Software Supply Chains and ISACs – The Inevitability Curve EP13
Phil Englert and our host Chris Blask have been co-chairing a CISA working group on software bill of materials (SBOM) sharing. The working group has developed a process to help ISACs and similar organizations determine the control architecture necessary to manage the distribution of SBOMs among their members.
Transcript
This is Textron tv. Hello, and welcome to another episode of The Inevitability Curve. As always, I am your host, Chris Blak.
I'll have an interesting guest with me today, as hopefully we always do, and we'll pick a topic and look back where we've been. How did we get to where we are right now? What does now even look like?
You know, what is today? What's the space that we're currently existing in? And with that, perhaps, what are the range of possibilities going forward?
And joining me today is a very good friend and sort a constant working partner these days. Phil Angler. Phil, how are you?
I'm doing well, Chris, and thanks for having me on your episode. Couldn't be happier. So for everybody else's background, so you can see in the, uh, Phil's title, Phil is the, uh, VP of Medical Device Security, I believe, right title with the Healthcare Isec.
There's Healthcare Information Sharing and Analysis Center. And this is a, a group of organizations that, uh, centered around the, the need to have a US public private, uh, facility to share threat intelligence, vulnerability information around the, I think currently, I believe 16 critical sectors as we define them here in the us. So the healthcare ISAC is, has been around, oh, probably 30 years since now almost, Well, since 2010, right?
We were formed in 2010. The Health ISAC is a member driven organization, you know, that specifically fosters the sharing of InfoSec information across the entire healthcare sector, whether it's medical device manufacturers, large pharma, healthcare providers, academic medical centers, health information exchanges, uh, and the like. So, um, if you have a role in patient care, you know, either as a precursor as in medical device manufacturers or in direct patient care, or even managing, you know, the transactions that, that support patient care through insurance, uh, and health information exchanges and, and elements like that, they're eligible for membership.
Uh, we are about 900 organizations globally, uh, representing almost 12,000, um, individuals, uh, in those 900 organizations. So we like to say you, we've got 12,000 analysts working for you. Good explanation.
And so little, a little bit of background. So permanently, so there was the industrial control system isac, which is currently know a dormant, you know, uh, uh, or defunct or whatnot. But I led that with a gentleman by the name of Sean McGirk, who created the ICS cert and the N Kick, you know, some of the functions inside the US federal government and left, you know, to, to work with the private sector on that sort of information sharing.
And it's been a very interesting path. The ISACs, we'll get into this in the, in the discussion, but the ISACs were basically kicked off in the late nineties, you know, by a, you know, US federal Government recognition and working in the private sector to get, to get this going. Um, these days, normally in these, in these, this series, I don't talk about my other day jobs, but I am vice president of Strategy for sbe, that is a software bill of materials and SBO management, uh, vendor company.
Um, so, and that's gonna be part of our topic here. So just for transparency, everybody knows what my interests are, and SBE and Healthcare, healthcare ISAC have been partnering, you know, to help get supply chain information flowing through this ISAC infrastructure. And which is more the, the topic I think for today.
You and I have been working for the last, uh, well over the last couple of years, but you know, this, this calendar year has been interesting working with the Department of Homeland Security Cybersecurity and the infrastructure security agency, where we call it, we, we, uh, pronounce cisa. Um, we've been running a, a set of tiger teams, a set of working groups where we work with our peers in the industry and, and then the US public sector to try to solve certain, certain issues. And in that path, over the last couple years, there's been, uh, a couple interesting documents.
The information sharing side of this, you know, with my ISAC background, I come into SBOs and supply chain. These are the same sort of thing, same sort of concerns, same sort of mechanisms, um, and thinking we can leverage those and, and the artifacts we had to work with now mentioned two specific documents that people can look up if you like. gov/sbo, m sbo OM, and there is a, uh, SBO M sharing, um, lifecycle report that defines discovery, access and transport, which turns out to be important in the process of sharing, uh, the sensitive supply chain information.
There's a SBO m sharing roles and considerations document that a, a working group, uh, that I was, uh, in last year produced that looks at, you know, the author of an SBO m the consumer of an sbo. And more to our point here, uh, the distributor, the people in the middle, you know, how do I facilitate access to this information for a perfect example as an isac, you know, for my stakeholders and constituents. And we cycled through putting a process together this summer, and now we're cycling through other information sharing centers to see if we can help them move forward, which plays exactly to everything we're talking about today.
So, that's a very long intro to say that we're we gonna be talking about information sharing and threat intelligence sharing, and how we've gotten to where we are today, you know, what today looks like and what we can perhaps expect. Sure, sure. Yeah.
