Accenture’s Rick Driggers On What We Must Do To Protect Critical Industrial Systems From Cyber Attacks

Accenture’s Rick Driggers On What We Must Do To Protect Critical Industrial Systems From Cyber Attacks

Innovate and evolve. Development, implementation, and management of enterprise cybersecurity policies and procedures is often challenging for organizations across industry and government. This is especially true with organizations that have both information technology (IT) and operational technology (OT) environments. Enterprise policies should lean heavily toward the protection and integrity of business data and networks vice polices to improve safety, availability, reliability, performance, and resilience of operations.


As a part of this series, I had the pleasure of interviewing Rick Driggers.

Rick Driggers is Accenture Federal Services’ Critical Infrastructure Cyber Lead. Driggers formerly served as CISA’s Assistant Director for Integrated Operations. A former U.S Air Force Combat Controller, Driggers has deployed as a member of several military and international Special Forces operational and tactical teams. Driggers is a graduate of the Harvard Kennedy School of Government’s Senior Executive Fellowship Program.

Thank you so much for joining us in this interview series! Before we dig in, our readers would like to get to know you. Can you tell us a bit about how you grew up?

I grew up on the Gulf Coast of Florida in Sarasota. While that part of Florida is beautiful, with its white sandy beaches, my childhood wasn’t particularly great. Unfortunately, we had a lot of family issues, like many families do. In my early teens, I spent most of my time working with my grandfather on his cattle ranch. By the time I was 12, I was driving a pickup truck. I spent my summers and afterschool time rounding up and feeding cattle, bailing hay, as well as hanging and repairing fences. It made for long days. My grandfather paid me $1.00 an hour. One day, I came home from school and there was a green 1974 Chevy Nova in our driveway. My mom told me my grandfather bought me the car. I was ecstatic! Bench seats, AM/FM radio, column shift 3-speed, everything a 15-year-old could want. But that’s not the end of the story….

Usually, my grandfather paid me every week. But a month or so went by and he hadn’t paid me. So, I asked him one day during our lunch break if I could get paid. He said, “Absolutely, come up here to my office.” He proceeded to present a legal-size yellow tablet with the vehicle description, VIN number, purchase price and how many hours I’ve worked since he purchased the car. It was an important lesson; I learned I had worked 1,500 hours for that car!

Working for my grandfather, in addition to high school sports, gave me a strong work ethic and a taught me how to be resilient. Venturing out on my own and becoming independent was my primary goal as I entered my final two years of high school and ultimately was the reason that I joined the U.S. Air Force right out of high school. That’s where I really grew up……

Is there a particular story that inspired you to pursue a career in critical infrastructure? We’d love to hear it.

The tragic events of 911 happened nine months after I was medically discharged from Air Force. Those events had me searching for ways to either get back into the military or pursue some line of work to support special mission units as a civilian to serve overseas with my team, which deployed within weeks of 911.

At the same time, I found out that I had a 5-year-old nephew in custody with the Department of Children’s and Families. Once I learned this, I immediately took custody of him in November 2001 and eventually adopted him a couple years later. This changed my priorities and I had to think of ways to still serve, but not in overseas, high-risk environments. I found that opportunity in 2002 at the Joint Personnel Recovery Agency, and then, in 2003, with the Department of Homeland Security within what is now the Cybersecurity and Infrastructure Security Agency (CISA). I remained with DHS for the remainder of my government career. I was drawn to the critical infrastructure mission because of its complexity across the broad spectrum of evolving threats, new technologies, diverse sectors, and the partnerships landscape. We put significant effort into building those partnerships with other federal departments and agencies, state and local government entities, industry, and likeminded foreign countries. We didn’t always get it right, but we always led with trust and a focus on mission outcomes.

Can you share the most interesting story that happened to you since you began this fascinating career?

In my earlier days, I deployed all over the globe and had the opportunity to work alongside some of the most elite special operators in the world while in the Middle East, South America, and Eastern Europe. As a young airman, I was on a team of four divers that recovered the remains of Spirit 03, an AC-130 Gunship that was shot down during Operation Desert Storm while supporting troops in combat. Being a part of the team that ultimately helped get those men home was probably the most rewarding thing I’ve ever done in my career.

You are a successful leader. Which three character traits do you think were most instrumental to your success? Can you please share a story or example for each?

  • Stay mission focused. It’s important to always stay focused on mission outcomes, rather than competition among my peers or peer organizations. So much is lost when organizations compete within themselves for resources or mission relevance. It’s easy for individuals to get distracted by personal success for awards, recognition, a promotion, or a broader mission space. But if those goals don’t align with the overall mission outcomes, the whole team and ultimately the organization suffers. Staying mission focused elevates you, your team, and the entire organization.
  • Be a team player. There’s always strength in numbers. In the critical infrastructure security community, we work across a diverse group of partners with unique skillsets, capabilities, and experience that contribute to the security mission. Together they are far more effective than one organization working on its own. It’s important to communicate, stay focused, and leverage the strengths of each member of your team to achieve your common goals.
  • Display professional courage. I think this is the most important and, potentially the most challenging, trait for any leader. You must always have the courage to confront a difficult issue or make an important decision. So many leaders avoid doing so for fear of conflict, retaliation, or making the wrong decision. Putting off tough decisions doesn’t make them go away, it makes them worse. I like the expression, “It’s better to get red once than pink one thousand times”.

Are you working on any exciting new projects now? How do you think that will help people?

I was recruited to Accenture Federal Services (AFS) to establish an Operational Technology (OT) practice, a subsidiary of Accenture. We also have several ongoing projects to align our government clients to the 2021 Cyber Executive Order. We’re expanding our business alliances to include many OT security companies, and we are hiring OT and critical infrastructure professionals to bring the best and brightest talent to lend their expertise to AFS.

Of AFS’ existing work, one of the more exciting is with CISA’s Joint Cyber Defense Collaborative (JCDC). The JCDC is a public-private partnership focused on bringing industry and government together in new ways to operationalize the coordination and collaboration needed to elevate our nation’s collective defense to better protect and defend critical networks, systems, and infrastructure. While the concept of public-private partnerships has been around for some time, the JCDC is developing innovative, interagency approaches to engage with private industry and leverage unique security capabilities, authorities, and expertise across the cybersecurity community. Accenture was specifically invited to join thanks to our global experience protecting networks and systems across all critical infrastructure sectors.

Ok super. Thank you for all that. Let’s now shift to the main focus of our interview. In order to ensure that we are all on the same page let’s begin with some simple definitions. Can you tell our readers about the different forms of cyber-attacks?

There are many different types of cyber-attacks, from malware, phishing, SQL injection, man-in-the-middle attacks to insider threats. While it’s important for some to know the actual type of attack(s), most people just need to know that most of these attacks are conducted using very similar and simple techniques. And there are relatively easy things you can do to protect your yourself, like turning on multi-factor authentication, changing default passwords, and updating your device operating systems as soon as updates are available.

Who has to be most concerned about cyber-attacks? Is it primarily businesses or even private individuals?

It is inaccurate to call everything a “cyber-attack”. The term is a bit overused, kind of like “information sharing”. That said, everyone needs to understand they have a role to play in protecting themselves and their respective organizations from cyber vulnerabilities and threats. Individuals need to do their best to protect themselves regardless of whether they are at home or at the workplace. Industry should ensure they have good cybersecurity policies, processes, and practices in place on their corporate networks to protect their data and intellectual property, and on their industrial networks to protect safety systems and the reliability of their operations.

The central theme coming out of the White House from our National Cyber Director is that “to beat one of us you have to beat all of us”. That means cybersecurity is a shared responsibility between governments, businesses, and individuals. We all have a part to play.

Who should be called first after one is aware that they are the victim of a cyber-attack? The local police? The FBI? A cybersecurity expert?

You should execute your incident response plan if there is malicious activity on your networks. That plan should include communication protocols to notify leaders, organic or third-party incident response teams, and other entities in accordance with those protocols. Notification should include the FBI and CISA. CISA and the FBI have made significant progress in improving how efficiently and effectively they coordinate with each other to provide the very best support to victims and to protect victim identity. That said, the state, local, and federal government needs to continue to improve collaboration and coordination, especially across key departments and agencies with external cybersecurity responsibilities.

What are the most common data security and cybersecurity mistakes you have seen companies make that make them vulnerable to ransomware attacks?

Everyone and every company is vulnerable to ransomware, as long as they have computing devices that have internet access, even with the best cybersecurity polices and processes, governance, technologies, and professionals. It’s not a matter of “mistakes”. It’s a matter of mitigating the impacts and recovering from ransomware attacks.

For companies, the basics go well beyond what individuals should do. Companies need to ensure they have an appropriate level of cybersecurity commensurate with the risks they face (for example financial institutes are at higher risk of attack than a small retail company) and how critical they are to our daily lives (for example a small water treatment plant is at higher risk of attack than a large real estate development firm).

Companies need to implement multi-factor authentication and change default passwords. Governance processes are also critical within companies so that everyone understands their cybersecurity roles and responsibilities, ensures there is an active cybersecurity awareness program, and adheres to password management policies and procedures.

What would you recommend the government or tech leaders to do to help limit the frequency and severity of these attacks?

Continued streamlining and improvements in coordination and collaboration across government will make it easier for industry to engage and partner with the government to provide valuable insights and request support, if needed. We also need to ask if we’re getting the ROI from the number of resources we have allocated to cybersecurity. I’ve heard for many years we need to increase the cybersecurity budgets for departments and agencies to protect their networks and systems. And while I agree with that in theory, we also need better use of shared and enterprise services across departments. For example, we have a lot of Department level CIO’s that don’t have authority across the entire department and have to negotiate with sub-Department CIOs to gain visibility across the enterprise or implement enterprise level solutions and polices.

Technology leaders should also continue to invest in our nation’s workforce, working closely with government and academic institutions. This is a national security imperative in my opinion. Leaders at all levels of government, education and technology need to work together to solve the cyber workforce shortage. We need solutions to establish more K-12 programs to expose more kids to cybersecurity principles and careers. At the same time, we should teach the next generation to be much more responsible in digital world, in much the same way we do in the physical world. Think about it. We teach our kids to call 9–1–1 and not to talk to strangers. But we don’t have the same sense of safety and security in the digital world!

Ok, thank you. Here is the main question of our interview. What are the “5 Things We Must Do to Protect Critical Industrial Systems from Cyber Attacks” and why?

  • Bridge the cultural divide. Often, when we work with critical infrastructure (power, clean water, transportation, and manufacturing) owners and operators, the one significant issue we find is a massive cultural divide between the people running corporate network(s) and those running the industrial or operations network(s). Unfortunately, we see owners and operators buying and installing technology when the real issue is organizational culture which can only be fixed with engaged leaders, accountability, updated policies, governance, and training. We also see this across all sectors and within the government.
  • Be a partner. Current events prove how important critical infrastructure is to the nation’s security, economy, public health, and democracy. The cyber-attack on Florida’s Oldsmar Water Treatment Plant and Colonial Pipeline are clear examples of our exposure and need for better collaboration. In addition, the establishment of new public and private partnership initiatives such as CISA’s Joint Cyber Defense Collaborative (JCDC) and the DOE’s Energy Threat Analysis Center demonstrate the continued need to evolve and strengthen these types of partnerships. It’s been said 1,000 times…” cybersecurity is a “team sport” which requires industry and government to continue building upon recent successes to maintain and expand trusted partnerships.
  • Innovate and evolve. Development, implementation, and management of enterprise cybersecurity policies and procedures is often challenging for organizations across industry and government. This is especially true with organizations that have both information technology (IT) and operational technology (OT) environments. Enterprise policies should lean heavily toward the protection and integrity of business data and networks vice polices to improve safety, availability, reliability, performance, and resilience of operations.
  • Gain visibility across the enterprise. Enterprise visibility leads to improved asset management. That leads to increased knowledge of network topology and configuration, which allows for the implementation of enterprise security practices and better governance across the enterprise. This establishes a unified team working toward common goals and objectives, which creates an environment to reduce duplicative efforts and streamline security functions. It all starts with visibility.
  • Invest in your workforce. Cybersecurity workforce investments need to be equitable across IT and OT. Implementing cybersecurity in OT environments is somewhat unique from the way cybersecurity is traditionally accomplished in IT business systems, mainly because OT and industrial control system (ICS) assets control physical infrastructure or safety processes, and, if not operating properly, could put people and/or property at risk. Managing cybersecurity in OT environments requires unique skills and expertise to understand, not only how to secure ICS assets, but also what the ICS assets control in the environment, and how critical they are to a particular process or functionality within the facility.

How can our readers further follow your work online?

My LinkedIn is: Rick Driggers | LinkedIn

This was very inspiring and informative. Thank you so much for the time you spent with this interview!

About The Interviewer: David Leichner is a veteran of the Israeli high-tech industry with significant experience in the areas of cyber and security, enterprise software and communications. At Cybellum, a leading provider of Product Security Lifecycle Management, David is responsible for creating and executing the marketing strategy and managing the global marketing team that forms the foundation for Cybellum’s product and market penetration. Prior to Cybellum, David was CMO at SQream and VP Sales and Marketing at endpoint protection vendor, Cynet. David is the Chairman of the Friends of Israel and Member of the Board of Trustees of the Jerusalem Technology College. He holds a BA in Information Systems Management and an MBA in International Business from the City University of New York.

TechVIP InterviewsAccenture
DL
Written by

David Leichner

Editor & Journalist · Authority Magazine

Editor and journalist at Authority Magazine, sharing in-depth executive interviews, leadership insights, and empowering stories from world-class founders and creators.

Authority Magazine
Published inAuthority MagazineTop Lessons, Top Authorities · 42K Followers

Exclusive, curated interviews with the leaders and changemakers shaping tomorrow. Leadership lessons, industry deep dives, and executive profiles.