David Formby begins with a discussion of the difficulty of extending visibility to Purdue Reference Model Level 1. Then he discusses the bleeding edge of Controller Endpoint Detection and Response (CEDR) to Collect, Centralize, Explore, and Analyze data on the PLC.
David provides examples of potential security related events that could occur in the PLC and how these could be detected.
There is a shout out to the PLC Security Top 20 List in the Collect capability and a highlight of scan cycle time.