Clean Energy Cybersecurity Accelerator Program – Duncan Greatwood, Xage Security
Just last December, the U.S. Department of Energy’s National Renewable Energy Laboratory announced the first cohort of its Clean Energy Cybersecurity Accelerator program and Xage Security was selected for this fast-paced project. CEO of Xage Security Duncan Greatwood, talks with sustainability and climate contributor Bonnie Schneider about cybersecurity and renewable energy.
Transcript
This is texturing TV. Thanks for joining us on Tech strong TV. I'm Bonnie Schneider and joining me now is Duncan Greatwood.
He is the CEO of zage security to discuss renewable energy and cybersecurity Duncan it is so great to have you on it's really my pleasure. Thanks very much. That's great.
Well, just last December the US Department of energy is natural renewable energy laboratory announced the first cohort of it's clean energy cybersecurity accelerator program and zage security was selected. So congratulations first of all and and tell us how it's been going. It hasn't been that long.
But what have you been doing so far? Yeah, well, it's it's a very active program. Actually, it'll be all done by by the end of March this first phase.
So I'm it's launched right into it and you know renewable energy is an opportunity to improve resilience and security and it's also a risk that security might get worse. So we kind of have to balance off those those two things and and really what the program is doing is is stimulating some of the risk situations that happen in renewable energy infrastructure and then bringing a few of the nearest most innovative solutions and and dropping them into those environments and sort of saying well, you know, if those new Solutions were there with the hackers be stopped or would they still be able to go and do their do their bad work that they want to do so, that's really what's going on right now at at nrel and the facilities that they provide Well, just in backtrack a little can you tell me a little bit about zage security how you got started? And what what you're working on in general?
Yeah, you bet so they security is a cyber security company that targets what we sometimes call real world operations and that means anything where there's a physical aspect or things that we rely on every day. How do we how do we transport ourselves? How do we create our food?
How do we create and use energy? And that's a new area in cyber security to a large extent until a few years ago wasn't really an area of deep activity. But of course in the last few years it's become, you know, very sensitive area.
You know, we do rely on those things every day and there's a whole bunch of Bad actors who are either trying to extract ransomware from private companies or attack things from a national security perspective. The the war in Ukraine is intensified concerns and acts like the colonial pipeline hack of 2021 and was was about a bit of a warning sign for the whole of that. That they needed to start paying more attention to it.
So zage is taking a new approach in that industry historically cyber security in that space has been about keeping the bad guys off the network. So just not allowing them in at all. And then secondly, if something did go wrong it would be to detection solution.
So you like having a you know video camera on your house you'd have detection solution. So somebody was rutling around then you might have a chance of spotting in and both those approaches are kind of broken down because the bad guys do get on the networks fairly regularly and just knowing that they're there is useful. But of course we much rather just stop them and being able to do what they want to do or just detecting it and that's the approach that's age is bringing that we are providing a what we call a fabric which is really just overlay of software components that we drop into the operation and which is there to make sure that nobody can do things that an authorized to do and so we kind of take control of access and interactions that are happening between the different systems and different equipment and we we impose this method of authentication and And authorization to control what's happening that you know previously didn't exist.
And that's super relevant to situations like renewable energy and like what nrel is doing, of course in renewable environments. There are often lots of little solar Farms little wind farms very distributed the old wave doing energy or if you giant power stations are very different kind of a model. And so when you have these distributed environments that institutes a whole bunch of new risks, they have to interact with each other in new ways and and they you know, sometimes they're working you might be windy today.
It might be sunny today. It might be that you're using a nuclear energy today but constantly varying and so it's very complex set of controls that has to exist and today's this really here to help us solve those problems. That's a really good point that you mentioned where you have these environmental factors that come into play and in the wake of climate change where we're seeing more of these extreme weather events.
How is that affected cyber security and post new challenges for you? It has well, I I think it it's a multi-layer answer to that to that question. So firstly it's accelerating the push for renewable energy as we all know and so we have to make sure that the resilience of grid is increased not decreased when we do Embrace Renewables.
And yeah, I think the story today on that is makes quite honestly, sometimes it is increased sometimes not and there's also Direct effects on the grid when when there are either weather events or wildfires or any other consequences that can come from climate change. You probably remember a couple of years ago. There was a big ice storm in Texas and too many I started in Texas, but once in a while they do it's very intense and we're not quite a long time and they you know, they had to bring in tens of thousands of outside technicians from outside from outside of the State of Texas and give them access to the, Texas.
Infrastructure to help them fix it. You can imagine if you take 50,000 people who've never had access before and give them access to your digital infrastructure. That's going to be some of them who have malware on their laptops and maybe they don't even notice there, but they do and so you're you're kind of In responding to weather events, you're actually exposing a whole bunch of cyber risk in that process and that increases the need and the intensity of the urgency of you know, let's make sure that that one person who has malware on their laptop that they can, you know, worst case maybe they in fact one substation in the grid, they're not infecting every substation in the grid not allowing kind of a digital contagion to happen across the grid when those things do happen.
Do do end up jumping into the system, you know. Yeah, and so keeping this Security in mind and looking at these new Arenas where we could have more threats to security. How would you go about how do you go about testing these measures particularly in the energy sector?
Yeah, and so, you know, there are multiple levels of testing that go on. There are commonly defined sets of standards and and tool sets that a company that's buying so I have Security will run through and they'll test for you know vulnerabilities in the security solution itself. And also whether the security solution is able to block attacks against the thing that is trying to protect and in real world infrastructure.
The Baseline is often very low so that maybe equipment with no password at all or it may seem to have a password actually very easy to bypass. And so what zace is bringing is the ability to overlay on top of what we might call that Legacy equipment or Legacy architecture ones cyber security methods, so Just as if you want access to your bank account, you might have to sign in with a password and you might have to provide a second proof like you proof why your cell phone that it's really you. Well we can in we can impose those kind of multi-layer protections even on top of these older pieces of infrastructure.
And so a test range like the nrel is providing will run through all of those kind of attacks, you know, is it is it resistant to a password attack? Is it resistant to a so-called MFA bombing or MFA exhaustion attack and so on and so on so they have a whole Suite of things that they run through and they're also Looking at the real world resilience of this thing. So if you're solar farm is disconnected from the outside world.
Does it continue to work can the security measures work locally even without being able to refer back to some Central Security point and and that kind of resiliency is just as important as the cyberkind you don't want diver to kind of bring things to a halt just because it's lost the network connection or any of the other problems that they can happen in day-to-date is alive and so they're testers also run through those kind of scenarios and you know, making sure that it'll work in practice as well as in theory. Has there been any challenges that unexpected things that happened in your development, especially working in Renewables? Yeah, I I think the you know cyber Security's constantly throwing up new challenges.
It's the nature of hackers that they're inventive people and you know, it's quite a entrepreneurial community in its own strange way that people are coming up new ideas and new approaches all the time. And I I think for us. For a long time there was kind of doubting people's minds, you know, did they really need to take these strong measures and I you know as a sort of hinted governments ago.
I think only in the last 18 months has the whole industry sort of shifted perspective and say, you know, what doesn't matter whether we're oil and gas pipeline or a solar farm or we're you know, we're manufacturing, you know packaged Foods. We are critical infrastructure. We are under attack and they've shifted their mindset and you know technical term that sometimes is a zero trust approach.
So they're not gonna trust you just because you appeared on a network or just because you have one one the laptop or what have you the the sort of adopting these much stronger approaches and I guess with our cyber perspective some ways it surprises that they took them so long to get there. They took them, you know took me a while to realize that they had Do it but I think the flip side of that is how fast people have been able to move especially in the last 12 months in really, you know, kind of starting to to aggressively head down that that path and you know companies like utility companies. They have a well learned reputation for a stately rate of progress on many issues that's going to how they operate by default.
But whether it's it's you know Renewables or many of these other areas, you've seen people who kind of previously might have taken 10 years to adopt a new approach kind of saying hey, you know what we want to get this rolled out in in training too or 2023 or some you know, quite quite rapid timescale. Yeah, that's true. It's interesting.
You meant the pacing has picked up now. I was reading about your background and how you've previously worked in leadership roles at Apple Topsy post-path in your ex, you know vast experience in this cybersecurity world. Have you ever seen an acceleration like this happening where there has to be this this very up to the minute progress expected in cybersecurity?
Yeah, I I think we have seen this Loop before a little bit. I think in the last time we went around it was really more focused on Purely digital environments. So so and they're just distinction here between the world of the carpeted office building, you know, imagine you're working in insurance company, you know, really your processing documents backwards and forwards and if you wind back 15 years then many of those environments were similarly poorly protected.
Once you got inside the firewall you could do many many things that were bad and that sort of switch into protecting individual assets individual pieces of data that happened in it 15 plus years ago is now happening in Crystal infrastructure. And you know, it's it's a change of mindset for sure and you know, every customer we talked to you know, it's a different state some of them have already fully embraced in there. Hammering down the path.
Some of them are you know uncertain, you know, does this apply to me and do I need to do it and others of them? I honestly are still in this resistance mode a little bit. You know, I don't want to do this.
I you know, I can figure out okay Ram, but you know the lessons of the last cycle I think in in the IT world as opposed to the operational. Well the lessons in it were eventually everybody kind of Embraces in people that pragmatic and they they find Solutions like say the let them do it in a practical way and it's not quite the nightmare that they perhaps thought. It would be when they when they first started looking at it and you know really for these businesses.
It's a requirement now and when a requirement exists a hard requirement like this one then Solutions begin to make themselves known of which, you know say to certainly important I think. said that is true coming more to light as you said with all different sorts of threats posing on organizations more and more each day and Duncan Greatwood. Thank you so much for sharing your insights from Sage security.
Congratulations again on the accelerator program. You're going to have a very busy next couple of months. I'm sure.
Yeah, no doubt. There's my pleasure. Thanks for talking great.
Well, thank you so much for joining us on Tech strong TV. Thanks Duncan. We're gonna have a lot more coming up.