And just, you know, to provide a little bit of, uh, historical context, right? Especially around healthcare. Um, in December of 2022, the Omni Moss bill got passed.
It included, uh, a large portion of the Patch Act, which gave the FDA statutory authority for, uh, cybersecurity of medical devices. So this was a huge change. Prior to that, the FDA only had statutory authority only safety over safety.
And since, you know, we know that there's an intersection of safety and security, right? But it's a Venn diagram, and sometimes the van is a little gray as to exactly how those impacts are, because they're not always direct. Uh, and with cybersecurity, it's, and particularly in medical devices, it's not always obvious, right?
So in that it precluded or included the, the, the need for medical device manufacturers to provide to regulatory agent the FDA, the regulatory agency in a submission that an SOMB provided. So the sub assets of a medical device be identified and declared, and also the threats to the device itself, as well as the risk assessments of the components chose, chosen to provide the clinical functionality needs to be addressed and mitigated to a controlled state, right? Um, so there's uncontrolled and controlled state, meaning that it can be managed through either patches, compensating controls, uh, other elements in place, um, and it does not propose a safety risk to patients or patient populations or staff.
So those, so that element was a game changer here. And so when that happened, the Health ISAC saw an opportunity as a trusted, uh, source and a trusted venue of security information exchange to extend that to the SBOs and other security artifacts. So what we set up was with, uh, the cooperation of, of CY Beats, um, we identified a tool that would allow manufacturers to, uh, produce, assemble, and prepare for distribution, uh, SBOs, and then make those available to healthcare providers.
And not just member healthcare providers, but any healthcare provider because, you know, um, not every member, um, or not every healthcare entity is a member of Health isac, but we didn't want to preclude the opportunity to distribute, you know, critical, um, information to those entities. So we're sharing from member healthcare organizations to healthcare delivery organizations, And, you know, the policies that led to that, you know, what led to start with that, because I think it's a, a linear sort of thing, right? You know, I, from, it's now, you know, some are smacking around 30 years, you know, that I've been asked by journalists, you know, you know, what about this and that, you know, quite often it's what about this, you know, latest US federal government move or legislation or statement or whatever.
It's, and I found over the years that, that I can honestly answer, it's kind of following the evolutionary path that I would've reasonably expected, right? You know, stocks net, you know, when the, when the, uh, uh, first operational technology cyber attack, you know, against in, you know, critical infrastructure happened in this case, you know, a nuclear enrichment facility in the tans around 2010, you know, the activity probably started around two, 2006. And the, uh, uh, a French pressed journalist, uh, contacted me and tried really hard to gimme, say, you know, you're living at the glass house throwing stones.
And my answer is like, anybody that didn't think that right about now in the nation state level, you know, that's the sort of thing you should worry about, or, you know, pro or con, you know, defend against you or use as a, as a tool of statecraft is missing the point, right? And this, what you just said about policy and supply chain, I think is a good, another good example. You know, it's easy for us to say that should have been in place in 1979.
It's like, no, I mean, there's no way to explain to the stakeholders, the legislators that you know, their voters why we need to spend any time and, you know, and what the answer is. Um, but now we have to, you know, we we're getting to the point where we can't keep, for example, the healthcare infrastructure working without that sort of timely, transparent, you know, trusted, um, uh, uh, pathways. So, so let me back to the policy parts, right?
So there's the, there's, correct me this, when I always get this wrong. There was a presidential directive in 1996 or 1998 that started of the isac, uh, I think 96 9 6. But don't quote on that.
And that said, and to, to the point that I'm trying to get to here, the interesting thing to me in that of everything else was that what it said, there shall be an singular information sharing analysis center. And there immediately, you guys, as we discussed, turned out there's a bunch of different sectors, and having multiple ISACs focusing on different things turned to be better. And in fact, the National Infrastructure Protection Plan, you know, the whole structure that the US federal government uses to deal with all of this was built around that experience by that taking a step moving forward.
So there should be one and learning immediately, oh, okay, there should be bunches. And we're still on that path today, leading to exactly what you just said, that in this environment, you know, federal agencies like the FDA can take logical steps that make sense, you know, and, and, you know, require those or provide the opportunities for organizations like is a, to say, you're right, we can do that and lines up with our goals and motivations. It's kind of optimistic.
We actually got that, right. It is o optimistic, you know, and, and, um, there's the healthcare Sector Coordinating Council, which really is a public-private government, uh, uh, collaboration to, to look at things more at a, at a high level policy level, if you will. Um, and one of their, uh, mantras, you know, is to beat one of us, you must beat all of us.
So we know that together we are stronger. If, if a bad actor is attacking, you know, one member of our, of our organization, and that information is shared, those IOCs are shared out right to other members, then they can ingest those into their detect and response capabilities in their own environments, right? And be much better prepared to thwart or respond and minimize the damages.
So, you know, the concept of, you know, each of us watching out for each other and helping each other and, um, sharing the information, you know, willingly, we share it, uh, in, in the sticks and taxi protocol, right? There is a bit of safe harbor protection that information shared in the ISACs is, you know, um, can't be used against the agencies, right? That, that share that information.
And that's a very important point because it's one of the reasons that we thought, you know, now let's share these SBOs and other security artifacts between the manufacturers and the healthcare providers that operate them. And having, you know, that, that we can share this, we share it under with an understanding, you know, that it's not public information, that it's controlled information, you know, that it's to be used, you know, in its attendant purpose and not, uh, put out in the public space, you know, but really to, with the goal of increasing the resilience of, in the entire healthcare sector, And it's those sorts of practical applications of policies, right? You know, we in here in the states need to understand, you know, the impact.
All these structures we put together, you know, through all our conversations, literally just a bunch of working groups, the sector coordinating councils, as you say, these are people, you know, representing public sector in the, in a sector, representing the private sector, sitting down repeatedly and having conversations and structuring and figuring out the process. You know, this has a huge impact on the world. You know, my involvement, you know, in per sector has been more in the electric sector than healthcare over the decades.
And I've watched the creation of the NERC sip the acronyms on North American Electric re reliability council, critical infrastructure protection, uh, um, regulations, you know, vow shalt, you know, if you're a regulated US utility and do these 13 things, and I've watched this evolved, and I've used that with, you know, some of our friends who helped create that to help other nation states put together similar structures. You know, they may have four sectors and instead has 16 or do things one way or the other. But we keep creating repeatable structures where trusted information can be shared, which in our professional lives is a, is a empirical thing.
And in, you know, as we all understand in the public sphere right now, there's a lot of angst about, right. You know, how do we, how can we really know what's real? Well, examples, isec, all these different interests, public sector and private sector and non-profit and for-profit and consumers and distributors can all get down and literally trust each other enough to handle sensitive information in reliable ways that addresses everybody's concerns.
Wow. Yeah. It's, it's, that's an important point, right?
It's, it's the ability to share information and not only security information. You know, when you know new technologies come out, you know, we are talking about, you know, like chat GTP or, or AI or, or, or elements like that. What are the policies?
What are the constraints? What are the risks of using, you know, chat TPP, you know, and other, uh, artificial intelligence engines in the healthcare environment, you know, knowing that they have great promise to build inefficiencies and, and provide benefits of patient care, but they're not without risks, you know, knowing that AI is, you know, designed to provide an answer, though, not necessarily the correct answer or even the truth, right? So that's a risk in that technology.
Um, caregivers may not understand that non-technical people, you know, that are more focused on biology and chemistry and not on electron flow and ones and zeros may not quite understand the nuances of that. So bringing the entire organizations together, right, having these discussions, sharing this information, you know, helping people get, you know, to where they need to be faster, you know, by doing it collectively. And, and working cooperatively is a powerful way, you know, that we enrich the, uh, member organizations, you know, we have 24, I think currently different working groups, you know, one of them is the medical Device Security council, where we're the only group in the world that brings manufacturers and healthcare providers to the table to talk about how do we secure the medical device, you know, environment from concepts from the r and d through delivery, you know, uh, configuration integration, you know, maintenance and monitoring, you know, and, and remediation and response while it's in, you know, the healthcare environment.
How do we take maybe 1200 different models makes and models of equipment and stick them into a single organization's network, you know, that have endpoints counted in the tens, if not hundreds of thousands, you know, and then manage the interoperability so that we're, we're trusting the information and utilizing the information to improve patient outcomes. You know, and I say that, and I, and it's, you know, I go back to accountable care, which incentivized healthcare to generate the data to show that the outcomes they're delivering today are better than the outcomes they were delivering yesterday. And that kind of pushed the whole interoperability.
We were taking devices that were basically pneumatic or mechanical devices and putting electronic sensors in them, and then creating this, these data sets, which we could then analyze, you know, what was happening on the device, what were the treatments, what were the utilizations, what kind of protocols did we use for scanning, you know, and taking images, creating diagnostic imagings, and then turning that into, and looking at studying that, using scientific analysis to determine, you know, can we impact patient care in a positive way? It's a wonderful opportunity. It's why I've been in this business for 35 plus years, you know, because it's amazing every single day, you know?
But as we've, as we've put this information in and created these large data sets, at the same time, we painted a target on our back. And because healthcare is a very emotional business, you know, we don't care. It's my son, my daughter, my mother, I don't care what it costs.
We'll figure that out later. That's, you know, sometimes risk management gets thrown out the window when you are thrown into or drawn into the healthcare sector. And so finding that balance between the promise, you know, of improved care and reducing managing the risks and the, you know, if, if, uh, if we were to go back to the IT folks that were often seen as barriers to innovation because of the cybersecurity risks, you know, um, and that friction, uh, we are now beginning to deal with as an industry, we've learned how to have these strong conversations.
We've brought cybersecurity to the board, and they understand the risks that are there. Healthcare still pays enormously change. Health paid a $20 million, uh, ransom, you know, within a few weeks of being, of, of being ransomed, which is unbelievable.
If we go back to 2019, I believe it was when Presbyterian, um, hell or, um, yeah, pres, not Presbyterian, but the, uh, large healthcare system in LA that got hit in urban, you know, they paid, I think, $17,000 in, in ransom. You know, so, so the opportunity for criminals to, to make money in healthcare is very real. It's very rapid.
Um, and so we continue to be a, a target, uh, for that. They say that healthcare is much weaker than, you know, much less protected than other industries. I think a couple of things might contribute to this perception, and I'm not sure that I've seen empirical data that it actually is, but because of the breadth and depth of technology that we have, the breadth of relationships that we have with all these different organizations, you know, just create more opportunities for bad actors to find weaknesses within any system, uh, there and exploit those.
So it's important for us to, you know, think about these, um, these systems, uh, in a holistic fashion, but because of the depth and breadth of technologies, the span of relationships that we develop to develop, to deliver healthcare, you know, from the acute care centers, you know, to, you know, the laboratories that do special clinical diagnostics to the imaging centers, to the surgical centers that all operate out, that right down to primary care providers, that, that are the first point of entry, you know, to, you know, the therapy centers that you see afterwards, you know, that, that help you go, so help you, uh, finish your treatment regimen, right? All of these connections create, you know, a, a increase, I guess, our threat surface, right? And we need to think about that.
Sharing security information is one way to help organizations really, you know, drive focus on what's real, what's, um, what needs to be, what are the, what creates the largest risk for those organizations and help them, you know, to deliver the, the protections that are necessary to, to reduce those risks. And this, you know, We're, we're at that point in the conversation to look at the future. And I think this is a, a, a perfect crux, right?
Because in the early nineties when I was getting involved with security and then critical infrastructure, you know, I, I found, I really liked working in, you know, what we call operational technology, OT now, right? And you start looking at the sectors and, you know, I've worked with nuclear power, security and everything else. How, how extreme do you want to get, right?
And things are what they are. And if you wanna deal, you know, start in the early nineties dealing with nuclear plant cybersecurity, you're first gonna deal with how are we doing it now, right? And it turns out there's a lot of good lessons in that, right?
But healthcare, I, I can I, as you're talking, I'm trying to remind me of a conversation. I can almost remember exactly what it was, but it was 1992 for sure the first time. I'm like, yeah, but you're healthcare, which means that a critical infrastructure, you're literally plugging into human beings, not just a generator or a power turbine or a, you know, a, a maritime, uh, system.
And you use terms like teaching hospitals. So you have a university and the infrastructure mixed all together so that the, you know, universities are, are classic hives of hackers, right? You know, just a very curious bunch young folks.
So we take the most critical thing from a human perspective and mix it with the most hard, you know, and then the networks are mixed up and everything's connected and all along, you know, this is among honestly my earliest inevitability curve thoughts. It's like, well, if someday we address all that, someday we can do not only the things you just said, but take that to 11, right? That that device in, you know, connected to inside that patient is in real time acting on and trusting information that it's getting not just from a second party, but a 15th party through 17 different connections.
And it still works. And we can do that because we will find ways to build the trust, you know, and we'll, it'll take as long as it takes, a lot of it will be humans, right? Be building trust with actual organizations and comparing that to how we're doing things already.
And based on that, taking a step forward. So what do you think this tells us about the, the, the future? You know, what do you think the next pick timeframe you want 10, 20, 30, 300 years?
Where are we going? So the, you know, the technology will only continue to advance, right? Um, every seven years, I forget the principle, right?
That says it doubles every seven years, right? Like so many things, um, we know the promise of improved care. You know, the, the capability to utilize, you know, adaptive learning, machine learning, AI to help evaluate information passed along, um, uh, and shape care delivery is going to be real.
And that means more data, right? And so that means more devices that can be, you know, connected to a network, right? Um, with the patch act and the other requirements in there that new technology be delivered, you know, be developed in a safe, you know, uh, or a secure development framework, that there is a mechanism in place to monitor the health of the components after a device is put into the market and to develop patches and, uh, updates to keep those devices cyber secure.
You know, the FDA has said, you know, um, and, and I don't think this is their quote, but, but engineering is about making sure that certain things happen, and cybersecurity is about making sure certain things don't, right? And so that's an important concept, right? The ability to build in detection, the ability to have a device that fails safely, you know, so that it doesn't, if it is compromised, right?
That it doesn't lose the data that it has, that it doesn't, that it can't do something it's not supposed to do. You know, and you made a very important point, right? That, you know, iot is iot, the difference between IO OT and traditional computing is that it does interact with the environment that it can either sense the environment or act upon it, right?
And whether that's creating energy from, from nuclear fusion, you know, uh, controlling, you know, uh, floodplains through dams, whether that's distributing power, distributing people through the airline industry, distributing produce or, or products through transportation, you know, or delivering healthcare, right? In healthcare, the environment is very often the patient themselves, right? So that's people, and again, there's that emotional aspect that, that, that doesn't exist in some other, uh, industries.
So we have a couple of things, right? Um, you know, we need to be, get better about sharing information, right? We have to think that, that, uh, you know, stop thinking that if I, if I give somebody my sbo, you know, the hackers will get it, and then they'll know what's in my device and they'll be able to, you know, tell or find exploits in that, right?
So there's two things that have to happen. One, we have to build devices that have fewer vulnerabilities, right? Meaning that we make better selection of components that we, that we select components that have a longer life, support life in them as we're building and, and delivering these products into market, that we understand where the risks lie, and we're honest with ourselves, we're honest with our customers about where those risks are, you know, so that we can under, you know, evaluate those risks, determine whether we're okay with them, right?
We're, we are, are all, we do risk assessment every day. Uh, we cross the street, it's a risk assessment. I turn left, you know, can I cross?
Yes, I'm good to go. Nope. Car's coming.
I'm not. That's a risk assessment. Doctors do risk assessments every day, right?
They, a patient comes in, they present with symptoms, uh, uh, a physician, you know, will consider what are the treatments that are available? And what they want to do is, is select the one that provides the best outcome. Not necessarily to make you wholly health, but give you the best outcome with the least downside, right?
That's risk management. That's what we do in healthcare. And so it requires information to do that.
So sharing, you know, SBOs freely amongst, you know, the, the makers of the devices and the users of the devices only allows the users to a understand, you know, what is the density of certain components in my environment? Where are they, how do they interact with what's critical in order for me to provide healthcare? Not all vulnerabilities, you know, are the same, have the same risk, have that they may not really impact the functionality of a device, even if they were exploited.
Uh, and, you know, there are devices that don't have, uh, an equal weight in producing the healthcare outcome. You know, you can replace, you know, a, a bear hugger with blankets that come out of a warming cabinet if you want to control a patient's temperature. So there's, there's methods that we can use to, to get around things that may not be cyber connected, um, to that.
And so it's important for organizations to understand, a, what their critical devices are for delivering the mission, right? And then what are the risks within those critical components of mission delivery? And then having plans to respond and recover from those gracefully so that they can get back to the business of mission delivery.
You know, should there be an interruption? And it doesn't matter whether that interruption is cyber related, a bad actor or physical, you know, as in a component failure. You know, we still have to think, if this goes down, what does it do to my ability to do my job?
And how am I gonna get around it until I can get back to doing it correctly? Very well said, and I would love to keep saying things with you all day long, and I wish we had, uh, more time for this, but for the, the exigencies of, uh, content creation, we should probably, uh, find an end of this now. So, just wanna thank you for all your time, you know, for your time today, you helping people understand these things and, you know, have some clarity and some hope for the future.
And, and all the work, you know, you and I have done together, I think makes the world a better place. It's, well, I appreciate our, uh, collaboration, Chris. It's been enlightening for me.
Um, I'm a clinical engineer. I fixed medical devices. Cyber is my second skill.
It's my second language, if you will. And so leaning into experts like yourself has been super beneficial. So appreciate that.
Thank you. And thank all of you out in the world, you know, for spending your time with us today. Remember to be kind to yourselves, be nice to people around you, and look forward to seeing you again in the continually wonderful future.


