Quantifying Risk Reduction Achieved By OT Security Controls

Jake Gentle

S4x24 - ICS Security Conference · Day 3 · Stage 2

Overview

Jake Gentle's presentation at S4 tackled a critical blind spot in current cybersecurity risk assessment methodologies, particularly within Operational Technology (OT) environments: how to quantify risk for assets that lack published vulnerabilities. Traditional risk models heavily rely on Common Vulnerabilities and Exposures (CVEs) and Common Vulnerability Scoring System (CVSS) scores. However, in OT, where assets have exceptionally long lifespans, receive infrequent updates, and are often sourced from a vast and sometimes obscure vendor landscape, many devices present with "zero vulnerabilities" – leading to a dangerous perception of "zero risk."

Watch on YouTube

Visual summary for Quantifying Risk Reduction Achieved By OT Security Controls by Jake Gentle
Visual summary for Quantifying Risk Reduction Achieved By OT Security Controls by Jake Gentle

Key moments

  1. 0:00 Quantifying risk when no vulnerabilities exist in OT
  2. 2:00 Analysis of vendor vulnerability disclosure and behavior
  3. 4:00 Why traditional risk models fail without vulnerabilities
  4. 5:00 Introducing alternative risk parameters: vendor and device measures
  5. 6:00 Three key parameters for assessing vendor security commitment
  6. 7:00 Five key parameters for assessing device-specific security
  7. 8:30 Simulation results and the proposed scoring methodology
  8. 10:00 Recommendation: review most common devices in your environment

Quantifying Risk Reduction Achieved By OT Security Controls

Speakers: Jake Gentle

Conference: S4

YouTube: https://www.youtube.com/watch?v=Jpj7zzsPHQg

Overview

Jake Gentle's presentation at S4 tackled a critical blind spot in current cybersecurity risk assessment methodologies, particularly within Operational Technology (OT) environments: how to quantify risk for assets that lack published vulnerabilities. Traditional risk models heavily rely on Common Vulnerabilities and Exposures (CVEs) and Common Vulnerability Scoring System (CVSS) scores. However, in OT, where assets have exceptionally long lifespans, receive infrequent updates, and are often sourced from a vast and sometimes obscure vendor landscape, many devices present with "zero vulnerabilities" – leading to a dangerous perception of "zero risk."

This talk introduced a novel, structured approach to assign a quantifiable risk score to these seemingly "secure" OT assets. By developing an alternative risk parameter that considers both vendor security posture and device-specific security attributes, Gentle proposed a method to move beyond the limitations of CVE-centric assessments. The initiative aims to provide asset owners with a practical framework to identify, assess, and ultimately prioritize previously unquantified risks, thereby enabling more informed decisions about security controls and driving overall risk reduction in OT.

The importance of this work cannot be overstated. As OT environments become increasingly interconnected, the assumption of "no risk" for assets without CVEs creates significant exposure. Gentle's methodology offers a pathway to comprehensive risk visibility, fostering a more proactive and data-driven approach to OT security that can ultimately influence vendor behavior and enhance the resilience of critical infrastructure.

Background

▶ Watch: Quantifying risk when no vulnerabilities exist in OT (0:00)

The foundational premise of current cybersecurity risk management largely rests on the identification and assessment of vulnerabilities. For decades, the industry has relied on databases like the National Vulnerability Database (NVD) and scoring systems like CVSS to assign a numerical value to the severity and exploitability of known security flaws. This system works reasonably well for Information Technology (IT) assets, where software updates are frequent, and a robust ecosystem exists for reporting and cataloging vulnerabilities.

However, the OT landscape presents unique challenges that render this traditional approach inadequate. OT assets, such as Programmable Logic Controllers (PLCs), Distributed Control Systems (DCS), and Human-Machine Interfaces (HMIs), are designed for decades of operation, often with minimal or no software updates throughout their lifecycle. This leads to a situation where many OT devices simply do not have publicly disclosed CVEs. When traditional risk calculation models are applied, these assets often register a "risk zero," creating a false sense of security for asset owners. As Gentle highlighted, the critical question becomes: "Does unknown risk equal to no risk?"

