Prepare and Secure Critical Infrastructure for the Future of Digitalization
Download resourcesAbout this session
Dr. Tim Nedyalkov, technology information security officer at the Commonwealth Bank of Australia and formerly head of cybersecurity for the Riyadh Metro and the Australian Broadcasting Corporation, presents a three-phase, nine-step model for securing critical infrastructure as IT and OT converge. He first sets out why the problem is hard: legacy systems designed without security, flat networks, default credentials from vendor manuals, unmanaged remote access left over from the pandemic, years of uptime with hundreds of pending patches, and criminals who do not care how a vulnerability is rated. The preparation phase aligns stakeholders on a common purpose (no harm to health, safety or environment, no unplanned disruption), maps contractual, supply-chain, regulatory and timeline commitments, builds an asset inventory with verified network diagrams and traffic analysis, and folds cyber risk into the existing risk framework. The security phase covers trust with business stakeholders, awareness, cross-training IT and OT engineers, a NIST CSF-based maturity model, 12-to-18-month remediation roadmaps and one-page executive reporting. The last phase is staying relevant through what-if scenarios built from incidents at competitors.
Digitalization is here to stay, and critical infrastructures are not an exception. Even before the pandemic, we have seen an increased number of connected OT systems to the Internet. It leads to no separation of IT & OT networks due to the increase in data, connectivity, complexity and costs. What makes the protection for the digitalization of critical infrastructure complex is the convergence between IT & OT. Threats that commonly impact IT can move between cyber and physical environments. Therefore, cyber security is a key factor for the success of digitalized critical infrastructure. Successful long-term protection includes understanding stakeholder expectations, establishing a core cross-functional engagement model, building a roadmap of strategic initiatives and staying relevant with the latest security threats. The presentation will share key principles and guidelines that I developed and refined over the years working in several industries. The application of the principles has helped prepare and secure critical infrastructure for the future of digitalization holistically and consistently. Session Overview: ● How to set the foundations for the future of digitalized critical infrastructure ● What the key initiatives are, and how to effectively identify and execute them ● How to ensure long-term protection of digitalized critical infrastructure
Key takeaways
- Start every OT security engagement by agreeing a common purpose with stakeholders (no harm to health, safety, security or environment, no unplanned disruption, no productivity loss) and test every planned action against it.
- Challenge any network diagram older than three years, assign an owner to it, and run traffic analysis to find unexpected connections such as equipment reaching the internet.
- Fold cyber risk into the organisation's existing risk framework (for example the 5x5 matrix) with tangible operational, cost, reputational and regulatory impacts rather than a separate cyber scale.
- Plan remediation in 12-to-18-month roadmaps, execute hard for ten months, then reassess and be willing to stop or pause activities that are not delivering value.
- Report to executives in one page or three slides, mapped to the five NIST CSF functions, and stick to facts; the goal of a five-minute board slot is to be given more time next time.
Speakers
Dr. Tim Nedyalkov brings over 18 years of multi-industry experience in Information Technology and Cyber Security across Europe, the USA, Australia, and the Middle East. He is a Technology Information Security Officer at the Commonwealth Bank of… Read moreRead less
Dr. Tim Nedyalkov brings over 18 years of multi-industry experience in Information Technology and Cyber Security across Europe, the USA, Australia, and the Middle East. He is a Technology Information Security Officer at the Commonwealth Bank of Australia and Executive Member of the CyberEdBoard Global Community. Most recently, he established the cyber security practice for the $24 Billion Riyadh Metro transport network, one of the world's largest public transport infrastructure projects. He holds a doctorate in Cyber Security/Information Assurance from the University of Fairfax, and a master's in Information Technology Management from the University of Sydney. His certifications include C|CISO, CISSP, CCSP, CEH, CISA, CISM, CRISC, CGEIT, CDPSE, ISO 27001 LA, and Agile PM. Dr. Nedyalkov has been a frequent keynote speaker and panelist at over 30 industry-leading conferences. In addition, he is an active contributor to cyber security industry publications, white papers and community initiatives. He was featured in Top Cyber Magazine, Industrial Cyber, RSA Conference, BankInfoSecurity, InfoRiskToday, and CyberEdBoard Profiles in Leadership. Dr. Nedyalkov has been globally recognized as Cybersecurity Influential Voice and 40 under 40 in Cybersecurity. In addition, he was nominated for the Cyber Security Professional of the Year 2019 in Australia.