Espionage vs. Sabotage
About This Session
What's old is new again. 50 year old (!) cybersecurity theory (Bell/La Padula vs. Biba) teaches us that a detailed asset inventory showing us where is the information we must protect is the wrong first step when we are trying to prevent sabotage vs. prevent espionage. In espionage, information is the asset - we need to know what and where it is to prevent theft and leakage. In sabotage, information is the threat - the first inventory is not of assets and information, but of data flows / attack vectors. The most important such vectors are not internal to the system, but vectors that cross consequence boundaries. When preventing sabotage, securing connectivity across consequence boundaries is not a "compensating measure," but a primary protective measure. The latest cross-agency guidance authored by the UK NCSC "Secure connectivity principles for Operational Technology" makes this distinction clear. The guidance offers strong advice for controlling the movement of incoming information flows, including hardware-enforced / ASIC-based "unhackable" inspection of dangerous incoming information. In this presentation we look at the latest advice in terms of (long forgotten) 50-year-old theory, and look at it in light of the latest threats and attacks highlighted in the (open, public) data set of cyber attacks with physical consequences in 2025.
Speaker
Andrew Ginter
VP Industrial Security - Waterfall Security
At Waterfall Security Andrew leads a team of experts who work with the world's most secure industrial enterprises. Before Waterfall, he led the development of high-end industrial control system products at HP, of IT/OT middleware products at Agilent , and of the world's first industrial SIEM at Industrial Defender. Andrew is the author of three books on industrial / OT cybersecurity with 35,000 copies in print. He co-hosts the Industrial Security Podcast and contributes regularly to industrial security standards and best-practice guidance.
