Imagine, the power goes out, not for a moment, but for days. And the reason is not extreme weather, but a cyber incident. Hello and welcome to the second episode of the Caesar Prospectus. I'm Berthold Kerl, CEO of KuppingerCole, a leading analyst firm in the middle of Europe, and we are focused on identity and cybersecurity. In this series, I speak with leading security executives about how we can protect the digital foundations of our economy and society.
As you know, a breach caused by a cyber attack, a compromised supplier, a faulty patch rolled out, or a disruption deep in the digital supply chain is a real threat. And for security leaders in critical infrastructure, this is not only a business problem. It is a problem for potentially millions of people who depend on energy to heat their homes, run their hospitals, basically keep their lives moving. To discuss this, I can't think of anyone better than this my guest today, with someone who lives this responsibility every day.
I welcome René Rindemann, CISO of E.ON, one of the leading energy companies in Germany and across Europe. René, great to have you with us.
Berthold, thank you very much. And let's hope that the doomsday scenario that you painted at the beginning will never, ever happen. Let's do so.
Yeah, before we go deeper into the questions, I'm sure the audience is interested to hear something about you. So you are CISO at E.ON. What does cybersecurity responsibility actually look like there and how would you describe your role as a CISO?
Yeah, happy to do so. So let me first explain a bit how we are structured within E.ON. So we are structured in three segments. The first segment is energy networks, where we operate electricity and gas networks, 1.6 million kilometers of grid. The second one is customer solutions. We are serving approximately 47 million customers across Europe.
And the third segment is what we call energy infrastructure solutions, where we are creating solutions that help our customers to decarbonize, to make use of heat, to, for instance, create electricity, where we are supporting data centers with additional power connection if they cannot be connected to the grid at the moment. So this is how we are structured. Cybersecurity. So my team is looking after all these three segments.
Where, as you rightly said, we have critical infrastructure in. I tend to say it's really the mother of critical infrastructure because without electricity, nothing will work anymore, unfortunately.
And hence, we have a big responsibility towards society. And my team consists out of approximately 300 cybersecurity experts looking after these three segments. And in these three segments, we have IT and we have OT. And we are one cybersecurity organization that is looking after both. So we don't separate between IT and OT. It's different. It has different requirements concerning the security. But nevertheless, we treat them both the same with the same team. But there's an interesting point, because that is clearly a differentiating factor compared to other industries.
And as far as I know, the speciality of OT is that these systems are often decades old. And therefore, were never built for a connected world. Is this a special problem or challenge to you?
So, yes, that was the myth, let's say, 10 years, 12 years back. Everyone was always saying OT is so different because the systems are so old. Already when we created the unit back in 2014, we said like, this will definitely change. And already at that point in time, it was changing.
And hence, we took the decision that we put the responsibility for both IT and OT security into this one cybersecurity function. It turned out that this was the right decision. Why? Because with the digitization, we are now seeing that the speed of change of technology in OT is increasing heavily. Yeah. So we see the speed increasing, but we also see or maybe due to this, we also see more and more convergence of IT and OT. These long investment cycles are over. We are investing way faster in OT technology. We are very often using classical IT technology also in OT.
The protocols are in the meantime, I would say to 80, 90 percent based on IP. So we see a very, very clear convergence.
And hence, it's almost the same technology and you should apply similar or the same security measures, but be a bit more careful when it comes to changes in this critical environment. Yeah, let me come to talk about the threat, which is not new.
However, it is still all around us. Yeah. Ransomware remains to be one of the most pressing issues, especially for critical infrastructure in particular. I think 50 percent of the global ransomware attacks are targeted towards infrastructure still. And I know a study which says that in 2035, two thirds of all energy and utilities organizations were hit by ransomware. How do you look at this threat? It is definitely one of the biggest threats, maybe even the biggest one. What we also see more and more due to the geopolitical situation is really targeted attacks by nation state sponsored actors.
But these two are definitely the main threats, not only for us, I would say, also for others. And concerning the stats that you have just quoted, I am always a bit careful because I'm asking myself if the classical ransomware attacker in the morning is standing up and then saying, OK, today I will attack critical infrastructure and is then maybe not successful over weeks or months, or if he or she is just standing up in the morning and just starting attacks. And if by accident, critical infrastructure is on the hook, it's nice because then maybe more money can be asked or requested.
But that is always for me the question, is it really targeted on critical infrastructure or is it just a bycatch that critical infrastructure was targeted and hit by such an attack? Nevertheless, threat number one. Yeah. Yeah. In order to protect you for that, but not only for that, I think you have, like many other big organizations, probably accumulated a slew of tools over the years, potentially overlapping functions, high integration effort, growing complexity to manage this all. When you think about tool modernization, what is the real objective?
Is it about chasing the latest and the greatest, placing whatever feels outdated, or is it more about simplifying the architecture or driving down costs and complexity? So what are your priorities in that regard? So let me first look at tooling and technology in IT and OT, and let's put cybersecurity aside for a moment. So looking at technology in IT and OT, for me, the main benefit there is really standardization. And with this standardization, also centralization, and with this reducing the attack surface to a minimum. I'm always comparing it with children.
It's easier to look after one or two children than to look after 10 or 12 children. And hence, one should challenge why a company does need 12 email systems or 20, and not only one or two, just to give you an example. Why a company does need 5, 10, 15 different billing systems, and not only one or two. Why a company does need so many different file sharing systems, and so on and so on. So looking at IT and OT, it's clearly standardization, centralization, and hence, reducing the attack surface.
Of course, you would also save money with it. But that is my reason why I heavily push, and luckily everyone is supporting this in our organization for standardization. Looking at cybersecurity, I mean, everyone working in cybersecurity knows all these calls and emails coming from different vendors where they want to upsell. You are right, we have quite a bunch of cybersecurity tools in our organization. And one and a half years ago, we called out the time of consolidation. So at that point in time, we said, no, we will not invest into additional cybersecurity tools.
We will first ensure that we use all the tooling we have to at least 80%. That is also a reason why we are not investing in any AI or agent AI tooling, cybersecurity tooling, because we are saying, hey, we have so many tools, and they all can play a role in securing agents and AI that we are now using these existing tools. You mentioned a very, very important point, which is standardization, which somehow leads to consolidation. So how comfortable are you really with the fact that most of the security tools we all rely on come from one country, the US, or at most tools you add, Israel?
Doesn't that create dependencies? Yes, it does. And it's definitely a buy-in, or a lock-in, a lock-in that's developed over the last years where we had the US as a partner, as a reliable partner. I still think that we will continue having this reliable partner. So I'm convinced that the US will not use these tools against us. Why? Because it would massively harm the economy in the US, and it would be against the Make America Great plans of Mr. Trump.
So hence, yes, it is an issue, and yes, we have to catch up in Europe. But it is a risk that we, for the time being, have to simply accept. I think we are using one or two cybersecurity solutions indeed from Europe, but you're right, the remainder is mainly from the US. Now you triggered me to ask this follow-up question. So if you look for new tools or new capabilities, and you have the choice between an equal choice, obviously, of a European company, would that trigger you to go for the European solution then? Hard to answer.
It would be definitely something that we would consider during the tender, yes. Is it my main criteria? I would say no, because for me, it's more important that the tools are integrating into other tools properly, and that the tools are also integrating properly into IT and OT systems.
Yeah, but definitely something we would bear in mind. As you know, we at Kupping & Kohl, we come from the identity angle, identity security, etc. And when you look at, again, the stats of the cyber attacks, the majority had to do in some way or the other with stolen credentials or misused access rights, etc. What is your view on the importance of identity, identity management for both IT and OT?
Yeah, I mean, it's super important. Maybe it's even the most important. It's one of the pillars in the zero trust concept. And this is why we have a strong focus on it. So super important.
Also here, coming back to your previous question, difficult to find solutions not coming from the US, especially when you are in the Microsoft environment. So from a technology point of view, from a threat point of view, it's super important. So you mentioned zero trust. So I guess that you are now really implementing it or have implemented it. So it's not just a marketing term. It's an important concept you are following. Correct. Zero trust is not new and actually we are following it already, not under this term of zero trust, but we were building into the same direction for years.
Have we implemented it fully? No, I think no one really has it implemented fully, but it's super important that whatever you do, you follow this concept in order to make it more and more complete. Now we have talked a lot about old concepts or old things like ransomware and zero trust.
Now, something a little bit newer, AI, obviously, we can't have a discussion without talking about AI and of course, we all know it can be used as an attack tool, but also as a defense instrument. So where do you see the opportunities or threats coming from AI?
Yeah, let me first come back to your question regarding US-American tools, Israeli tools, European tools. So I think we as Europeans need to really speak with how we treat AI, because as you rightly said, it has its upsides and its downsides. I think we have, with the AI Act, looked too much at the downsides and this is why it's not now hard for us to really make use of AI. So that's a kind of bureaucracy we need to urgently change, because the bad out there, they are not caring about any AI Act, they just use it against us.
And if we want to be able to defend us also with AI, we have to have less hurdles to do so. I'm not talking business opportunities that we might lose due to these regulations.
So, but coming back to your question, we are using already for a while AI to also defend us. We have different toolings in place that we are using. I have to admit that we are also playing around a lot, because all the AI solutions that are offered in the market are, when you look deep into the details, not as mature as you were promised that they are. But we are using it and we will continue using it also to overcome the resource scarcity, to ensure that we are faster in replying to attacks. I think that the one people where you can be sure that they are using AI are the employees, right? Yes.
And of course, as much as this drives productivity, it is also a growing security risk and it's called shadow AI, basically. So how do you deal with that? When you look at the strategy of E.ON, we have digitization and growth besides sustainability in our strategy, and you cannot digitize and you cannot grow with digitization if you are too strict in what your employees are allowed to use and what not. And I think you also have to trust your employees. They think about what they are doing.
So what we have done is we have given out guardrails to all our employees, but we have not blocked anything. There is one AI that we have blocked, so that cannot be used within E.ON anymore, but all the others can be used, but with awareness, with talking, with explaining, our colleagues get some guardrails and we trust that they play around with it in order to support the strategy and to help E.ON grow.
Yeah, so the trust is here, your main approach to deal with this problem, yeah. And trust, but also creating awareness, educating our colleagues.
Yeah, so I think as a CISO, the first focus naturally is to preventing damage from happening in the first place, but let's be honest, in a world of ransomware, supply chain attacks or whatever, the question is not how do we prevent an incident, it's also how do we stay operational when it happens. Now, I know that you just recently also assumed now the role of the Business Continuity Management at E.ON, so how do you bring these two worlds, that's a good opportunity to bring these two worlds together, I think, yeah, so how are you going about that?
When we started investing in cyber security back in 2014, we were focusing 100% on prevention and one of the reasons why we started investing was because we realized you cannot prevent anything, everything, things will happen and then it's important that you detect those very fast, that you react to those very fast.
And that was also one of the reasons why we have now done a reorganization, because during several crisis management trainings that we conducted over the last two to three years, we always came to this point, okay, and now how would we recover, what would we do, what is our minimum viable company, what is the right order to bring the systems back up and running.
Have we done enough testing, disaster recovery testing, but also testing our Business Continuity Management plans and so on, and actually we came to the conclusion, maybe not, yeah, and hence we said we need to put more focus on it and we need to strengthen this organization. And it also makes sense to put this organization very closely together with cyber security, because we are protecting these systems, we are monitoring these systems that are underlying our critical business processes.
Yeah, so this year, next year is a very, very strong focus here on Business Continuity Management that started with this reorganization. And for me, it's key.
I mean, we all remember the, I think it was the first big ransomware attack against Mask in, when was it, 2017? I think in our cyber security community, almost everyone talked to the CISO of Mask in the meantime, and he's always saying that the most important thing is Business Continuity Management recovery and building your minimum viable company.
So, that's a good bridge to my next question. So, crisis exercises are well-established, they are also demanded by regulation, but they can easily become a routine obligation.
So, what makes an exercise really valuable in your view? So, how do you make sure that it's not just a checkbox activity? We are putting very, very much effort into the preparation of those exercises and make them very different to the last exercise.
So, sometimes we are exercising only, let's say, with a group-wide crisis management team. Yeah, so basically the headquarter only. The next time we do it together with one business unit or with two business units, then we take an international business unit to it. In the next weeks, we will also do it with one of the TSOs in Germany jointly. And having always these different setups and these different trainings, that makes it really interesting. And I think I speak also for my dear colleagues, they all love it. We always have good fun, but it's also hard work.
But we really see that we become better. And so, for us, this is not only a tick in the box. It's really important because we know about our responsibility towards society and hence we take this really seriously. Thank you.
Now, I have a personal, quite personal question to you. Burnout and high turnover among TSOs are rather tremendous problems across all industries, not just energy or critical infrastructure. Do you have a personal recipe how to deal with that? Yes. My personal recipe is don't take yourself too seriously. Because everyone is replaceable and you have done a good job when you make yourself obsolete in the organization. And I'm regularly practicing and training also this. I'm just coming back from a four weeks vacation in Australia and my team did a brilliant job and kept all our lights on.
And this is my recipe. I think very often we are really thinking like we are not replaceable and thus we have to work again and again and show how important we are. And that's not healthy. So it's rather thinking about make yourself obsolete in the organization, then it's still secure, still resilient, then you have done a good job. Thank you for this honest answer.
Now, as last time, I always try to do a quick fire round. So a short questions where you have the opportunity for spontaneous answers, whatever comes to your mind first.
Yeah, so, all right, so then that's all I know. I'm curious.
It's, it's, it's going to be fun. Okay, so the first one is cyber security budgets gets cut. What do you cut first?
Oh, that is not fun. That is a hard question. What do I cut first? Just what comes to your mind. I think everyone has in the organization, some topics that are kind of the icing on the cake. And this is what I would reduce. If I would now say I would reduce trainings in our cyber range, that would not be good and not be fair. And my colleagues would be very angry with me. Same as if I would say I would cut on awareness. Same as if I would say I would cut on penetration testing. So I think I would cut something everywhere because everyone is doing a bit too much.
That maybe we can stop doing without losing too much maturity. Thank you, good answer. A Caesar from Europe and a Caesar from the US. Where do you see the biggest differences in mindset? I think the Caesar from the US are very, very compliance focused. I see Caesar from Europe being more business focused. And that does not mean that they are not compliant. But the business support is definitely there. And that does not mean that they are not compliant. But the business support is their first priority and compliance is the second. All right.
Which password in cybersecurity should be abolished immediately? But there are so many.
Currently, I would say resilience. All right. It's not only cybersecurity, but resilience is for me very buzzing currently. What was the most important moment in your career that shaped you as a security dentist? I would say feeling and seeing the trust and the backing of the board. And also from our colleagues when we were in an attack situation and how we collaborated during this situation, that really shaped me because I realized that when the shit hits the fan, we bring all hands on deck and then we work together. So that shaped me the most. Ransomware payment.
Never under any circumstances or does it depend on the situation? Never. Who do you trust less? You sort of answered that already. Who do you trust less? A hacker or a compliance officer? Can I have a joker? Because I don't want to mess up with our compliance officer. Right. I appreciate that.
Yes, of course, the hacker. What is the first thing you check in the morning and what should you actually check first? I think the first thing you check in the morning is the security of your system. Should you actually check first? The first thing that I check in the morning is the temperature of our coffee machine. And when it's at 124 degrees, then I pour my first coffee. All right. So it's not work? It's not security related? No.
Typically, seriously, the coffee is the first thing. And then I read the news a bit, but also not too much. I also try to take the time in the morning to really get up to speed. My final question.
Obviously, we also have some younger listeners or watchers here. What is your recommendation to the people who are about to start their career in cybersecurity?
Yeah, one thing I said already earlier. Don't take yourself too serious. Really look after yourself. Mental health is super important and it will also help you to make your career. Be curious. Be brave. Just do things. Don't ask for permission always before you do something. And then just get things done. I think you can show the best of you just by getting things done and by delivering. And that's super important. And when you do this, then my experience is that you could get also promoted because of that. These would be my three things to consider for young talents in their early career.
René, thank you for being with us and for those very direct answers. Very much appreciated. From what I take away from this conversation is that cybersecurity in critical infrastructure is not just a technology problem, but it's also a leadership challenge. It contributes to that challenge. And staying operational when the world around you becomes unpredictable is, of course, very, very important.
René, thank you very much. It was a good discussion. And I also thank everyone watching this episode of the CISO Perspective. If you find this valuable, share it with someone who should hear it as well. We'll be back soon with the next episode. Until then, I know you don't like it, René. Stay resilient.
Thank you, Bernadette. And thanks for listening, colleagues. Bye.