1660604796863 Cg1111securitymoney

Answer to Our Question of the Month

Nov. 3, 2011
Would You Pay for Outside Help to Address Cybersecurity Issues?

"Would you be willing to pay for outside help to address your cybersecurity issues?" Walt, here are my two cents, based on some bizarre experiences.

As so many other things in life, industrial control system (ICS) security is mostly about the money. As anybody can guess, I'm getting several requests these days for consulting and for giving talks. Funny enough, especially what look like the more serious requests often turn out to be blunt attempts to exploit our hard work on Stuxnet for free. (I spent over $100,000 on our Stuxnet research.)

So, for example, the World Institute for Nuclear Security (an organization associated with IAEA) invited me to speak at their conference without an honorarium and even expected me to cover travel and accommodation by myself. A vendor consortium consisting of the big names in automation rejects my request for honorarium because they "are a non-profit organization." A European government invites me to talk at its annual CERT conference with no compensation "because they are a government." (We still laugh about that one.) A defense contractor inquires about "collaboration" on cybersecurity issues in its weapon system, indicating that its staff doesn't have a clue, and is never heard of again after receiving a moderate quote for consulting services. The list could go on.

Anybody may forgive me if I have come to think that so many players in the ICS security game really don't belong there, as they're just looking for a free lunch to pimp up their marketing collateral. I'm afraid that some time the society may have a price to pay for this ignorance. Anyway, to close somewhat more optimistically, there are a few others who treat the subject more seriously, evidenced by how they open their pocket books. And, as the saying goes, you get what you pay for.

Ralph Langner
Langner Communications
www.langner.com

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...