Note: When I found this and saw that the CFP closes in two days, I made a submission at work. It was not "detailed," as I was at work and didn't have much time to spend on it. This is a more detailed description of the same proposal.
Introduction - How I ended up involved in ICS security
What are Industrial Control Systems?
SCADA and Me - Comic for "children and managers"
Why should you be interested in ICS?
"Cyber is the new squirrel" - It gets blamed for every power outage
What protocols are we talking about?
There's more, these are the ones I'm most familiar with from the electric industry.
CIA Triad
ICS thinks about Availability 90%, Integrity 9%, and Confidentiality 1% (if that)
"Insecure by Design"
Lack of authentication in pretty much every protocol
Why do electrical engineers dislike us security people?
Ego - Hackers can be pompous assholes (nobody in this Room, I'm sure)
Transition - So how do you get involved in ICS security?
Free Tools
Shodan
Free CTFs
How are these different than "traditional" CTFs?
Free Training
DHS stuff - Highlighted by Idaho National Lab's Red Team/Blue Team exercise
Other Training/Events
4SICS - Sweden (Not close by, not even a little)
Most Important - Relationships
After spending five years teaching middle school and high school, Brandon Workentin switched careers and got a degree in Cybersecurity and Networking. Like most programs, this was very IT-centric, but his first job in the new career was at a non-profit focused on cybersecurity in the electric sector. He received a crash course in DNP3, Modbus, and why control system operators don't like security people.