Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion centers around our water supplies. There are a lot of really wild things happening right now with attacks like Volt Typhoon and Salt Typhoon. Josh has an amazing ability to make these sort of discussions easy to understand without spreading FUD. Josh also has suggestions for actions that need to be taken to help deal with these problems. It’s not all technical solutions, there are non technical things we can do to help reduce the risk posed by our technical systems failing.

This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.

Episode Transcript

Josh Bressers (00:00) Today Open Source Security is talking to Josh Corman, cyber safety philosopher warrior. Josh is a legend in the US public sector for and I I’m actually really excited for you to be here, Josh, because I know in an enormous amount of this audience is

Not in the US as well as not plugged into public policy. So you have an amazing amount of knowledge and experience to share with us. So welcome to the show, man. I am very excited.

Josh Corman (00:19) Mm.

Thank you. I love the the episodes of yours I’ve heard and I think this is overdue. We should maybe do it on an interval.

Josh Bressers (00:31) Yeah.

Yeah, for sure. Absolutely. And for the pe the people listening, so when I talked to Casey Ellis like a month ago, he mentioned something called the five Ps. Josh is the person who made them up. So that is very exciting.

Josh Corman (00:42) I’m just observing patterns and philosophers like consonants and alliteration. So it was it was actually pr pretty important. When I and the cavalry launched, so what is it, almost thirteen years ago on August first, we said we had to lead with empathy, being a helping hand instead of a pointing finger. And as we started to engage these safety regulated industries where bits and bytes meet flesh and blood

They didn’t understand why good faith hackers would report issues to them. They thought it was extortion or they wanted money or fame. So I had to kind of come up with a really simple way.

Josh Bressers (01:12) Mm.

Josh Corman (01:17) to show that you know hacking isn’t a crime, it’s magic. There’s good wizards and bad wizards. Thank goodness we have Hermione and Gandalf and Harry Potter to fight the dark arts. But also amongst us we don’t all agree. We’re all motivated differently as a protector or puzzler, prestige, profit, or protest, slash patriotism. And boy did that melt their anxiety to see, my goodness, if you’re losing sleep because we don’t fix a medical device issue because you think people might die, we’re making your job really hard.

Josh Bressers (01:25) Right, right.

Yeah. Yeah.

Josh Corman (01:47) And we said, yes, yes, you are. so yeah, that was a pretty I think rhetorical accessible short lists, odd numbered lists, lists that either rhyme or have parallelism or consonants or alliteration. You know, we’d have a lot of knowledge in cybersecurity, but we are not incredibly effective communicators or storytellers, and that that is a very important part of being successful in the public policy arena.

Josh Bressers (02:14) Yeah, we we are terrible communicators. I mean, even amongst ourselves I think we’re terrible communicators. It’s I mean, it it’s a hard skill. I’m not gonna like fault fault us for being, you know, terrible or anything like that. But yes, I agree with you a hundred percent.

Josh Corman (02:18) Yeah.

Which are you by the way? Which which do you major in? Which do you minor in? For Protector Puzzler, Prestige Prophet? Yeah. Yeah, that’s me.

Josh Bressers (02:31) protector and puzzler for sure. Yeah. I mean that’s

always been my thing. It’s I mean it was funny. Josh and I before we hit record mention you know, Josh mentioned like profit was was not the motivation and an an enormous number of people have made quite a lot of money off many of Josh’s ideas. So thank you, sir, for the hard work.

Josh Corman (02:49) I call myself an idiot altruist. but yes. Yeah, yeah.

Josh Bressers (02:55) Yeah. Well, I mean you have a Captain America shield behind you which kind of fits

that yeah, it it fits. Right.

Josh Corman (03:02) This was my view at CISA so when I was meeting govies who didn’t want to work with a whippersnapper from the private sector, like it became an icebreaker on, you know, can’t wait to combine my powers with your powers, like, you know, what gets you out of bed in the morning, stuff like that.

Josh Bressers (03:16) Right, right. Yeah,

I mean, look, the government’s a great example of that, right? Like virtually everyone working in public sector they could make a ton more money if they went into the private sector, but for whatever reason they choose to stay and and you know, do their thing. It’s probably I assume patriotism is the P driving a lot of that, but yeah, yeah.

All right, man. it was good. It was fun. we talked a lot about just vulnerability disclosure, which was this was right after Glasswing kind of happened, which is I know that’s, I mean, I know you have some thoughts on that. So maybe let’s let’s dive into Glasswing, man. I I think that this is a perfect spot to just do that, because I know you were mentioning some things you will say, complaints you have about it, which I completely agree with.

Josh Corman (03:35) So I’ll have to I’ll have to list in a Casey’s episode.

Oof.

Look, I’m a I’m a lover and a fighter or a little bit of a fighter, but I fight for righteous things and I try to fight with you know, inspire people to to fight. Sure that might stick with some people and might get mocked by others. But I mean we’re kinda jumping towards some of the end here, but

Josh Bressers (04:03) Nice. I mean you’re a philosopher warrior, Josh. Like

Josh Corman (04:20) Look, I’ve I’ve been working on where bits and bytes meet flesh and blood formally since we launched the cavalry’s. It it was usually on top of my day jobs, but at times I’ve had to like pause my private sector career to either go run cyber statecraft at the Atlantic Council nonprofit or do a congressional task force on health care, or during the pandemic I went into CISA for eighteen months to the day to run Operation Warp Speed Security and keep hospitals and water afloat. so

I I am very much focused on where bits and bytes meet flesh and blood. And right now it’s my f you know, my full existence in a nonprofit initiative funded by Craig Newmark called Undestruptible 27. It’s around Volt Typhoon is a Chinese military operation in US water power transportation comms to keep us out of their fight with Taiwan.

And it’s very high consequence, very high stakes. No water is no hospital in two to four hours. So, you know, here I am focused on an incredibly hard thing that the government probably should be doing instead of civil society. It’s going pretty well. Our theory of change is getting traction. We could talk about that. I hope to talk about that. But while my eye is on the prize for like a twenty twenty-seven, twenty eight, twenty-nine conflict over Taiwan with China.

Josh Bressers (05:12) Yeah, yeah.

Josh Corman (05:36) You know, we now have Iran, more active on US water, given the the war and the conflict. And then Mythos. I know Mythos is just a flashpoint. It’s yes, exquisite marketing and a real substantive public recognition that we’ve crossed some thresholds in app sec and product security, in asymmetry between the ease of offense versus the ease of defense.

And when I saw Glasswing about to be announced and ultimately announced, my first instinct was a little different than the most of the takes you’ve heard. it was, for the love of God, please tell me you have major OTICS players in there.

So OT is unlike IT or information technology, OT is operational technology. It’s the things that go boom or explode or move physics, not information. So programmable logic controllers, industrial equipment, robots on a manufacturing assembly line, HVAC, you know, there is no IT without functioning OT.

Josh Bressers (06:38) Yeah, yeah.

Josh Corman (06:39) But like the big names that you would see in Glasswing, some of them kind of made sense if we were only in an IT exposure. But many of those same vulnerabilities that Mythos and its peers, plus or minus a few generations with harnesses, can now find and weaponize are also going to affect cyber physical damage in lifeline functions like water, like power, like food supply manufacturing.

So, you know, one of the tenets of I am the Calvary is malicious intent is not a prerequisite to harm. So even if the people leveraging these tools aren’t attempting to hit a US water plant, they may hit that. And no water is no hospital in two to four hours. So I was quietly saying, are there any OTICS? The answer was no. I said, I will voluntarily provide you a list.

of the most important starting points or watering holes to get amplification. And that was slow. And then you saw you know other manifestations of this where was it OpenAI had their version and they’re like, you think mythos is dangerous? Hold my beer. We’re gonna give this to everybody with the email address. and if the whole point was to give a preview for defenders

Josh Bressers (07:54) Yeah, right, right.

Josh Corman (08:01) And a head start for 100 days. That theoretically undermines that. But even though OT people I saw trying to get in there were pretty much on hold in a waiting room. If you don’t already know tip of spear models and how to use them, it was there was a really big divide. Like the the help you were getting from the Frontier Labs were for people that they were already very tightly working with. So it’s not malicious, but by omission, I’m like, okay.

What about cyber physical things that underpin society? What about public safety, human life? And even on IT OT column split, where there was nobody in OT, they were the haves, not the have nots. They were the top cream of the crop. Like the the the supply chain down market for either is either unsupported end of life out of business or difficult to patch, or the smaller IT and OT teams. So the presence of a patch available.

Josh Bressers (08:43) Yeah, right, right.

Josh Corman (08:58) is part of the completion, but until that patch is applied everywhere through the operational environment, no one’s safe. So if you’re in a foot race between discovering the latent flaw, weaponizing the ba latent flaw, creating a vaccine for the latent flaw in the form of a patch, and deploying said patch to affected areas, Glasswing was only aimed at the head start to d to create a patch.

And down market, especially in OT, you might only have one change management window a year.

Josh Bressers (09:30) Right. Yes. Well and and look, this is something that I know in IT we struggle with because obviously we we have patches for our computers, we update our computers, generally things are fine. Even if we screw it up, we have what? Maybe an hour of downtime and then we fix it and whatever, we write a report. Versus when you have a water system or a power plant or a hospital, an hour of downtime could be like literally people dying, right? And and that’s hard to wrap my head around sometimes.

Josh Corman (09:53) Mm.

Yeah.

I mean, there’s different scenarios we could double click on, but you know, when when we started Cybermed Summit dot org, that’s a five one C three, we we found two hackers that grew up going to DEF CON, went to med school, and became, you know, physicians. And they said, Hey, a lot of the stuff you talk about with the cavalry, you know, hacking a pacemaker for ninety-something percent of people would just make tired. It’s not a big deal. I’m like, should I stop working on this? And they said

No, you could absolutely kill people, just not the way you’re talking. So we started to lean in and we went you know, we went to doctors just like f pilots do flight simulators, doctors do these things called ER simulations. On a regular interval, they just come in, you know, what do you do when there’s a pregnant woman who needs a fibulator? There’s two heartbeats.

So it’s known but rarer. So you’ll come into a sim, a simulation, and you’ll test your drills with an actor and surgical dummies. And it’s very real and very palpable. but it makes sure that, you know, most of the time, they say most of the time it’s a horse, but sometimes it’s a zebra. So that those edge cases when you should be kicking in some critical thinking on is this a horse or a zebra? So we started doing those, and part of that.

Josh Bressers (11:04) It’s

Josh Corman (11:11) was we had some extra time where like, let’s just do a ransomware simulation. In round one, we’ll take out the hospitals building automation. In round two, we’ll do the same thing for all the hospitals in Phoenix, Arizona. And in round three, we’ll do an a Arizona Diamondbacks bombing, like a Boston Marathon bombing. So you have elevated need with diminished capacity. And we knew at some point they’d probably flip to something called crisis standards of care. Where instead of fixing if you and I both walk into the ER at the same time

And you’ve got a scratch on your face and I got a major arterial bleeder in my leg, they’re gonna go for me. Whereas in a crisis standard care, they’re gonna say, Josh is gonna die. it’s it’s moral to fix those that can be treated. So you’ll get a color coded badge or tarp that you’re put on. And so we knew they’d flip to that. But what we didn’t think of, our biggest surprise in our very first Cybermed summit was it was 117 degrees out.

Josh Bressers (11:45) Yeah, right, right.

Josh Corman (12:07) And by shutting off the building automation with a hard-coded or excuse me, a default maintenance password, HVAC went down. And since HVAC went down in an all-glass building in 117 degrees heat, we had 45 minutes to evacuate the building, including people in comas, recently had surgery. It’s an oven. It’s inhospitable for humans. So, you know, there’s other stats we we often throw around that are real, like

Josh Bressers (12:20) Wow.

Right, right. Wow.

Josh Corman (12:33) You know, 4.4 minute delay for hearts can affect mortality rates for heart conditions. one, three or four hours enough to be a life or death fork for stroke or brain. there’s the golden hour for other s other maladies that are time sensitive. So delayed and degraded care ha does and has led to loss of life and worsened outcomes. So when you add cyber to these things, we’re now creating more exposure to accidents.

and adversaries that can affect those outcomes.

Josh Bressers (13:05) This is mind boggling and this is like I so it it’s also for anyone listening. there is an article I will put in the show notes on Wired that literally just came out a little while ago about the water system in the US that that Josh has quoted in. I’ve not read it yet, and I told him like I haven’t read this yet because when I saw the headline, I know it’s gonna be in it, and I don’t I I don’t want to read it. Like I know what this is going to say. And like your hospital story is like the same thing. It’s like, my goodness, this is so much worse than I expected. But it’s it’s just like

Josh Corman (13:13) Hm.

Josh Bressers (13:34) It’s mind boggling to me, like, okay, so actually here’s a question for you. And this goes both ways, right? It w you tell these stories, I read these articles, and it feels like I need to go live in a cave because everything is terrible. But at the same time, like society is functioning. Like I can currently go to a hospital, I pay my bills online, like I have water coming out of my tap. And I think this is one of the challenges as well, is a lot of people will say, You’re just making this crap up, you’re crying wolf, you’re trying to scare me, right? ‘Cause it

Josh Corman (13:44) Mm.

Josh Bressers (14:02) Like there’s a dichotomy here that I I definitely have to struggle with.

Josh Corman (14:03) Yeah.

So, I mean this is l let’s get philosophical, okay? I’ve had a lot of projects over my career, some of which, you know, cause you and I to meet in the app sec and product security world and SBOM and the the through line even before Cavalry was

Josh Bressers (14:15) Yep, yep.

Josh Corman (14:23) I believe and have believed and it’s getting worse, so it’s been always true, but the degree matters, that you know, as humans, as a species, we tend to adopt technologies for their immediate and obvious benefit. But we’re really bad at the cot the delayed, less obvious cost of those benefits.

Josh Bressers (14:36) Yes.

Josh Corman (14:42) So we tend to race to embrace something and only later find out, asbestos is bad, or levitamide causes birth defects, or you know, this thing, maybe you shouldn’t make deep-sea submersibles out of, you know, carbon fiber. so

We on the whole, most of these tech adoptions work out pretty well. But some of them have less obvious costs. Just look at social media and its effect on our youth or mobile phones or epidemics of loneliness and and whatnot. So zooming out, as I started I am the Calvary, which became more about public safety, human life, just not just impacts on society. The idea was that our dependence on connected technology

Was growing faster than our ability to secure it. We were struggling to protect credit cards and websites. What made us think the same vulnerable software was appropriate for connected medical devices, cars, high-speed rail, factories, oil and gas pipelines. And the cybersecurity, the nascent cybersecurity industry, at least from the outside, projected that we had things mostly under control.

But the truth is we’ve been prone, we’ve been prey, we just lacked predators with the right appetites. And most of our failure modes were within tolerable limits for the confidentiality of information. And I was worried that those same weaknesses could allow failure.

modes for the unavailability of time-sensitive medical care or for cyber physical damage of pipelines or for a crisis of competence in the public to trust connected self-autonomous vehicles. So it’s not that we couldn’t be hacked, it’s that we lacked had hackers that wanted cyber physical damage. So we would increasingly, as that dependence rose, then we would say, okay, through our overdependence on undependable things, we’ve ex created the conditions.

Exposes to accidents and adversaries. So accidents meant things like the CrowdStrike glitch. It wasn’t even a hack. But that glitch took out lots of air travel, lots of medical care across the country. Some quantified in a peer-reviewed study on its one-year anniversary last summer, also in wired. the

You know, when you’re overdependent on a undependable thing, you’re taking a gamble and we continue to push more and more and more and more dependence, but we haven’t made the digital infrastructure proportionally dependable. I mean, you and I are both very much embroiled in the SBOM plus plus community, but one of my lines made it into Biden’s lips in Executive Order 14028. If you read the opening, it says something at the end of in the end, the trust we place in our digital infrastructure should be proportional.

to how trustworthy and transparent that infrastructure is, and to the consequences we will incur if that trust is misplaced. And there’s a lot baked into that, because I’m a disciple of the you know, the amazing Dan Geer so I it there’s a lot to unpack in there. But that is the the rub here is that

Software is not nearly as dependable as steel and concrete, but we’re increasingly depending upon it in more and more places and in more dangerous places. And unless and until we right-size dependence to dependability, we’re seeing a growth here. I think the real Rubicon we’ve crossed is most of our predators wanted money or information. And they were stealthy and they were quiet.

We are now in an era of disruption and destruction. And these articles, if you read the wired one, we haven’t really described it, but Volt Typhoon is a People’s Liberation Army set of units that has deliberately compromised US infrastructure laying in wait for a time and place they’re choosing because they want to keep us out of the fight with Taiwan. It’s to do two things. It’s to delay and degrade mobile.

Forced mobilization, which is the movement of troops and equipment to the war theater, even a day or two. And the second reason is they want to sow chaos on civilian infrastructure or or undermine public support for our intervention overseas. And that latter one is outrageous in the intentions of international law and our laws of armed conflict. But it’s in this really interesting gray space where we don’t know how to do something until they actually detonate. So they’re sitting there like a digital bomb.

But they’re also not done any harm yet. And people can’t, their imagination fails them to say, how did this happen? And they’re often getting in through KEVs or known exploited vulnerabilities in security products or edge edge products. And it’s, you know, shame on us as a cyber industry to allow people to believe that we mostly had cyber tamed. And shame on us for, you know, the the cobbler’s kids have no shoes that the things we buy to keep

Josh Bressers (19:28) Yeah. I know, right?

Josh Corman (19:43) Bad guys out of our homes or the things letting them into our homes. And while, you know, maybe you don’t think the Chinese military would pull the trigger, they’re certainly on public record and unclassified hearings and information in U.S. water facilities, for example. And I’m not comfortable living under sword of damocles that like where they can hold us hostage because we’ve allowed ourselves to be so prone.

So a lot of the the project work is what’s realistic in the time frame we have to buy down risk and how do we do ruthless prioritization. But it should be unarguable that we are overdependent on undependable technology, which exposes us to accidents and adversaries. But this patch, unlike the others, whether it’s China, Iran, you know, Russia, if they pick a fight with us, they have the means, motive, and opportunity. The question is, do they have the will to use it? And

As we get into a Mythos era, Mythos plus plus, you’re now democratizing a whole lot more players or as powerful as maybe nation states to disrupt and destroy, even if that’s not their intention.

Josh Bressers (20:51) Okay, so I have maybe a a vaguely related question. Is you just mentioned a whole bunch of the the cyber just kind of adversaries, you know, specifically on water. But like there are a multitude of examples. This is across the board of like Western countries attacking, you know, eastern countries, of of every country attacking almost everyone else, it feels like, using some sort of cyber attacks.

Josh Corman (21:00) Yeah. Yeah.

Josh Bressers (21:16) And yet there there doesn’t seem to be any sort of response most of the time. It feels like we’re just like, well, well, I guess China attacked us again. And it’s like, what? I mean, and and we do the same thing, right? Where we we the the Iran centrifuges are another one where it was almost certainly a Western country that did that. And it’s like, well, I guess that happened. Like it it feels it feels so weird to me that all of these things keep happening and we’re like, okay.

Josh Corman (21:40) Yeah.

I mean, we could have a multi hour podcast on just that. I can tell you how it happened, what order it happened in, what the seminal moments were. but we have a Geneva Convention for physical things and international norms and treaties. We don’t ha w there was a deliberate pushback on introducing a Geneva Convention for cyber.

Josh Bressers (21:49) Ha ha.

Josh Corman (22:09) I’m gonna give you the very fast version here. And a lot of the US Five Eyes Allies countries in NATO didn’t want to maybe limit our possibility space and be hoisted by our own petard. So so people deliberately dragged their feet on introducing a Geneva Convention for cyber. There was actually a one of Andy Greenberg’s stories on not Petya is most of the people that matter for the international UN NATO cyber

braintrust were all together in Tel Aviv for Cyber Week in person when not Petya hit. I was actually delivering a twelve minute keynote on stage and at minute eight not Petya hit and everyone’s phones and pagers lit up. And so we had a big fight the next day at the Munich Security Conference Roadshow and the Russians were there in the room as part of the fight. And I was one of the only ones that had the

the boldness to say, I know you don’t want a Geneva Convention for cyber, but for the love of God, can we please have a no fly zone for hospitals? That any cyber munitions used intentionally or otherwise that affect hospitals should be a war tri a war crime. And so th those things made it into the book and the Wired article, but

You know, for a while we didn’t want to do this. McCrystal in the during the Obama era said any attacks on designated critical infrastructure, even if they start in cyber, our response can it can be made outside of cyber, so that was floated as a concept, but not enforced later when tested. And you know, cyber is a weird place to use munitions. When you drop a bomb, you know the rough yield and the rough blast radius.

But you know, not Petya for example, was a nation state, Russia, against a military target of in Ukraine. It was designed to stay isolated to Ukraine, but it escaped its intended blast radius and did a billion dollars of damage to Mersk in the US.

and elsewhere. The Mer the Mersk impact was a total of ten billion estimated the first day between the various victims. So cyber munitions and cyber physics are a weird beast. And as such I think it’s a very dangerous weapon to use and shouldn’t be, or we should have the right incentives.

to do so. And that like I said, it could be an entire episode on how we got there. Some of those very same people that push back on baby steps towards norms are now in this Volt and Salt Typhoon era wishing they had they’re they’re expressing regrets publicly. but the bottom line is, you know, we we

for the time being are overdependent on this undependable stuff. It exposes us. The next conflict will be a hybrid conflict. Just like, you know, if you can use drones, you will use drones. There is some use of cyber in Ukraine. There’s some use elsewhere. we have not yet crossed that threshold. I hinted in the article and on this chat, or at least our pre-chat, the typhoons pre-positioning nonsense language,

Josh Bressers (24:59) Yeah, yeah.

Josh Corman (25:17) The fact that there hasn’t been damage yet or payload, they’ve done everything but that. Like if if you if you and I, you know, we have families, we have homes. If someone broke into our house and didn’t steal anything yet, it’s still breaking and entering. And if someone like, you know, sets up the ability to destroy and sabotage your water plant or your, you know, your boiler,

Josh Bressers (25:28) Right.

Josh Corman (25:39) It’s still, you know, sabotage attempt whether they succeeded or not. And yet our policy thresholds are really we balk and we hesitate that it hasn’t crossed that f that unacceptable threshold. But just even a public sixty minutes piece on Littleton, Massachusetts, a town with about ten thousand people, no military, no manufacturing. They’re just small town America, which is the point of volt typhoon.

But they found it and they temporarily evicted it, but it hadn’t done damage. So even the news cycle has a hard time covering things that haven’t, quote, done damage yet. So what you’ll find if you read that article is the entire insurance industry wanted to be tested on something like Volt Typhoon at a national scale. So we ran a simulation, invited Andy to watch Chatham House, Andy Greenberg. And that’s what the story is: is how that played out.

Josh Bressers (26:18) Yeah, yeah.

Josh Corman (26:38) And hint it’s pretty bad. I I

Josh Bressers (26:41) I I know what

I know what I’m gonna I’m gonna read it after this, but man. Okay. All right, Josh. So let’s do this, right? We’re kinda coming to the end here, and I think you just scared at least me half to death with with all of this. And it it does sound dire, but i give us hope, right? Make me make me able to go back to work and not like just curl up in a ball under my desk for the rest of the day.

Josh Corman (26:48) Yeah.

So one of the threads we pull in undisruptible27.org, or you can even just go to u27.org and get there. Yeah. I made it easier because no one could spell undisruptible. so u27.org will get you there. But we likened it early in the first year. We’re in we’re we we just we’re wrapping up basically the second year of funding from Craig Newmark. Craigslist it

Josh Bressers (27:14) I will put a link in the show notes.

Josh Corman (27:32) The idea was when a hurricane’s gonna make landfall, you don’t say, well, let’s not tell anybody, because they can’t stop it anyhow, right? So when it comes to a natural disaster, then what you you do is you tell them what you know, you tell them what you don’t know, you inform, influence, inspire. You have to level the people. You never wanna exaggerate it, and you never wanna downplay it and coddle them. You have treat them like adults.

Josh Bressers (27:40) Yeah, yeah.

