility and the critical safety functions they perform.

Protecting such an intricate, interconnected, and safety-critical system requires a solution that understands the specific interplay between these layers, the proprietary protocols often used, the functional safety requirements, and the regulatory mandates. A generic OT solution, lacking this deep contextual awareness, would struggle to provide meaningful security insights or effective protection against threats targeting the unique operational logic and vulnerabilities of a railway.

Demo / Proof of Concept

▶ Watch: Challenge 2: Distinguishing 'by design' alerts from real threats (6:00)

The provided transcript does not include a specific section detailing a live demo or a proof of concept. Miki Shifman primarily focuses on the theoretical and practical arguments for vertical-specific solutions, illustrating concepts with examples from the rail industry rather than demonstrating a particular tool or attack.

Defensive Implications

▶ Watch: The critical twofold role of industry-specific regulations (6:40)

The arguments presented by Miki Shifman carry significant implications for OT defenders across all critical infrastructure sectors. The overarching message is that a "one-size-fits-all" approach to OT cybersecurity is no longer sufficient; instead, defenders must embrace and demand vertical-specific context in their security strategies and solutions.

First and foremost, defenders need to recognize that their asset inventory efforts must go beyond basic device identification. It is crucial to build an inventory that maps assets to their business functions and operational roles. This means understanding not just what a device is, but what it does within the industrial process. This deeper contextual understanding enables more accurate risk assessments, allowing defenders to prioritize security controls and incident response efforts based on the potential impact to critical operations rather than generic technical vulnerabilities.

Secondly, defenders must be wary of alert fatigue caused by generic security solutions that lack the context to differentiate between true threats and normal operational events. They should seek solutions that are intelligent enough to understand the "by design" behaviors of their specific industrial systems. As Shifman illustrated with the rail example, where numerous functions can cause trains to stop for safety reasons, a context-aware system can filter out these benign operational events, allowing security analysts to focus on legitimate security alerts. This precision is vital for efficient incident response and preventing the waste of valuable resources on false positives.

A concrete example of how vertical context aids defenders comes from the Q&A session. Shifman explained how Cylus's rail-specific solution, by monitoring wireless traffic in the rail environment for security threats like evil twins, can also provide operational value. In the US, Positive Train Control (PTC) systems sometimes cause trains to stop due to missed messages or timing issues. A rail-contextual security solution can help operators investigate these operational events by providing data on wireless communication anomalies that might explain why a train stopped. This capability not only enhances cybersecurity but also improves operational efficiency by enabling faster resolution of incidents that impact availability and throughput. By saving analysts time in investigating operational events, it leads to significant Opex savings and quicker restoration of services.

Furthermore, defenders must deeply understand the regulatory landscape governing their specific industry. Security solutions should not just detect threats but also actively help achieve and demonstrate compliance with relevant standards and mandates (e.g., TSA regulations, NERC CIP, CENELEC for rail). This means selecting solutions that are built with an awareness of these regulations and can provide the necessary audit trails and reporting capabilities.

In summary, defensive implications include:

  • Prioritize contextual asset intelligence: Go beyond basic inventory to understand business function and operational role.
  • Demand high-fidelity alerts: Seek solutions that differentiate between security threats and "by design" operational events in your specific industry.
  • Leverage security tools for operational insights: Recognize that deep vertical context in security solutions can also enhance operational efficiency and incident investigation for non-cyber events.
  • Align security with regulatory compliance: Choose solutions that inherently support and empower compliance with industry-specific regulations, reducing manual effort.
  • Invest in specialized knowledge: Develop or acquire expertise in the unique operational technologies, protocols, and processes of your specific industrial vertical.

By adopting these principles, defenders can move towards a more precise, efficient, and ultimately more effective cybersecurity posture tailored to the unique challenges of their critical infrastructure.

Key Takeaways

  • Industry Context is Essential for Precision: Effective OT cybersecurity demands deep, vertical-specific industry context to achieve precision in asset identification, threat detection, and response. Generic solutions often lack the granularity needed for accurate security outcomes.
  • Generic OT Solutions Fall Short: While an improvement over IT-centric approaches, generic OT security solutions have a low common denominator across industries, leading to significant gaps in protection for specialized sectors.
  • Context Prevents "Glorified Spreadsheets" and False Positives: Without understanding an asset's business function and a system's "by design" operational behaviors, security efforts result in incomplete inventories and a flood of misleading alerts, wasting resources.
  • Deep Protocol Understanding is Crucial: Merely identifying a protocol is insufficient; understanding its application layer, bit-level meaning, and industry-specific configurations is vital for detecting sophisticated threats.
  • Regulations are Twofold: Industry-specific regulations act as both constraints on what security actions can be taken and as mandates for compliance, which vertical solutions can uniquely empower.
  • Vertical Solutions Drive Business Value: Beyond pure security, solutions with deep industry context can provide operational value, such as aiding in the investigation of operational events (e.g., Positive Train Control issues in rail) and leading to significant Opex savings.

About the Speaker(s)

Miki Shifman is the co-founder of Cylus, a company established in 2017 that specializes in rail cybersecurity. His professional focus is on developing and implementing cybersecurity solutions tailored specifically for the unique challenges and complexities of the rail industry's operational technology environments. His expertise lies in understanding the distinct functional applications, device profiles, supplier ecosystems, regulatory frameworks, and protocol nuances that differentiate the rail sector from other critical infrastructures.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk by Miki Shifman, co-founder of rail cybersecurity firm Cylus, makes a compelling and well-supported argument for the necessity of vertical-specific OT cybersecurity solutions. Moving beyond the generic "OT vs. IT" debate, Shifman effectively demonstrates why a "one-size-fits-all" approach fails within diverse industrial sectors. Using the complex rail environment as a detailed example, he highlights how deep industry context in functional applications, device profiles, protocols, and regulations is crucial for accurate asset discovery, high-fidelity alerting, and ultimately, real operational value and Opex savings, offering a clear strategic direction for asset owners and…

Heather Calloway (CISO) — STRONG ACCEPT

Miki Shifman's S4 talk compellingly argues for vertical-specific OT cybersecurity solutions, moving beyond generic approaches that fail to address the unique complexities of critical infrastructure sectors. He precisely diagnoses how a lack of deep industry context leads to incomplete asset inventories, an abundance of false positives, and an inability to meet nuanced regulatory compliance, directly impacting an organization's risk posture and operational efficiency. This is a critical strategic insight for any CISO overseeing operational technology environments, providing a clear path to more precise security, reduced operational expenditure, and stronger institutional accountability.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference