Industrial Cybersecurity Insider
Industrial Cybersecurity Insider
0
Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode features insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world.
Jaksot
-
Why Industrial Cyber Risk Is Escalating (And How To Stop It) 16.09.2026 20minThis highlight episode pulls the sharpest moments from past conversations into one continuous argument about why industrial cyber risk keeps escalating and why so many programs stall before they start. Craig Duckworth and Dino Busalachi open with a number that should stop any executive team cold: one manufacturer lost roughly $500 million in valuation inside 60 hours, and that loss had nothing to do with lost production. From there the conversation gets practical. They explain why a plant floor security program cannot be run entirely from the data center, why asset inventory and communication flow mapping must come before any discussion of segmentation, and what distinguishes warranted traffic from unwarranted traffic within a control system environment. Jim Cook joins to break down the difference between a flat network and what the team calls a super flat network, where drives, flow meters, robots, and business systems all share the same space. Together, they make the case that zero trust in operational technology must be built from the bottom of the stack upward, using what they describe as the bucket approach, rather than layered over the plant with enterprise tooling that nobody on site knows how to operate. The episode closes on ownership: who is accountable, who the plant manager actually trusts, and why the people who design and build the machines belong in the room from day one. If you are responsible for production uptime and for protecting the assets that create it, this one is a fast tour of the decisions that matter most.Chapters:(00:00:00) A $500 Million Valuation Loss In 60 Hours(00:01:00) Why Industrial Cyber Risk Is More Urgent Right Now(00:03:00) Why IT Cannot Secure The Plant Floor Alone(00:05:00) Asset Inventory And Communication Flows Come First(00:07:00) Building A Defensible Architecture In OT Environments(00:09:00) Flat Networks Versus Super Flat Networks(00:11:00) The Bucket Approach To Segmentation(00:14:00) Vetting A Cybersecurity Partner The Right Way(00:16:00) Tabletop Exercises With The Executive Team(00:19:00) Who Actually Owns Industrial CybersecurityLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
The “Don’t Touch It” Problem Hiding on Your Plant Floor 08.09.2026 33minMost plants are running production on infrastructure nobody wants to touch. Somebody installed it years ago, that person is long gone, and the standing rule is to leave it alone so it keeps working.In this episode, Dino sits down with Jeff Slapp, cofounder, CTO and head of produduct development at SteelDome, to talk about what it would take to change that. Jeff has spent almost 30 years building and running data centers, starting with VMware back in 1998, and he admits that until recently he couldn't have properly defined OT, even though control systems, safety systems, and fire suppression were around him the entire time.They dig into why so many manufacturers still have hundreds of standalone HMIs, why a capital project is the real moment to think about security, and why IT/OT convergence rarely shows up in practice the way everyone talks about it. Jeff also walks through what it means to stand up a full production platform, complete with secure remote access, in about 90 seconds instead of nine months.They close on the reality that this is a people problem more than a technology problem, and why AI on the plant floor will only be as good as the foundation it runs on.Chapters:(00:00:00) If technology is not saving time, money, or mistakes, what is the point?(00:01:12) Jeff Slapp's 30-year journey from early VMware to co-founding SteelDome(00:04:35) What a universal infrastructure operating system means for the plant(00:06:24) An IT veteran admits OT was around him the whole time, and he never saw it(00:10:03) Legacy plants, standalone HMIs, and the "nobody touches it" problem(00:13:22) Kasm and secure application delivery: the missing third layer(00:18:04) Time to value: a full production platform in 90 seconds, not nine months(00:21:56) Democratizing infrastructure and where AI meets industrial security(00:25:14) Secure by design: build cybersecurity into the capital project(00:28:38) Asset inventory gaps, the IT/OT convergence myth, and closing thoughtsLinks And Resources:SteelDome WebsiteJeffrey Slapp on LinkedInWant to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
