
Risk
Thursday, September 23, 2021
There is a large effort to quickly bring SBOM to the OT industry. Then What? (Physical Live)
There is a large effort to quickly bring SBOM to the OT industry. Then what? I get impact analysis will in part be faster. But what about provenance? What happens if a US company discovers there is a SW component from China? Or the Chinese discover the component they thought was from Hong Kong is actually from Japan? The geopolitical implications can be significant. How is the drive towards regionalism and away from globalism going to affect our industry?
Friday, September 24, 2021
Building Control Systems-Don’t Trust Anybody or Anything (Physical)
In this era of converged Building Control Systems, the HVAC, Lighting, Fire, Parking, Elevators, Digital Signage have now become attack surfaces that can be used to compromise not just the building systems, but also the tenants and visitors of the building and their organizational IT systems. In this session we will explore some of the best practices for adopting Zero Trust architectures, use of Cloud services, SOC-as-a-Service, and Contingency Planning/Disaster Recovery for when a cyber incident does occur. Buildings are exceptionally difficult to protect as they are used in every sector but can have different ownership types (REITS, government, private sector), levels of physical security (contract guard, secure facility, Defense Industrial Base, etc.), different levels of energy security (stand-by power, prime power, Distributed Energy Resources), different levels of recovery/resiliency (medical, data centers, commercial office space, residential, etc.) and different financial business models (Triple Net Lease, Energy Savings Performance Contracts, LEED, EPA Energy Star, etc.). The session will look at the proliferation of attack surfaces address, examine the cost savings versus the potential impacts, how to balance risk to succeed -what does that risk management strategy look like? The building owners ultimately need to decide if they are sacrificing security for efficiency and the role their building will play in their portfolio for the next decades.