Industrial Cybersecurity Insider
Industrial Cybersecurity Insider
0
Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode features insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world.
Episod
-
From NSA Threat Intelligence to Factory-Floor Cybersecurity 17.08.2026 32minCybersecurity in an industrial environment isn't just an IT concern. It's a question of whether the business can keep operating, and whether people stay safe when systems fail.Craig Duckworth talks with Tim Hoffman, a former NSA director of threat intelligence whose career spans military intelligence, defense, healthcare, finance, critical infrastructure, and industrial operations. They discuss why CMMC needs to be treated as a cultural shift rather than a compliance exercise, how CISOs earn trust with plant teams, and why leaders have to translate cyber risk into terms the board actually understands.Tim explains why tools alone can't protect OT. Craig ties digital safety back to the drills and routines plants already run. And together they look at where AI helps, where it adds risk, and why two fundamentals still matter most: clear processes and the discipline to practice them.Chapters:(00:00:00) Why Security Tools Cannot Solve Operational Risk(00:01:00) Lessons from an NSA and Mission Critical Security Career(00:05:00) Why CMMC Must Be More Than a Compliance Checklist(00:08:00) Closing the Authority Gap Between IT and OT(00:12:00) Translating Cyber Risk Into Cost and Human Consequences(00:17:00) Why OT Security Demands More Than IT Tools(00:19:00) AI, Faster Attacks, and the Need for Human Judgment(00:25:00) Start With Process and Build the Discipline to Follow It(00:27:00) Treating Cyber Response Like a Plant Safety Drill(00:31:00) People and Process Come Before TechnologyLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityTim Hoffman on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Your Most Critical Network May Be Your Least Protected 10.08.2026 33minThe air gap you're counting on probably isn't there. Dino Busalacchi sits down with cybersecurity veteran and Tulane University Cybersecurity Professor Joshua Copeland, to talk about the realities of protecting industrial environments, where uptime, safety, and production come first. They dig into why legacy systems can't be secured like IT, how routine security tasks can disrupt physical operations, the leadership gap between IT and OT, and why cybersecurity needs to be treated as digital safety. A practical listen for CISOs, CIOs, engineering leaders, and plant operators.Chapters:(00:00:00) Why operational technology is critical to everyday life(00:03:00) Legacy systems and the hidden opportunity in OT security(00:07:00) Ransomware, AI, and attacks designed for physical outcomes(00:10:00) How standard IT security tools can stop production(00:13:00) What cybersecurity events get wrong about OT(00:16:00) The leadership gap and the myth of isolated systems(00:20:00) Why cybersecurity should be treated as digital safety(00:23:00) Compliance, asset inventory, and aging industrial equipment(00:27:00) Building the next generation of OT security professionals(00:31:00) Why every part of modern life depends on OTLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityJosh Copeland on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of 04.08.2026 34minCraig Duckworth sits down with Jowanza Joseph, CEO of Parakeet Risk, to unpack why third-party risk has become one of the most urgent challenges facing manufacturers and critical infrastructure operators. Jowanza spent 15 years in engineering roles at Adobe, Pluralsight, and MasterCard before founding Parakeet Risk to serve an industrial sector he saw as the most underserved when it comes to technology. Together they address why simply knowing who your vendors are is harder than it sounds, how insurers are moving past checkbox questionnaires and demanding real evidence of controls, and what happens when contracts require you to identify a new asset in your OT environment within five minutes. They also get honest about the organizational problem few want to own: security leaders who carry responsibility for the plant floor without the authority to change anything on it. Jowanza closes with a practical, low-cost starting point for any organization and a look at where vendor attestation is headed over the next five years.Chapters:(00:00:00) Why industrial companies must become cybersecurity companies(00:02:08) Cataloging and prioritizing your most dangerous vendors(00:04:37) The