B|Sides Edmonton 2023
De-mystifying Zero Trust in Industrial Control System Environments
Stephen Mathezer
September 25, 2023 at 7:50:00 p.m.
(PIC 120/122)
Next to AI, "Zero Trust" and OT/ICS Security continue to be among the hottest topics in cybersecurity. It seems like everyday there is a new offering or recommendation around "Zero Trust" for OT. But what exactly is "Zero Trust" in OT and how do we apply modern "Zero Trust" principles in an environment that is often change averse and many years behind the cybersecurity curve? Let's define "Zero Trust" and talk about what it *really* means in an OT context, what is already in place to support it, and how we can practically and meaningfully improve security in these environments. There is no magic bullet, but it isn't an all or nothing proposition either, I will discuss ways that we can both leverage existing architecture and technology and set ourselves up for future success.