Mark Fabro successfully married tech knowledge and C-level chops to help elevate his role and SCADA security to the next level. Dan Kaplan reports.
There was a time in Mark Fabro's career when he was perfectly content avoiding the men and women in the corner offices.After all, it was the early 2000s and Fabro was buried deep in the weeds of critical infrastructure research, focusing on challenges like threat profiling and recognition, risk analysis, intrusion testing, data collection and “grid” cracking. Coveted skills, for sure, but not something to which a power company CEO was giving much thought at the time.
“Really, the insider was one of the only things you had to worry about, other than natural or manmade system incidents or failures that could impact production,” recalls Fabro.
Then, around the middle of the decade, things started to quickly change. The systems that manage, direct and regulate utilities, like chemical plants and oil-and-gas refineries, increasingly became connected to the public internet and the corporate network, effectively opening the door for the first time to the threat of malware. All of a sudden, the prospect of a hacker shutting off the lights to millions of people shifted from a Hollywood script idea to something that could at least pass the plausibility test.
The men and women in the boardroom started perking up. And with that, Fabro's career path changed.
Suddenly came the need for people with technical talents who could also convey the threat and business challenge posed by supervisory control and data acquisition (SCADA) systems to upper management, in easy-to-understand terms.
Fabro, who now serves as president and chief scientist of Lofty Perch, was a natural. In June, as a testament to his work in this field, he was named information security professional of the year at the 2011 SC Awards Canada.Fabro, whose company specializes in assessments, training and compliance strategies for critical infrastructure entities, says industrial control systems – which provide “national security, economic security and quality of life” – traditionally were isolated from the corporate environment. But that changed with the rise of internet connectivity.“The business demanded they start getting connected and working together,” Fabro, 44, explains. “Now you have executives who want to instantaneously know what's going on in the control system environment. The competitive advantage lies in how fast you can get situational awareness from your control system into the corporate space to shape and meet supply and demand.”
| “The competitive advantage lies in how fast you can get situational awareness from your control system into the corporate space to shape and meet supply and demand.” – Mark Fabro, president and chief scientist of Lofty Perch |
Michael Assante (right), the former chief security officer at the North American Electric Reliability Corp., which oversees U.S. electric grid operators, says he contracted Fabro a few years ago to work with the utilities so they could better understand their risks.“One of the major contributions that Mark brought to the table is the issue of understanding cybersecurity in the context of industrial technology, control systems and SCADA,” Assante says. “Mark does an incredible job of bridging the gap between the hard, technical story and how it matters to you. He just has a lot of resonance when he speaks.”Assante cites his reasonable and responsible approach that never relies on the fear card. Fabro also has a way of connecting – not just with business executives – but also those SCADA experts who may not be too familiar with cybersecurity.| “Mark can sit down with a control systems engineer and have the capability of communicating...” – Michael Assante, the former CSO at the North American Electric Reliability Corp. |
Rick Moy (right), president and CEO of NSS Labs, an independent network testing firm, says control systems present a unique challenge with which end-users are not familiar.“It's hardware and software together,” Moy says. “There's a lot more moving parts than, say, patching Adobe Flash. Those processes are not really developed. We're early in the maturity cycle. We're somewhere in the early to mid-90s right now, compared to quote-unquote internet security. There really isn't much awareness yet. We just saw the beginning with Stuxnet. There aren't a lot of guidelines for folks to follow. It's a very new juncture.”But this general lack of polish around SCADA security doesn't mean the answer is panic, says Fabro.| “There aren't a lot of guidelines for folks to follow. It's a very new juncture.” – Rick Moy, president and CEO of NSS Labs |
MF: I have a few things that are ongoing, and almost all of them are in support of outreach and education. I am lucky to be involved in the Canadian Industrial Cybersecurity Council, which I chair, and our focus is to review Canadian public sector security activities or programs and ensure they take into account vital SCADA and control system assets.
I also support the Repository for Industrial Security Incidents (RISI) at securityincidents.org, perhaps the largest database available for SCADA and control systems security incidents.
Lastly, I am also working to ensure security is integrated into the engineering curriculums, so that our SCADA and control system engineers of tomorrow have a headstart in knowing how to protect vital systems, as well as build and operate them.
SC: What's your best advice for control system personnel when it comes to building a strong security program?
MF: My experience has taught me that strong SCADA/control systems security programs are created by teams – teams that are comprised of both IT security and control system engineers. Modern SCADA and control systems have matured to be very IT-based, but the uniqueness and nuances associated with industrial automation simply does not allow for IT security best practices to always be mapped directly. I recommend that collaborative teams be formed, and that the great products developed by ISA [International Society of Automation], NIST or the Department of Homeland Security Control Systems Security Program (CSSP) be used as a starting foundation for program development.
SCADA bypass: PLC versus HMI
In May, a scheduled conference talk on vulnerabilities in Siemens industrial control systems was shelved after the affected vendor was unable to develop a working fix in time and expressed concern.Researcher Dillon Beresford, an analyst at NSS Labs, decided to pull the plug just hours before he was set to hit the stage, due to the potential of real-life harm that the presentation could have caused. (Now that a patch is in place, Beresford plans to present his findings this month at the Black Hat conference in Las Vegas).
Considering the sensitivity of SCADA products, one might expect more instances like this in the future, says Rick Moy, president and CEO of NSS. Especially if the vulnerabilities are present in programmable logic controllers, or PLCs, systems that directly connect to production instruments, such as valves and motors.
As a result, flaws in PLCs are potentially more dangerous than SCADA bugs in a human machine interface (HMI), which is software used to program PLCs, Moy says.
“If it's in a PLC, then an attacker could access that PLC directly without going through a user's workstation,” he says. “It allows an attacker to completely bypass security controls.” – Dan Kaplan
