By Gregory Hale
Bolt on security has been an issue across the manufacturing industry from day one because the current products ended up created in an era when there was no idea there would ever be a cyber anything much less the increased levels of connectivity we are seeing today.
Responsibility to create security in a bolt-on environment often ended up diverted across different factions: The manufacturer because it was their company; service providers because they were hired to build a security program, and to a lesser degree the technology manufacturer (or supplier) to create more secure products.
Now, government agencies across the globe are chiming in saying technology manufacturers should build security in by design and products are secure by default and that is why they created a document called “Shifting the Balance of Cybersecurity Risk: Security-by-Design and Default Principles.” This is a document released last week and created by Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation, National Security Agency, Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand’s Computer Emergency Response Team, United Kingdom’s National Cyber Security Centre, Germany’s Federal Office for Information Security (BSI), and the Netherlands’ National Cyber Security Centre.
The document said every technology manufacturer should build their products in a way that prevents customers from having to constantly perform monitoring, routine updates, and damage control on their systems to mitigate cyber intrusions. This way, technology manufacturers should take ownership for improving the security outcomes of their customers.
While no one can deny the need for heightened levels of security, but why are governments around the world now getting involved and is that needed?
Cyber Breach Impact
“Government agencies want technology manufacturers to prioritize creating secure products by design a default,” said Dewan Chowdhury, chief executive and found of security provider, malcrawler. “They want to make security a core business goal rather than just a technical feature. The industry should strive to create products that are secure ‘out of the box’ and require minimal additional security measures from customers. Remember, it’s the customers that drive this. If customers push for it, they will make cybersecurity functionality into their product line.
“The feds are getting involved because of the increasing number of cyber breaches impacting critical industries (food, oil & gas, water, etc.). These disruptions have created risks to the economic, national security, safety, and health risk of nations. Insecure technology and critical system vulnerabilities can make a new attack surface that can lead to malicious cyber intrusions. The involvement of federal agencies and other foreign government entities is an effort to encourage technology manufacturers to improve the security outcomes of their customers,” Chowdhury said.
“Let’s put some basic flaws in the guidance up front and center,” said Joel Langill, founder and managing member of the Industrial Control System Cyber Security Institute LLC. “All the resources cited are from other government agencies around the world … Though this is paramount for the U.S. and CISA, it fails to look at some of us that have been in this field longer than most of them.
“It also seems the limited resources cited shows CISA is still focused on looking at only a small subset of those resources available from the typical ‘5 Eyes’ for Five Countries that are within the U.S. intelligence oversight and review umbrella. A myopic view in addressing a global problem.
“Where are some of the recommendations and guidance of for example some Gulf Corporation Council (GCC) countries that are much more aware of their threats and how to direct their strategies at addressing the reduction of risk against these threats?” Langill asked.
Define Secure by Default
In the guidance, the authors talk about secure by default, but Langill said there needs to be an understanding of what that means.
“So, let’s begin with the fact that one can define ‘secure default’ that addresses a large-scale audience,” Langill said. “Security is a direct measure of addressing specific risk and mitigating it to ‘a level that is at or below an organization’s risk tolerance.’ How in the world can a single federal agency determine this risk tolerance and determine what is acceptable ‘default security?’ This is a joke and shows that the USG does not even appear to be following their own Risk Management Framework approach. What is secure for one organization is insecure for another. Period.
For others, the terminology could seem confusing.
“I really don’t like the name ‘secure by design’ but it’s far too late to change it,” said Andrew Ginter, vice president industrial security at Waterfall Security Solutions. “Way too many security practitioners and purchasers naively assume that ‘secure by design’ products are invulnerable. The doc says they are not, but only several pages after it introduces the concept and term. Too many also believe that assembling a bunch of secure-by-design products into a system results in a secure system – it doesn’t. It is absolutely possible to configure a bunch of secure-by-design products into a woefully insecure system. Secure by default – has the same problem with terminology, but for some reason I don’t see people as confused by this term as they are by ‘secure-by-design.’
In terms of what this guidance means for the industry, the answer is right now, not much.
“In the short term, it does not mean a whole lot,” said Peter Lund, vice president of products – OT security at OPSWAT. “As stated, ‘the authoring agencies recognize the contributions by many private sector partners in advancing security-by-design and security-by-default.’ This guidance is not new and more of a summary of best practices that other industries doing a good job have been doing for a long time. For example, major U.S.-based utilities that have adopted NERC-CIP and are routinely audited rarely have an OT cyber event.”
Again, the guidance reiterates what has been said before.
Accountability
“As outlined in the National Cybersecurity Strategy, ‘we must begin to shift liability onto those entities that fail to take reasonable precautions to secure their software while recognizing that even the most advanced software security programs cannot prevent all vulnerabilities,’ and, ‘companies that make software must have the freedom to innovate, but they must also be held liable when they fail to live up to the duty of care they owe consumers, businesses, or critical infrastructure providers,’” Lund said. “It’s not surprising this guidance was released or that they will likely start holding companies accountable for not following guidance when there are obvious security issues. This could come in the form of audits/findings and, in extreme cases, fines.”
“The White House’s recent release of a National Cybersecurity Strategy is a strong step forward in recognizing the importance of securing our critical infrastructure,” said Mark Carrigan, senior vice president of process safety and OT cybersecurity at Hexagon. The proposed strategy contains several good initiatives but is also concerning depending upon how the program is put into legislation.
“Pillar Two, Disrupt and Dismantle Threat Actors is a positive development. As a general rule, the U.S. government should be taking the lead ‘on offense’ when dealing with cyber threats, while industry should take the lead ‘on defense.’ The government has the authority and resources to develop strategies and programs to go after our adversaries who are often harbored by foreign governments – industry cannot take the lead in disrupting their behavior. Industry is better suited to defining and implementing defensive measures to prevent and respond to attacks.
“Pillar Three, Shape Market Forces to Drive Security and Resilience could create serious concerns if not implemented properly, especially the section on shifting liability for insecure products and services. Cybersecurity best practices move much faster than government regulation. Who will ultimately be responsible for determining that a software provider developed their products in a secure and safe manner? As an example, a software product may come with a recommendation to implement various firewall rules to prevent attacks and data exfiltration. If those rules are not implemented by the owner operator, will the vendor be liable in case of an attack? Did the need for a firewall rule imply the product was ‘insecure by design?’ Poorly designed regulations will create a field day for liability attorneys and will force companies to divert investments into managing their own legal risks rather than improving cybersecurity.
Changes Mean Huge Costs
“Finally, there is an elephant in the room that is yet to be addressed. There is a lot of emphasis on implementing zero trust technology to improve cybersecurity. The vast majority of our energy sector is controlled by systems that have no ability to implement zero trust at the ‘final mile’ (the point where a command is calculated and sent to a device that controls the process). In order to implement zero trust through the entire OT network, control system vendors will need to completely redesign their technology and owner operators would need to replace all of their current systems. The cost will be in the many billions of dollars. Are vendors and owner operators truly ready to make this investment, and is the cost worth the security gains? This debate must be settled,” Carrigan said.
Lund agrees some of points within the guidance are exactly what some cyber experts would consider, however, if all suggestions ended up implemented, product implementation would change.
“All of the content within the guidance aligns with what an ‘expert’ would suggest. What changes is the need for companies to invest in the tools and experts to follow this guidance. This will no doubt impact the cost of products, and in some cases, slow the speed at which products and updates are brought to market.”
In the document there is discussion about to whom the responsibility of security falls.
“‘The burden of security should not fall solely on the customer.’ This is absolutely true for consumer goods, but less so for business or heavy industry,” Ginter said. “End users have to accept some of the responsibility for security and the document doesn’t highlight this strongly enough. Secure by design is a solution, but how much of the problem is solved and for whom is not clear in the document. Consumer goods have different security requirements from industrial automation for small shoe factories, and both have very different requirements vs. rail switching system automation. Secure-by-default seems clearer – it means nobody has to turn on security features. This is useful because far too many consumers and even business and industrial customers either don’t think to, or don’t know how to, turn these features on.”
Common Sense
Applying common sense to security seems to be going by the wayside.
“When you spend $250 on a PLC, why would anyone expect that it is a safe and secure control appliance when compared with another similar product in terms of features and functions that costs 100 times more?” Langill asked. “Let’s just compare a simple Siemens S7-1200 and an S7-400. This is where I am particularly disappointed with the USG report in their failure to acknowledge what France ANSSI has done with their efforts along this same path. Different applications … different requirements. They also are completely blind to the working of IEC/ISA 62443 and the direct incorporation of risk management and reduction against product selection and configuration.”
In the end, the guidance points to the obvious. Security is an evolving process, and everyone need to work together to achieve a holistic security end goal.
“The document seems a net positive contribution to best practice, but it would help if it did a better job of combating the impression that many practitioners have of this approach being a silver bullet,” Ginter said.
“The power utility industry in America, which NERC-CIP regulates, has really changed how technology is provided to power utility companies,” Chowdhury said. “Because of the demand for cybersecurity functionality driven by regulation and customers, cybersecurity features are built into some of the most minuscule products. I’ve come across many products that the first thing you must do before configuring the device is create a unique username and password, no more default usernames and passwords out of the box. Secure by design has been a long process for the power utility industry, but we are seeing the fruits of this in the past few years.”

