The Cyber Informed Safety System

Kenneth Titlestad

S4x24 - ICS Security Conference · Day 3 · Stage 2

Overview

In an era where critical infrastructure faces escalating cyber threats, Kenneth Titlestad’s S4x24 talk, "The Cyber Informed Safety System," presents a compelling argument for re-evaluating how operational technology (OT) environments prioritize and manage safety in the face of cyber-attacks. Titlestad challenges the conventional binary approach to system failures – where systems either operate perfectly or shut down completely – by advocating for more granular, "safer modes" inspired by the aviation industry and consumer automotive systems. The core of his proposal is to extend the established principles of Safety Instrumented Systems (SIS) to create a new paradigm: a Cyber-Informed Safety System.

Watch on YouTube

Visual summary for The Cyber Informed Safety System by Kenneth Titlestad
Visual summary for The Cyber Informed Safety System by Kenneth Titlestad

Key moments

  1. 0:00 Introduction: The blue screen of death in critical systems
  2. 2:00 Three golden rules for OT cybersecurity: Aviate, Navigate, Communicate
  3. 4:00 IT's approach: Safe mode and degraded modes
  4. 5:00 Car example: Degraded mode, 'full performance not available'
  5. 5:30 Understanding Safety Instrumented Systems (SIS) for critical safety

The Cyber Informed Safety System

Speakers: Kenneth Titlestad

Conference: S4

YouTube: https://www.youtube.com/watch?v=ux0wbPXywzs

Overview

In an era where critical infrastructure faces escalating cyber threats, Kenneth Titlestad’s S4x24 talk, "The Cyber Informed Safety System," presents a compelling argument for re-evaluating how operational technology (OT) environments prioritize and manage safety in the face of cyber-attacks. Titlestad challenges the conventional binary approach to system failures – where systems either operate perfectly or shut down completely – by advocating for more granular, "safer modes" inspired by the aviation industry and consumer automotive systems. The core of his proposal is to extend the established principles of Safety Instrumented Systems (SIS) to create a new paradigm: a Cyber-Informed Safety System.

The talk emphasizes that while security is crucial, safety remains the ultimate goal in critical OT environments. Drawing parallels between a pilot facing a system failure and an OT operator dealing with a cyber incident, Titlestad underscores the need for resilience and continuous operation of critical functions, even when compromised. This perspective shifts the focus from merely preventing breaches to designing systems that can intelligently degrade, maintain essential safety functions, and allow for recovery, thereby ensuring the ongoing safety of personnel and the public.

This approach is particularly vital for sectors like energy, manufacturing, and transportation, where system downtime or uncontrolled states can have catastrophic physical consequences. Titlestad's vision aims to harmonize the often-conflicting demands of availability, safety, and security, providing a framework for developing more robust and resilient critical infrastructure capable of navigating the complex interplay of functional safety and evolving cyber threats.

Background

▶ Watch: Introduction: The blue screen of death in critical systems (0:00)

The landscape of Operational Technology (OT) has undergone a significant transformation, moving from isolated, proprietary systems to interconnected networks that increasingly leverage IT technologies. While this convergence offers efficiencies and advanced capabilities, it also exposes OT environments to the same cyber threats that plague traditional IT networks. However, the stakes in OT are fundamentally different. A cyber-attack on an enterprise IT network might lead to data loss or financial impact, but an attack on an industrial control system (ICS) or SCADA system can result in physical damage, environmental harm, and, most critically, loss of human life.

Historically, OT systems have relied on functional safety principles, often codified in standards like IEC 61508 and IEC 62443, to prevent dangerous states. At the heart of this is the Safety Instrumented System (SIS), an independent layer designed exclusively to bring a process to a safe state when predefined dangerous conditions are detected. As Titlestad highlights, the SIS is often depicted in architectural diagrams (e.g., from IEC 62443) as sitting "on the side" of the main Process Control System (PCS), emphasizing its independent and overriding role in safety. However, these systems were primarily designed to respond to physical process deviations, not sophisticated cyber-attacks that could manipulate sensors, actuators, or the control logic itself.

The problem Titlestad addresses is the lack of a robust, standardized, and widely adopted framework for handling cyber-induced safety events in OT. Traditional IT responses, such as a "blue screen of death" followed by a complete system reboot or entering a rudimentary "safe mode," are often inadequate or unacceptable in critical OT contexts where continuous operation, even in a degraded state, is paramount. The challenge lies in bridging the gap between traditional functional safety engineering and modern cybersecurity practices, ensuring that safety remains the ultimate priority while acknowledging and mitigating advanced persistent threats and sophisticated cyber-physical attacks. This necessitates a shift from a binary "secure/not secure" or "operational/shutdown" mindset to one that embraces resilience and granular degradation as core design principles.

Key Findings

▶ Watch: Three golden rules for OT cybersecurity: Aviate, Navigate, Communicate (2:00)

Titlestad's talk distills several key findings and principles essential for building a more resilient and safe OT environment in the face of cyber threats:

  1. Safety as the Ultimate Goal: The paramount objective in OT is safety, not just security or availability. While security enables safety and availability supports it, the system's ultimate purpose is to protect people and the environment. This foundational principle must guide all design and incident response strategies.
  2. The "Aviate, Navigate, Communicate" Framework for OT: Inspired by the aviation industry's golden rules for pilots in distress, Titlestad proposes applying "Aviate, Navigate, Communicate" to OT cybersecurity:
  • Aviate: Continue critical operations; maintain control and prevent immediate catastrophe. This translates to resilience – ensuring essential business functions persist even under attack.
  • Navigate: Understand the current state of the system and the desired safe state. This requires reliable information and situational awareness, which can be compromised in a cyber-attack.
  • Communicate: Exchange information with relevant personnel and systems to coordinate response and recovery. This highlights the need for secure and resilient communication channels.
  1. Beyond Binary: Granular Safer Modes: The talk strongly advocates for moving beyond the binary "on/off" or "fully operational/fully shut down" approach to system failures. Instead, OT systems should be designed with multiple, granular safer modes or degraded operational states. This concept is analogous to an IT system's "safe mode" or a car's "full performance not available" warning, where non-critical functions are deprioritized or disabled to maintain essential operations and safety.
  2. Cyber-Informed Safety System (CISS) Concept: The most significant contribution is the conceptualization of a Cyber-Informed Safety System. This extends the well-understood and independently designed Safety Instrumented System (SIS) model to explicitly address cyber-induced safety risks. Just as an SIS monitors physical process parameters to trigger a safe state, a CISS would monitor cyber-related indicators to initiate appropriate "safer modes" or safety actions, ensuring protection even when the primary control system is compromised.
  3. Harmonizing Availability, Safety, and Security: Titlestad acknowledges the inherent tension between availability, safety, and security in OT. The talk concludes that while complex, the community must strive to harmonize these three pillars. A Cyber-Informed Safety System, with its emphasis on resilient operation and granular safe states, is presented as a crucial step towards achieving this balance, ensuring that security measures enhance, rather than detract from, overall safety and availability.

Technical Deep Dive

▶ Watch: IT's approach: Safe mode and degraded modes (4:00)

The core technical proposition of "The Cyber Informed Safety System" is to adapt established safety and resilience principles from other high-stakes domains to address the unique challenges of cybersecurity in OT. This involves a multi-faceted approach, integrating concepts from aviation, IT, and traditional functional safety.

Aviation's Golden Rules in OT Context

Titlestad draws a direct parallel between a pilot facing a critical system failure and an OT operator confronting a cyber-attack. The aviation industry's three golden rules—Aviate, Navigate, Communicate—are presented as a powerful framework for OT incident response:

  1. Aviate: In aviation, this means keeping the plane flying. In OT, it translates to maintaining the most critical operational functions and preventing catastrophic physical events. This principle underpins the concept of resilience. Instead of immediate shutdown (which can sometimes be more dangerous than controlled operation), the focus is on sustaining essential processes, even if degraded. This requires systems to be designed with inherent capabilities to shed non-critical load, isolate compromised components, and continue fundamental operations necessary for safety. For example, in a power grid, "aviate" might mean maintaining frequency and voltage within safe limits, even if generation capacity is reduced or control systems are partially impaired.
  2. Navigate: A pilot must know their current position and how to get to a safe landing. In OT, this means having accurate and trustworthy information about the current state of the industrial process and the cyber environment. During a cyber-attack, the integrity of sensor data, control commands, and network communications can be compromised. A Cyber-Informed Safety System would need robust, out-of-band monitoring and validation mechanisms to provide an uncorrupted view of the process state. This could involve redundant physical sensors, independent diagnostic systems, and secure channels for critical data. Understanding where the system should be (the safe state) is equally important, guiding the actions taken to mitigate the incident.
  3. Communicate: Pilots communicate with air traffic control and crew. OT operators need to communicate effectively with incident response teams, management, and potentially external stakeholders. This communication must be reliable and secure, especially when primary communication channels might be compromised. The ability to provide and receive validated information is critical for coordinated response and recovery efforts.

The Concept of Granular Safer Modes

A significant technical departure from traditional IT "safe mode" is the emphasis on granular safer modes. Unlike a Windows "safe mode" that often disables most functionality for troubleshooting, Titlestad envisions multiple, pre-defined operational states that are neither fully operational nor fully shut down. He cites the example of a car displaying "full performance not available," where the system prioritizes safety by reducing engine power or disabling certain features.

In an OT context, these granular modes could include:

  • Reduced Production Mode: Lowering throughput while maintaining process stability.
  • Manual Control Mode: Shifting from automated control to direct human intervention for critical functions.
  • Segmented Operation Mode: Isolating compromised parts of the network or process while allowing healthy segments to continue.
  • Safe Hold Mode: Bringing the process to a stable, non-productive state that prevents escalation of danger, but is less drastic than a full emergency shutdown.

Implementing such granular modes requires sophisticated engineering, including:

  • State Machine Design: Defining clear transitions between operational states based on detected threats or conditions.
  • Prioritization Logic: Programming the system to automatically prioritize safety-critical functions over performance or non-essential operations.
  • Independent Control Paths: Ensuring that the logic for entering and maintaining safer modes is robust and isolated from the primary control system, making it resilient to cyber-attacks targeting the main PLC/DCS.

Leveraging Safety Instrumented Systems (SIS)

The most innovative technical aspect of Titlestad's proposal is the extension of the Safety Instrumented System (SIS) concept. An SIS is a specialized, independent system designed to protect against specific hazards by taking the process to a safe state when predefined conditions are met. As per IEC 62443, SIS typically sits "on the side" of the Process Control System (PCS), meaning it operates autonomously and takes precedence when safety thresholds are crossed.

Titlestad proposes a Cyber-Informed Safety System (CISS) that mirrors the SIS architecture but is triggered by cyber-related events or risk levels. Instead of monitoring physical parameters like temperature or pressure, a CISS would monitor:

  • Cybersecurity Posture: Indicators of compromise (IOCs), network anomalies, unauthorized access attempts, integrity violations of control logic or firmware.
  • Risk Level Assessment: Dynamic evaluation of the threat landscape and the system's vulnerability.
  • Operator Input: Manual override or selection of a safer mode by a human operator based on cyber incident intelligence.

The CISS would act as an independent layer, much like an SIS, to implement the granular safer modes. This independence is crucial: if the main PCS is compromised, the CISS, being separate and potentially using different communication paths and control logic, could still function to maintain safety. This might involve:

  • Activating Redundant Safety Barriers: Triggering physical safeguards that are independent of the primary control system.
  • Enforcing Network Segmentation: Activating firewalls or blocking rules to isolate compromised zones.
  • Initiating Controlled Shutdowns: If a safer mode is not feasible, performing a controlled, pre-programmed shutdown to a known safe state, rather than an uncontrolled crash.

