What They Don’t Tell You About Critical Infrastructure

Summary: The video discusses the author’s perspective on a paper related to resilience in the context of industrial control systems (ICS). The author expresses skepticism about the emphasis on prevention rather than recovery, highlighting the challenges and costs associated with implementing effective recovery strategies. The conversation reveals new insights regarding the MITRE ATT&CK framework for ICS.

Keypoints:

  • The author views the paper as a “resilience theater,” suggesting a facade of effectiveness in prevention strategies.
  • There is a belief that building recovery mechanisms in ICS will be expensive and challenging.
  • The author expresses surprise at treatments of strategies like bug bounty programs being deemed “thorny.”
  • The paper provided the author with new information regarding the MITRE ATT&CK framework for ICS.
  • The author acknowledges both positive and negative aspects of the article’s content.

Youtube Video: https://www.youtube.com/watch?v=ALj4gt-G_xc
Youtube Channel: Security Weekly – A CRA Resource
Video Published: Sat, 26 Apr 2025 21:00:20 +0000