The Blind Spot Between IT and OT Isn't Where or What You Think 31.08.2026 35minManufacturing cybersecurity can't succeed when IT acts as the enforcer and OT sees security as an obstacle to production. CyberHoot founder Craig Taylor joins Dino Busalachi to explain why punishment-based awareness programs create resistance, how positive reinforcement can turn employees into an active layer of defense, and why cyber preparedness belongs beside safety, quality, uptime, and availability as a core plant metric. They discuss the overlooked role of system integrators and machine builders, the danger of unmanaged laptops and remote access, the false comfort ofair-gappedd systems, and the growing risk that AI poses to aging industrial technology. Craig also shares a simple framework called PAR, which means pause, assess, and report, and makes the case for short, practical training that rewards people for speaking up before a mistake becomes a shutdown.Chapters:(00:00:00) Why IT should empower OT(00:05:18) Connecting cyber awareness to plant uptime(00:10:04) The missing role of system integrators(00:15:07) Building a culture that rewards reporting(00:20:01) Legacy equipment, limited resources, and better incentives(00:24:06) Vulnerable plants and the air gap myth(00:29:07) Treating cybersecurity like plant safety(00:34:00) The personal value of cyber literacyLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityCraig Taylor on LinkedInFor 20% Off CyberHoot 1st Year, mention Industrial Cybersecurity InsiderDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Why Detection Alone Can't Stop the Next OT Attack 25.08.2026 32minDetection got fast, but remediation didn't. And that gap is exactly where attackers live.Manufacturers have spent the last decade building visibility into their plants: sensors, dashboards, alerts flying into every SOC. But knowing about a threat and fixing it are two different problems, and most industrial teams are still solving the second one at human speed. A ticket gets opened. A maintenance window gets scheduled. Three departments get looped in. Meanwhile, the attacker isn't waiting for anyone's approval.In this episode, Craig Duckworth talks with Tal Kollender, founder and CEO of Remedio, about what's actually keeping industrial environments exposed: misconfigurations left untouched for months, unnecessary services quietly giving attackers a path to move laterally, and aging systems nobody wants to be the one to touch. Tal makes the case that patching alone will never close this gap and explains why safe automated remediation is becoming essential as AI accelerates attacks faster than most security teams can keep up.They also dig into the reality of OT: uptime and safety come first, IT security tools often can't reach the controls layer, and the wrong change can cause real damage on the plant floor. It's a candid look at what it takes to align security and operations, and why building that trust is the real first step toward proactive protection instead of reactive cleanup.If you're responsible for securing a plant floor, a fleet of facilities, or the budget behind either one, this conversation gives you a clear, practical way to think about closing the gap between seeing a threat and actually stopping one.Chapters:(00:00:00) Why machine speed detection needs machine speed remediation(00:01:00) Tal’s path from teenage hacker to cybersecurity founder(00:06:00) Misconfigurations and lateral movement in industrial environments(00:11:00) Why patching and configuration changes are difficult in OT(00:15:00) Moving from reactive detection to proactive hardening(00:17:00) Aligning people, process, and technology(00:22:00) AI adoption, unmanaged risk, and doing more with less(00:25:00) Bridging the IT and OT divide without disrupting operations(00:29:00) The first practical step toward proactive industrial securityLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityTal Kollender on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
From NSA Threat Intelligence to Factory-Floor Cybersecurity 17.08.2026 32minCybersecurity in an industrial environment isn't just an IT concern. It's a question of whether the business can keep operating, and whether people stay safe when systems fail.Craig Duckworth talks with Tim Hoffman, a former NSA director of threat intelligence whose career spans military intelligence, defense, healthcare, finance, critical infrastructure, and industrial operations. They discuss why CMMC needs to be treated as a cultural shift rather than a compliance exercise, how CISOs earn trust with plant teams, and why leaders have to translate cyber risk into terms the board actually understands.Tim explains why tools alone can't protect OT. Craig ties digital