DEF CON 33 - Safeguarding the Industrial Frontier   OT SOC & Incident Response - Adam Robbie

DEF CON 33 - Safeguarding the Industrial Frontier OT SOC & Incident Response - Adam Robbie

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 20:08

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video discusses the challenges of establishing and managing OT Security Operations Centers, emphasizing that legacy industrial equipment lasting 30+ years 2:26-2:33 creates unique security challenges not found in IT environments.

Key Takeaways:
• Most OT devices lack adequate logging for security investigations, with over half of equipment not having necessary information 1:35-1:40
• OT and IT have fundamentally different risk profiles - business risk versus potential human lives at stake 10:43-10:45
• Organizations should integrate OT security personnel with operations teams rather than maintaining separate silos 14:47-14:50
• Building relationships with operational staff is crucial for distinguishing between actual security incidents and normal operational issues 13:22-13:24

Most organizations with dedicated OT SOCs are in the privileged minority, requiring practical solutions with limited resources 12:12-12:13.

Sources:

  • 2:26-2:33 Discussion on 30-40 year longevity of OT equipment
  • 1:35-1:40 Challenges with inadequate logging in legacy devices
  • 10:43-10:45 Different risk profiles between IT and OT
  • 14:47-14:50 Integrating OT security with operations teams
  • 13:22-13:24 Importance of relationships with operational staff
  • 12:12-12:13 OT SOCs as a privilege for few organizations

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So you talk about uh the sock and you talk about how you're depending a lot on network data for the sock, but when we talk about the logs to actually do an investigation in the sock or even to do an incident response, we'll get into a little bit of this later when we under the scope of an OT sock. But um when we talk about secure by design, there's also you talk about secure by operations. Um, I guess bringing this into a conversation about the sock, which uh, Adam wants to talk to about a lot. Where are we at with these devices actually sending logs that are not just about temperature and pressure and operations, but also sending the type of logs that are relevant to a security investigation? Well, you all have much more um hands-on experience, but just from a standpoint of logging and in…