Bottom line: The exercise demonstrated the importance of integrating human and machine intelligence to enhance OT cybersecurity.
What's happening: The exercise involved 120 OT professionals from 30 countries, including representatives from 15 major industrial control system (ICS) vendors, such as Siemens, GE, and Rockwell Automation, and was conducted in collaboration with the National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA). The exercise took place on October 15-16, 2022, and involved 23 CVEs, including those related to the Log4j vulnerability.
What to do: Security leaders should prioritize the development of a threat intelligence program, leveraging human and machine intelligence to inform OT cybersecurity decisions, and establish a standardized framework for sharing and analyzing ICS-related threat information.