safety back to the drills and routines plants already run. And together they look at where AI helps, where it adds risk, and why two fundamentals still matter most: clear processes and the discipline to practice them.Chapters:(00:00:00) Why Security Tools Cannot Solve Operational Risk(00:01:00) Lessons from an NSA and Mission Critical Security Career(00:05:00) Why CMMC Must Be More Than a Compliance Checklist(00:08:00) Closing the Authority Gap Between IT and OT(00:12:00) Translating Cyber Risk Into Cost and Human Consequences(00:17:00) Why OT Security Demands More Than IT Tools(00:19:00) AI, Faster Attacks, and the Need for Human Judgment(00:25:00) Start With Process and Build the Discipline to Follow It(00:27:00) Treating Cyber Response Like a Plant Safety Drill(00:31:00) People and Process Come Before TechnologyLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityTim Hoffman on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Your Most Critical Network May Be Your Least Protected 10.08.2026 33minThe air gap you're counting on probably isn't there. Dino Busalacchi sits down with cybersecurity veteran and Tulane University Cybersecurity Professor Joshua Copeland, to talk about the realities of protecting industrial environments, where uptime, safety, and production come first. They dig into why legacy systems can't be secured like IT, how routine security tasks can disrupt physical operations, the leadership gap between IT and OT, and why cybersecurity needs to be treated as digital safety. A practical listen for CISOs, CIOs, engineering leaders, and plant operators.Chapters:(00:00:00) Why operational technology is critical to everyday life(00:03:00) Legacy systems and the hidden opportunity in OT security(00:07:00) Ransomware, AI, and attacks designed for physical outcomes(00:10:00) How standard IT security tools can stop production(00:13:00) What cybersecurity events get wrong about OT(00:16:00) The leadership gap and the myth of isolated systems(00:20:00) Why cybersecurity should be treated as digital safety(00:23:00) Compliance, asset inventory, and aging industrial equipment(00:27:00) Building the next generation of OT security professionals(00:31:00) Why every part of modern life depends on OTLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityJosh Copeland on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of 04.08.2026 34minCraig Duckworth sits down with Jowanza Joseph, CEO of Parakeet Risk, to unpack why third-party risk has become one of the most urgent challenges facing manufacturers and critical infrastructure operators. Jowanza spent 15 years in engineering roles at Adobe, Pluralsight, and MasterCard before founding Parakeet Risk to serve an industrial sector he saw as the most underserved when it comes to technology. Together they address why simply knowing who your vendors are is harder than it sounds, how insurers are moving past checkbox questionnaires and demanding real evidence of controls, and what happens when contracts require you to identify a new asset in your OT environment within five minutes. They also get honest about the organizational problem few want to own: security leaders who carry responsibility for the plant floor without the authority to change anything on it. Jowanza closes with a practical, low-cost starting point for any organization and a look at where vendor attestation is headed over the next five years.Chapters:(00:00:00) Why industrial companies must become cybersecurity companies(00:02:08) Cataloging and prioritizing your most dangerous vendors(00:04:37) The hidden layers of subcontractors in your supply chain(00:06:42) Cyber insurance moves past the checkbox era(00:10:47) Contracts that demand new asset identification in five minutes(00:12:58) AI is multiplying vulnerabilities faster than solutions(00:16:31) Three hallmarks of a strong third party risk program(00:21:14) Incident response, game days, and who falls on the sword(00:23:42) Responsibility without authority across the IT and OT divide(00:28:31) Where to start today and the future of vendor attestationLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Supply Chain Risk: What Manufacturers Need to Know 27.07.2026 22minTwo global dairy producers made headlines this week after breaches that started with third party vendors.Dino and Craig break down how it happened and why it keeps happening. They walk through the reality of remote access on the plant floor, from cellular modems to TeamViewer installs nobody remembers approving, and explain why a single sensor in a plant might show you 25 percent of your assets at best. The conversation gets to the root of the problem: people, not technology. OT teams still lock IT out of critical systems, CISOs carry responsibility without authority, and incident response plans rarely account for the integrators working across multiple plants at any given moment. If you lead security for a manufacturing organization, this episode arms you with the tough questions to bring back to leadership before your company is the one filing with the SEC.Chapters:(00:00:00) - The CISO gets hung out to dry, not the third-party vendor(00:01:02) - Two global dairy producers breached through third-party vendors(00:02:12) - The messy reality of remote access on the plant floor(00:03:47) - Why IT has no visibility into what's connected in manufacturing(00:05:29) - North-south versus east-west traffic monitoring(00:06:41) - The culture problem of OT locking IT out(00:08:14) - Responsibility versus authority for CISOs(00:10:47) - The budget excuse and the real cost of downtime(00:14:32) - Incident response plans that leave system integrators out(00:18:56) - SEC filings, brand damage, and the tough questions to askLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Plant Floor Cybersecurity Starts at the Top. Not the Server Room, with Robert Maxwell 22.07.2026 30minFor industrial leaders responsible for keeping plants productive, connected, and secure, cybersecurity cannot sit only with IT. Robert Maxwell joins Dino to address the leadership and operational gaps that leave OT environments exposed, especially when aging control systems, diverse automation platforms, and decentralized plant operations are part of the picture. They discuss what it takes to move beyond fragmented ownership and point solutions: giving an accountable leader the authority to coordinate security across IT, OT, engineering, operations, and outside partners. The conversation covers practical priorities for building a durable cyber program, including organization-wide awareness, stronger visibility into industrial assets, and a security strategy that can keep pace with AI adoption. The takeaway is clear: cybersecurity is an operational investment that protects uptime, production, and long-term business resilience.Chapters:(00:00:00) Cybersecurity is a management responsibility(00:01:00) Robert Maxwell’s journey into cybersecurity(00:04:35) Why organizations need a clear cybersecurity owner(00:08:40) Building a long-term security strategy across the business(00:12:00) What happens when companies ignore cybersecurity(00:14:10) Why vendor-led security programs fall short(00:17:05) The IT and OT divide in manufacturing(00:20:00) AI, data protection, and the growing security challenge(00:23:25) Visibility gaps across manufacturing plants(00:26:20) Why leaders should view cybersecurity as an investmentLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityRobert Maxwell on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Trust But Verify: Why Every Air-Gap Claim Deserves Scrutiny 14.07.2026 30minThis week we're bringing back one of our most requested episodes, because the problem it covers hasn't gone away.Dino and Jim break down one of the most dangerous assumptions in industrial security: that OT environments are air-gapped and therefore safe. Through real examples from actual plant floors, they show exactly how that assumption falls apart, from cellular modems inside machine centers to third-party technicians on guest Wi-Fi to VPN concentrators IT doesn't know exist, and explain why the gap between IT and OT teams is just as much an organizational problem as a technical one. They also get into why point-in-time assessments aren't enough, where zero trust runs into its limits in industrial settings, and what continuous visibility on the plant floor actually looks like. If you're responsible for securing manufacturing or critical infrastructure, this one is as relevant today as when it was first recorded.Chapters:(00:00:00) - The Air Gap Myth: Introduction(00:03:00) - How OT Devices End Up Connected Without IT Knowing(00:07:00) - Why Plant Managers Bypass IT Security(00:12:00) - The Compliance and Insurance Stakes(00:15:00) - Why Zero Trust Struggles in OT Environments(00:17:00) - Bringing in Outside Experts to Find the Truth(00:20:00) - Supply Chain and Hidden Connectivity(00:24:00) - What Visibility Tools Reveal on the Plant Floor(00:26:00) - Wrap-Up: Trust But Verify, Then Monitor ContinuouslyLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
The Real Cost of Delaying OT Cybersecurity Investment 07.07.2026 35minCraig and Jim revisit one of their most practical conversations: how to build a compelling business case for OT cybersecurity budget. They break down the IT/OT ownership gap that leaves manufacturers exposed, explain how to frame liability, physical risk, and financial impact in language executives actually care about, and walk through the options every organization faces.From doing nothing to running a proof-of-concept pilot site that generates real, quantifiable data. They also tackle the role of cybersecurity insurance, why every company needs OT on its risk register, and how the concept of technology debt can finally help leadership understand the cost of decades of deferred OT security investment. Whether you're approaching this from the IT side, the OT side, or somewhere in between, this episode gives you the framework to start the budget conversation before a breach forces it.Chapters:(00:00:00) - Introduction: The High Stakes of OT Cybersecurity(00:01:00) - Why Budgeting for OT Security Is So Difficult(00:04:00) - How to Get Executives to Actually Listen(00:06:00) - Liability: Speaking the Language of Leadership(00:11:00) - Building Your OT Cybersecurity Business Case(00:13:00) - Ownership and Visibility: The First Questions to Ask(00:17:00) - Proof of Concept: Using Real Data to Drive Decisions(00:20:00) - Cybersecurity Insurance and the Third Leg of the Stool(00:26:00) - Risk Management, Roadmaps, and Playing the Long Game(00:31:00) - Technology Debt and Final TakeawaysLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInJim Cook on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Your Organization Says It's 'Green' on Manufacturing Security: Here's Why That's Dangerous 30.06.2026 22minWho actually owns OT cybersecurity? And when something breaks, who's accountable?In this episode, Craig and Dino tackle a question most manufacturing organizations still haven't answered.They address why CISOs are often handed responsibility for OT security without the authority to act on it, and how plants can score "green" on a compliance dashboard while remaining blind to 80% of their actual assets.They also dig into the role OEMs and system integrators should be playing in building security into project proposals from day one, and why most still aren't.From virtual patching for legacy systems that can't be touched, to the fast-growing OT security market, this is a grounded conversation for plant leaders, engineers, and security teams trying to close the gap between IT and OT.Chapters:(00:00:00) - Who Really Owns OT Cybersecurity?(00:02:00) - Asset Owners Bear the Ultimate Responsibility(00:04:00) - Responsibility Without Authority: The CISO's Dilemma(00:06:00) - Why OEMs and SIs Aren't Including Cybersecurity in Their Proposals(00:08:00) - The False Sense of Security Driving Dangerous Blind Spots(00:10:00) - How Organizations Claim "Green" While Missing 80% of Their Assets(00:13:00) - Half Measures vs. a Real OT Cybersecurity Strategy(00:16:00) - The Growing OT Security Market and Why Some Still Aren't Paying Attention(00:18:00) - Incident Response Drills and AI Accelerating the Threat Landscape(00:20:00) - Breaking Down the IT/OT Trust Barrier for GoodLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
It's Control System Integrity not just OT Cybersecurity 24.06.2026 18minMany manufacturers don't realize that an investment in OT Cybersecurity also enhances Control System Integrity.In this rewind episode, Craig and Dino dig into why so many OT intrusion detection platforms get installed but never become truly operational.They address what gets lost when IT owns the tool while OT owns the equipment, and why the word “cybersecurity” itself can stall progress the moment it lands on the plant floor.They land on a question every CISO, plant leader, and engineering director should be asking right now: who at your sites actually knows how to use the tools you have already paid for, and how do you bring the OT ecosystem into the room before the next outage forces you to?Chapters:(00:00:00) Cold Open: The Diagnostic Tool Sitting Unused in Your Plant(00:01:00) Shadow OT Versus Shadow IT and Why the Distinction Matters(00:02:30) Why IT Gets Left Out of Industrial Lifecycle Decisions(00:04:00) Reframing Cybersecurity as Control System Integrity(00:05:00) The 8:10 AM Production Shutdown Mystery(00:07:00) Three Rogue Servers Hiding in Plain Sight(00:08:00) A Brewery, a Misconfigured Module, and a Network No One Could Diagnose(00:10:00) Buying an MRI Machine and Refusing to Turn It On(00:12:00) Bringing the OT Ecosystem to the Table(00:15:00) Why IT Needs New Friends in ManufacturingLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Is AI Becoming Your Plant Floor's Biggest Vulnerability? 15.06.2026 27minCraig and Dino dig into the widening gap between IT and OT and why the plant floor keeps getting left behind. They break down what Dragos ' acquisition of Phosphorus signals for the future of IoT security in manufacturing, from cameras and label printers to X-ray inspection systems that ship with default passwords and almost never get patched. The conversation gets sharp on artificial intelligence: the same models helping plants work smarter are now lowering the barrier for attackers, putting Stuxnet-style capabilities into the hands of people who lack the resources and sophistication that nation states once needed. Craig and Dino expose the everyday habits that leave operations vulnerable, including system integrators plugging personal laptops straight into production networks, locked USB ports that solve only half the problem, and remote access so wide open that a single entry point can expose an entire plant. They argue that nobody truly owns OT cyber hygiene, that frameworks like IEC 62443 and the NIST 800 82 series get named in RFPs but rarely enforced, and that leaders keep tripping over dollars to pick up nickels by choosing the cheapest bid over real protection. It's a candid, experience-driven look at why industrial security moves so slowly and what plant leaders, engineers, and security teams can actually do about it.Chapters:(00:00:00) - AI Enters the OT Battlefield(00:01:30) - Why IoT Is Creeping Onto the Plant Floor(00:03:30) - Printers, Cameras, and the Default Passwords Nobody Owns(00:06:00) - Dragos, Phosphorus, and the Managed Services Question(00:08:00) - How AI Lowers the Bar for Attacking Control Systems(00:09:40) - Stuxnet Then vs. AI-Powered Attacks Now(00:12:00) - The Laptop in the Plant: Contractors, USBs, and Open Networks(00:16:00) - Frameworks on Paper vs. Reality (IEC 62443 & NIST 800-82)(00:19:00) - Tripping Over Dollars to Pick Up Nickels(00:24:00) - Short-Tenure CISOs and Why You Shouldn't Go It AloneLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Is Your IIoT Strategy Creating More Security Risks? 08.06.2026 22minCraig and Dino address one of the most overlooked problems in OT security: the IIoT devices your security tools don't automatically detect.Most OT intrusion detection platforms do a reasonable job of identifying core control-layer assets such as PLCs, drives, and motor control centers. The problem is everything else. Laptops plugged into the network, third-party devices brought in by contractors, and a growing range of connected IIoT equipment often go completely undetected. Those are the gaps where risk accumulates.Craig and Dino explain why the belief that machines are air-gapped is a dangerous myth, how PLCs acting as gateways prevent intrusion detection platforms from seeing the devices behind them, and why an asset inventory is not the same as knowing your real risk and CVE exposure in multi-vendor environments.They reframe OT cybersecurity as a process-integrity problem and show how unmanaged network activity, third-party remote access, and even routine IT security scans can quietly degrade OEE and trigger unplanned downtime that costs millions.Using predictive-maintenance analogies such as thermal, harmonics, and vibration sensing, they make the case for treating digital anomalies the same way mature plants already treat mechanical ones.They close by examining why so many OT detection tools become shelfware, how to escape alert fatigue, and the two practical paths to real IT/OT convergence: building the right relationships with OEMs, system integrators, and AEC partners, and designing security-ready facilities from the ground up.It's a practical listen for CISOs, plant and engineering leaders, and OT/IT teams responsible for securing manufacturing and critical infrastructure.Chapters:(00:00:00) - Why No Industrial Asset Is Truly Air-Gapped(00:01:08) - IoT vs. IIoT: How OT Assets Get Classified(00:03:15) - The Control-Layer Blind Spot: Drives, Robots, and Motor Controls(00:05:25) - How PLC Gateways Hide Assets From Intrusion Detection(00:07:30) - Asset Inventory Isn't Risk: The CVE Gap in Multi-Vendor Plants(00:08:55) - When Cyber Blind Spots Become Costly Downtime(00:10:05) - Process Integrity: How Security Scans Disrupt Production(00:11:35) - Predictive Maintenance Meets Digital Anomaly Detection(00:17:45) - Avoiding OT Shelfware and Alert Fatigue(00:19:45) - IT/OT Convergence: Choosing a Partner and Building Secure-by-DesignLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Five Federal Agencies. One Zero-Trust OT Briefing. Most Haven't Read it. 03.06.2026 35minThe joint CISA, FBI, Department of War, Department of Energy, and Department of State briefing on adapting Zero Trust to operational technology landed on April 29. Has OT leadership read it?In this episode, Craig and Dino address how the European Cyber Resilience Act is quietly forcing US plants into failed audits, why IT teams still see less than a third of OT assets, how EDR tools are taking down $100K-an-hour packaging lines, and why only a handful of integrators in North America have a real OT cybersecurity practice. They walk through what zero trust and micro-segmentation actually look like inside a 20-year-old plant with flat layer-two networks, DLR rings, jump boxes, and Cradlepoint workarounds, and lay out the first concrete move every CISO and CIO should make to start closing the IT/OT gap.Chapters:(00:00:00) - Cold Open: How the European CRA Is Failing US Plants(00:01:30) - The April 29 CISA/FBI Zero Trust in OT Briefing Nobody Read(00:05:00) - Compliance Without Teeth: Why US Regulations Aren't Moving the Needle(00:07:30) - When CrowdStrike Shuts Down a $100K-an-Hour Packaging Line(00:10:30) - The Visibility Gap: IT Sees Less Than a Third of OT Assets(00:15:30) - OEM Resistance: The Million-Dollar, Six-Month Cybersecurity Tax(00:18:30) - The Cradlepoint Workaround: How Plant Managers Bypass IT(00:21:30) - Layering Zero Trust onto a 20-Year-Old Plant Without Rip-and-Replace(00:25:30) - Why Only 5–10 of 1,000 Integrators Have a Real OT Cyber Practice(00:31:30) - Where CISOs Should Actually Be Looking (Hint: Not RSA or Black Hat)Links And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
IT vs OT: The Internal Misalignment Costing Manufacturers Millions 27.05.2026 34minMost manufacturing organizations still operate with a dangerous blind spot: IT and OT teams working in completely different dimensions with no shared visibility into plant floor cybersecurity.In this episode, Dino and Jim break down why 90% of manufacturers remain in the unaware-to-awareness phase when it comes to OT cybersecurity. They address what happens when IT tries to shoehorn enterprise security into operational environments they don't understand, and how the lack of collaboration between these two groups leads to costly unplanned downtime — sometimes at $100,000 per hour or more.Drawing from real client engagements, they reveal why OT must take a leadership role in cybersecurity (just like safety), how OT IDS tools can deliver operational value far beyond threat detection, and what it actually takes to get IT and OT speaking the same language before a breach forces them to.Chapters:(00:00:00) - Why IT and OT Need to Get to the Table Now(00:01:47) - Cats and Dogs Living Together: The IT/OT Culture Clash(00:03:00) - 90% of Manufacturers Are Still in the Dark on OT Cyber(00:06:00) - What Is OT and Why Don't OT People Know They're OT?(00:08:45) - Real Client Story: The Missing OT Team on a Global Kickoff(00:13:00) - Ask Forgiveness, Not Permission: How OT Workarounds Create Risk(00:15:00) - The OT IDS Tool Nobody's Sharing With OT(00:19:30) - Why Manual Discovery Assessments Are Throwing Money Away(00:21:00) - 15 Switch Manufacturers in One Plant: The Architecture Nightmare(00:25:30) - OT Cybersecurity Is the New Safety — Treat It Like One(00:29:00) - Final Advice for IT and OT Teams Ready to ConvergeLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
OT Security Isn't an IT Problem: What it Takes to Get it Right 18.05.2026 27minCraig sits down with Wil Klusovsky, a 26-year cybersecurity veteran and CRO at viLogics, to break down why asset visibility and exposure management are the foundation of any solid OT security strategy.From the myth of the air-gapped shop floor to the real-world math behind quantifying cyber risk in dollars and cents, Will and Craig explore how manufacturers can move beyond fear-based selling, bridge the gap between IT and operations, and build programmatic cybersecurity that protects both production uptime and the bottom line.They discuss how to frame cyber risk as business risk, why compensating controls and context matter more than raw vulnerability numbers, and why the CISO's real job is "chief inside selling officer."Chapters:(00:00:00) - Welcoming Will to the Podcast!(00:02:12) - Why Asset Visibility Is the Starting Point for OT Security(00:03:48) - The Air Gap Myth and Legacy Systems on the Shop Floor(00:04:52) - Translating Cyber Risk Into Dollars and Cents(00:07:05) - Quantifying Downtime: Mean Time to Recovery and True Cost of Ownership(00:09:55) - Risk Appetite: Spend to Mitigate or Accept the Exposure?(00:11:32) - Who Really Owns the Risk? Executives, Not CISOs(00:13:00) - Uptime, OEE, and Why Cybersecurity Risk Is Business Risk(00:15:45) - Remote Access Risks and Competing Priorities on the Shop Floor(00:18:04) - The "Chief Inside Selling Officer" — Getting Buy-In Before Budget(00:19:48) - The Get Out of Jail Free Card: Aligning Incentives Across Teams(00:22:30) - Context Over CVE Counts: 600 Critical Vulns, Zero Exploitable(00:25:42) - Prioritizing Remediation by Business Impact, Not Severity Score(00:26:30) - Wrap-Up and Part 2 Preview: Business Impact AnalysisLinks And Resources:Wil Klusovsky on LinkedInWant to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
OT Cybersecurity: Is the Purdue Model Still Useful? 12.05.2026 48minIs the Purdue Model outdated, or simply misunderstood? In this episode, Dino sits down with Ken Kully (Rockwell Automation) for a candid, practitioner-level conversation about what the Purdue Model still gets right.They discuss where it falls short in modern environments, and why “IT/OT convergence” remains more of a people-and-process challenge than a technology problem. They break down the reality on the plant floor: long-lived legacy systems, inconsistent architectures across sites, limited maintenance windows, and the operational consequences of downtime. The discussion also tackles the everyday friction points: MFA, shared operator accounts, unmanaged vendor laptops, and remote access “surprises”, and why you can’t improve OT security posture without a trustworthy asset inventory and segmentation that keeps systems “in their lane.”Chapters:(00:00:00) Intro + why this Purdue conversation matters now(00:01:00) Ken’s background: from process environments to OT cyber delivery readiness(00:04:00) The big question: has the Purdue Model outlived its usefulness?(00:07:00) Framework vs. strict blueprint: “Purdue enough” in real plants(00:09:00) IT/OT convergence: why it’s a people + process problem (not tech)(00:12:00) The “silver tsunami” and why security UX fails on the plant floor(00:15:30) MFA, shared logins, and why “security gets in the way” still shows up(00:18:00) Legacy reality: Windows 98/7 boxes, vendor lock-in, and downtime economics(00:21:00) Discovery first: diagrams, configs, and why documentation is always missing(00:23:30) Purdue as a map: brokering traffic, one-up/one-down, and the “3.5” DMZ(00:26:00) When devices try to “escape the box”: unexpected outbound comms + exposure risk(00:28:30) Vendor/OEM access: the unmanaged laptop problem in OT(00:32:00) Asset inventory as the unlock: you can’t defend what you don’t know exists(00:34:00) Why IT often won’t “crawl the plant,” and what that means operationally(00:36:30) Scale problem: 30 plants, 30 realities—standardize globally, execute locally(00:38:30) The SI/OEM “third leg”: why trusted integrators are key to sustainable OT security(00:40:30) Closing + crossover: continuing the discussion on Ken’s OT After Hours podcastLinks And Resources:Kenneth Kully on LinkedInWant to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Federal Agencies Can Enter Private Networks to Hunt Malware. Is Your Plant Prepared? 06.05.2026 31minDino and Jim break down a major shift in the cyber threat landscape: federal agencies obtaining legal authority to enter private networks to hunt down state-sponsored malware, and what that signals for industrial organizations. They discuss why critical infrastructure and supply chains are prime targets, how “soft targets” in OT and building automation get exploited, and why many companies still lack visibility into what’s happening on the plant floor. The conversation zooms in on real-world exposure points, especially unmanaged vendor remote access and end-of-life equipment, and closes with practical themes for leadership.Stop assuming “IT has it covered” Define measurable OT security outcomesStart taking steps that make disruption harder and detection faster.Chapters:(00:00:00) Why identity, trust, and vendor access are breaking down in modern plants(00:01:00) The episode’s trigger: government-led operations to remove malware from private networks(00:03:00) “Machete scanning” and why IT-style tactics can disrupt OT operations(00:05:00) The real target set: critical infrastructure, supply chains, and smaller utilities with limited resources(00:08:00) Collateral damage and how cyber “weapons” trickle down to criminal ransomware(00:13:00) Why OT is still a soft target: visibility gaps, unpatched systems, and weak segmentation(00:14:00) Remote access everywhere: OEM/SI pathways, unknown identities, and lack of governance(00:20:00) The logging gap: what IT sees vs. what OT can’t see (and why that matters for incident response)(00:24:00) Building automation and facilities systems as weak links attackers love(00:26:00) Executive accountability: what boards should be measuring after breaches (and why progress stalls)Links And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!
Suosittu maassa
Tämä podcast esiintyy myös näiden maiden podcast-listoilla.