The technical realization of a CISS would involve:

  • Dedicated Hardware and Software: Separate from the main control system.
  • Robust Integrity Controls: Ensuring the CISS itself is highly resilient to cyber-attack.
  • Secure Communication Protocols: For interacting with sensors, actuators, and human-machine interfaces (HMIs) in a compromised environment.
  • Validation and Certification: Rigorous testing and certification processes, similar to those for traditional SIS, to ensure its reliability and effectiveness.

This deep dive illustrates that "The Cyber Informed Safety System" is not merely a conceptual idea but a call for a fundamental shift in how OT systems are engineered, demanding a holistic integration of cybersecurity into the very fabric of functional safety design.

Demo / Proof of Concept

▶ Watch: Car example: Degraded mode, 'full performance not available' (5:00)

The talk by Kenneth Titlestad was primarily conceptual and focused on presenting a new framework and set of principles for OT cybersecurity and safety. As such, the presentation did not include a live demonstration or a detailed proof of concept of a Cyber-Informed Safety System in action. The speaker utilized analogies from aviation and the automotive industry to illustrate the concepts of degraded modes and resilient operation, rather than showcasing a specific technical implementation.

Defensive Implications

▶ Watch: Understanding Safety Instrumented Systems (SIS) for critical safety (5:30)

The principles outlined in "The Cyber Informed Safety System" offer critical defensive implications for organizations operating in OT environments. Adopting this cyber-informed safety mindset can significantly enhance resilience and reduce the potential for catastrophic outcomes during cyber incidents.

  1. Embrace "Aviate, Navigate, Communicate" as Incident Response Pillars:
  • Aviate (Maintain Critical Functions): Defenders must design systems and develop incident response plans that prioritize the continuity of essential safety-critical functions. This means investing in resilience engineering, including redundant systems, fail-safe mechanisms, and the ability to shed non-critical load during an attack. Incident responders should be trained to stabilize the process and prevent physical harm as their absolute first priority, even if it means sacrificing some data or non-essential operations.
  • Navigate (Situational Awareness): Robust, out-of-band monitoring and detection capabilities are paramount. Defenders need independent systems to validate process data, identify cyber intrusions, and assess the true state of the OT environment. This could involve passive network monitoring, anomaly detection, and the use of dedicated, hardened sensors for critical parameters that are isolated from the primary control network. The goal is to provide trustworthy information even when the main control system is compromised.
  • Communicate (Secure & Resilient Channels): Establish secure and redundant communication channels for incident response teams, operators, and emergency services. These channels should be resilient to network outages or compromises affecting the primary OT network. This includes out-of-band voice communications, satellite links, or physically isolated networks for emergency coordination.
  1. Engineer for Granular Safer Modes (Degraded Operation):
  • Move beyond the binary "run or shut down" mentality. Organizations should invest in designing and implementing systems that can transition into multiple, pre-defined degraded operational states or "safer modes." This requires a deep understanding of the process, identification of critical functions, and engineering controls that can gracefully reduce performance or functionality while maintaining safety.
  • This might involve developing specific control logic for each degraded mode, ensuring that the transition to and operation within these modes is thoroughly tested and documented. It also implies a re-evaluation of current safety standards to include cyber-induced degradation scenarios.
  1. Develop a Cyber-Informed Safety System (CISS) Strategy:
  • Inspired by the Safety Instrumented System (SIS), organizations should consider developing an independent layer specifically designed to respond to cyber-induced safety risks. This CISS would act autonomously from the main Process Control System (PCS) and be triggered by cybersecurity events (e.g., detection of malware in a PLC, integrity violation of control logic, or unauthorized commands).
  • The CISS would then initiate pre-programmed safety actions, such as shifting to a safer mode, activating physical safety barriers, or performing a controlled shutdown. This requires careful architectural design to ensure the CISS itself is highly secure, resilient, and isolated from potential cyber threats targeting the primary control system.
  1. Prioritize Integrity and Availability of Safety Systems:
  • Since the CISS concept relies on independent safety layers, it is crucial to ensure the integrity and availability of these systems. This means applying the highest levels of cybersecurity to SIS and any proposed CISS components, including robust authentication, access control, secure configurations, and continuous monitoring for tampering.
  • Regular audits and penetration testing specifically targeting the resilience of safety systems against cyber-attacks are essential.
  1. Integrate Cyber Threat Intelligence into Safety Risk Assessments:
  • Existing safety risk assessments (e.g., HAZOP, LOPA) primarily focus on physical hazards and component failures. These need to be updated to explicitly include cyber-attack scenarios as initiating events for safety-critical conditions. This allows for a more comprehensive understanding of potential attack paths and the necessary safeguards.
  • This integration should lead to the definition of Cyber Security Levels (CSLs) for OT components, similar to Safety Integrity Levels (SILs) for SIS, guiding the rigor of cybersecurity requirements.
  1. Training and Drills:
  • Operators and incident response teams must be thoroughly trained on how to identify cyber-induced safety events, how to operate in degraded modes, and how to execute the "Aviate, Navigate, Communicate" principles. Regular tabletop exercises and full-scale drills simulating cyber-physical attacks are crucial to validate procedures and ensure personnel proficiency.

By proactively addressing these defensive implications, organizations can move beyond a reactive security posture to one that embeds cybersecurity deeply within their operational safety framework, ultimately enhancing the resilience and safety of critical infrastructure.

Key Takeaways

  • Safety is the ultimate goal in OT: While security and availability are crucial, the paramount objective in critical infrastructure is to ensure human and environmental safety, especially when facing cyber threats.
  • Adopt Aviation's "Aviate, Navigate, Communicate" principles: These three rules provide a robust framework for prioritizing actions during an OT cyber incident, focusing on maintaining critical operations, understanding the situation, and effective communication.
  • Design for granular "safer modes": OT systems must move beyond binary failure states (on/off) towards multiple, pre-defined degraded operational modes that prioritize safety and allow for continued, albeit reduced, functionality during an incident.
  • Extend the SIS concept to cyber threats: The well-established model of independent Safety Instrumented Systems (SIS) should be adapted to create "Cyber-Informed Safety Systems (CISS)" that respond to cyber indicators to initiate safe states or degraded modes.
  • Harmonize Availability, Safety, and Security: Achieving a balance between these three often-conflicting pillars is complex but essential for resilient critical infrastructure, requiring a holistic approach to system design and incident response.
  • Prioritize resilience engineering: Systems must be designed with inherent capabilities to withstand and recover from cyber-attacks, ensuring that critical functions can persist even under duress.

About the Speaker(s)

Kenneth Titlestad delivered the talk "The Cyber Informed Safety System" at the S4 conference. The provided transcript and metadata do not offer further professional details about his title, company, or background beyond his name.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Titlestad's "The Cyber Informed Safety System" is a critical and highly impactful re-evaluation of operational technology (OT) safety in the face of sophisticated cyber threats. By extending the established Safety Instrumented System (SIS) model to create a Cyber-Informed Safety System (CISS) and advocating for granular 'safer modes' inspired by aviation, he presents a novel and essential framework for resilient critical infrastructure. This isn't just theory; it's a blueprint for engineering systems that can intelligently degrade and maintain critical functions under duress, forcing a necessary shift in how we approach OT safety design.

Heather Calloway (CISO) — MUST SEE

Titlestad's talk offers a critical, long-overdue paradigm shift for managing cyber risk in operational technology. By extending the proven Safety Instrumented System (SIS) model to create a Cyber-Informed Safety System (CISS) and advocating for granular, 'safer modes' of operation, he moves beyond theoretical discussions to provide a concrete strategic framework. This presentation is essential for any CISO or board member grappling with the existential risks of cyber-physical attacks, forcing a re-evaluation of how we design for resilience and ensure safety when systems inevitably fail.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference