Building ICS/OT Security Communities
Peter Jackson
S4x24 - ICS Security Conference · Day 3 · Main Stage
Overview
In this insightful S4x24 talk, Peter Jackson, OT Cyber Security Manager for SGSECL and a SANS instructor, passionately articulates the critical need for robust community building within the Industrial Control Systems (ICS) and Operational Technology (OT) security domain. Drawing on his experience as the founder and facilitator of the NZ ICS Cyber Technical Network, Jackson presents a compelling narrative of how a grassroots initiative can evolve into a thriving hub for hundreds of practitioners dedicated to tackling the unique challenges of securing industrial environments. His presentation serves not merely as a case study but as a powerful call to action, urging individuals to become "change agents" and actively contribute to their local and regional OT security defenses.

Key moments
- 0:00 Introduction: The strength of community in OT security
- 1:00 Speaker's background and founding NZ ICS Cyber Technical Network
- 1:30 Call to action: Be a change agent for your community
- 3:50 Transitioning from control systems to OT security awareness
- 4:10 First seminars: Addressing the ICS/OT security knowledge gap
Building ICS/OT Security Communities
Speakers: Peter Jackson, OT Cyber Security Manager, SGSECL
Conference: S4
YouTube: https://www.youtube.com/watch?v=JLmmTSwFzu8
Overview
In this insightful S4x24 talk, Peter Jackson, OT Cyber Security Manager for SGSECL and a SANS instructor, passionately articulates the critical need for robust community building within the Industrial Control Systems (ICS) and Operational Technology (OT) security domain. Drawing on his experience as the founder and facilitator of the NZ ICS Cyber Technical Network, Jackson presents a compelling narrative of how a grassroots initiative can evolve into a thriving hub for hundreds of practitioners dedicated to tackling the unique challenges of securing industrial environments. His presentation serves not merely as a case study but as a powerful call to action, urging individuals to become "change agents" and actively contribute to their local and regional OT security defenses.
The core of Jackson's message revolves around the strength derived from collective knowledge and shared problem-solving. He emphasizes that the complex and rapidly evolving threat landscape confronting critical infrastructure necessitates a collaborative approach, moving beyond isolated efforts. By fostering environments where practitioners can openly discuss, debate, and "hash out those hard problems," communities like the NZ ICS Cyber Technical Network empower individuals, elevate the collective understanding, and ultimately fortify the resilience of essential services against cyber threats. This talk is particularly relevant for security professionals, industrial engineers, and organizational leaders seeking practical strategies to enhance their OT security posture through collaborative engagement.
Jackson's personal journey from a control engineer to an OT cybersecurity leader underpins his advocacy for community. He highlights the common realization of "conscious incompetence" – moving from not knowing what one doesn't know to understanding the vast gaps in knowledge – as a pivotal moment that spurred the creation of his network. This talk provides a blueprint for how to bridge those knowledge gaps, cultivate expertise, and translate complex technical concepts into actionable strategies for diverse stakeholders, ultimately contributing to a stronger, more informed global OT security ecosystem.
Background
▶ Watch: Introduction: The strength of community in OT security (0:00)
Peter Jackson's journey into OT security mirrors that of many professionals in the field: a foundational career in control systems engineering, followed by a gradual but critical shift towards understanding and mitigating cyber risks in industrial environments. Initially a "baby control engineer," Jackson quickly immersed himself in the intricacies of Programmable Logic Controllers (PLCs), industrial processes, and ultimately, functional safety systems. His experience as a functional safety engineer proved particularly instrumental, providing him with a profound appreciation for the parallels between safety and security – an analogy he frequently leverages to communicate complex cybersecurity concepts to non-technical stakeholders within industrial organizations.
A significant turning point in Jackson's career, and a catalyst for his community-building efforts, came when he was seconded into a role focused on what we now recognize as OT security. This transition marked a shift from a state of "unconscious incompetence" – not knowing the extent of his knowledge gaps in cybersecurity – to "conscious incompetence," where the sheer scale of unaddressed security challenges within industrial control systems became starkly apparent. While the energy sector had historically demonstrated a more mature approach to ICS security, Jackson observed that the broader community of practitioners, particularly those served by system integrators, largely remained unaware of the sophisticated threats and best practices required for robust defense.
This widespread lack of awareness and fragmented knowledge became the driving force behind the creation of the NZ ICS Cyber Technical Network. Jackson recognized that individual organizations and practitioners were grappling with similar "hard problems" in isolation, hindering collective progress. The existing landscape was characterized by a deficit in platforms for shared learning, peer mentorship, and collaborative problem-solving, particularly for intermediate-level challenges. To address this, he envisioned a community where experts and novices alike could converge, share insights, and collectively elevate the regional understanding and capabilities in OT/ICS cybersecurity. This initiative was designed to fill a crucial void, providing a structured yet informal environment for practitioners to grow, learn, and contribute to a stronger collective defense.
Key Findings
▶ Watch: Speaker's background and founding NZ ICS Cyber Technical Network (1:00)
The primary finding presented by Peter Jackson is the remarkable success and scalability of a community-driven approach to enhancing OT/ICS cybersecurity capabilities. The NZ ICS Cyber Technical Network, initiated from a modest seminar, has burgeoned into a vibrant community of approximately 400 practitioners. Notably, around 300 of these members are based in New Zealand, with a significant number of additional members from Australia, demonstrating the regional impact and appeal of the network. This growth underscores the profound need for such platforms and the effectiveness of Jackson's model.
Several key elements contributed to this success:
- Structured Educational Events: The network's genesis lay in seminars, starting in 2017. These events were designed to be informative and engaging, featuring both local and international presenters. The content was often structured around established frameworks like the NIST Cybersecurity Framework's five functions, providing a common language and systematic approach to understanding and implementing security measures. This structured learning environment helped demystify complex topics and offered practical guidance.
- Facilitated Dialogue and Problem-Solving: A crucial component of the seminars was the inclusion of panel discussions involving speakers and attendees. These sessions were specifically designed for "hashing out" intermediate-level ICS and OT security challenges. This interactive format fostered a sense of collective ownership over problems and enabled participants to learn from diverse perspectives and shared experiences, moving beyond theoretical knowledge to practical application.
- Strategic Communication Analogies: Jackson highlights the effectiveness of the safety security analogy when engaging with non-technical stakeholders. Industrial organizations inherently understand the concept of safety maturity journeys, making it a powerful tool for translating the importance and progression of cybersecurity maturity. Similarly, he emphasizes the value of translating the control room alarm management mindset – a well-understood operational concept – into an OT SOC alert management mindset, bridging the gap between traditional operations and modern security operations.
- Integration of Cybersecurity into Existing Standards: Jackson notes the significance of updates to standards such as IEC 61511, which now explicitly introduces cybersecurity as a requirement for Safety Instrumented Systems (SIS) within their functional safety life cycle. This integration underscores the converging nature of safety and security in industrial environments and provides a regulatory impetus for adoption. His involvement with the ISA 18 committee on alarm management further exemplifies the commitment to integrating security considerations into foundational operational practices.
These findings collectively demonstrate that proactive, community-led initiatives, built on structured learning, collaborative problem-solving, and effective communication strategies, are not only viable but essential for elevating the maturity of OT/ICS security across diverse industrial sectors.
Technical Deep Dive
▶ Watch: Call to action: Be a change agent for your community (1:30)
While Peter Jackson's talk is primarily focused on community building, it implicitly touches upon several critical technical and standards-based aspects that underpin effective OT/ICS security. The community's discussions and educational initiatives are rooted in addressing the unique technical challenges of securing industrial environments.
One of the most significant technical standards highlighted is IEC 61511, which pertains to functional safety and Safety Instrumented Systems (SIS) for the process industry sector. Jackson specifically mentions the update to this standard that introduces cybersecurity as a requirement within the functional safety life cycle. This is a profound development, as SIS are critical components designed to prevent hazardous events and mitigate risks in industrial processes. Traditionally, the focus of functional safety has been on hardware reliability and software integrity from a safety perspective. The integration of cybersecurity requirements means that engineers and practitioners must now consider how cyber threats could compromise the integrity, availability, or confidentiality of SIS, potentially leading to catastrophic safety incidents. This mandates a holistic approach where cybersecurity assessments and controls are applied rigorously throughout the entire life cycle of safety instrumented functions, from design and implementation to operation and maintenance. The community's discussions would undoubtedly delve into practical interpretations of these requirements, methods for conducting cybersecurity risk assessments for SIS, and strategies for implementing secure architectures that preserve safety functions.
Another area of technical focus is alarm management, with Jackson specifically referencing his support for the ISA 18 committee. The ISA-18 standard, "Management of Alarm Systems for the Process Industries," provides guidance on the design, implementation, operation, and maintenance of alarm systems. In an OT context, effective alarm management is crucial for operators to respond quickly and correctly to abnormal situations. Jackson draws a vital parallel between the control room alarm management mindset and the OT SOC alert management mindset. This translation is technically significant because it bridges the operational understanding of process deviations with the security understanding of anomalous network behavior or system compromise. In a control room, an alarm signals a process upset; in an OT Security Operations Center (SOC), an alert signals a potential cyber intrusion. Both require rapid, accurate assessment and decisive action. The technical challenge lies in correlating disparate data sources – process alarms, network logs, endpoint telemetry – to differentiate between operational anomalies and malicious activity, and to establish clear thresholds, prioritization schemes, and response protocols for security alerts that are analogous to established alarm management practices. This involves understanding industrial protocols, device behaviors, and the potential impact of cyber events on physical processes.
Furthermore, the seminars structured around NIST frameworks (specifically the five functions: Identify, Protect, Detect, Respond, Recover) provide a robust technical and procedural backbone for the community's learning. These frameworks offer a systematic way to categorize and address cybersecurity activities. For instance, "Identify" involves understanding industrial assets, vulnerabilities, and risks; "Protect" entails implementing technical controls like network segmentation, access control, and secure configurations for PLCs, Human-Machine Interfaces (HMIs), and Supervisory Control and Data Acquisition (SCADA) systems. "Detect" focuses on deploying sensors and analytics to identify anomalies indicative of cyber threats, often leveraging techniques like deep packet inspection (DPI) for industrial protocols. "Respond" and "Recover" involve developing and testing incident response plans tailored to the unique constraints of OT environments, such as prioritizing operational continuity over data forensics in certain scenarios. The community would engage in detailed discussions on how to practically apply these NIST functions within specific industrial contexts, considering the constraints of legacy systems, proprietary protocols, and the paramount importance of safety and availability.
In essence, while the talk champions community, the very "hard problems" that necessitate such a community are deeply technical. They involve the secure integration of IT and OT networks, the application of cybersecurity principles to deeply embedded and often purpose-built industrial hardware and software, the nuanced detection of threats within operational data, and the development of incident response strategies that account for both cyber and physical impacts. The community provides the forum for dissecting these complexities, sharing technical solutions, and collaboratively developing best practices that are both theoretically sound and practically implementable.
Demo / Proof of Concept
▶ Watch: Transitioning from control systems to OT security awareness (3:50)
This particular talk by Peter Jackson focused entirely on the conceptual framework and practical implementation of building an ICS/OT security community. As such, there was no technical demonstration or proof of concept presented during the session. The speaker's objective was to inspire and guide attendees on creating similar networks, rather than showcasing specific tools, vulnerabilities, or defensive technologies.
Defensive Implications
▶ Watch: First seminars: Addressing the ICS/OT security knowledge gap (4:10)
The establishment and growth of communities like the NZ ICS Cyber Technical Network carry significant defensive implications for the broader OT/ICS security landscape. These implications extend beyond individual organizations, contributing to regional and even national cybersecurity resilience.
Firstly, enhanced knowledge sharing and collective intelligence are paramount. The "hard problems" in OT security – such as achieving comprehensive asset visibility, detecting sophisticated threats within industrial protocols, or developing incident response plans that prioritize safety and operational continuity – are rarely solved in isolation. A community provides a trusted forum where practitioners can share lessons learned, discuss emerging threats, and validate defensive strategies. This collective intelligence accelerates the adoption of best practices and helps organizations avoid common pitfalls, effectively raising the baseline security posture across the region. For instance, discussions around the practical implementation of network segmentation in brownfield sites or the nuances of configuring Intrusion Detection Systems (IDS) for Modbus/TCP traffic can lead to more effective deployments.
Secondly, the community fosters standardization and consistent application of frameworks. By structuring seminars around established guidelines like the NIST Cybersecurity Framework, the network promotes a common understanding and consistent approach to security. This is crucial for defenders, as it allows for interoperability in threat intelligence sharing, facilitates benchmarking, and ensures that fundamental security controls are being addressed across different sectors. The explicit inclusion of cybersecurity requirements in IEC 61511 for Safety Instrumented Systems (SIS), as highlighted by Jackson, further reinforces the need for a standardized approach to integrate safety and security, ensuring that critical safety functions are not inadvertently compromised by cyber vulnerabilities.
Thirdly, the community acts as a force multiplier for skill development and workforce empowerment. The OT security talent gap is a well-documented challenge. By creating a platform for mentorship, peer learning, and access to international expertise, these networks help upskill existing professionals and attract new talent to the field. Jackson's own journey from control engineer to OT security specialist, aided by SANS training, demonstrates the transformational power of dedicated learning. The ability to translate the control room alarm management mindset to an OT SOC alert management mindset is a prime example of a critical skill developed through such community interactions, enabling more effective monitoring and response within Operational Technology Security Operations Centers (OT SOCs).
