August 19, 2026

00:47:24

Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure
KBKAST
Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

Aug 19 2026 | 00:47:24

/

Show Notes

Karissa Breen sits down with Gijo Varghese, Chief Security Officer at OT cyber security firm Secolve, to unpack an uncomfortable trade-off: the same connectivity and AI making power, water and transport smarter are also making them easier to break. Gijo explains how IT and OT convergence has widened the attack surface, why decades-old control systems were never built to touch the internet, and how a single IT intrusion can spill into the physical world. He walks through the incidents that prove it, from the 2015 Ukraine grid attack to Colonial Pipeline, where operators went to run the system by hand and found the people who knew how had all retired, to the Jaguar Land Rover breach that rippled through 5,000 suppliers and cost the UK economy billions. The throughline for boards and executives: a cyber incident stops being a security event the moment it becomes a public safety failure. Gijo makes the case for the kill switch, tested manual fallbacks, and treating resilience rather than compliance as the real measure of readiness.

About Gijo: Gijo Varghese is a cyber security veteran, critical infrastructure defender, and the Chief Security Officer of Secolve. His passion in life is to protect the systems society depends on – power grids, transport networks, and biomedical health systems – keeping people, communities, and businesses safe from cyberattacks. With over 25 years of experience across IT and OT security, Gijo has spent his career at the frontline of Australia’s most essential industries, most recently leading cyber resilience at Endeavour Energy for six years, with prior roles at Transport for NSW, SA Health, CyberCX and Wipro Consulting. 

Secolve is Australia’s leading OT cybersecurity firm, providing cyber advisory, offensive security, and training services to mines, factories, hospitals, transport networks, and energy ecosystems. As Secolve’s first CSO, Gijo leads the firm’s consultancy and professional services team, transforming complex OT cyber risks into practical action across executive, engineering, and operational teams. 

Keywords: critical infrastructure security, OT security, IT/OT convergence, SCADA, ICS, cyber resilience, kill switch, Colonial Pipeline, Jaguar Land Rover, SOCI Act, CI45, incident response, operational technology, AI cybersecurity, public safety, board governance, cyber warfare, business continuity

View Full Transcript

Episode Transcript

Gijo Varghese [00:00:00]: Any digital breach, be it cyberattack or a technology failure that manifests into a physical consequence, is a time when the cyber incident just stops being a security event and it becomes like a physical safety failure. VO [00:00:21]: From KBI Media, I'm Karissa Breen, and this is KBKast. KB [00:00:28]: My guest today is Gijo Varghese. Chief Security Officer at Secolve, and a man who's spent 25 years on the OT side of cyber, the systems that keep the power on, the water safe, and the trains moving. We get into why critical infrastructure being smarter has quietly made it more fragile and why every serious operator now swears by a kill switch. The question nobody wants to say out loud. Is the day the people who could run it all by hand have retired, what exactly is the backup plan? VO: If today's episode lands for you, do 2 things: hit follow and send it to one person in your network who needs to hear it. That's how shows like this grow. Alrighty, let's get into it. KB [00:01:19]: So, Gijo, thanks for joining me today. I want to perhaps start with Given your background, your pedigree in this space, here's a question for you. Do you believe we've made critical infrastructure more vulnerable at the moment than sort of making it smarter? And when I mean smarter, I mean like, you know, the use of AI and all the cool stuff that's happening in the market. I want to start there first to get your view given your background. Gijo Varghese [00:01:44]: Yeah, Karissa, 100% yes is the answer, but I'll give you a bit of a background. When operational technology devices designed, they were never designed to be connected to key systems or to internet. The designers always assumed that there's gonna be an air-gapped environment, which means that there is a clear delineation between IT systems and operational technology systems. But as we start making things smarter and the need that we wanted these systems to become much more insightful. we started connecting them. And as the connections start beginning, we've started to see that there's been massive attack surface increase. And that's one of the biggest impact why smarter devices are making critical infrastructure more vulnerable. But the other dimension to this, Karissa, is there is a massive need because of customer requirements to converge operational technology systems into IT systems. Gijo Varghese [00:02:55]: And this is called as the hyperconvergence cycle between IT/OT systems, where we are trying to merge these physical operational technology systems into corporate networks. And that again brings this problem that now an attacker is able to use common IT exploits like phishing and credential thefts to really jump into operational technology systems through tools and tactics that can be used in the And third, most important thing, Karissa, in the OT context is operational technology and industrial control systems are designed to stay for 20 years or even longer. And you are then talking about, say, a PLC system that was actually built in, say, 20 years before. And those systems do not have the same security controls and encryption methodologies that comes with IT systems. And we've seen this play out that in the Ukraine regional grid compromise that happened in 2015, attackers actually used the IT credential compromise and exploited that IT credential to hack into a SCADA system and flip a substation offline. So that is why I think we are in a state where making critical infrastructure smarter is making the whole ecosystem vulnerable to cyberattacks. KB [00:04:30]: So a lot of the people that I've interviewed on the show over the time, and we've spoken a lot about the conundrum with having OT systems in isolation, but then with that is you might have like a 100-year-old controller and it's super old school. You know, you can't even connect it to the internet. You have to get some person to go up in a tower to go and look at it in the middle of nowhere. And then the other side of that is, well, we have to connect it to make our life easier, but then when we connect it to the internet, we have problems then. So it's sort of like, I can see benefits to both sides, but would you say this is the issue that people are facing? Because if something is a controller that's so old school in isolation, it's not going to be able to do much. But then once it's connected, whilst it can do more things in terms of capability, it opens up another array of issues that we're going to talk about today. But would you say that How do people approach this now? Because historically, folks that were in the OT space, as you would very well know, were very against and apprehensive about, you know, creating their systems to be a little bit more online, so to say, so to speak. So talk me through how this lifecycle's sort of gone of people being apprehensive to now it's okay to now we must sort of do it because of this push in the whole AI space to stay competitive? Gijo Varghese [00:05:57]: Yeah, look, I don't think we should be very conservative in this thinking. You know, when you look at these systems, these systems can have huge value addition to consumers as they are connected to corporate network and to internet. But when you do that, you must do that with adequate safeguards. And that's where people fall out. You know, it's like essentially carefully retrofitting and having this clinical surgery carried out, that you converge these systems with adequate segmentation. And so following some basic rules in hygiene to make sure that you are having proper segmentation and segregation so you can control and isolate it, isolate these critical systems, making sure that your remote access is controlled to make sure that anybody who's accessing that is controlled and somebody's monitoring them, making sure that you have a very good incident response plan. And fundamental to this, in heart, all of this connectivity is to assume that, look, cyber incidents can happen. And when cyber incidents happen, the organization is ready to respond and make it much more resilient. Gijo Varghese [00:07:20]: So I think that's where we need to focus on that. A, apply the basic protection needs, but focus more on incident response and recovery so that you can still use these value-added benefits of AI, but at the same time, keep your critical infrastructure protected so that it's not causing physical harm to people and consumers who are using it. KB [00:07:48]: So when you say clinical surgery, Gijo, what do you mean by that specifically? Gijo Varghese [00:07:52]: So it is about having a look at what are these systems, mission-critical systems in your operational technology network? How do they operate? What are the dependencies of these systems? How are they connected? And how do you make sure that you can safely segment it, segregate it, and also provide the right level of access control? And more importantly, making sure that if there is a cyber incidence in this environment, you're able to adequately detect them, respond to those cyber incidents, and in case there is a cyber attack, you are able to isolate them, recover that with a freshly, newly built system so that you can bring back the operation of that environment. So you are ultimately not impacting safety and reliability of the service. A good example, Karissa, is, you know, not a cyber incident, but even a technology incident. Just recently, a fortnight ago, we had a telecommunication provider in Australia having a technical issue, and the whole of the trams in Melbourne stopped working, and it just went into a grinding halt. And that's what the physical consequences are, that if you don't plan these well and you don't have resiliency and reliability set up and planned and tested, you would have physical consequences where people are not able to call up 000 as a number, or trams just stop and you're not able to go anywhere. KB [00:09:29]: So I want to get into this a bit more because so many people come on here and talk about resiliency. We need to be resilient, we need to have a plan, we need to prepare, all of this stuff. But we're seeing it in our own country, in Australia, where Like you said, Telstra had a problem and then people couldn't call triple zero, people couldn't get home, took them hours, stuff that we've seen equally, you know, with Optus in Sydney, et cetera. So if these are big billion-dollar companies, what chance then do we have? And these got big IT teams, big security teams. What chance has people who don't have that capability? Are we, do you believe, given your experience, we're going to face this problem regardless? Because I mean, these aren't one-man band fish and chip shops on the northern beaches of Sydney. These are very big companies. So if they're not demonstrating it, and yes, we can say that there's, you know, there's errors and people make mistakes and all this sort of stuff. But as an industry, we're all sort of saying, hey, we need to have this level of resiliency. KB [00:10:31]: What do those downstream impacts then have on smaller companies that don't understand this, don't have this capability? For example? Gijo Varghese [00:10:39]: Yeah, look, Karissa, I think, I think we need to bring these 2 fundamental principles, right? One is technology is inherently weak and technology is inherently not reliable fully. So you need to always make sure that you have alternative plans and not only rely and think of technology. Classic example is you can always have a calculator because you've got You've got a calculator with you and you can quickly calculate. But in an event that there is no calculator, you still need to have some basic mathematics that you can perform some basic calculations to carry out a simple, you know, a simple day-to-day activity. So that's the essence of it. That what I'm trying to come back is ultimately, irrespective of you use technology or not, the risk of providing reliable service is at the hands of an asset owner, the person who is at the job to keep the power on, the water safe, and hospital running. And that's probably why you see a lot of these OT engineers having this reputation of fiercely being protective of their systems, because they really understand that they could have physical consequences if Things are not deployed in the right manner. And the challenge in the OT environment, operational technology environment, to the IT network is that operational technology environments operate in real-time system status, which means that there is absolute zero tolerance for latency. Gijo Varghese [00:12:22]: And that's because even a millisecond delay in sending a critical command from, say, a SCADA system to a control breaker could have significant safety impact to a crew member who is working to resolve a problem in the grid. And so it's important that whenever you consider adopting technology, you look at the risks associated to it and then think of alternative plans. And that's what Government is now mandating for critical infrastructure, at least they're seeing that critical infrastructure organizations are being targeted during cyber warfare. And you've seen that in this Russia-Ukraine war and the more recent one within the, the, the US-Iran war. Iran was targeting a lot of critical infrastructure sectors in the Middle East, in the countries that never thought they were part of the war, like Kuwait, Saudi Arabia, United Arab Emirates, were having impacts with airlines and airports being impacted or water utilities, you know, facilities being targeted. So how do you manage them? It's about managing that risk through manual processes sometimes to make sure that these essential services still work irrespective of what happens outside. Whether a geopolitical issue or a massive sustained cyber attack. And so governments have released multiple great articles on this, Karissa. Gijo Varghese [00:14:01]: One good article is the CI45 article that USCISA and the Australian ACSC have released where critical infrastructure organizations can take that and look at it And use those guides to isolate these critical infrastructure environments and operate them independently to what is happening in the external world. So yeah, the message is always have a backup plan and make sure you test that backup plan and always assume that there could be a breach and you would use these plans in case of a breach or a technology problem. KB [00:14:44]: Okay. A couple of questions in there. Do you think that people, as in today, assume that they won't be breached? I'm talking about like big players, like critical infrastructure companies. Surely there's not someone out there that's like, geez, you know what? I don't think we're going to get breached. I understand, you know, a mum and dad retail shop in Ballarat in Victoria, but I don't understand that a critical infrastructure company that is responsible for managing water plants and energy and all sorts of things can go, you know what, I just don't think we're going to be breached. Surely that's not the conversation. Gijo Varghese [00:15:17]: I think that's a very good question, but give you an honest response. You know, the assumption is technology is inherently weak. Anything that we have built, we've built with flaws, and that's why vulnerabilities exist. And you now have systems in AI that is able to easily detect these vulnerabilities in much more faster pace. But what I'm coming to is that when you have these great tools that can break technology, but also nations that have larger workforces who are employed to identify these weaknesses in technology, you can almost never assume that cyberattacks will stop. KB [00:16:01]: Cyberattacks will always occur. Gijo Varghese [00:16:04]: And I think the mindset in which we need to operate is that irrespective of how big your company is, you adopt technology to enable efficiency and speed of operations and market reach and facility for your consumer. But you always must assume that this can fail at any point in time and you need to have backup plans for it. KB [00:16:31]: So the tech side of it, I understand. Of course there's going to be vulnerabilities, there's always going to be cyber issues going on. It's more like the mindset though of these people, executives in these businesses. Do they genuinely think at the end of the day, don't think we're going to have a breach? Surely they can't think like that. Like, I get that 10 years ago, but not today. Not with everything that's happened, what's happened recently, even the last 24 hours down there in Australia, we reported on it. So Would you agree with that statement? Surely not. That's not a thing still. Gijo Varghese [00:17:00]: I think boards are now getting to realize about the technology impact. 20 years back when I started in cyber industry, I still used to kind of explain to even technology experts what IT security was all about. And I started with a slide of confidentiality, integrity, and availability, and how that could potentially impact businesses and their services. But that's gone with quite a lot of good regulations coming in. Boards are now having years to understand impacts of cyber risks and technology failures in the organization. Essentially, they are directors who come from legal, financial, or corporate governance background. They're not probably industrial cyber experts or probably even you know, general cyber experts. So naturally they lean towards a lot of compliance framework for proximity of safety. Gijo Varghese [00:18:03]: But I think at large, when organizations treat compliance as a distinction rather than just a baseline and an intent to manage, that's when the maturity changes. I used to report to boards who are very mature and they understood that technology failures and cyber attacks could happen any point in time. It's about how do we work together? And there were constant conversations of, are we able to isolate our critical systems during an active breach? Are we able to operate systems in a degraded manner, yet in a state that the service is not impacted? And that's the beauty of a lot of the operational technology that if you understand and plan ahead well, which a lot of the critical infrastructure are good at because they are crisis experts. They are essential services and they manage crisis at large. They understand that, you know, you might not need technology always. You could literally go down to these substations, deploy 1 or 2 field crew, and they could do manual switching to make sure that customers are getting their services that they need. So it's all about making sure that you're not connecting to internet when there is a massive sustained attack, making sure that you are able to operate and provide that service and understand that risk of when you need to invoke a cyber incident response plan and when do you invest on cybersecurity to protect the environment and how do you then proactively monitor these environments to make sure that there is a cyber attack, you're able to detect them and then command to respond. I think that mindset's coming into the board of directors, to the senior leadership, and largely it's driven by a lot of this compliance obligation. Gijo Varghese [00:19:59]: Here in Australia, we have the SOC Act, which has clearly identified all the critical infrastructures, and they've put in responsibility to the board of directors and to the leadership to make sure that cyber is just not a cyber team's problem, but essentially it's the organization's problem. I feel that cyber is moving towards a nation's problem because a simple cyber attack can have significant consequence to economy if we don't manage them as well. So yeah, it's moving into that realm, but there's lots to do. There's also bits around the cultural element. It's not just about using technology without really understanding the risk. So even Consumers like me and you, when we use tools like Facebook and digital banking, we need to understand the risks that comes along with it. And we need to make sure that we are putting reasonable security, that we are, we are cyber safe and cyber savvy when we are working in newer environments like the internet. KB [00:21:10]: We'll come back to that after a quick word from our sponsor. Engineering teams are increasingly being pulled into the compliance conversation, and it's not where you want your sprint hours going. Vanta automates the painful bits of ISO 27001, SOC 2, and GDPR, so your team can spend less time on audits and more time building things that matter. Visit vanta.com/KBKast. That's vanta.com/KBKast. Okay. So I want to go down the path around the plan. Couple of things there. KB [00:21:48]: My first question would be using your example around the calculator. Yes, when we don't have one, we have to be able to know how to add things up and get the answer right. So my concern now is, and I'm speaking to people all around the world or people, let's look at AI, for example, and people saying, you know, human in the loop, on the loop. Let's go back to in the loop. So it's like, hey, I don't know this answer, therefore I'm gonna, you know, ping KB and say I need the answer because I'm not sure, right? Haven't seen this before. I was talking to someone who's going to come on the podcast and they were saying to me, KB, human on the loop is pretty much useless now because people are just going to go, yes, it's all good because people are becoming like manufacturing that laziness. People aren't going to go through it. That was the intent to be like, well, what we'll do is we'll reduce all of these alerts. KB [00:22:35]: And then we'll get KB one every arbitrary 50 times to manually go and have a look at something and approve it or not approve it, or, you know, understand and dissect it. But now this dude's saying, hey, we can't even do that now. So it's completely thrown all the people that I've just interviewed on about human in the loop. And he's saying, I don't believe in that now. The reason why I bring that context to you, Gijo, is because if we don't have systems, And people are now relying on 2 2 and someone's giving you 5. Like, what hope do we have if we can't even do stuff with systems? And now you're saying we're going to have to resort back to people using their brain. What's happening there? Because there's so many studies, you know, on how people are retaining information. They're struggling more than ever before we've ever seen. KB [00:23:23]: They've got younger school students that can't even, you know, read and write properly. Like, this is very rudimentary sort of stuff. Like, we're not asking people to send a rocket ship into space with pen and paper. Like, so I'm— my concern is if we can't get it right with the tools and the systems, how are we supposed to get it right without them? Gijo Varghese [00:23:43]: It is the conundrum, right? Technology is moving in such a fast pace with AI that it, you know, literally is changing where we are with respect to the risk and how do we manage that risk. You know, we're all trying to understand from a cyber practitioner and data protection experts of how do we do that. But it's fundamentally much more simpler when we look at it from a critical infrastructure perspective of generally, you know, a human perspective that there is a need to understand that technology is only going to be an enabler. It can't be the forefront of everything. It must only be an enabler to a human. When there were times when we didn't have calculators and computers, we had a heap, a lot of human resource doing the same thing, a bit slow. But with all these tools, what's happening is that it is becoming faster and much more efficient. So you probably don't need the same number of people to do the same activity. Gijo Varghese [00:24:48]: So understanding that the context is you can use technology when it is normal, And when things go bad is when you need to start having that balance between, you know, using technology to carry out everything in your life to making sure that your most critical processes, practices in your personal life and practices within the critical infrastructure operations have a backup plan. And organizations understand, like in critical infrastructure organizations, they clearly have like a disconnection switch. We call the kill switch where business leaders and technology leaders now are practicing plans where they have the authority to safely pull off the cord when they need to and understand that there is an attack. You know, we need to kind of disconnect and we need to start practicing that. If we don't practice the disconnection cord, Karissa, you would see something like Colonial Pipeline incident. And what happened in the Colonial Pipeline incident was it's a compromise of the IT billing system. And the compromise took a shape into a fact that they were worried that it could potentially reach the operational technology environments, that is the pipeline management systems. And so proactively, they shut down the pipeline digital systems and soon realized that they didn't have operators to manually operate these pipelines. Gijo Varghese [00:26:31]: They didn't have the expertise because people who were manually operating these pipelines all were retired. So they had to gain that insight. And if you realize, for over weeks in the US Eastern Coast, people were queuing up with plastic bags to get these, you know, these petrol. And there were downstream effects in terms of economical impact. There was chaos in that part of the world. And what it proves is that if we don't really identify and practice this manual disconnection practice quite often, you could literally be in a very bad case. In Colonial Pipeline, literally was a shutdown and paralysis of a community in a region. So that's why I think regulators have now released good guidance through CI45, at least in the critical infrastructure and operational technology environment. Gijo Varghese [00:27:32]: There is a focus now to essentially make sure that these core engineering networks do not rely on internet or on corporate network. And they understand that they could have a position to disconnect the virtual mission-critical systems from actual corporate networks, and they can then operate them for sustained period of time. And in CI45, they're talking about operating these kind of disconnected environments for a period of 3 months or greater. And what it helps is to test and make sure that you are still able to provide essential services to keep these physical operations on. So you still have some services, on essential services like water, electricity, and transport, even if