The 30-Year Device and the Missing Audit Log

▶ Watch (0:43)

Over half of OT equipment in operation today cannot produce usable audit logs. Legacy devices run for 30 years or more. Some RTUs were still running Windows 2012 as of 2021. The person who installed a device may have retired or died. Replacing equipment is not an option: no capital budget exists and there is no maintenance window long enough. SOC teams must work with incomplete visibility into devices they cannot touch or replace.

OT SOC Ownership Is a Top-1% Privilege

▶ Watch (5:24)

The panelists asked the DEF CON audience to raise their hand if they operate an OT SOC. A few hands went up. For an electric cooperative serving 50,000 customers, hiring a senior SOC analyst is unaffordable. MSSPs fill the gap for some organizations. Running any SOC at all costs real money. Joe Marshall put it plainly: if you already have one, you are operating in the top 1% of security operations globally.

When the Analyst Knew, and When the Manager Said No

▶ Watch (9:06)

Five years ago, a SOC team monitored a client with both IT and OT environments. When an alert fired, the analyst investigated the IT SIEM, escalated, and closed the ticket without checking the OT SIEM tool. He didn’t know how to use it. A later analyst did know, but his manager told him not to bother. The reason: if something got escalated, the manager had no idea what to do with it.

Physical Proximity as Incident Response Infrastructure

▶ Watch (14:43)

Ukraine’s power grid defenders embedded cyber security teams directly inside bulk power dispatch centers. Analysts sit next to the engineers they need to consult. A 30-second walk replaces a multi-step escalation chain. Joe Marshall, who has spent 13 years working in power grid security globally and through the current war, argues this physical integration model should become standard. Ukraine figured out how to ask the right person immediately, in person, when something looks wrong.

Asset Inventory Before the First Tabletop

▶ Watch (17:07)

No OT environment is a single-vendor installation. Even the best asset management tools capture only a fraction of what is on the network. Boots on the ground fill the gaps. With a real inventory, teams can run tabletops that map critical processes and rehearse failover decisions before an incident forces them. Colonial Pipeline is the reference case: no one had a rehearsed answer to whether OT operations could continue after an IT network shutdown.

Reframing the Budget Ask as a Risk Decision

▶ Watch (19:07)

Cybersecurity is a cost center. CFOs don’t like it. Adam Robbie’s approach: never open with a budget number. Present the specific threat, lay out the consequence if nothing is done, then ask leadership whether they want to accept that risk. CFOs who resist security spending typically refuse the risk. That refusal becomes the budget approval. The ask changes from a cost line into a decision already made by the people who own the outcome.

Notable Quotes

If everything’s critical, nothing’s critical. Joe Marshall · ▶ 11:03

Welcome to security. I know. Joe Marshall · ▶ 4:43

make friends in OT donuts. Joe Marshall · ▶ 18:53

Key Takeaways

  • Over half of OT devices lack audit logs; 30-year lifespans mean the gap won’t close fast.
  • Having any OT SOC at all puts an organization in the top 1% of security operations globally.
  • Embedding SOC analysts inside operational dispatch centers reduces alert resolution time to seconds.
  • OT tabletops require a real asset inventory first; tool coverage alone is insufficient.
  • Present threats as risk decisions, not budget requests, to get CFO buy-in.

About the Speaker(s)

Adam Robbie is Head of OT Security Research at Palo Alto Networks, a role he has held since 2022. He brings over 10 years of experience across OT and IT industries and has published with SANS and IEEE. He holds GICSP and GRID certifications and a Master of Science in Electrical Engineering. As an Adjunct Professor, he has taught cybersecurity at George Washington University, University of Michigan, and University of Wisconsin. Previously at Deloitte, he focused on ICS/IoT penetration testing, threat hunting, risk assessment, and vulnerability research.