Fourthly, communities enhance situational awareness and threat intelligence sharing. In an environment where threats are increasingly sophisticated and targeted, real-time or near-real-time sharing of threat indicators, attack methodologies, and defensive counter-measures is invaluable. While formal Information Sharing and Analysis Centers (ISACs) exist, regional technical networks can complement these by providing a more informal, practitioner-to-practitioner channel for discussing specific incidents or observations relevant to local infrastructure. This can lead to earlier detection of attacks and more coordinated defensive actions.
Finally, these communities build regional resilience and trust. By fostering relationships among professionals from diverse organizations and sectors, the network creates a web of trust that is essential during crisis situations. In the event of a significant cyber incident affecting critical infrastructure, pre-existing relationships and channels of communication can be leveraged for rapid coordination, mutual aid, and collective recovery efforts. This collaborative defense mechanism is a powerful deterrent and a vital component of national security.
In summary, building ICS/OT security communities is not just about sharing knowledge; it's a strategic imperative that directly strengthens defensive capabilities by promoting collaboration, standardizing practices, developing expertise, enhancing threat intelligence, and ultimately fortifying the resilience of critical industrial operations against an ever-growing array of cyber threats.
Key Takeaways
- Community is paramount for OT/ICS security: The complex and evolving nature of industrial cyber threats necessitates collective knowledge sharing and collaborative problem-solving to strengthen defenses.
- Individuals can be change agents: Peter Jackson's journey demonstrates that a single motivated individual can initiate and grow a thriving community, transforming an idea into a network of hundreds of practitioners.
- Leverage existing operational understanding: Analogies like the "safety security analogy" and translating "control room alarm management mindset" to "OT SOC alert management mindset" are highly effective for engaging diverse stakeholders, including non-technical management.
- Structured frameworks provide a roadmap: Utilizing established guidelines such as the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover) and integrating standards like IEC 61511 for cybersecurity in Safety Instrumented Systems (SIS) offers a systematic approach to education and implementation.
- Focus on "hashing out hard problems": The community's value lies in providing a forum for intermediate-level practitioners to openly discuss, debate, and collectively find solutions to the unique and often challenging aspects of OT/ICS cybersecurity.
- The NZ ICS Cyber Technical Network serves as a successful model: Growing from approximately 20 to 400 practitioners, this network exemplifies how regional initiatives can significantly elevate the overall cybersecurity posture of industrial sectors.
About the Speaker(s)
Peter Jackson is a distinguished professional in the field of Industrial Control Systems (ICS) and Operational Technology (OT) security. He currently serves as the OT Cyber Security Manager for SGSECL, leading a team of dedicated OT security consultants and engineers based in New Zealand. Jackson is also a respected instructor for SANS ICS 515, a course focused on ICS visibility, detection, and response, reflecting his deep expertise in practical defensive strategies. His career trajectory is rooted in industrial engineering, having started as a control engineer and subsequently gaining extensive experience as a functional safety engineer and in alarm management, where he supports the ISA 18 committee. Most notably, Peter Jackson is the visionary founder and facilitator of the NZ ICS Cyber Technical Network, a successful community initiative dedicated to fostering collaboration and knowledge sharing among OT security practitioners in New Zealand and Australia.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Dr. Kozlov, this talk by Peter Jackson is a critical blueprint for strengthening OT/ICS defenses through community building. Jackson, speaking from direct experience as the founder of the successful NZ ICS Cyber Technical Network, outlines a practical, grassroots approach to address the pervasive knowledge gaps and isolation in industrial cybersecurity. While not a deep technical dive into vulnerabilities, it provides a substantive case study on how to foster collective intelligence, standardize practices, and empower practitioners, effectively raising the baseline security posture for critical infrastructure. This isn't theoretical fluff; it's a proven model with tangible results…
Heather Calloway (CISO) — STRONG ACCEPT
Peter Jackson's talk on building ICS/OT security communities is a compelling and practical demonstration of how collective action can significantly enhance critical infrastructure resilience. He effectively articulates the systemic challenges of fragmented knowledge and skill gaps in OT security, offering a proven model for fostering shared learning and problem-solving. The talk excels in translating complex security imperatives into understandable business and operational terms through powerful analogies, providing a clear blueprint for leaders and practitioners to become "change agents" and strengthen regional defensive capabilities.