hidden layers of subcontractors in your supply chain(00:06:42) Cyber insurance moves past the checkbox era(00:10:47) Contracts that demand new asset identification in five minutes(00:12:58) AI is multiplying vulnerabilities faster than solutions(00:16:31) Three hallmarks of a strong third party risk program(00:21:14) Incident response, game days, and who falls on the sword(00:23:42) Responsibility without authority across the IT and OT divide(00:28:31) Where to start today and the future of vendor attestationLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Supply Chain Risk: What Manufacturers Need to Know 27.07.2026 22minTwo global dairy producers made headlines this week after breaches that started with third party vendors.Dino and Craig break down how it happened and why it keeps happening. They walk through the reality of remote access on the plant floor, from cellular modems to TeamViewer installs nobody remembers approving, and explain why a single sensor in a plant might show you 25 percent of your assets at best. The conversation gets to the root of the problem: people, not technology. OT teams still lock IT out of critical systems, CISOs carry responsibility without authority, and incident response plans rarely account for the integrators working across multiple plants at any given moment. If you lead security for a manufacturing organization, this episode arms you with the tough questions to bring back to leadership before your company is the one filing with the SEC.Chapters:(00:00:00) - The CISO gets hung out to dry, not the third-party vendor(00:01:02) - Two global dairy producers breached through third-party vendors(00:02:12) - The messy reality of remote access on the plant floor(00:03:47) - Why IT has no visibility into what's connected in manufacturing(00:05:29) - North-south versus east-west traffic monitoring(00:06:41) - The culture problem of OT locking IT out(00:08:14) - Responsibility versus authority for CISOs(00:10:47) - The budget excuse and the real cost of downtime(00:14:32) - Incident response plans that leave system integrators out(00:18:56) - SEC filings, brand damage, and the tough questions to askLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Plant Floor Cybersecurity Starts at the Top. Not the Server Room, with Robert Maxwell 22.07.2026 30minFor industrial leaders responsible for keeping plants productive, connected, and secure, cybersecurity cannot sit only with IT. Robert Maxwell joins Dino to address the leadership and operational gaps that leave OT environments exposed, especially when aging control systems, diverse automation platforms, and decentralized plant operations are part of the picture. They discuss what it takes to move beyond fragmented ownership and point solutions: giving an accountable leader the authority to coordinate security across IT, OT, engineering, operations, and outside partners. The conversation covers practical priorities for building a durable cyber program, including organization-wide awareness, stronger visibility into industrial assets, and a security strategy that can keep pace with AI adoption. The takeaway is clear: cybersecurity is an operational investment that protects uptime, production, and long-term business resilience.Chapters:(00:00:00) Cybersecurity is a management responsibility(00:01:00) Robert Maxwell’s journey into cybersecurity(00:04:35) Why organizations need a clear cybersecurity owner(00:08:40) Building a long-term security strategy across the business(00:12:00) What happens when companies ignore cybersecurity(00:14:10) Why vendor-led security programs fall short(00:17:05) The IT and OT divide in manufacturing(00:20:00) AI, data protection, and the growing security challenge(00:23:25) Visibility gaps across manufacturing plants(00:26:20) Why leaders should view cybersecurity as an investmentLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityRobert Maxwell on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Trust But Verify: Why Every Air-Gap Claim Deserves Scrutiny 14.07.2026 30minThis week we're bringing back one of our most requested episodes, because the problem it covers hasn't gone away.Dino and Jim break down one of the most dangerous assumptions in industrial security: that OT environments are air-gapped and therefore safe. Through real examples from actual plant floors, they show exactly how that assumption falls apart, from cellular modems inside machine centers to third-party technicians on guest Wi-Fi to VPN concentrators IT doesn't know exist, and