there is kind of massive geopolitical issues or cyber tensions in the wild. The kill switch or the disconnection theory is the most important thing to know that you still have a plan to disconnect from technology and then live, you know, pragmatically, very practically without these things. KB [00:28:48]: So going into that then a bit more, would you say Australia has that capability in place now, to your point, that they've got disconnected environments? If something were to happen, there's a breach, there's an outage, something's happened, that they can still— and what the example was coming to my mind, I've spent a lot of time in regional Australia. When the power would go out, we'd have a generator. It would back up very quickly. There may have been a small gap, then there's a generator. Obviously in big metropolitan cities, you don't really need that. But I'm saying that that's what comes to mind as an analogy example for people to imagine, to be like, okay, we're running a water plant. Some, there's an issue, right? There may be a delay. There shouldn't have to be, but now we're going to revert back to more manual processes. KB [00:29:30]: So would you say Australia across the nation is in a position where that's a thing or is that in, in the works? It's going to become a thing. Gijo Varghese [00:29:39]: It's of course going to be a thing that they're trying to do. Like, I think a lot of these kind of technology, you know, issues have brought in quite clearly the fact that we need to start really understanding how these technologies are interconnected and connected to an instance. So there is a genuine awareness that at least for systems that are connected to essential services, there is a need for us to have backup plans. And Australia has started to get into that journey through this SOCI Act, which is this— that is the law that kind of identifies critical systems and, you know, mandates them to identify critical technology systems, plan to not only kind of detect them and register them, but also assess risks around cyberattacks and other technology failures. And then it also mandates some of those most systems of systems, they call them system of national significance, to even test those systems with incident response plans. And they also are mandating them to, you know, with some new regulations, they're mandating them to put some best-in-class, best-practiced security approach. So They're in the journey. And having said that, these are only gonna make a cyberattack harder to occur, but it's still open to have vulnerabilities and technology will always have vulnerabilities and that'll always be exploited. Gijo Varghese [00:31:22]: So cyberattacks will now not stop. It's about how do you run when there is a sustained cyberattack. And this, this is the mindset that Australian critical infrastructure are bought into in terms of how do we become cyber resilient. That's the journey that Australian critical infrastructure are going through. KB [00:31:43]: So then when we say cyber resilient, I'm assuming that to the outside world, it shouldn't be obvious that there's an issue, that power issue, a telco issue, a water issue, a supermarket issue. It should just be like, it's happening behind the scenes sort of thing. Like there's an issue, but like you can't tell. Because there's that plan, there's that resiliency plan. Is that, when do you think hypothetically we'll get there? Because we've already seen things recently about what's happening and we can talk about the flow-on effects of, you know, people getting injured, but then also just the issues it has for businesses, people, you know, taking 4 hours to get home in the Melbourne CBD in Australia. People can't talk to one another. Like there's so many, there's so many issues that start to spiral. Then you've got to deal with the people online that are losing their mind. KB [00:32:34]: Because Australia is relatively mature in their thinking. Do you think it'll get to a stage relatively soon? And yes, we can say the compliance and the SOCI Act and the government and all these sort of things, but there's still probably going to be a gap for these more regional players that are like, well, I don't know how to do that effectively. Because I've been hearing that in people that are talking to me in my network. So do you think Australia will get to that position, or do you think that that's their vision, whether that comes true or not, who knows? Gijo Varghese [00:33:00]: Yeah, look, as long as there is cyberattack, you would still see consequences of these attacks, Karissa. That's the fact. And cyberattacks will not stop soon. It's only going to increase. The sophistication is only going to increase. And what organizations, nations need to understand is that this is going to be there and how do we plan for such a risk while you use digital technologies, it's great to use them because they bring in efficiency, productivity, and speed to market. There is a need for understanding that if these technologies are not available on a long and sustained region, at least the critical services run. Services such as hospitals run, make sure that there's no safety incidences with trains, making sure that critical electricity services are running on critical sectors like hospitals. Gijo Varghese [00:34:04]: So there is a need for government to understand the interdependencies, which I think not just Australian government, but you can see a lot