To address this, the presented research involved an extensive analysis of multiple customer environments. The team examined 20 sites across different regions and industries, discovering over 200 distinct vendors. While well-known names like Siemens, Rockwell, and Schneider Electric were present, a significant proportion were lesser-known or even obscure manufacturers. Further analysis of CISA advisories over an eight-year period revealed telling statistics: only 34% of vendors appeared more than once, indicating a systematic approach to security and vulnerability disclosure. A substantial 66% of vendors, however, appeared only once, suggesting a non-systematic or reactive stance to security issues. Even more concerning were the thousands of vendors who had never appeared in any advisory.

Based on this, OT assets were categorized into three groups concerning CVE presence:

  1. Many Known CVEs: Typically larger vendors (e.g., Siemens, Rockwell, Schneider) who demonstrate a systematic approach to security by frequently disclosing and patching vulnerabilities.
  2. One to Three Known CVEs: Vendors whose limited disclosures suggest a non-systematic or ad-hoc approach to vulnerability management.
  3. No Known CVEs: Assets that have existed for years without any reported vulnerabilities, often leading to a "risk zero" assessment.

The core focus of Gentle's research and the proposed methodology targets the second and third categories, aiming to provide a robust framework for quantifying the inherent, unaddressed risk in these prevalent OT scenarios. The current dependency on CVEs leaves a vast segment of OT infrastructure unassessed and potentially exposed, making a new approach imperative.

Key Findings

▶ Watch: Why traditional risk models fail without vulnerabilities (4:00)

The central finding of this research is the critical inadequacy of traditional, CVE-centric risk assessment models for a significant portion of the OT landscape. The "risk zero" fallacy, where the absence of published vulnerabilities is equated with the absence of risk, represents a dangerous blind spot for asset owners and critical infrastructure operators. The study empirically confirmed that a substantial number of OT vendors and devices either have very few or no publicly reported CVEs, necessitating an entirely new paradigm for risk quantification.

To address this, the research introduced a novel alternative vulnerability risk parameter. This parameter is designed to provide a quantifiable risk score even in the absence of traditional CVE data. The key innovation lies in its dual-pronged approach, focusing on two distinct categories of measures:

  1. Vendor Measures: Assessing the security posture and practices of the manufacturer itself.
  2. Device Measures: Evaluating specific security attributes and lifecycle characteristics of the individual OT product.

The talk highlighted specific, actionable factors within these two categories that, when combined, can yield a meaningful risk score. For instance, a vendor's public vulnerability management policy or its CVE Numbering Authority (CNA) status are strong indicators of its commitment to security, even if individual products have few CVEs. Similarly, device-level factors like firmware update recency or End-of-Life (EOL) status provide crucial insights into its ongoing security posture.

By systematically evaluating these factors, the methodology effectively transforms previously unquantifiable risks into actionable intelligence. The research demonstrated that through careful parameter selection, weighting, and a simplified scoring mechanism (inspired by CVSS), it is possible to generate a non-zero risk score for assets that would otherwise be overlooked. This fundamental shift from purely reactive, vulnerability-driven assessment to a proactive, attribute-based evaluation represents a significant contribution to OT security risk management.

Technical Deep Dive

▶ Watch: Three key parameters for assessing vendor security commitment (6:00)

The proposed methodology for quantifying risk in the absence of traditional CVEs is built upon a structured assessment framework that combines both macro-level vendor attributes and micro-level device characteristics. This framework systematically assigns scores to various parameters, culminating in a comprehensive risk score for each OT asset.

The first set of parameters, Vendor Measures, focuses on evaluating the manufacturer's overall commitment to security. Gentle outlined three key components:

  1. Vulnerability Management Policy: This assesses whether the vendor has a publicly available and transparent policy for managing vulnerabilities. Key indicators include a clear disclosure process, a dedicated security response team, and a commitment to addressing reported issues. The presence of such a policy indicates a proactive and responsible security posture.
  2. Certifications and CNA Status: This parameter considers various security certifications a vendor might hold. Examples include general cybersecurity management certifications like ISO 27001, or more specific OT-related certifications such as IEC 62443-4-1 (which pertains to secure development lifecycle processes). Additionally, CVE Numbering Authority (CNA) status is a strong indicator. A CNA is authorized to assign CVE IDs to vulnerabilities, signifying a vendor's active participation in the global vulnerability ecosystem.
  3. Provision of General Security Guidance: This evaluates whether the vendor provides comprehensive security guidelines or best practices alongside its products. This could include configuration guides for secure deployment, recommendations for hardening devices, or general security whitepapers. The provision of such guidance reflects a vendor's understanding and promotion of secure operational practices.

