Iñaki Eguia

Hewlett Packard Enterprise (Spain)

Compliance vs. Risk Analysis for the Development of Novel Reference Security Architectures Beyond the Purdue Model in Industry

In industry, various regulations and standards (NCA-OTCC, 62443, ISA-TR84-00-09-Part-1, NISTIR) establish a series of controls. Risk analysis methodologies and compliance approaches are based on these controls but pursue different objectives: the former addresses cybersecurity from its core—system vulnerabilities—although the approach may not always be as structured. Compliance, on the other hand, relies primarily on checklists or control-based frameworks to identify gaps in a system. Compliance methods are generally more formal and provide greater certainty to the industry, as they align better with the overall risk framework managed by the organization (very aligned with safety). For this reason, compliance is more widely adopted. However, risk analysis delves deeper into actual vulnerabilities, allowing for the formulation of new requirements. This leads to the redesign of cybersecurity with more practical approaches, resulting in the development of novel architectures going eve beyond reference model like Purdue Model in case of OT. Several examples from the chemical industry, which operates dozens of sites/plants worldwide, will be presented. Risk: Remote multi-account access by OT vendors providing cloud services to L2 for managing DCS systems (Honeywell or Yokogawa). Novel Architecture: Implementation of OT Landing Zones to enable secure external management by vendors. Risk: Control system alert mechanisms in plants do not encrypt or classify the information sent via email to the corporate network, potentially allowing legitimate messages to be compromised if the source is breached. Novel Process/Architecture: Creation of a standardized process across multiple plants that enables encryption in legacy systems, based on the identification of common risks among subsidiaries.

Comprar Tickets

Iñaki Eguia is an expert in products and OT/IoT cyber-security for large industries and Critical Infrastructures. With more that 20 years of experience, he was one of the first director of a private dedicated industrial SOC/CERT in Spain and one of the first in Europe. He is a great expert in the provision of ICS services to critical infrastructures and large industry. He also holds the GCISP certification (profession in industrial cyber security), and is Lead Auditor 27001 (IT) and has audited dozens of industrial and critical infrastructure organisations in the last 18 years. Iñaki Eguia is a well-known cybersecurity practitioner that converges IT-OT worlds and has knowledge and expertise of many vendors for different workstreams (IAM, SOC, Endpoint, Risk Management and other remediation programmes) Iñaki Eguia had been the first smartgrid specific cyber security training provider in Europe in 2013. He has been a professor in the master's programme on cybersecurity at the University of Deusto and the University of Monterrey in Mexico (UDEM); an active member of the cybersecurity standardisation group for the smartgrid at ETSI/CENELEC and an advisor to INCIBE/CNPIC in the area of industrial cybersecurity as well as comprehensive security. He worked in the Accenture European Cybersecurity Market Wide as Sr. Manager and SME (SOC, MDR, Global Security Strategy and remediation programmes for Industry) to develop business and assist different market units in large scale transformation IT/OT projects. He worked for a strong technical and technological focus on the IIoT, MSS and SOC domain in order to increase the competences of our customers, closing big deals and delivering high-complex projects for Electrical Utilities sector. Currently, He leads OT/IIoT cybersecurity practice in HPE. He manages and executes complex offering and delivery with strong focus in Energy sector: Utilities and Oil and Gas.