of the Western government in Europe kind of understanding and seeing this. You know, UK and US have always had a critical infrastructure Protection Program right from 2008. So like they probably pioneered the Critical Infrastructure Protection Program. But what Australia is leading is that they are able to bring, the regulators are able to bring in industry and have a very open conversation on the risk. And they're collaboratively working on how do you manage these kind of risks to make sure that the country is not kind of paralyzed. And you've seen that in the Jaguar Land Rover cyber incident, right? The incident was a very simple intrusion into the corporate IT network, and they found out that they couldn't just contain it. And soon it started impacting their production processes. There was never an impact on the OT systems, production just stopped because it was all about ransomware. Gijo Varghese [00:35:20]: So it started impacting their production lines. And soon over 5,000 supply chain companies, which were, you know, moms and dad businesses, started to have impacts because their businesses were fully and solely relied on the main Jaguar Land Rover company. And what happened to the government was the government had to kind of bail out these countries. And there was like a consequence of close to $2.5 billion for UK economy. So the data breach is probably something that you can still manage, but, you know, these kind of larger consequences on a critical infrastructure could have macroeconomic disasters that are triggered essentially because of digital connectivity. So when emergency services like trains come to a grinding halt, you know, like national manufacturing collapses, the primary concerns that we have is how do we move away from containing malware to how do we actually keep the nation moving? That's the conversation that Australia is having with its critical infrastructure sector. And that's the intent of the regulation. Again, you can take the regulation as it is and just do tick-in-the-box exercise just to comply to the regulation. Gijo Varghese [00:36:48]: But then you are not managing the risk, and that's when you get exposed to these incidences. So my simple answer is, if you use technology, you are always gonna see a technology failure or a cyber incident. And this is not gonna go away. It's about understanding the risk and the fact that if If these risks materializes, have plans to manage them better, that you're still not impacting the most important services of the nation, and you're still keeping the nation's economy on and not cause any massive physical consequences like human lives lost as a part of this process. So that's where the thinking Yes, at large. KB [00:37:36]: So going back to the kill switch, so as you mentioned before, my question to you, G. Joe, would be critical infrastructure leaders, just so they can foresee a problem happening. So they're like, okay, this is a risk. We're gonna have to, you know, leverage the kill switch. Obviously that impacts efficiency and all sorts of things. Do you think though, it may, there may be a case in the future where someone does it prematurely? And therefore, once it's premature, it's like, well, it was— we thought it was a risk and it was a risk, but it wasn't as bad as we thought. I'll give you an example. When you're on a flight and then you have the in-flight meal service happening and they're like, oh, we've hit some turbulence, we have to wrap up everything, everyone's going to sit down. KB [00:38:17]: And it was very minimal. And then everyone's annoyed because they have to restart the whole thing again. So my question then would be, are we going to see instances where it's premature, and then because it's premature, it's done a lot of other damage in terms of downstream impacts, other flow-on effects, those sort of things. Would you— do you think that that's going to be another issue that opens up as well, where it's like, we had every intention because if we didn't, we could foresee a massive issue, but perhaps it wasn't as bad as what it was? Gijo Varghese [00:38:48]: 100% yes, Kerissa. I think, to be frank, business Business and technology leaders today have the authority to make that decision. In a way, a lot of critical infrastructure practice disconnection of IT/OT networks as a part of their incident response playbooks. However, these incident response playbooks assume that these scenarios are just for, say, maybe at max 3 weeks. But what you're seeing as a part of technology enhancements through AI and digital warfare is that these incidents can be for sustained period of time. We were working in a critical infrastructure organization on the CI45 guidelines to plan the isolation points and then think of what is the actual impact to the business. The business started to realize how they were dependent on digital processes. And this is the journey that organizations are currently having now that they understand there is a massive dependency on digital infrastructure. Gijo Varghese [00:40:00]: And they now are looking at how do I change my business continuity plan to have more manual processes in case these technology failures happen? What you're seeing today is sudden, sporadic knee-jerk reactions that there is a cyberattack or there is a technology failure, and people are waking up to the fact that an essential service has just gone out because it was largely dependent on another service. So