Skip to content

Cybersecurity Tabletops - Building Resiliency and Relationships

Presenter:

Randy Petersen

This talk makes the case that threat modeling in OT environments is often disconnected from how attacks actually unfold, leading to defenses that look good on paper but fail under real-world conditions.

Key takeaways

  • Threat models are too theoretical
    • Built around assumed architectures and clean diagrams
    • Don’t reflect how systems are actually deployed and used
    • Miss the messy, real-world attack paths
  • Attack paths are what matter
    • Adversaries don’t follow neat boundaries
    • They chain together small weaknesses across IT and OT
    • Risk lives in the path, not the individual vulnerability
  • OT environments break traditional modeling
    • Legacy systems, undocumented changes, and workarounds
    • Incomplete asset inventories
    • Constant drift from original design
  • Static models quickly become outdated
    • Environments evolve faster than documentation
    • Threat models become stale almost immediately
    • Without continuous validation, they lose value
  • Validation is the missing step
    • Modeling needs to be tested against reality
    • Red/purple teaming helps validate assumptions
    • Continuous iteration is required

Latest

Cybersecurity Has a Startup Discovery Problem

Cybersecurity Has a Startup Discovery Problem

Security leaders need emerging cybersecurity technology faster than ever, but finding the startups actually worth their time is getting harder as AI accelerates both innovation and cyber threats. Starting with CYBR.SEC.CON, we plan to do something about it.