Josh Corman (27:56) So one thread here is this is a lot more like unnatural disasters concurrently in a man-made capacity that exceeds our response c capabilities. So that’s one thread. The other is you have to meet people where they are, use their love language. So we’ve been saying when everything’s critical, nothing is, and we’ve really prioritized the things that if they’re shut off for 24 to 48 hours, people die, or there’s societal psychological impact.

So we looked at the nexus of water and hospitals. And there’s 151,000 water facilities in the US, but only four hundred and twenty of them are in the ISAC. So there’s really no public-private partnership yet. There’s no you have more regulation for your PCI, DSS, credit card than you do for water.

And instead of saying let’s just become overwhelmed, there’s only six thousand of those water facilities that support a hospital. So we’re really surgically focused on we’re gonna innovate narrowly with twelve US hospitals, replicate why these are the other six thousand.

And take the recipes and blueprints we made and give them to everyone else so they can do the same for their top priority. And it sounds overwhelming, but where the threat comes from cyber, what we’re heartened by is that our approach is the solutions come from engineering. And I don’t mean software engineering, I mean physical engineering. We’re stealing lightweight practical pieces from Idaho National Labs, Cyber Informed Engineering. And what we’re saying is if you can cause a a water hammer to burst a water main on Main Street.

What’s the mitigation against that? Well, there’s physical mitigations, and we found that for under $10,000 in a hospital town, we can implement engineering mitigations that the engineers in town know how to do. They’re familiar, effective, and affordable. And it won’t stop you from getting hacked, but it will stop the highest consequence failures. And I think the solution for our space is we need to get a reckoning and a soul searching on how do we better articulate.

credibly and honestly, how the the risks of overdependence and undependable technologies. How do we fit stop overstating our defensive capabilities and mitigations? In the areas where we are over dependent, we should look first to engineering resilience mitigations and then start to crawl walk run on more effective

and reasonable cyber steps. So I wanna stop the bleeding with engineering and then pivot to a more informed and right size risk decision on dependence and dependability.

Josh Bressers (30:30) This is a really interesting way to look at this that I don’t think I’ve ever even really thought about. Cause I mean, as a as a IT security type, every solution is an IT problem, right? Like everything. I’m gonna fix it with all the security problems we’re gonna fix with technology, right? But you’re talking about like in Meat Space using meat space solutions to technology problems, which is not

Josh Corman (30:38) Mm.

Yeah.

Josh Bressers (30:57) It’s something my brain knows what to do with even at this point.

Josh Corman (31:02) Well, it you know, I I gotta come up with a better analogy, but like you you’ve heard the old expression when you’re holding a hammer, everything looks like a nail. So we try to treat every cyber threat with a cyber fix. And sometimes the more rational choice is if every time I touch this wire I get shocked, stop touching the wire, right? it could be you know, it’s some of these 151,000 water facilities, there’s really fifty five thousand or three hundred and sixty five days a year, they’re called community water.

Josh Bressers (31:11) Yes, correct.

Josh Corman (31:32) Facilities.

Out of these, some of them aren’t yet connected, and maybe they should stay that way. Some of them recently connected, but they have no budget or time or expertise for cyber, so they may want to practice downtime manual operations. Some of them are so overdependent on AI and services and cloud enabled automation, they couldn’t go back to manual if their lives depend on it, and their lives literally might. So we’re trying to at least be honest with them to say, we have a new predator, we have

Josh Bressers (31:37) Yeah, seriously.

Josh Corman (32:03) Have new hazards. We have more than one new predator, but we have new predators. We have new hazards. Here’s your cost benefit. You are in the best position to decide if you should reduce dependence, add engineering, add cyber, maybe a little both. But we can’t coddle people, lie to people, sell them snake oil. We we will still try to, but we’re in a place now where the consequences aren’t just like, you know.

Josh Bressers (32:26) yeah, yeah.

Josh Corman (32:31) vendor FUD and vendor snake oil can continue to dominate. We actually have to look at at least in safety regulated industries, life safety, cyber physical systems, we need a better version of cyber advice that starts with resilience, safety in engineering, and then weaves in

more candid, more honest, more effective advice than we have given to date. We might have gotten away with it pre-Mythos era, but playtime’s over. we’re gonna have to make some adjustments and I hope that we make intelligent ones soon enough.

and at least for inspiration, Undestruptable twenty seven might show the way. We we also testified to the house recently, so I have a couple of links or videos I can give you there. But you know, their first instinct was how do we get cyber talent in the water and I said, Please don’t, not yet. Like, first things first.

Josh Bressers (33:28) Yeah.

Yeah, I I watched your testimony. It was it was phenomenal. I mean and you you always do a good job and and I feel like you have that that talent to speak to lawmakers using language they obviously understand ‘cause that that’s a hard skill. Like you think talking to normal people’s hard. Like talk to a lawmaker sometime.

Josh Corman (33:32) thank you. Yeah.

And look, government is frustrating, government is slow, government is currently broken. I wish CISA was better funded. I wish different decisions were made. You know, Europe has its own strengths and weaknesses too. But like I’m really impressed with them that in a pretty nonpartisan way, they asked really good questions. The original purpose was how do we get more cyber into long term research and development grants and labs, but they pivoted very quickly to say, wow, this could hurt people now. And

Josh Bressers (34:12) Yeah, yeah.

Josh Corman (34:14) It was pretty impressive. you know, we we tend to think of the Congress people say the internet is a series of tubes and we make fun of them. But now we’ve connected the internet to a series of actual water tubes and they’re actually bursting, if our adversaries choose to do so. So I I think we’re living in interesting times for the protectors and puzzlers listening, there is

a really an incredible opportunity here to test yourself, redo critical thinking, take your boredom and apply it to something that might protect your household, your town, your state, or even your country.

We will figure this out. It’s just how much blood and treasure is lost until we do. And I’m a I’m a warrior. I’m fighting for I’m not giving up. I’m not hiding in a hole. I think what we did is we experimented on what can work, and now that we’re seeing it work, we’re gonna ramp up our public education of yes, it’s scary, but you are not powerless. Here are some things you can do.

Josh Bressers (34:54) Yes. Yes.

Nice. And I th I think that’s a huge deal. ‘Cause I think it’s easy to just say there’s nothing we can do. well, let’s give up. And that sucks.

Josh Corman (35:16) Yeah. Well,

at a minimum you and your household can make sure that you have three weeks of water on hand, whether it’s water filtration like life straws or purification, so that maybe you reduce the drain on your town as they do their natural response. It may take longer than people think. But there’s other things you can do, like we’re gonna start equipping at besides Las Vegas we have a two and a half day track in the cavalry room.

where we’re gonna give people shovel ready action. Well, here’s five questions you can ask Town Hall. here’s resources and blueprints you can share. We had to be quiet while we were building them, but now we’re gonna start ramping them up. And as far as the OT

Josh Bressers (35:46) Nice.

Okay, and this is coming out at B

Sides Las Vegas, which is in what, like about a month from when we’re speaking at the moment?

Josh Corman (36:01) Yeah, it’s the first week

of August, so about a month from now, yeah. Depends on when you post this.

Josh Bressers (36:04) Okay, so we’ll

keep it this’ll be pretty actually be pretty close to that. So anyone listening, I’ll I’ll update the show notes with whatever the link is after the fact because Yeah, that’s true. Nice, that’s really cool. Holy cow, I can’t wait to see that. That’s gonna be awesome, man.

Josh Corman (36:13) Sure. And we live stream, so you can get it for free. Yeah. Yeah.

Yeah, there’s lots to talk about and lots to do, but I hope Cyber stops having stop we I hope we stop having the old tired arguments and trying to hold on to the past. we have higher consequences now. We have more more indifferent predators now, and thanks to AI tools, we have more people able to to fight in that weight class. So we’re gonna have to make adjustments. I hope they’re informed, rational, safety.

biased adjustments and I hope you can use your platform to help cause those conversations and spread the word.

Josh Bressers (37:00) Amazing. I’m I’m calling it. Like that’s it. I think that’s the best ending we could possibly have, Josh. Thank you so much, man. I’ve learned an amazing amount. I can’t wait for you to come back and hopefully give us good news next time.

Josh Corman (37:11) Tell me how you

like the Wired article. It was a risky adventure, so all right, bye.

Josh Bressers (37:15) Amazing. All right.

All right. Thanks, Josh.