Embracing Emerging Technologies to Protect from Past and Future Threats

Dan Gunter

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

In this insightful talk at S4, Dan Gunter addresses the critical need for the industrial cybersecurity sector to adopt emerging technologies and embrace a higher degree of automation in its defense strategies. Drawing parallels from the evolution of control systems and the advancements in autonomous vehicles, Gunter argues that current cybersecurity practices in Operational Technology (OT) environments are struggling to keep pace with the scale and sophistication of modern threats, primarily due to severe resource constraints in human expertise and incident response capabilities.

Watch on YouTube

Visual summary for Embracing Emerging Technologies to Protect from Past and Future Threats by Dan Gunter
Visual summary for Embracing Emerging Technologies to Protect from Past and Future Threats by Dan Gunter

Key moments

  1. 0:00 Embracing emerging technologies and current ICS challenges
  2. 2:00 Incident response bottlenecks and resource limitations
  3. 3:00 Struggling with sophisticated cyber threats like Volt Typhoon
  4. 4:00 Introducing automotive automation levels as a new model
  5. 6:00 Applying automation levels to industrial cybersecurity and AI

Embracing Emerging Technologies to Protect from Past and Future Threats

Speakers: Dan Gunter

Conference: S4

YouTube: https://www.youtube.com/watch?v=Uj-l08LL_iM

Overview

In this insightful talk at S4, Dan Gunter addresses the critical need for the industrial cybersecurity sector to adopt emerging technologies and embrace a higher degree of automation in its defense strategies. Drawing parallels from the evolution of control systems and the advancements in autonomous vehicles, Gunter argues that current cybersecurity practices in Operational Technology (OT) environments are struggling to keep pace with the scale and sophistication of modern threats, primarily due to severe resource constraints in human expertise and incident response capabilities.

The core premise of the presentation is that while traditional best practices like passive network monitoring, segmentation, and security awareness are foundational, they often fall short in practical implementation across vast, geographically dispersed industrial sites. Gunter proposes a model for applying levels of automation to industrial cybersecurity, similar to the SAE J3016 standard for vehicle automation, to systematically enhance defensive postures, accelerate incident response, and bridge the significant talent gap plaguing the industry. This shift is presented not as a replacement for human analysts, but as a necessary evolution to empower them and address the escalating challenges posed by adversaries like Volt Typhoon.

This article will delve into Gunter's proposed framework, examining the current state of industrial cybersecurity across the NIST Cybersecurity Framework functions, highlighting the limitations of current approaches, and exploring how advanced automation, particularly with the aid of Artificial Intelligence (AI), can transform how critical infrastructure is protected from both known vulnerabilities and emergent threats. The discussion emphasizes the practical steps and conceptual shifts required for asset owners and vendors to move towards a more resilient and automated defense ecosystem.

Background

▶ Watch: Embracing emerging technologies and current ICS challenges (0:00)

The landscape of Industrial Control Systems (ICS) has undergone profound transformations, evolving from simple relay logic to complex Programmable Logic Controllers (PLCs) and integrated digital systems. Each technological leap, while enhancing operational efficiency, has introduced new attack surfaces and security challenges. Historically, OT environments prioritized safety and reliability over cybersecurity, leading to a unique set of vulnerabilities and operational constraints.

Today, industrial cybersecurity faces several systemic challenges. Passive network monitoring (PNM), while a best practice for gaining visibility into network traffic and detecting anomalies, often struggles with scalability, cost per sensor, and deep protocol understanding for proprietary or less common ICS protocols (e.g., Gs STI, Schneider Unity). This limits its effectiveness in providing comprehensive observation across dozens to hundreds of sites. Furthermore, traditional defensive measures like firewalls and vulnerability assessments, while crucial, are often implemented manually or with limited automation, leading to slow response times.

The most critical bottleneck identified by Gunter is in incident response (IR). Asset owners, despite managing extensive infrastructure, typically have small in-house IR teams (e.g., 2-7 responders for dozens to hundreds of sites). Outsourcing to vendors offers limited relief, as even large cybersecurity firms often possess a similarly constrained pool of specialists (e.g., 7-9 IR analysts). This creates a significant bottleneck at the response stage, leading to scenarios where incident responders are overbooked, or the time taken to collect forensic artifacts from compromised sites can stretch from weeks to months (e.g., 2-4 weeks for the Air Force CERT to receive artifacts from remote bases). Such delays are catastrophic when dealing with sophisticated, persistent threats like Volt Typhoon, which leverage living off the land (LotL) techniques, making detection and eradication at scale incredibly difficult for small, overstretched teams. The integration of IT and OT, while bringing benefits, also introduces new complexities and potential threat vectors that further strain limited resources.

Recognizing these challenges, Gunter proposes a paradigm shift, drawing inspiration from the Society of Automotive Engineers (SAE) J3016 standard for vehicle automation levels. This standard defines a spectrum from Level 0 (no automation, human drives) to Level 5 (full automation, vehicle drives itself). The key insight is that automation is a spectrum, not an overnight switch, and it can be applied to complex, safety-critical systems like vehicles. This framework provides a structured approach to thinking about increasing automation in industrial cybersecurity, moving from predominantly manual operations to systems that can make more autonomous decisions, albeit with varying degrees of human supervision.

Key Findings

▶ Watch: Incident response bottlenecks and resource limitations (2:00)

The central finding of Gunter's talk is the proposal for a novel framework that applies levels of automation to industrial cybersecurity, mirroring the successful model seen in the automotive industry with SAE J3016. This framework aims to address the critical resource constraints and response delays inherent in current OT security practices.

Gunter outlines a progression of automation levels for industrial cybersecurity:

  • Levels 0-2 (Human-centric): In these initial stages, security operations remain heavily reliant on human analysts for triage, alert correlation, and decision-making. Automation primarily provides support to human operators, such as basic data collection or initial filtering of alerts.
  • Levels 3-5 (System-centric): As automation advances, the system takes on increasingly more decision-making responsibility. This includes automated collection, correlation, and triage of security events, potentially leading to automated responses or mitigations with minimal human intervention. Gunter suggests that Artificial Intelligence (AI) will play a crucial role in enabling security operations to ascend these levels, allowing systems to make more informed decisions and reducing the supervision required from human analysts.

A critical observation is the current state of industrial cybersecurity across the NIST Cybersecurity Framework (CSF) functions:

  • Identify: Gunter classifies this function as largely analyst-supported. While tools exist for asset identification, risk analysis, and firmware versioning, there's a significant opportunity for deeper, process-aware identification.
  • Protect: This function is predominantly manual, indicating a reliance on human intervention for implementing protective measures like segmentation and access controls.
  • Detect: This area sees the most automation and investment, largely categorized as analyst-supported. The speaker attributes this to substantial venture capital funding directed towards passive network monitoring (PNM) tools. However, even with these tools, human analysts are still heavily involved in interpreting outputs and responding to alerts.
  • Respond & Recover: These functions are identified as the weakest links, largely remaining manual and suffering from severe human resource limitations. The inability to rapidly deploy incident responders to geographically disparate sites or quickly collect forensic artifacts (often taking 2-4 weeks) highlights a critical gap.

The overall key finding is that while some progress has been made in identification and detection through tooling, the industry is largely stuck at the lower automation levels, particularly in the crucial response and recovery phases. Embracing higher levels of automation through a structured framework, leveraging AI, and focusing on process-aware data integration are presented as essential pathways to overcome these limitations and build more resilient industrial cybersecurity operations.

Technical Deep Dive

▶ Watch: Struggling with sophisticated cyber threats like Volt Typhoon (3:00)

Dan Gunter's proposition for applying automation levels to industrial cybersecurity is rooted in the practical necessity of scaling defense capabilities against sophisticated threats like Volt Typhoon, especially given the chronic shortage of human experts. The model extends the principles of SAE J3016 to the realm of OT security, envisioning a future where systems take on more proactive roles in protecting critical infrastructure.

At the foundational Levels 0-2 of ICS cybersecurity automation, human analysts remain firmly "in the loop."

  • Level 0 (Manual): All security operations, from monitoring to incident response, are performed manually by human analysts. This is the baseline, characterized by reactive measures and heavy reliance on individual expertise.
  • Level 1 (Assisted): Tools begin to provide assistance, such as basic network monitoring for known signatures or simple asset inventory. Analysts are still responsible for all decision-making and correlation, but they receive raw data or initial alerts from automated systems.
  • Level 2 (Partial Automation): Systems can perform specific, well-defined tasks autonomously, such as initial alert triaging or basic data collection. For instance, a Passive Network Monitoring (PNM) tool might flag anomalous Modbus traffic, but a human analyst still needs to investigate, correlate with other events, and initiate a response. The system provides support, and can even suggest actions, but the human retains ultimate control and decision authority, much like a car with lane assist and adaptive cruise control.

Moving into Levels 3-5, the degree of system autonomy increases significantly:

  • Level 3 (Conditional Automation): The system can perform more complex functions, including collection, correlation, and initial triage of events across multiple data sources. It can make recommendations or even execute certain responses under specific conditions, but still requires human oversight to take over when conditions are outside its operational design domain. This is where AI begins to play a transformative role, sifting through vast amounts of data to identify subtle patterns and reduce false positives, thereby elevating the efficiency of human analysts.
  • Level 4 (High Automation): The system is capable of performing all security tasks within a defined operational domain without human intervention. This might include automated threat hunting for living off the land (LotL) techniques, automated containment of compromised assets, or even the proactive hardening of configurations based on detected vulnerabilities. Human intervention is only requested in exceptional circumstances or for strategic oversight.
  • Level 5 (Full Automation): The system operates autonomously in all conditions, handling all security functions without any human intervention required. This is the ultimate, long-term vision, where the cybersecurity system is fully self-sufficient, adapting to new threats and maintaining security posture continuously.

Gunter highlights how this automation framework can specifically enhance key functions of the NIST Cybersecurity Framework:

Identify: Current asset identification tools often provide basic information like firmware versions or what's behind a Modbus gateway. However, Gunter envisions a "super process aware" identification, where automation correlates cybersecurity events with operational data. He references a 2018 talk at Pi World with Mark Johnson Barbier (SRP) on correlating Pi historian event data frames with cybersecurity incidents. This deeper level of automation would enable systems to not just identify assets, but understand their operational context, detecting changes in process variables that might indicate a cyber-physical attack, similar to a smartwatch detecting health anomalies before a human is aware. This requires integration of network and host data with OT process data, allowing automated systems to make more nuanced correlations than a human could manage at scale.

Recover: This is currently a highly manual and resource-intensive phase. Gunter points to the potential of automation to enable rapid reconstitution of compromised systems. This includes:

  • Automated Configuration Backups and Restoration: Systems could automatically store and push PLC logic or configurations without manual intervention if a PLC is wiped.
  • Rapid Machine Reconstitution: Some vendors are already building hardware devices capable of quickly re-imaging Windows machines or other OT assets.

The challenge lies in managing the scale and complexity across diverse OT environments (e.g., refineries vs. substations), but automation offers a path to significantly improve recovery times, moving from weeks to potentially hours or minutes.

The technical underpinning of this vision involves:

  • Advanced Data Ingestion and Normalization: The ability to collect diverse data (network, host, process data from historians, logs) from various OT devices and normalize it for analysis.
  • AI/Machine Learning (ML) Algorithms: For automated correlation, anomaly detection, threat hunting for LotL techniques, and decision-making at higher automation levels. This includes understanding proprietary protocols and identifying subtle deviations from normal operational baselines.
  • Orchestration and Automation Platforms: To coordinate automated actions, from data collection and analysis to response execution (e.g., blocking traffic, reconfiguring devices, pushing known good configurations).
  • Contextual Awareness: Integrating process awareness into security tools, allowing them to understand the impact of cyber events on physical operations and prioritize responses accordingly.

This technical deep dive reveals a roadmap where automation, powered by AI, systematically augments human capabilities, allowing for a more proactive, scalable, and resilient defense of critical industrial infrastructure.

Demo / Proof of Concept

▶ Watch: Introducing automotive automation levels as a new model (4:00)

The provided transcript does not describe a specific live demonstration or proof of concept presented by Dan Gunter during his talk. The presentation focuses on a conceptual framework for automation in industrial cybersecurity and discusses the current state and future possibilities rather than showcasing a particular tool or system in action.

Defensive Implications

▶ Watch: Applying automation levels to industrial cybersecurity and AI (6:00)

The implications of Dan Gunter's proposed automation framework for defenders in the OT space are profound and necessitate a strategic shift in how cybersecurity is conceived and implemented. The core message is clear: reliance on purely manual processes is unsustainable against the backdrop of escalating threats and persistent resource constraints.

Defenders should actively pursue technologies and strategies that enable a progression towards higher levels of automation, particularly in the Respond and Recover functions, which are currently the most vulnerable. This involves:

  1. Strategic Investment in Automation Platforms: Beyond basic passive network monitoring, organizations need to invest in platforms that can automate data collection, correlation, and initial triage across diverse OT assets. This includes solutions capable of processing network traffic, host logs, and crucially, operational data from systems like Pi historians. The goal is to reduce the manual burden on analysts, allowing them to focus on complex investigations and strategic decision-making.
  1. Embracing Process-Aware Security: Moving beyond generic IT security principles, defenders must seek solutions that embed process awareness. This means understanding the unique operational context of each industrial process, correlating cybersecurity events with changes in physical parameters, and prioritizing responses based on potential impact to safety and operations. Tools that can dynamically map control system dependencies and integrate with process control logic will be invaluable for achieving "super process aware" identification and detection.
  1. Automated Incident Response and Recovery Playbooks: Developing and implementing automated playbooks for common incident types can dramatically reduce response times. This includes automated containment measures (e.g., network segmentation, device isolation), rapid forensic data collection (eliminating the 2-4 week delay cited by Gunter), and automated recovery procedures. For instance, having systems that can automatically push known-good configurations to PLCs or quickly re-image compromised Windows machines in an OT environment can significantly mitigate the impact of a successful attack. This requires rigorous testing to ensure safety and prevent unintended operational disruptions.
  1. Leveraging Artificial Intelligence (AI): AI is not a silver bullet but a powerful enabler for higher automation levels. Defenders should explore AI-driven solutions for anomaly detection, threat hunting (especially for living off the land techniques like those used by Volt Typhoon), and predictive analytics. AI can help correlate disparate events, identify subtle indicators of compromise that human analysts might miss, and prioritize alerts, thereby augmenting the capabilities of limited human teams. It's crucial to focus on AI applications that provide explainability and can be validated by human experts.
  1. Addressing the Talent Gap Proactively: While automation helps bridge the resource gap, it also changes the skill set required. Defenders need to focus on training existing personnel in automation technologies, data science, and advanced analytics. The role of the human analyst will shift from manual data crunching to overseeing automated systems, validating AI outputs, and handling the most complex, novel threats.
  1. Framework Adoption: While Gunter notes that some clients use ISA/IEC 62443, he highlights NIST CSF as another valid framework, noting it was "written for OT." Regardless of the chosen framework (NIST CSF or ISA/IEC 62443), defenders should use it as a structured backbone to assess their current automation levels across functions and identify areas for improvement. The goal is to systematically elevate capabilities from manual to analyst-supported, and eventually to highly automated, especially in critical areas like response and recovery.

By strategically adopting these approaches, defenders can move beyond reactive, manual processes to build a more proactive, scalable, and resilient industrial cybersecurity posture capable of protecting critical assets from both current and future threats.

Key Takeaways

  • Current OT Cybersecurity is Strained: The industrial cybersecurity sector faces severe challenges due to limited human resources, slow incident response capabilities (e.g., 2-4 weeks for artifact collection), and the inability of current tools (like passive network monitoring) to scale effectively across numerous, geographically dispersed sites.
  • Automation as a Solution: Dan Gunter proposes applying a levels of automation framework, inspired by SAE J3016 for autonomous vehicles, to industrial cybersecurity operations. This framework outlines a progression from manual human-centric security to highly automated, system-driven defense.
  • NIST CSF Gaps: While Identify and Detect functions within the NIST CSF are often "analyst-supported" due to tool investments, Protect, Respond, and Recover remain largely "manual," highlighting critical areas where automation is urgently needed.
  • AI's Role in Elevation: Artificial Intelligence (AI) is crucial for moving security operations up the automation levels, enabling systems to make more decisions, reduce human supervision, and effectively handle the collection, correlation, and triage of security events at scale.
  • Process-Aware Identification & Automated Recovery: Future automation should enable "super process aware" identification (correlating cyber incidents with operational data like Pi historian events) and rapid, automated recovery mechanisms (e.g., automatically pushing PLC logic or reconstituting Windows machines) to significantly reduce downtime and impact.
  • Strategic Shift Required: Defenders must make strategic investments in automation platforms, embrace process-aware security, develop automated incident response playbooks, and proactively train personnel to oversee and leverage these advanced automated systems to build a more resilient and scalable defense.

About the Speaker(s)

Dan Gunter is a cybersecurity professional with experience in large-scale network defense. Notably, he previously worked for the Air Force CERT (Computer Emergency Response Team), where he was involved in responding to incidents across a massive network comprising two and a half billion assets and serving 800,000 users. This experience provided him with firsthand knowledge of the challenges associated with scaling incident response and threat hunting across extensive, geographically dispersed environments, particularly the delays in collecting forensic artifacts.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Dan Gunter's talk at S4 presents a compelling and novel framework for scaling industrial cybersecurity defenses through systematic automation, drawing parallels with automotive automation standards. He effectively highlights the critical limitations of current manual incident response capabilities in OT environments, particularly against advanced threats like Volt Typhoon, and proposes a structured approach to leverage AI and process-aware data for automated detection, response, and recovery. The talk offers a practical roadmap for asset owners struggling with resource constraints and provides actionable insights for building more resilient critical infrastructure.

Heather Calloway (CISO) — STRONG ACCEPT

Dan Gunter's S4 talk provides a critical and actionable framework for industrial cybersecurity leaders to address the systemic resource and response challenges in OT environments. By adapting the concept of automation levels from autonomous vehicles, he offers a clear strategic path for asset owners to move beyond manual, overstretched operations towards more resilient, AI-augmented defense. This presentation is a necessary call to action for CISOs in critical infrastructure, emphasizing the institutional shifts and technological investments required to protect against sophisticated threats like Volt Typhoon.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference