Transcript
environment? So in my world, my company is highly decentralized, so it adds a little bit more, an extra wrench into that challenge. A lot of it is that initial training and awareness to let people understand why we're doing it, and then having a good mechanism to tell them how we're going to evaluate whether we're doing a good job or a bad job. So I hear that as kind of a common theme, just this cultural challenge that comes up. Is that something you think is a fair statement? A very fair statement, and with the diverse plants that we have, each different type of plant has a different culture as to how they approach things. So culture is huge. It also plays into that codependency between IT and OT, because they both need to work together. So you need that culture where they actually collaborate. Is cyber a little less of a foreign concept to the hardhats, so to speak, the engineers? Yeah, it's not as prevalent. We do have sites that are well along their way on that journey, and they fully understand it. They have their process to do their patching on their regular cadence. But then we have the others that it's not in their forefront. So in terms of our discussion about protecting the network at some measure of scale, how important is a strategy like segmentation to successfully complete this journey? So it doesn't really matter which framework you look at. Segmentation I think is number one. Everybody says you must have segmentation. In some of our facilities, segmentation is difficult, right? Because it's old equipment, et cetera, and it makes it a little bit harder. But segmentation is our primary piece that was our number one on our OT program, and we're still actively pursuing. I mean, I hear it's a pretty complex challenge for a lot of companies. What did you run into in terms of some of those challenges? How did you overcome them? It's an IT technical challenge for the most part, because typically the IT team owns the network until you get inside that cabinet. So from that perspective, a lot of plants didn't have the network guy, right? So they have good active directory, everything else. But from a network perspective, we found that some plants had to basically outsource to... We had third party providers that we vetted that could come in and actually help them, because yeah, it's just not something that they do on a daytime basis. So what would your role be, is just a matter of identifying the right assets to kind of... Our role was a little more high level, because Magna is like corporate group division. So obviously the plants are division level. So ours was more giving a high level idea of what segmentation should be. So where IT is, where that line is between IT and OT and that DMZ. But we kind of let the plants decide whether certain devices belong to DMZ, manufacturing, et cetera. So I wanted to dig into your talk here at Nexus a little bit about just how, again, this journey toward kind of automating firewall reviews, understanding, just using that as a kind of a baseline, the baseline standards that go into that. If you can kind of just maybe a two minute kind of overview of what you shared, that would be amazing. Okay. So again, we got to this position because we put firewalls in, but it's decentralized. So how do I know if they did a good job or a bad job? So what we did is we went through our basic configuration settings and we said, hey, these 15 items are important. So we should see these 15 items or not see them. We shouldn't see a public IP address, for example. But then we looked at the rules and there were different conduits, right, between IT, manufacturing, DMZ. So we had all those conduits and we knew that some were riskier than others. And so what we did is we said, we have a risky conduit and then we looked at rules and we broke them down basically on source, destination, destination port. What you had enabled in the rule would rate the rule from poor to best. So you take that poor to best, match it with the risk, blend it together and you get a score. So we scored each of the conduits, add it all up and here's your score out of 100. From my perspective, it was more, I needed an easy mechanism that I can kind of see, are we using the tool? That's all I was really looking for. As time goes on, I can see us upping the baseline to say, we expect you to have this score versus that score. Can you share some of those things that go into that baseline kind of establishing? It's interesting because what we did with the risk is we gave more points to a higher risk conduit, right? So that's where the points are associated. Coming into it, we expect that there's going to be more good rules than best rules. So the expectation is we're going to have this baseline here, but allowing the plants to understand that here's how we expect to see things, gives them that feedback to know that, okay, so I need to go do X. I need to add these rules or be more specific in my rules, which reduces the risk while bringing up their score. So it's trying to help them understand what they need to do versus just kind of saying you need better rules. I mean, every OT environment is obviously different, but I mean, do you see this being applicable elsewhere, any kind of factory setting, any kind of OT setting, this approach? Yes. I believe the approach can be used at any place where you're doing OT. As long as you have a firewall, I think being able to look at it and kind of say, how well are you using this tool? A different plant might have a different risk ratings for their conduits, but that's the flexibility of the tool. And in terms of the outputs, what are you specifically doing with that information as a matter of just better tuning of the firewall or were there eye openers maybe you didn't expect? Well, actually, this is all part of our OT KPI. So this feeds into our KPI of how well a plant is doing our OT program. So that was the initial use of it. But last year, Jim Tassel from Kellanova was on and he showed a way to show the KPIs. So when you got your number, you could see where you went wrong. So I actually used his knowledge and can break down. So here's your configuration score. Here's where you did right. Here's where you did wrong. Same with the conduits, where you can improve. So we use that to kind of help move us forward. And in terms of just firewall configurations and rules, are there some must haves in there that you could share? From a configuration perspective, there are some. So we expect that we're going to see that it's clustered. We expect that there's going to be, we use Fortinet tooling. So we expect that there's a Fortinet EA enabled on there. So it's in support, etc. So there's certain things that we expect in that area. From the rule base, we expect certain criteria of, we want to see DMZ, we want to see MFG, we want to see IT. So that way we can look it down. We do not want to see an any zone, where you don't specify where you're coming from or where you're going to. So there's certain things that we expect and we rate them accordingly. And just kind of this journey toward automation, I mean, is there a point where you kind of know you're ready to turn it on? That's a very good question. So this idea came early this year, and it's taken us a while to go through, can I actually parse that firewall and look at it? What can I do? How would I rate it? And we went through all these pieces. It took a while to get there. Because we're decentralized, there's an onboarding process, so the site has to grant us access so we can actually read the config. So getting that data has been the initial challenge. Looking at the data and how we display it has also been something like, ooh, I guess we need to show it this way versus that way. I started with negative numbers. You start at 100 and you lose. But it was confusing when you're trying to display it because it just didn't make sense compared to all the other KPIs. So we had to change our ways.