The second set of parameters, Device Measures, delves into the specific security characteristics of an individual OT product:

  1. CVE for Similar Devices: In the OT space, many devices belong to families or series from the same vendor. This parameter looks for published CVEs for other devices within the same product family or series. The presence of vulnerabilities in related products can indicate potential design flaws or common security weaknesses that might exist in the device under assessment, even if it has no direct CVEs.
  2. Potential Attack Surface: This assesses the configurable security features of the device. It considers factors such as the availability of strong password policies, robust authentication mechanisms (e.g., multi-factor authentication), and the ability to restrict or disable unnecessary open ports and services. A larger, unmanaged attack surface increases inherent risk.
  3. Firmware and OS Versions Recency: This parameter evaluates how recently the vendor has released updates for the device's firmware or operating system. Frequent and recent updates indicate ongoing software investment and a commitment to addressing bugs and security patches, even if not explicitly tied to a CVE. Conversely, outdated firmware suggests neglect and potential unaddressed vulnerabilities.
  4. Lifecycle Status: The End-of-Life (EOL) and End-of-Support (EOS) status of a device is a critical risk factor. Devices nearing or past EOL/EOS no longer receive security updates or vendor support, leaving them highly vulnerable to emerging threats. Tracking this for OT devices, often with unique catalog numbers and long lifecycles, is particularly challenging but essential.
  5. IEC Certification: Beyond vendor-level certifications, some OT devices may carry specific IEC certifications at the product level, indicating adherence to certain security standards during their design and manufacturing.

Each of these parameters is assigned a score, typically on a scale of one to five, similar to the CVSS framework. Gentle explained that simulations were conducted using dozens, if not hundreds, of devices and vendors to determine the appropriate weights and impact of each parameter on the overall score. This weighted sum then produces a quantifiable risk score for the asset, providing a clear, numerical representation of its security posture that was previously absent. The goal is to provide a simplified yet robust model that can be practically applied by asset owners to assess their diverse OT environments.

Demo / Proof of Concept

▶ Watch: Five key parameters for assessing device-specific security (7:00)

While the S4 presentation did not feature a live, interactive demonstration of the risk quantification tool, Jake Gentle introduced the concept of a risk calculator developed based on the presented methodology. The speaker acknowledged that the public web page for this calculator was not fully ready by the conference deadline, but emphasized its availability through a QR code provided at the booth and in the presentation materials.

The intention behind this calculator serves as the practical proof of concept for the framework. It allows asset owners to input information regarding the identified vendor and device measures, and subsequently receive a calculated risk score. This calculator is designed to be a community-driven initiative, with plans to release it in an open-source format, likely on a platform like Git. The objective is to encourage broader adoption, gather feedback, and facilitate the development of a shared repository of scores.

Gentle highlighted that the calculator had been internally tested against "good vendors, bad vendors, good products, bad products" to validate its effectiveness and consistency. The invitation was extended to the audience to utilize the tool and provide feedback, reinforcing the collaborative nature of the project. This calculator represents the tangible application of the theoretical framework, enabling asset owners to move from a conceptual understanding to practical, data-driven risk quantification for their OT assets.

Defensive Implications

▶ Watch: Recommendation: review most common devices in your environment (10:00)

The framework presented by Jake Gentle offers profound defensive implications for organizations operating OT environments, moving them beyond the dangerous "risk zero" fallacy. By providing a structured method to quantify risk for assets without traditional CVEs, defenders gain unprecedented visibility and actionable intelligence.

