Ben Miller is Director, Threat Operations Center at the industrial cyber security company Dragos, Inc. where he leads a team of analysts in performing active defense inside of ICS/SCADA networks. In this capacity he is responsible for performing a threat hunting, incident response, and malware analysis mission for the industrial community.
Previous to his role at Dragos, Inc. Ben was the Associate Director, Electricity Information Sharing & Analysis Center (Electricity ISAC) and led cyber analysis for the sector. He and his team focused on leading edge cyber activities as they relate to the North American bulk electric system. Ben was recognized as instrumental in building new capabilities surrounding information sharing and analytics in his five years at the E-ISAC. Prior to joining the E-ISAC, Ben built and led a team of 9 focused on Network Security Monitoring, forensics, and incident response at a Fortune 150 energy firm. His team received numerous accolades from industry and law enforcement. During this time he also served in a CIP implementation project and various enterprise-wide mitigation programs. Ben has over 18 years’ experience and currently holds the CISSP and GIAC GREM certifications.
Ben has served in various roles including both planner and player roles in GridEx I, II, and III. He served as a member of the NERC Cyber Attack Task Force, an acknowledged contributor to NIST SP 800-150, a panel member of the NBISE Advanced Defender panel, and adviser on CI Advanced Defender Training program. Ben is an accomplished speaker in various venues including SANS, ICSWJG, ShmooCon and others.
AKA: Millers Crossing The S4 Debates have become popular and this is a great followup from last years OT SOC or Enterprise SOC debate. Question: Are Specialized OT Tools and Talent Required to Detect Attacks on ICS? Arguing the Positive / Yes specialized OT tools and talent are required: Ben Miller of Dragos Arguing the Negative […]