Productize Your ICS Security Program

Tomomi Aoyama

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

Tomomi Aoyama's S4 talk, "Productize Your ICS Security Program," delves into the profound challenges faced by Operational Technology (OT) security professionals in gaining organizational buy-in and effectively implementing robust security measures. Aoyama candidly shares her frustration with the common sentiment of "I told you so" within the OT security community, highlighting a deeply ingrained disconnect between security practitioners and their diverse stakeholders. The core premise of the talk is that the traditional, technically focused approach to OT security awareness and program development is often "selfish," failing to resonate with the distinct priorities and concerns of business units, operations teams, and executive leadership.

Watch on YouTube

Visual summary for Productize Your ICS Security Program by Tomomi Aoyama
Visual summary for Productize Your ICS Security Program by Tomomi Aoyama

Key moments

  1. 0:00 Introduction: Speaker's vision for OT security awareness and past frustrations.
  2. 1:00 Understanding stakeholders: Why convincing them about OT security is hard.
  3. 2:30 Realization: The 'S4 bubble' contrasts with external OT security challenges.
  4. 4:00 Reality Check: Increasing threats, slow budget growth, CISO burnout.
  5. 6:00 Mandate Shift: CISO ownership and complex cross-functional coordination.

Productize Your ICS Security Program

Speakers: Tomomi Aoyama

Conference: S4

YouTube: https://www.youtube.com/watch?v=XHl-Rpay-eo

Overview

Tomomi Aoyama's S4 talk, "Productize Your ICS Security Program," delves into the profound challenges faced by Operational Technology (OT) security professionals in gaining organizational buy-in and effectively implementing robust security measures. Aoyama candidly shares her frustration with the common sentiment of "I told you so" within the OT security community, highlighting a deeply ingrained disconnect between security practitioners and their diverse stakeholders. The core premise of the talk is that the traditional, technically focused approach to OT security awareness and program development is often "selfish," failing to resonate with the distinct priorities and concerns of business units, operations teams, and executive leadership.

The presentation advocates for a paradigm shift, urging the OT security community to adopt a "product mindset." This involves treating OT security programs not as abstract technical mandates, but as essential services that must be "sold" and tailored to meet the specific needs and language of their "customers" – the various organizational stakeholders. Aoyama argues that in an environment characterized by escalating threats, slow budget growth, and rampant CISO burnout, a smarter, more empathetic, and collaborative approach is not merely beneficial but absolutely critical for the sustained success and maturity of OT security initiatives.

This talk is particularly significant for anyone involved in industrial control systems (ICS) and critical infrastructure security. It moves beyond technical vulnerabilities to address the human and organizational factors that frequently impede security progress. By dissecting the root causes of stakeholder disengagement and offering a framework for more effective communication and collaboration, Aoyama provides a vital roadmap for bridging the chasm between security imperatives and operational realities, ultimately fostering a future where OT security is universally understood, valued, and integrated.

Background

▶ Watch: Introduction: Speaker's vision for OT security awareness and past frustrations. (0:00)

The landscape of Operational Technology security is increasingly fraught with challenges, creating a high-pressure environment for professionals in the field. Tomomi Aoyama highlights several critical factors contributing to the current predicament, which collectively underscore the urgent need for a more strategic and inclusive approach to OT security program development.

Firstly, the threat landscape is continuously expanding, with consequences of successful attacks becoming progressively more severe. Despite this escalating risk, the investment and budget allocated to OT security programs are growing at a notably slow pace. This creates a significant disparity between the perceived need for enhanced security and the resources available to address it, forcing security teams to achieve more with less.

Compounding the resource challenge is a concerning trend in talent acquisition and retention. A recent study conducted in Europe, involving thousands of critical infrastructure organizations, revealed that half of them had no plans to hire additional information security personnel within the next two years. This statistic points to a severe talent gap and a lack of proactive investment in human capital for cybersecurity. Furthermore, the immense stress faced by cybersecurity professionals is reaching breaking point. Gartner made a "very bold strategic assumption" that by 2025, half of all CISOs or cyber security executives will retire or change careers due to stress-related factors. This burnout crisis threatens to deplete leadership and expertise at a time when it is most needed.