Firstly, asset owners can now proactively identify and prioritize OT assets that previously appeared secure but inherently carry significant risk. This allows for the targeted allocation of resources for mitigation and remediation efforts, focusing on devices with high calculated risk scores, even if no CVEs are published. This is particularly crucial for critical infrastructure, where the impact of a security incident can be catastrophic.

The methodology provides clear steps for asset owners to begin this process:

  1. Review most common devices/vendors: Start by assessing frequently deployed assets, as these represent a broader organizational exposure.
  2. Detect devices/vendors with no published CVEs: Specifically target the assets that fall into the "risk zero" category, applying the new framework to uncover hidden risks.
  3. Detect End-of-Life (EOL) / End-of-Support (EOS) devices: This is a critical indicator of increased risk in OT. While challenging to track for diverse OT devices, identifying EOL/EOS assets allows defenders to plan for replacement, isolation, or enhanced compensating controls.

Beyond internal prioritization, the initiative has the potential to drive significant change in the OT vendor ecosystem. As the proposed scoring methodology gains community traction and becomes a widely used benchmark, it could incentivize suppliers to improve their security postures. Vendors receiving consistently low scores (indicating higher risk) based on their vulnerability management policies, certifications, or product security guidance may be compelled to invest more in security to remain competitive and trusted. This creates a powerful market-driven mechanism for enhancing security throughout the OT supply chain.

Ultimately, this framework empowers defenders to build a more comprehensive and accurate picture of their OT risk landscape. It enables a shift from reactive patching based on known vulnerabilities to a proactive, holistic risk management strategy that accounts for the unique characteristics and challenges of industrial control systems.

Key Takeaways

  • Traditional CVE-centric risk models are insufficient for comprehensive risk quantification in Operational Technology (OT) environments, leading to a dangerous "risk zero" fallacy for many assets.
  • A novel, structured approach is necessary to quantify inherent risk for OT assets with few or no published vulnerabilities, moving beyond reliance on Common Vulnerabilities and Exposures (CVEs).
  • The proposed methodology introduces two main categories for assessment: Vendor Measures (assessing manufacturer security posture) and Device Measures (evaluating specific product attributes).
  • Key Vendor Measures include vulnerability management policy, certifications (e.g., ISO 27001, IEC 62443-4-1, CVE Numbering Authority (CNA) status), and provision of general security guidance.
  • Key Device Measures encompass CVEs for similar devices, potential attack surface, firmware and OS versions recency, lifecycle status (e.g., End-of-Life (EOL), End-of-Support (EOS)), and IEC certification at the device level.
  • The initiative aims to be a community-driven, open-source tool (a risk calculator) to foster better OT security awareness, provide a common scoring repository, and potentially drive improved security practices from OT suppliers.

About the Speaker(s)

The presentation was delivered by Jake Gentle. While his specific title and company were not explicitly stated in the talk or metadata, the context of his presentation ("as us as a vendor," "including us as a vendor") strongly suggests he works for a cybersecurity vendor specializing in OT security. His work focuses on developing innovative approaches to risk quantification for industrial control systems, particularly addressing the challenges posed by assets with limited or no reported vulnerabilities. He is a proponent of community collaboration and open-source initiatives to enhance OT security awareness and practices across the industry.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Gentle's presentation tackles the critical 'risk zero' fallacy in Operational Technology (OT) environments, where the absence of CVEs leads to a dangerous underestimation of risk. The proposed methodology introduces a novel, structured framework to quantify inherent risk for OT assets by systematically evaluating vendor security posture and device-specific attributes. This is a substantive defensive innovation with significant practical impact for critical infrastructure, offering a pathway to move beyond reactive, CVE-centric assessments to a proactive, attribute-based approach.

Heather Calloway (CISO) — STRONG ACCEPT

Jake Gentle's presentation addresses a critical and dangerous blind spot in OT risk management: the 'risk zero' fallacy for assets lacking traditional CVEs. His proposed framework, which quantifies risk based on vendor posture and device attributes, is a significant step towards enabling clear risk ownership, informed executive decisions, and institutional accountability in environments where traditional models fail. This work provides a much-needed mechanism for asset owners to move from unquantified exposure to actionable risk intelligence, directly impacting business resilience.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference