


Adam S. Lee serves as Vice President and Chief Security Officer at Dominion Energy. He spent 22 years with the FBI, including as Special Agent in Charge of the Richmond Division. He is a graduate of San Francisco State University and holds a J.D. from John F. Kennedy University. He leads the company’s Corporate Intelligence and Security (CIS) organization, overseeing both physical and cybersecurity efforts.
Navigating Threats with Precision and Insight
In 2018, I retired from a 23-year career with the FBI and from government Senior Executive Service to become Dominion Energy’s first security executive. In my present role, I lead a workforce focused on security risk to the people, customers, assets and reputation of one of the nation’s most significant critical infrastructure elements. Dominion Energy provides energy resources to the National Capitol Region and the many military, USIC and commercial technology assets located there. CIS has four branches – cyber, physical, intelligence, and compliance. I also oversee the company’s aviation and travel programs and its Unmanned Systems Group.
From Risk to Resilience`
Risk comes from threats, gaps and vulnerabilities in the cyber and physical realms and can be external, internal or a combination of both. Managing security risk requires companies to effectively respond to tactical security events. More importantly, however, companies must be able to be predictive and preventative through effective strategic mitigation strategies which consider cyber and physical threat vectors. Following compliance standards, frameworks and maturity models is a good start but companies must understand their risk profile and build defences that make sense for them. Convergence of cyber and physical security is not merely shared leadership and co-location. A holistic understanding of risk that drives personnel allocation and investments is essential to effective convergence.
Instrumental Role of Behavioural Analytics and Intelligence
User behaviour analytic tools form the technology core of any effective insider threat program. Often, security leaders without experience in government, industries which serve government or the military, seek to police cyber hygiene through their insider threat programs. This renders the analysts crafting the UBA tool’s use cases as policy cops rather than threat hunters. Proactive monitoring and user behaviour analytics should be entirely focused on the witting bad actor within your company. It should not be focused on the careless policy violator. You will, of course, catch many policy violators with no intent to harm the company, but that is not who the analysts are hunting for.
Companies must attune their insider threat programs to the culture of the workforce, the leadership’s expectations of employee experience. The programs must also align with the prohibitions relative to civil rights in the workplace. CIS’s methodology is to totally anonymize the employees within the tools our analysts use. They have only a number identifier and are unaware of the employee’s identity and position within the company. They only see behaviour on the network and their use cases within the tool.
Each year, our CIS analysts build a risk register in partnership with our business segments, other internal stakeholders, and external partners (USIC, law enforcement, peer utilities, etc.) to guide our resources and budget. Yearover-year, industrial control systems (ICS) compromise is at the top of the list with the highest impact, operationally and reputationally, to the company. This is no surprise, as our promise to our customers is the delivery of reliable, affordable, and increasingly clean energy. ICS systems are those systems that control the making and moving of energy. With the grid being powered by dispatchable and non-dispatchable generation, digitally enabled controls are becoming more and more critical to the operations of every large utility. This means an expanding attack surface in operational technology. We partner with outstanding companies like Dragos to enable our identification and isolation of anomalies within ICS systems and mitigate them while maintaining operational resilience. Dragos telemetry informs the businesses, while also informing our SOC analysts within CIS’s Threat Response and Analysis Center.
Public-Private Lens on Infrastructure Security
The federal government’s response agencies (FBI, CIA, NSA, DHS-CISA, USSS, etc.) study (and investigate, in the case of the FBI and the USSS) every major cyberattack, in every company, in every sector, in the U.S., and, in many cases, in the world. I believe government experience provides an understanding and a context for nation state plans and intentions and sophisticated non-state actors’ schemes and crimes which you can’t get anywhere else. For me, this perspective started the conversation around risk and what the greatest security threats were to our company, and were we properly scoping and resourcing them. Government service alums are less likely to silo their security functions and are far more sceptical of vendor pitches for the security “silver bullet.”
There are some quality consultants in the space. We partnered with McKinsey and Company to converge our security organization and to create our Threat Response and Analysis Center. My first bit of advice, whether for engaging consultants or embarking on a converged security operating model for your organization, is to focus on the concept of risk.
Leverage technology solutions, but don’t become fixated on them. Don’t allow a culture of “gates, guards, and guns” to persist in your physical security teams. Ensure there is alignment among your security leadership team that the priorities to address are those things which could cause the greatest harm to the people, the customers, the assets, and the reputation of your company.