explain why the gap between IT and OT teams is just as much an organizational problem as a technical one. They also get into why point-in-time assessments aren't enough, where zero trust runs into its limits in industrial settings, and what continuous visibility on the plant floor actually looks like. If you're responsible for securing manufacturing or critical infrastructure, this one is as relevant today as when it was first recorded.Chapters:(00:00:00) - The Air Gap Myth: Introduction(00:03:00) - How OT Devices End Up Connected Without IT Knowing(00:07:00) - Why Plant Managers Bypass IT Security(00:12:00) - The Compliance and Insurance Stakes(00:15:00) - Why Zero Trust Struggles in OT Environments(00:17:00) - Bringing in Outside Experts to Find the Truth(00:20:00) - Supply Chain and Hidden Connectivity(00:24:00) - What Visibility Tools Reveal on the Plant Floor(00:26:00) - Wrap-Up: Trust But Verify, Then Monitor ContinuouslyLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
The Real Cost of Delaying OT Cybersecurity Investment 07.07.2026 35minCraig and Jim revisit one of their most practical conversations: how to build a compelling business case for OT cybersecurity budget. They break down the IT/OT ownership gap that leaves manufacturers exposed, explain how to frame liability, physical risk, and financial impact in language executives actually care about, and walk through the options every organization faces.From doing nothing to running a proof-of-concept pilot site that generates real, quantifiable data. They also tackle the role of cybersecurity insurance, why every company needs OT on its risk register, and how the concept of technology debt can finally help leadership understand the cost of decades of deferred OT security investment. Whether you're approaching this from the IT side, the OT side, or somewhere in between, this episode gives you the framework to start the budget conversation before a breach forces it.Chapters:(00:00:00) - Introduction: The High Stakes of OT Cybersecurity(00:01:00) - Why Budgeting for OT Security Is So Difficult(00:04:00) - How to Get Executives to Actually Listen(00:06:00) - Liability: Speaking the Language of Leadership(00:11:00) - Building Your OT Cybersecurity Business Case(00:13:00) - Ownership and Visibility: The First Questions to Ask(00:17:00) - Proof of Concept: Using Real Data to Drive Decisions(00:20:00) - Cybersecurity Insurance and the Third Leg of the Stool(00:26:00) - Risk Management, Roadmaps, and Playing the Long Game(00:31:00) - Technology Debt and Final TakeawaysLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInJim Cook on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Your Organization Says It's 'Green' on Manufacturing Security: Here's Why That's Dangerous 30.06.2026 22minWho actually owns OT cybersecurity? And when something breaks, who's accountable?In this episode, Craig and Dino tackle a question most manufacturing organizations still haven't answered.They address why CISOs are often handed responsibility for OT security without the authority to act on it, and how plants can score "green" on a compliance dashboard while remaining blind to 80% of their actual assets.They also dig into the role OEMs and system integrators should be playing in building security into project proposals from day one, and why most still aren't.From virtual patching for legacy systems that can't be touched, to the fast-growing OT security market, this is a grounded conversation for plant leaders, engineers, and security teams trying to close the gap between IT and OT.Chapters:(00:00:00) - Who Really Owns OT Cybersecurity?(00:02:00) - Asset Owners Bear the Ultimate Responsibility(00:04:00) - Responsibility Without Authority: The CISO's Dilemma(00:06:00) - Why OEMs and SIs Aren't Including Cybersecurity in Their Proposals(00:08:00) - The False Sense of Security Driving Dangerous Blind Spots(00:10:00) - How Organizations Claim "Green" While Missing 80% of Their Assets(00:13:00) - Half Measures vs. a Real OT Cybersecurity Strategy(00:16:00) - The Growing OT Security Market and Why Some Still Aren't Paying Attention(00:18:00) - Incident Response Drills and AI Accelerating the Threat Landscape(00:20:00) - Breaking Down the IT/OT Trust Barrier for GoodLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
It's Control System Integrity not just OT Cybersecurity 24.06.2026 18minMany manufacturers don't realize that an investment in OT Cybersecurity also enhances Control System Integrity.In this rewind episode, Craig and Dino dig into why so many OT intrusion detection platforms get installed but never become truly operational.They address what gets lost when IT owns the tool while OT owns the equipment, and why the word “cybersecurity” itself can stall progress the moment it lands on the plant floor.They land on a question every CISO, plant leader, and engineering director should be asking right now: who at your sites actually knows how to use the tools you have already paid for, and how do you bring the OT ecosystem into the room before the next outage forces you to?Chapters:(00:00:00) Cold Open: The Diagnostic Tool Sitting Unused in Your Plant(00:01:00) Shadow OT Versus Shadow IT and Why the Distinction Matters(00:02:30) Why IT Gets Left Out of Industrial Lifecycle Decisions(00:04:00) Reframing Cybersecurity as Control System Integrity(00:05:00) The 8:10 AM Production Shutdown Mystery(00:07:00) Three Rogue Servers Hiding in Plain Sight(00:08:00) A Brewery, a Misconfigured Module, and a Network No One Could Diagnose(00:10:00) Buying an MRI Machine and Refusing to Turn It On(00:12:00) Bringing the OT Ecosystem to the Table(00:15:00) Why IT Needs New Friends in ManufacturingLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Is AI Becoming Your Plant Floor's Biggest Vulnerability? 15.06.2026 27minCraig and Dino dig into the widening gap between IT and OT and why the plant floor keeps getting left behind. They break down what Dragos ' acquisition of Phosphorus signals for the future of IoT security in manufacturing, from cameras and label printers to X-ray inspection systems that ship with default passwords and almost never get patched. The conversation gets sharp on artificial intelligence: the same models helping plants work smarter are now lowering the barrier for attackers, putting Stuxnet-style capabilities into the hands of people who lack the resources and sophistication that nation states once needed. Craig and Dino expose the everyday habits that leave operations vulnerable, including system integrators plugging personal laptops straight into production networks, locked USB ports that solve only half the problem, and remote access so wide open that a single entry point can expose an entire plant. They argue that nobody truly owns OT cyber hygiene, that frameworks like IEC 62443 and the NIST 800 82 series get named in RFPs but rarely enforced, and that leaders keep tripping over dollars to pick up nickels by choosing the cheapest bid over real protection. It's a candid, experience-driven look at why industrial security moves so slowly and what plant leaders, engineers, and security teams can actually do about it.Chapters:(00:00:00) - AI Enters the OT Battlefield(00:01:30) - Why IoT Is Creeping Onto the Plant Floor(00:03:30) - Printers, Cameras, and the Default Passwords Nobody Owns(00:06:00) - Dragos, Phosphorus, and the Managed Services Question(00:08:00) - How AI Lowers the Bar for Attacking Control Systems(00:09:40) - Stuxnet Then vs. AI-Powered Attacks Now(00:12:00) - The Laptop in the Plant: Contractors, USBs, and Open Networks(00:16:00) - Frameworks on Paper vs. Reality (IEC 62443 & NIST 800-82)(00:19:00) - Tripping Over Dollars to Pick Up Nickels(00:24:00) - Short-Tenure CISOs and Why You Shouldn't Go It AloneLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Is Your IIoT Strategy Creating More Security Risks? 08.06.2026 22minCraig and Dino address one of the most overlooked problems in OT security: the IIoT devices your security tools don't automatically detect.Most OT intrusion detection platforms do a reasonable job of identifying core control-layer assets such as PLCs, drives, and motor control centers. The problem is everything else. Laptops plugged into the network, third-party devices brought in by contractors, and a growing range of connected IIoT equipment often go completely undetected. Those are the gaps where risk accumulates.Craig and Dino explain why the belief that machines are air-gapped is a dangerous myth, how PLCs acting as gateways prevent intrusion detection platforms from seeing the devices behind them, and why an asset inventory is not the same as knowing your real risk and CVE exposure in multi-vendor environments.They reframe OT cybersecurity as a process-integrity problem and show how unmanaged network activity, third-party remote access, and even routine IT security scans can quietly degrade OEE and trigger unplanned downtime that costs millions.Using predictive-maintenance analogies such as thermal, harmonics, and vibration sensing, they make the case for treating digital anomalies the same way mature plants already treat mechanical ones.They close by examining why so many OT detection tools become shelfware, how to escape alert fatigue, and the two practical paths to real IT/OT convergence: building the right relationships with OEMs, system integrators, and AEC partners, and designing security-ready facilities from the ground up.It's a practical listen for CISOs, plant and engineering leaders, and OT/IT teams responsible for securing manufacturing and critical infrastructure.Chapters:(00:00:00) - Why No Industrial Asset Is Truly Air-Gapped(00:01:08) - IoT vs. IIoT: How OT Assets Get Classified(00:03:15) - The Control-Layer Blind Spot: Drives, Robots, and Motor Controls(00:05:25) - How PLC Gateways Hide Assets From Intrusion Detection(00:07:30) - Asset Inventory Isn't Risk: The CVE Gap in Multi-Vendor Plants(00:08:55) - When Cyber Blind Spots Become Costly Downtime(00:10:05) - Process Integrity: How Security Scans Disrupt Production(00:11:35) - Predictive Maintenance Meets Digital Anomaly Detection(00:17:45) - Avoiding OT Shelfware and Alert Fatigue(00:19:45) - IT/OT Convergence: Choosing a Partner and Building Secure-by-DesignLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Five Federal Agencies. One Zero-Trust OT Briefing. Most Haven't Read it. 03.06.2026 35minThe joint CISA, FBI, Department of War, Department of Energy, and Department of State briefing on adapting Zero Trust to operational technology landed on April 29. Has OT leadership read it?In this episode, Craig and Dino address how the European Cyber Resilience Act is quietly forcing US plants into failed audits, why IT teams still see less than a third of OT assets, how EDR tools are taking down $100K-an-hour packaging lines, and why only a handful of integrators in North America have a real OT cybersecurity practice. They walk through what zero trust and micro-segmentation actually look like inside a 20-year-old plant with flat layer-two networks, DLR rings, jump boxes, and Cradlepoint workarounds, and lay out the first concrete move every CISO and CIO should make to start closing the IT/OT gap.Chapters:(00:00:00) - Cold Open: How the European CRA Is Failing US Plants(00:01:30) - The April 29 CISA/FBI Zero Trust in OT Briefing Nobody Read(00:05:00) - Compliance Without Teeth: Why US Regulations Aren't Moving the Needle(00:07:30) - When CrowdStrike Shuts Down a $100K-an-Hour Packaging Line(00:10:30) - The Visibility Gap: IT Sees Less Than a Third of OT Assets(00:15:30) - OEM Resistance: The Million-Dollar, Six-Month Cybersecurity Tax(00:18:30) - The Cradlepoint Workaround: How Plant Managers Bypass IT(00:21:30) - Layering Zero Trust onto a 20-Year-Old Plant Without Rip-and-Replace(00:25:30) - Why Only 5–10 of 1,000 Integrators Have a Real OT Cyber Practice(00:31:30) - Where CISOs Should Actually Be Looking (Hint: Not RSA or Black Hat)Links And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
IT vs OT: The Internal Misalignment Costing Manufacturers Millions 27.05.2026 34minMost manufacturing organizations still operate with a dangerous blind spot: IT and OT teams working in completely different dimensions with no shared visibility into plant floor cybersecurity.In this episode, Dino and Jim break down why 90% of manufacturers remain in the unaware-to-awareness phase when it comes to OT cybersecurity. They address what happens when IT tries to shoehorn enterprise security into operational environments they don't understand, and how the lack of collaboration between these two groups leads to costly unplanned downtime — sometimes at $100,000 per hour or more.Drawing from real client engagements, they reveal why OT must take a leadership role in cybersecurity (just like safety), how OT IDS tools can deliver operational value far beyond threat detection, and what it actually takes to get IT and OT speaking the same language before a breach forces them to.Chapters:(00:00:00) - Why IT and OT Need to Get to the Table Now(00:01:47) - Cats and Dogs Living Together: The IT/OT Culture Clash(00:03:00) - 90% of Manufacturers Are Still in the Dark on OT Cyber(00:06:00) - What Is OT and Why Don't OT People Know They're OT?(00:08:45) - Real Client Story: The Missing OT Team on a Global Kickoff(00:13:00) - Ask Forgiveness, Not Permission: How OT Workarounds Create Risk(00:15:00) - The OT IDS Tool Nobody's Sharing With OT(00:19:30) - Why Manual Discovery Assessments Are Throwing Money Away(00:21:00) - 15 Switch Manufacturers in One Plant: The Architecture Nightmare(00:25:30) - OT Cybersecurity Is the New Safety — Treat It Like One(00:29:00) - Final Advice for IT and OT Teams Ready to ConvergeLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
OT Security Isn't an IT Problem: What it Takes to Get it Right 18.05.2026 27minCraig sits down with Wil Klusovsky, a 26-year cybersecurity veteran and CRO at viLogics, to break down why asset visibility and exposure management are the foundation of any solid OT security strategy.From the myth of the air-gapped shop floor to the real-world math behind quantifying cyber risk in dollars and cents, Will and Craig explore how manufacturers can move beyond fear-based selling, bridge the gap between IT and operations, and build programmatic cybersecurity that protects both production uptime and the bottom line.They discuss how to frame cyber risk as business risk, why compensating controls and context matter more than raw vulnerability numbers, and why the CISO's real job is "chief inside selling officer."Chapters:(00:00:00) - Welcoming Will to the Podcast!(00:02:12) - Why Asset Visibility Is the Starting Point for OT Security(00:03:48) - The Air Gap Myth and Legacy Systems on the Shop Floor(00:04:52) - Translating Cyber Risk Into Dollars and Cents(00:07:05) - Quantifying Downtime: Mean Time to Recovery and True Cost of Ownership(00:09:55) - Risk Appetite: Spend to Mitigate or Accept the Exposure?(00:11:32) - Who Really Owns the Risk? Executives, Not CISOs(00:13:00) - Uptime, OEE, and Why Cybersecurity Risk Is Business Risk(00:15:45) - Remote Access Risks and Competing Priorities on the Shop Floor(00:18:04) - The "Chief Inside Selling Officer" — Getting Buy-In Before Budget(00:19:48) - The Get Out of Jail Free Card: Aligning Incentives Across Teams(00:22:30) - Context Over CVE Counts: 600 Critical Vulns, Zero Exploitable(00:25:42) - Prioritizing Remediation by Business Impact, Not Severity Score(00:26:30) - Wrap-Up and Part 2 Preview: Business Impact AnalysisLinks And Resources:Wil Klusovsky on LinkedInWant to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
OT Cybersecurity: Is the Purdue Model Still Useful? 12.05.2026 48minIs the Purdue Model outdated, or simply misunderstood? In this episode, Dino sits down with Ken Kully (Rockwell Automation) for a candid, practitioner-level conversation about what the Purdue Model still gets right.They discuss where it falls short in modern environments, and why “IT/OT convergence” remains more of a people-and-process challenge than a technology problem. They break down the reality on the plant floor: long-lived legacy systems, inconsistent architectures across sites, limited maintenance windows, and the operational consequences of downtime. The discussion also tackles the everyday friction points: MFA, shared operator accounts, unmanaged vendor laptops, and remote access “surprises”, and why you can’t improve OT security posture without a trustworthy asset inventory and segmentation that keeps systems “in their lane.”Chapters:(00:00:00) Intro + why this Purdue conversation matters now(00:01:00) Ken’s background: from process environments to OT cyber delivery readiness(00:04:00) The big question: has the Purdue Model outlived its usefulness?(00:07:00) Framework vs. strict blueprint: “Purdue enough” in real plants(00:09:00) IT/OT convergence: why it’s a people + process problem (not tech)(00:12:00) The “silver tsunami” and why security UX fails on the plant floor(00:15:30) MFA, shared logins, and why “security gets in the way” still shows up(00:18:00) Legacy reality: Windows 98/7 boxes, vendor lock-in, and downtime economics(00:21:00) Discovery first: diagrams, configs, and why documentation is always missing(00:23:30) Purdue as a map: brokering traffic, one-up/one-down, and the “3.5” DMZ(00:26:00) When devices try to “escape the box”: unexpected outbound comms + exposure risk(00:28:30) Vendor/OEM access: the unmanaged laptop problem in OT(00:32:00) Asset inventory as the unlock: you can’t defend what you don’t know exists(00:34:00) Why IT often won’t “crawl the plant,” and what that means operationally(00:36:30) Scale problem: 30 plants, 30 realities—standardize globally, execute locally(00:38:30) The SI/OEM “third leg”: why trusted integrators are key to sustainable OT security(00:40:30) Closing + crossover: continuing the discussion on Ken’s OT After Hours podcastLinks And Resources:Kenneth Kully on LinkedInWant to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Federal Agencies Can Enter Private Networks to Hunt Malware. Is Your Plant Prepared? 06.05.2026 31minDino and Jim break down a major shift in the cyber threat landscape: federal agencies obtaining legal authority to enter private networks to hunt down state-sponsored malware, and what that signals for industrial organizations. They discuss why critical infrastructure and supply chains are prime targets, how “soft targets” in OT and building automation get exploited, and why many companies still lack visibility into what’s happening on the plant floor. The conversation zooms in on real-world exposure points, especially unmanaged vendor remote access and end-of-life equipment, and closes with practical themes for leadership.Stop assuming “IT has it covered” Define measurable OT security outcomesStart taking steps that make disruption harder and detection faster.Chapters:(00:00:00) Why identity, trust, and vendor access are breaking down in modern plants(00:01:00) The episode’s trigger: government-led operations to remove malware from private networks(00:03:00) “Machete scanning” and why IT-style tactics can disrupt OT operations(00:05:00) The real target set: critical infrastructure, supply chains, and smaller utilities with limited resources(00:08:00) Collateral damage and how cyber “weapons” trickle down to criminal ransomware(00:13:00) Why OT is still a soft target: visibility gaps, unpatched systems, and weak segmentation(00:14:00) Remote access everywhere: OEM/SI pathways, unknown identities, and lack of governance(00:20:00) The logging gap: what IT sees vs. what OT can’t see (and why that matters for incident response)(00:24:00) Building automation and facilities systems as weak links attackers love(00:26:00) Executive accountability: what boards should be measuring after breaches (and why progress stalls)Links And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
The Phishing Attack That Could Have Shut Down a Plant Floor 29.04.2026 26minA real-world case study shows how a single phishing email led to credential and MFA compromise, creating an urgent question for any industrial organization: Did the attacker reach the OT environment? Dino and Jim walk through how OT visibility, secure remote access controls, and continuous monitoring enabled rapid validation of what happened. They were able to prove the breach did not impact control systems and avoid an expensive, safety-driven shutdown of a continuous manufacturing process. The episode connects technical controls to executive outcomes, including resilience, duty of care, and the financial reality that “not knowing” can be as costly as an actual compromise.Chapters:(00:00:00) Why continuous manufacturing makes “abundance of caution” shutdowns so costly(00:01:00) What “OT continuous monitoring” means and why it matters in real incidents(00:03:00) Safety and connected environments: why “it can go boom” changes the stakes(00:05:00) Baselines: defining “normal” so abnormal behavior is actionable(00:07:00) Incident story: phishing email leads to credential and MFA compromise(00:09:00) What the team validated: tracing access and confirming OT was not impacted(00:10:00) Lessons from Colonial Pipeline: inability to validate can force shutdowns(00:11:00) OT reality check: Windows assets, HMIs, historians, and engineering workstations(00:13:00) Secure OT remote access: why VPN-only access is not sufficient(00:16:00) The payoff: avoided downtime, avoided product loss, and avoided disruption(00:19:00) Executive view: duty of care, liability, compliance, and protecting enterprise value(00:23:00) The “air gap” myth and why defense-in-depth is the only practical pathLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Your Most Valuable & Underutilized Cybersecurity Asset 21.04.2026 25minIn this episode, Dino and LuRae address why system integrators, OEMs, and ecosystem partners are often a manufacturer’s most underused cybersecurity resource. Dino explains why many IT leaders lack real visibility into the plant floor, what it takes to operationalize OT security beyond “checking the box,” and why asset inventory is the first practical step toward protecting control systems. The conversation also covers the realities of remote access after COVID, the need for governance measures such as change control and auditing, and why manufacturers should build real partner relationships rather than purely transactional vendor engagements.Chapters:(00:00:00) OT security requires time inside the plant, not an “ivory tower” view(00:01:00) Introducing Dino and the topic: partners as a cybersecurity asset(00:02:00) Why OT assets get excluded from cybersecurity strategy(00:03:00) The real opportunity: system integrators and OEMs already in the plant(00:05:00) Getting started: identify who’s working in each facility(00:08:00) Step one: accurate OT asset inventory and visibility(00:10:00) Remote access: detect, audit, and control what partners are doing(00:12:00) “Compliance” vs. operational reality on the plant floor(00:16:00) Resourcing reality: why most teams cannot self-perform OT security(00:20:00) Final advice: budget, ROI of downtime, and act before the incidentLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
OT Patching vs IT Patching: What's Commonly Misunderstood 14.04.2026 27minMost cybersecurity teams treat patching like a universal fix. In manufacturing, that assumption can take down a production line, trigger a safety event, or void the warranty on a $2 million piece of equipment.In this episode, Dino Busalachi and Craig Duckworth break down why patching in operational technology environments is a fundamentally different problem than patching enterprise IT — and why closing that gap requires more than just pushing an update.The bottom line: A firewall is not a patching strategy. Neither is hoping your systems are isolated. Organizations that get this right use risk-based prioritization, lab testing, virtual patching, and real collaboration between IT and OT teams.If you are responsible for a plant floor — or for the people who are — this conversation is for you.🎙️ Industrial Cybersecurity Insider is where C-suite leaders, plant managers, engineers, and security teams come to close the gap between IT and OT.🔔 Subscribe so you never miss an episode.Chapters:(00:00:00) Why assessing OT cybersecurity posture and asset visibility is hard(00:01:00) IT patches constantly, OT rarely does, and why that gap matters(00:03:00) Downtime costs: a broken patch in OT can stop the entire plant(00:05:00) OEM “don’t touch it” policies and warranty pressure(00:08:00) M&A due diligence: buying plants without knowing the cyber condition(00:09:00) CrowdStrike outage example and why agent-based tools are risky in OT(00:10:00) Virtual patching: protecting PLCs and legacy assets you cannot patch(00:14:00) Vendor guidance, upgrade rewrites, and “acceptable risk” decisions(00:17:00) Hidden exposure: guest Wi‑Fi, tablets, remote access, and “air gaps”(00:20:00) Best practices: inventory, continuous monitoring, vulnerability metrics, and cross-team alignmentLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review! -
Who Actually Owns OT Cybersecurity? Not Who You Think 06.04.2026 30minDino and Craig break down what they are seeing in real industrial environments as companies begin the OT cybersecurity journey. They outline why most organizations are still in an “unaware to awareness” phase, what creates the “oh wow” moment after the first pilot, and why ownership and execution often falls to plant-floor teams and their OEM and integrator partners.The conversation covers the limits of surface-level visibility, why accurate asset inventory and remote access control are foundational, and how practical constraints like flat networks, legacy switches, warranty concerns, and limited human capital can stall progress.They also share cautionary examples of IT-first security tooling causing operational impact, and they close with a clear message: think globally, act locally, and build a defensible OT program that matches how plants actually run.Chapters:(00:00:00) Why OT vulnerabilities and remote access are the real “kicker”(00:01:00) The market reality: 60% unaware, 30% starting, 10% operationalized(00:03:00) Who owns remediation: IT vs OT and the plant-floor accountability gap(00:05:00) Why “visibility” often stops at Purdue Level 3 and misses Level 2 assets(00:07:00) OEMs, integrators, and why support models matter in OT cybersecurity(00:09:00) Flat networks, north-south traffic, and why you still miss panel-level devices(00:11:00) The human capital problem and why outsourcing is often unavoidable(00:18:00) A real-world warning: EDR in ICS can create massive operational cost(00:20:00) Safety, quality, and cybersecurity: the three things leaders will fund(00:24:00) Change management failures and why monitoring PLC edits mattersLinks And Resources:Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInThanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!
Popular di
Podcast ini turut muncul dalam senarai podcast negara-negara ini.