A significant organizational shift further complicates matters: a Fortinet report indicates that nearly 90% of organizations are moving the OT security mandate to CISOs. While this centralizes governance, it often places OT security under a "back office" function, creating a fundamental disconnect. CISOs are typically mandated with governance, risk management, and compliance, but they often lack direct authority over the operational teams responsible for physical equipment and production processes. Implementing actual changes in the OT environment requires engaging a multitude of specialized teams who sit within business units and production departments.

This organizational silo creates a complex web of necessary interactions:

  • Network Engineers in production teams are crucial for implementing network segmentation or security controls.
  • Site Managers and Plant Managers must be convinced of the necessity and value of security initiatives, often needing to understand security within the context of operational risk and production continuity.
  • Maintenance Teams control critical maintenance windows, which are essential for patching or system upgrades without disrupting operations.
  • Instrumentation Teams possess vital knowledge about specific vendors and industrial control systems, influencing procurement and integration decisions.
  • Beyond these, essential functions like Supply Chain, Procurement, and Legal Teams must also be engaged, especially with the emergence of new regulations. Legal teams, for instance, play a pivotal role in interpreting and enforcing compliance requirements.

Aoyama emphasizes that OT security professionals often approach these interactions from a "selfish" perspective, attempting to educate stakeholders on the intricacies of OT security without first understanding what those stakeholders truly care about. She uses the analogy of trying to convince children or pets to eat vegetables or medicine by explaining how healthy it is, rather than finding a way to make it appealing or addressing their immediate concerns. This failure to frame security in terms relevant to operational goals, business continuity, or regulatory compliance leads to disengagement and stalled progress, making OT security "not the center of the universe" for those who need to implement it.

Key Findings

▶ Watch: Understanding stakeholders: Why convincing them about OT security is hard. (1:00)

Tomomi Aoyama's talk, while not presenting traditional research findings, offers critical insights and observations regarding the systemic inefficiencies and stakeholder misalignment prevalent in current OT security program implementations. Her "findings" are essentially a candid assessment of the state of the industry, derived from extensive experience and supported by industry reports.

The primary discovery is that the effectiveness of OT security programs is severely hampered by a fundamental disconnect between security objectives and stakeholder priorities. Aoyama identifies this as a "selfish" approach from the OT security community, where the focus often remains on technical imperatives rather than understanding and communicating value in terms that resonate with operational teams, business leaders, and other organizational functions. This leads to a persistent struggle for resources, buy-in, and timely implementation.

Specific observations that constitute key findings include:

  1. Unsustainable Resource Scarcity and Burnout: Despite increasing threats and escalating consequences in OT environments, budget and investment growth for OT security remain "a bit slow." This, coupled with a lack of planned hiring for information security personnel (half of thousands of European critical infrastructure organizations have no plans), and the alarming prediction that half of all CISOs and cyber security executives will retire or change careers by 2025 due to stress (Gartner), paints a picture of an unsustainable operational model. Organizations are being asked to do "more, faster, better" with static or dwindling resources and an exhausted workforce.
  1. Organizational Mandate Misalignment: The shift of OT security mandates to CISOs in nearly 90% of organizations (Fortinet report) creates a critical governance-implementation gap. CISOs are responsible for governance, but the actual power to "touch the equipment" and implement changes lies with various operational and business units. This structural issue means that even with executive-level mandates, execution is often stalled due to a lack of direct control and a complex matrix of interdependencies.
  1. Cross-Functional Engagement Failure: Effective OT security requires seamless coordination across a wide array of internal and external stakeholders, including network engineers, site managers, plant managers, maintenance teams, instrumentation teams, supply chain, procurement, and legal. Aoyama highlights that current approaches frequently fail to engage these essential teams effectively, leading to delays, misunderstandings, and resistance. The inability to align security requirements with maintenance windows, vendor relationships, or regulatory compliance creates significant friction.
  1. The Need for a "Product Mindset": The overarching, implicit finding is that traditional awareness training and security mandates are insufficient. To overcome these challenges, OT security professionals must adopt a "product mindset." This means understanding that stakeholders are "customers" with distinct "needs" and "pain points." An OT security program, like a product, must offer a clear value proposition, be user-centric, and be "marketed" effectively to secure adoption and sustained engagement. Without this shift, OT security will continue to be perceived as an external imposition rather than an integrated component of operational excellence and business resilience.

