Pre-DEFCON Session: The B.A.S.I.C. Framework for Protecting OT

Pre-DEFCON Session: The B.A.S.I.C. Framework for Protecting OT

🎙 Mike Holcomb 👥 27K 📅 August 1, 2026 ⏱ 37 min 👁 446 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityICSB.A.S.I.C. frameworkbackup and recoveryasset managementnetwork segmentationincident response

Summary

In this pre-DEFCON session, Mike Holcomb introduces the B.A.S.I.C. framework for protecting OT/ICS environments. He begins by highlighting the increasing frequency of OT attacks, citing incidents like Colonial Pipeline and the recent AI-driven attacks. He emphasizes that attackers no longer need to be engineers, as AI tools can analyze HMIs and suggest attack vectors. The B.A.S.I.C. framework comprises five principles: Backup and Recovery, Asset Management, Secure Network Architecture, Incident Response Planning, and Continuous Monitoring (implied by the acronym). Holcomb stresses that most OT environments lack basic security measures, such as network monitoring, and that even simple steps like implementing a firewall between IT and OT can significantly reduce risk. He provides real-world examples, including the Jaguar Land Rover ransomware attack and the Port of Nagoya incident, to illustrate the importance of each principle. He also introduces a free resource, OT Threat Feed, to help organizations stay informed about sector-specific threats. The session concludes with a Q&A, where he addresses questions about AI in OT security and the challenges of implementing these measures in resource-constrained environments.

175 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners in OT security, especially those in small or medium-sized environments with limited resources. The B.A.S.I.C. framework provides a practical, prioritized approach that is often missing in discussions dominated by advanced tools. The argumentation is solid, grounded in real-world incidents and the speaker’s extensive experience. However, the presentation is largely anecdotal, and the framework’s effectiveness is not backed by empirical data or formal studies. The speaker does not provide a detailed comparison with existing frameworks like the SANS Critical Controls, which could strengthen the argument. The use of AI to generate attack lists is an interesting point, but the ethical and security implications are not deeply explored.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates good knowledge of the field and references several real-world incidents, but he does not provide formal citations or links to sources. The description includes a link to the OT Threat Feed, but no other external references. The title accurately reflects the content, and the session is well-structured. The speaker’s credibility is enhanced by his practical experience, but the lack of verifiable sources limits the scientific rigor. The session is an expert opinion rather than a peer-reviewed study, which is appropriate for a conference talk but should be considered when evaluating the reliability of the claims.

228 words

Title / Content Match

The title accurately reflects the content: a pre-DEFCON session introducing the B.A.S.I.C. framework for OT protection.

Quality & Reliability

7/10

The speaker is an experienced OT security practitioner, and the content is grounded in real-world incidents and practical experience. However, the presentation is largely anecdotal and lacks formal citations or peer-reviewed sources, and some claims are not independently verified.

Key Moments

Cited Sources

  • OT Threat Feed — Mentioned as a free resource for tracking OT threats by sector.

Concurring Sources

  • SANS Critical Security Controls for ICS — The speaker references the SANS critical controls, which align with the B.A.S.I.C. framework's principles.

Dissenting Sources

  • No formal sources found — The presentation lacks formal citations, making it difficult to verify specific claims independently.

Contribution & Novelties

The B.A.S.I.C. framework offers a simplified, actionable approach to OT security, emphasizing fundamentals over advanced tools. It is particularly valuable for organizations with limited resources. The session also highlights the role of AI in both attacking and defending OT environments, a relatively new and evolving area. The OT Threat Feed is a novel resource that aggregates sector-specific threat information.

Pour aller plus loin :

  • SANS ICS Security — Relevant for foundational training in OT security.
  • NIST SP 800-82 Rev.2 — Guide to Industrial Control Systems (ICS) Security, providing comprehensive guidelines.
  • MITRE ATT&CK for ICS — A knowledge base of adversary tactics and techniques specific to ICS, useful for understanding attack patterns.
  • Dragos — A leading OT security company, mentioned in the session, offering threat intelligence and services.

127 words

Radar Profile

The radar profile shows a balanced but moderate performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical value of the content. The lower scores in technical depth and reliability indicate that while the information is useful, it lacks formal rigor and advanced technical detail.

Reliability 6/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.