there is a need for government to come together, multiple critical infrastructure come together, understand in these and coexisting aspects of how they use technology and how they are dependent on each other, and then plan responses in a manner that it safeguards nation's economy. I think the fact that Australia has now got a national cyber coordinator kind of goes into that direction that we need to maybe manage that nationally. And this is happening throughout. You know, Australia has National Cybersecurity Coordinator. We also have UK NCSC building up a National Cybersecurity Coordination Centers. The same is with US, but you see that across in the Western world. And I think even in the developing environment economies, they are seeing the dependency of digital infrastructure in their environment and how they are potentially exposed due to these digital infrastructure and plan recovery resiliency. Gijo Varghese [00:41:42]: So the mindset that I'm coming to talk about here is that they're now starting to think of backup plans. They're starting to think of how do we isolate these entry points so that the kill switch is effective. And when they activate these kill switch, who takes that decision? So they're starting to think of Now, I don't want to be premature in making that decision. I want to make sure that these consequences or these have been detected. And therefore, then there is an immediate collaborative discussion between, say, regulators and the business leaders to make the right decision. And so, you know, there is proper communication protocols sent out. A good example for all of this is also COVID. Like, if you apply a national emergency situation like COVID, you know, social distancing was a big issue. Gijo Varghese [00:42:44]: And in a manner, every country got to understand the risk and they communicated about the risk and made sure that, you know, they identified that the way how business could operate now is working from home. And that work from home And never existed before COVID So it's about learning from incidences and managing through those incidences. KB [00:43:09]: And then, Gijo, final question for you. At what point does a cyber incident against critical infrastructure stop being a security event and become a public safety sort of failure? Like, when can it cause serious harm? And I know that we've sort of touched on it a little bit today, but it's just painting the picture of, example, a water plant, water being contaminated. That's an issue that could spiral very quickly. It's just to give a little bit more fidelity on that so people understand. Gijo Varghese [00:43:44]: Yeah, look, a cyber incident stops being just security even the very second a digital breach manifests into like a physical consequence. Say, for example, you know, I am in need of some money, a physical currency, and I don't have an ATM that is available to dispense that because the ATM is probably not available because it's got ransomware. It has physical consequences. It could be that, you know, in a developing world, they do not have the money to buy medicine, which could impact a person not getting the right medicine at the right time and has lost life. So any digital breach, be it cyberattack or a technology failure that manifests into a physical consequence, is a time when the cyber incident just stops being a security event and it becomes like a physical safety failure. The difference though is that there is like a cheese and chalk when you talk about IT incident to OT incident. In an enterprise where there's an IT incident, you're largely talking about a data breach or a financial loss. Ultimately, you know, it's about a system being off for a few hours. Gijo Varghese [00:45:07]: But in critical infrastructure, the moment there is an unauthorized line that closes, say, a valve of a a water treatment plant, or say changes a railway signal, or drops a power grid, or even halts manufacturing lines, like, you know, what happened with Jaguar Land Rover. It's moving off from, say, a physical intrusion from corporate network into, you know, like real economical impact to the country. It's about clearly differentiating what is a macroeconomic disaster from a simple digital connectivity to what is an emergency failure of, say, a train grinding to a halt, or say a manufacturing company just collapsing or partly collapsing some of the economy of a country. So for me personally, the reason why I'm very passionate about critical infrastructure protection, in a sense of protecting a cyber incident not happening in a critical infrastructure is that you're managing protection of livelihoods and human lives because there is always a physical consequence of a digital failure. And so that's what we need to primarily look at. You know, you can always have these other type of risks, which I feel you still can manage, but there's no cost to human lives that you can place. KB [00:46:42]: That was Gijo, everybody. A cyber incident stops being a security problem the moment it turns physical, the second a valve shuts or a train stops dead. So if you're on a board or you run a critical service, one question to go away with is, does anyone in your building still know how to run the place with the tech switched off, because there might come a day you need them. VO: I read every reply. If you've got some thoughts on this one, send me a message on LinkedIn. KBKast, Cyber For The C-suite.

Other Episodes