These findings collectively point to a critical juncture for OT security. The community must evolve its approach from merely identifying technical risks to strategically navigating organizational complexities and fostering genuine, value-driven collaboration.

Technical Deep Dive

▶ Watch: Realization: The 'S4 bubble' contrasts with external OT security challenges. (2:30)

The core of Tomomi Aoyama's talk focuses on the organizational, communication, and strategic challenges inherent in establishing and maturing OT security programs, rather than delving into specific technical vulnerabilities, exploit techniques, or architectural deep dives. The transcript does not contain discussions of specific industrial control system protocols, hardware vulnerabilities, software exploits, or defensive technologies like firewalls, intrusion detection systems, or secure coding practices relevant to OT environments.

Instead, the "technical" aspect of this presentation implicitly concerns the implementation of security measures within a complex operational technology environment. The speaker highlights the organizational friction encountered when attempting to deploy or enforce technical security controls. For instance, successfully patching a system (a technical task) is contingent upon coordinating with maintenance teams for a proper maintenance window. Similarly, implementing network segmentation (a technical architecture decision) requires convincing network engineers in production teams and gaining buy-in from site managers who prioritize operational continuity.

The talk underscores that even the most technically sound security solutions can fail if the organizational and human elements are not adequately addressed. The "technical deep dive" here is into the process of integrating technical security into operations, rather than the technical details of the solutions themselves. It's about the "how" of making technical changes happen in a real-world, highly sensitive OT context, emphasizing that the "how" is often more about people, processes, and politics than about bits and bytes.

Demo / Proof of Concept

▶ Watch: Reality Check: Increasing threats, slow budget growth, CISO burnout. (4:00)

The talk "Productize Your ICS Security Program" by Tomomi Aoyama is conceptual and strategic in nature, focusing on organizational challenges and communication strategies rather than demonstrating specific technical solutions or vulnerabilities. As such, the transcript does not include any description of a live demonstration or a proof of concept. The speaker's objective was to articulate a philosophical shift in how OT security programs are conceived and implemented within an organization, rather than to showcase a new tool or exploit.

Defensive Implications

▶ Watch: Mandate Shift: CISO ownership and complex cross-functional coordination. (6:00)

Tomomi Aoyama's talk, while highlighting critical problems, implicitly provides a powerful framework for defensive strategies in OT security. The core defensive implication is that effective OT security is less about technical prowess alone and more about strategic engagement, empathetic communication, and cross-functional collaboration. Defenders must evolve from a purely technical mindset to one that understands and addresses the broader organizational context.

Here are the key defensive implications:

  1. Shift to a Stakeholder-Centric Approach: Defenders must move beyond "selfish" security awareness training. Instead of merely explaining why OT security is important from a technical perspective, they must articulate its value in terms relevant to each stakeholder's job function and priorities. For plant managers, this might be operational uptime or safety; for CEOs, it's managing operational risk and financial impact; for legal teams, it's regulatory compliance. This involves understanding their "pain points" and framing security as a solution to their problems, thereby "productizing" security initiatives.
  1. Bridge the Governance-Implementation Gap: With nearly 90% of organizations moving OT security mandates to CISOs, defenders must actively work to bridge the divide between top-down governance and on-the-ground implementation. This means empowering and collaborating directly with network engineers, maintenance teams, and instrumentation teams who possess the practical knowledge and direct access to OT equipment. Security teams should act as enablers and facilitators, providing guidance and resources, rather than solely issuing mandates.
  1. Proactive Cross-Functional Engagement: Effective defense requires establishing strong relationships and communication channels with all relevant internal and external teams from the outset. This includes:
  • Production Teams (Network Engineers, Site Managers): Involve them in planning security changes to ensure feasibility and minimize operational disruption. Understand their constraints, such as limited maintenance windows.
  • Maintenance and Instrumentation Teams: Coordinate patching and upgrades with their schedules and leverage their vendor knowledge. They are often the gatekeepers of system changes.
  • Supply Chain and Procurement: Integrate security requirements into vendor selection and contract negotiations to mitigate supply chain risks.
  • Legal Teams: Collaborate on understanding and implementing new regulations, ensuring that security measures align with legal obligations.

Early engagement ensures that security is considered in the design phase of new projects, especially digitization initiatives, rather than being an afterthought.

  1. Optimize Resource Utilization Through Smarter Action: Given slow budget growth and the looming threat of CISO burnout, defenders cannot rely solely on increased headcount or budget. They must find ways to "act smarter." This implies:
  • Prioritization: Focus resources on the most critical risks and high-impact security controls.
  • Automation: Explore automation opportunities to reduce manual effort.
  • Process Improvement: Streamline security processes to increase efficiency.
  • Leveraging Existing Capabilities: Maximize the use of existing tools and personnel by upskilling and cross-training.
  1. Foster a Culture of Shared Responsibility: The talk implicitly advocates for moving away from security being solely the responsibility of the security team. By engaging stakeholders empathetically and demonstrating the direct value of security to their own objectives, defenders can cultivate a culture where OT security is understood and embraced as a collective responsibility critical to operational resilience and business success. This shared ownership is the strongest defensive posture an organization can achieve.

In essence, defensive implications extend beyond technical controls to encompass the entire organizational ecosystem, emphasizing that human and process factors are as critical as technology in securing OT environments.

Key Takeaways

  • Stakeholder-Centricity is Paramount: OT security program success hinges on understanding and addressing the specific needs and language of diverse stakeholders (operations, business units, executives, legal), rather than solely focusing on technical requirements.
  • Organizational Silos Impede Progress: The shift of OT security mandates to CISOs often creates a disconnect between governance and implementation, necessitating proactive cross-functional engagement across network engineers, plant managers, maintenance, and other teams.
  • "Selfish" Awareness is Ineffective: Traditional awareness training that solely explains technical OT security without tailoring the message to the stakeholder's immediate concerns and value drivers is largely ineffective and leads to disengagement.
  • Resource Constraints Demand Smarter Strategies: With increasing threats, slow budget growth, and high rates of CISO burnout (Gartner predicts 50% executive turnover by 2025 due to stress), OT security teams must find "smarter" ways to operate, optimize resources, and achieve objectives without relying on unsustainable increases in budget or personnel.
  • Product Mindset for OT Security: Treating OT security programs as "products" that need to be "sold" to "customers" (stakeholders) by demonstrating clear value and user-centricity is crucial for gaining buy-in and achieving widespread adoption.
  • Collaboration is the Cornerstone of Implementation: Effectively implementing OT security requires deep and early collaboration with a wide array of teams, from production-side network engineers and maintenance personnel to supply chain, procurement, and legal teams, integrating security into design phases and operational processes.

About the Speaker(s)

Tomomi Aoyama is the speaker for this S4 conference talk. While the transcript and metadata do not provide specific details about her title or company, her presentation demonstrates extensive experience and a deep understanding of the challenges in operationalizing OT security programs within complex organizational structures. Her insights are drawn from real-world experiences, highlighting the human and organizational aspects of cybersecurity in critical infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk by Tomomi Aoyama provides a brutally honest and highly pragmatic assessment of the systemic failures in operationalizing OT security programs. It skillfully dissects the "selfish" approach often taken by security teams and advocates for a "product mindset," treating security initiatives as services to be "sold" to diverse internal stakeholders. By highlighting critical data on CISO burnout, slow budget growth, and organizational silos, Aoyama offers a compelling framework for bridging the chasm between security mandates and operational realities, delivering a high-impact strategy for effective program implementation.

Heather Calloway (CISO) — STRONG ACCEPT

Tomomi Aoyama's talk on 'Productize Your ICS Security Program' delivers a crucial message for security leaders struggling with OT security adoption. It accurately diagnoses the systemic disconnect between technical security imperatives and organizational realities, advocating for a 'product mindset' to drive engagement and secure resources. This is not a deep technical dive, but a strategic imperative for any CISO or security executive navigating the complexities of critical infrastructure protection and organizational buy-in.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference