The Tabletop

Sean Cassidy has 25 minutes to figure out who's really inside the power grid (Live Tabletop Exercise)

Episode Summary

In this episode, host Khush Kashyap drops Plaid CISO Sean Cassidy into the following scenario: He is roleplaying the CISO at It’s Electric, a 10,000-employee utility serving customers across the country. Mid-morning on a Tuesday, a floor operator named Mike calls. His mouse started moving on its own, and by the time he grabbed the keyboard, someone had already been inside the plant’s control system and changed the configuration—changes that, left unchecked, could have cascaded into a wider power outage.

Episode Notes

You’re a CISO at “It’s Electric,” and you get an interesting call. A local power plant operator just watched his computer mouse move on its own…should he be worried? In this episode of The Tabletop, Sean Cassidy takes the hot seat and works the problem in real time.

Sean is an engineer who became a security leader. He started as a software engineer building firewalls at Cisco, co-founded the security company DefenseStorm, led information security at Patreon, and spent nearly seven years building the security function at Asana. He recently landed at Plaid, a company sitting at the intersection of consumers, financial institutions, and increasingly AI agents making financial decisions on their own. 

In this episode, host Khush Kashyap drops Sean into the following scenario: He is roleplaying the CISO at It’s Electric, a 10,000-employee utility serving customers across the country. Mid-morning on a Tuesday, a floor operator named Mike calls. His mouse started moving on its own, and by the time he grabbed the keyboard, someone had already been inside the plant’s control system and changed the configuration—changes that, left unchecked, could have cascaded into a wider power outage. 

Mike caught it manually. Then the logs widen the picture: not one compromised workstation, but three. They all trace back to a remote-access tool tied to a third-party vendor service account that was installed four years ago, never deprovisioned even though the contract expired 18 months ago, and now logging in from an IP address outside the US. Then a name surfaces: a former employee terminated six months ago whose shared credential still works.

Sean walks through scoping an OT incident with EDR and laptop forensics, why general counsel is his very first call, holding two theories at once (external actor versus insider) rather than betting early, when to pull in law enforcement, what belongs in a public holding statement, and the NERC CIP compliance exposure sitting underneath it all. Along the way, he makes the case that the real failure happened long before the incident, in the vendor and employee offboarding that nobody owns. At the end, he renders his verdict: real incident or constructed fiction?

Quotes

“This is where my mind goes from, ‘It could just be a Mike problem,’ to, oh, no, this is a real security incident.”

“General counsel is always my partner in crime. Or not crime - partner in doing it right.”

“When you’re terminating a relationship, nothing breaks if you don’t do anything. You don’t notice.”

“Usually it’s no one’s job to make sure vendors are turned off.”

“IT playbooks are really good for common events. A mouse moving on its own? That’s not in the playbook.”

Time Stamps

[00:00] Welcome to The Tabletop: Meet Sean Cassidy, CISO at Plaid

[00:18] The Rules: CISO at It's Electric, a 10,000-Person Utility

[00:56] The Scenario: A Mouse Moves on Its Own at a Power Station

[01:18] Inject One - Technical Escalation: Not One Workstation, but Three

[03:13] Your Next 10 Minutes: Scoping the Incident and Paging Responders

[03:59] Why User Reports Take a Back Seat to Forensics

[06:09] The First Call: General Counsel Before the CEO

[06:59] Inject Two - Human and Reputational Pressure: A Dead Vendor Account and a Foreign IP

[08:11] Four Years Undiscovered: The Board Conversation You Should Have Had Sooner

[08:53] Nation-State or Not: How Much to Say Before Attribution

[10:05] The Compliance Clock: NERC CIP Supply Chain and Remote Access

[11:00] The Twist: Your General Counsel Is Unreachable

[12:04] Inject Three - Values Tradeoff: A Former Employee's Name Surfaces

[12:48] Telling the CEO: Outside Attack or Inside Job?

[14:02] Law Enforcement Timing: The Cost of Moving Too Early or Too Late

[16:02] What Goes in the Public Holding Statement

[17:23] Three Weeks Later: CISA, ISAC, and the NERC Reporting Threshold

[19:11] The Moment of Truth: Real Incident or Fiction?

[20:49] Off the Table: Why Vendor Access Never Gets Cleaned Up, the OT Playbook Gap, and the Database That Vanished

Links

Connect with the guest and host on LinkedIn!

Learn more about: