The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label Dale Peterson. Tampilkan semua postingan
Tampilkan postingan dengan label Dale Peterson. Tampilkan semua postingan

Rabu, 12 September 2012

Offensive Tactics That You Won't Hear About At HackerCons

Here's a first look at the partial agenda for Suits and Spooks Boston. We're still finalizing content for some of our speakers (i.e., "to be announced"). You'll quickly see the reason why it's closed to journalists and why no presentations will be shared or made public. And you'll also see why Suits and Spooks isn't just another security conference. No one covers what we do.

8:30am Registration and Continental Breakfast

9:00am: David Bray: "The Need for a Science of Cybersecurity and Critical Infrastructure"

9:30am: Rob DuBois "How would a red team plan and launch an assault against a typical power plant"

10:00am: Dale Peterson: "How adversaries could take out thousands of power plants around the world as well as large parts of the electric transmission system"

10:30am: Break

10:45am: John Sullivan: "How a large municipal water system can be disrupted and why there's no defense against it"

11:15am: Dan Kuehl: to be announced

11:45am: Lunch

12:45pm: Christopher Ahlberg "How to create a targeting package against a corporation or individual using social media"

1:15pm: Henry Shiembob "How multi-national corporations watch for outside threats but miss the more dangerous insider threat"

1:45pm: Dan Geer: to be announced

2:15pm: Larry Castro: "A Policy Review of Pending Cyber Security Legislation and What an Executive Order Might Cover"

2:45pm: Break

3:00pm: Christopher Burgess: "Creating havoc through the disruption of medical devices and electronically altering patient data"

3:30pm: Derek Gabbard: to be announced

4:00pm: Zach Tumin: to be announced

4:30pm: Closing Remarks

The final agenda will be announced on October 1st. A full list of speakers and their bios is at the Suits and Spooks Boston web page. Our early bird registration rate of $295 ($100 savings off the standard rate) ends in six days so reserve your space today.


Options
Add to Cart View detail

Kamis, 23 Agustus 2012

Who Needs a Zero-Day? "Plants are Insecure by Design" - Dale Peterson

Dale Peterson of Digital Bond is one of the most respected security voices in the Industrial Control System community. He runs an annual SCADA security conference called S4 that's always filled to capacity and he has equal credibility with the U.S. Intelligence Community (Dale's an ex-NSA'er) and the private sector. His blog post "Suits & Spooks vs. Engineers" is a great read because it underscores an important issue: security engineers talking exclusively to other security engineers frequently results in nothing getting done. Here's how Dale put it in his article:
Over the past ten years have seen dramatic increase in cyber security of a specific DCS or SCADA system occur in two different ways: 
(1) A CEO/COO determines that ICS security is a top priority. In this case the security posture improves dramatically in 2 to 3 years. The security posture is at a level that most in the ICS security community believes is near impossible or doesn’t exist. 
(2) The Operations team determines that ICS security is a top priority. In this case the security posture improves to an appropriate level in 5 to 7 years. Improving ICS security is much more of a time investment than equipment purchase, so with the right emphasis and diligence over years an Operations team can get there. 
So one key is to convince CEO/COO or those that influence CEO/COO that run SCADA and DCS that they need to get serious about securing their ICS. Convince them it is in their best risk management interest to devote resources to this and measure results. Unfortunately, we are reaching few if any CEO/COO at ICSJWG, WEIScon, SANS Summits, … or on this website. 
Of course it would help if those active in ICS security would stop “the soft bigotry of low expectations”. The security deficiencies from insecure by design to basic security implementation vulns are frequently bemoaned, but the same people who recognize the dire situation more often make excuses that call people or companies out to fix the real problem.
Please read Dale's entire article, and if you agree, please support Suits and Spooks Boston by registering to attend and spreading the word. And if you want to add your company's name to the event, we're still looking for one more corporate sponsor.
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID