Critical Assets Podcast
Patrick Miller
0
The Critical Assets Podcast explores operational technology (OT) and industrial control system (ICS) security, with a focus on the standards and regulations that shape the field. Host Patrick Miller and his guests discuss practical ways to stay ahead of both adversaries and auditors. Episodes cover cybersecurity issues relevant to critical infrastructure and industrial environments. The show is produced by Ampyx Cyber, which also publishes related blogs and cybersecurity news at ampyxcyber.com.
Епизоде
-
Turning Cyber Risk Into a Decision You Can Defend 15.08.2026 49минPatrick Miller sits down with Scott Kannry, co-founder and CEO of Axio, to work through cyber risk quantification as a security decision tool for OT and critical infrastructure. Scott came up in the insurance industry at Aon in the early days of cyber coverage. He founded Axio with Dave White to close the gap between a technical security program and a number a CFO and a board can act on.The conversation stays practical. Why you start on the impact side instead of arguing about probability. How NERC CIP already thinks in consequence. Why the events that matter most are rare, huge, and short on data. How to compare controls, insurance, and compliance spend on the same dollar scale. What AI and quantum do to the "it will never happen" excuse. And a new D&O option for CISOs built on top of consistent quantification.Full show notes, links, and the episode transcript are on the Ampyx Cyber episode page at ampyxcyber.com/podcast.Topics covered:The founding of Axio and the insurance-meets-frameworks originA short history of cyber insurance, from data breach to business interruption to cyber-physicalThe four loss categories Axio uses, first and third party, financial and tangibleCoverage gaps for industrial facilities and the danger of assumed coverageImpact-first quantification versus probability-first modelingNERC CIP and consequence-only risk ratingFiduciary duty, duty of care, and defensible decisionsSecurity decision support versus vanity security metricsThe art and science of pricing control ROIAI and quantum, and why low-probability high-impact events deserve attention nowA D&O insurance option for CISOs tied to consistent quantification -
The Attack Surface You Eat: Cyber Risk in Food and Agriculture 08.07.2026 1ч 10минThe Attack Surface You Eat: Cyber Risk in Food and AgricultureKristin King joins Patrick Miller to make the case that food cybersecurity is not food security, and that food and agriculture is one of the most under-defended corners of critical infrastructure. From precision agriculture and processing plants to aquaculture, zoos, and aquariums, they trace where the OT and ICS risk actually lives, why the regulatory floor is so thin, and how the threat range runs from opportunistic ransomware to nation-state targeting and agroterrorism.Guest: Kristin King, founder and CEO of AnzenSage, CEO and co-founder of AnzenOT, host of the Bites & Bytes Podcast, and author of Securing What Feeds Us: Cybersecurity in Food and Agriculture (Wiley).Full show notes and every source referenced in this episode: https://ampyxcyber.com/podcast/the-attack-surface-you-eat-cyber-risk-in-food-and-agricultureGuest links AnzenSage: https://www.anzensage.com/ Bites & Bytes Podcast: https://www.bitesandbytespodcast.com/about Kristin King on LinkedIn: https://www.linkedin.com/in/kingmkristin Securing What Feeds Us (Wiley): https://securingwhatfeedsus.com/ -
Policy Pulse: Regulatory Roundtable - Cyber Strategy, Large Loads, AI & CISA in Flux 11.05.2026 1чPatrick Miller reconvenes with Joy Ditto (Joy Ditto Consulting) and Earl Shockley (INPOWERD) for a tour of the past two months in critical infrastructure policy. The episode opens on the administration's new National Cybersecurity Strategy and its six pillars, with focus on the openly offensive "shape adversary behavior" posture and the asymmetric risk it creates for asset owners likely to absorb retaliation.The panel then digs into the pressures reshaping the bulk electric system: data center designation, cloud-hosted control centers running NERC standards while the underlying compute is unregulated, and the physics of computational loads that behave nothing like traditional load. Earl walks through the recent NERC Level 3 alert on large load connections, an unusually serious signal that industry processes are behind.The discussion also covers April infrastructure executive orders that release funding but ignore cybersecurity, hyperscalers displacing utilities as the top buyers of bulk electrical equipment, the multi-agency zero trust in OT guidance, and CISA's leadership uncertainty after Sean Plankey withdrew his nomination. On the AI front, the group unpacks what Anthropic's Mythos and the Glasswing response mean for vulnerability discovery at scale, and why no OT vendors are on the Glasswing list.Closing thoughts include Joy's note on satellite cybersecurity and a rare bipartisan Senate trip to China, Earl's emphasis that computational load is now an enterprise governance issue rather than a technical one, and Patrick's plea to stop making the adversary's job easy.Topics coveredThe new National Cybersecurity Strategy and its six pillarsOffensive cyber posture and the asymmetric risk to asset ownersData center designation as critical infrastructureCloud control centers and the NERC 100-series standardsComputational load, grid stability, and loss of system inertiaNERC Level 3 alert on large load connectionsApril infrastructure executive orders and the missing cyber languageSupply chain shifts and hyperscalers as the top equipment buyersZero trust principles for OT environmentsCISA Fortify guidance and CISA's current leadership statusAnthropic's Mythos, the Glasswing response, and the OT vendor gapSatellite cybersecurity and bipartisan engagement on China policyBasic hygiene: get exposed devices off the internet -
Policy Pulse: Regulatory Roundtable - NERC CIP, Cybersecurity Strategy, AI & Electric Sector 01.02.2026 1ч 2минWelcome to the Policy Pulse Panel, a new monthly series within the Critical Assets Podcast. Hosted by Patrick Miller (Ampyx Cyber), Earl Shockley (CEO, Inpowerd), and Joy Ditto (CEO, Joy Ditto Consulting), this recurring panel dives into the most significant policy shifts and regulatory developments impacting critical infrastructure, operational technology (OT), and industrial cybersecurity. Each month, we unpack emerging legislation, agency actions, and standards updates - connecting the dots between policy and the practical realities faced by asset owners, utilities, vendors, and government partners. If you're trying to stay ahead of your auditors and your legislators, this is your monthly must-listen.https://ampyxcyber.com/podcast/policy-pulse-regulatory-roundtable-nerc-cip-cybersecurity-strategy-ai-electric-sector -
Vulnerability Overload: Making Prioritization Work in the Real World 20.07.2025 35минIn this episode, Patrick Miller speaks with Kylie McClanahan, CTO at Bastazo, about the practical (and often messy) realities of patch and vulnerability management in operational technology (OT) environments. Kylie shares grounded insights into patching challenges, the gaps between IT and OT remediation cycles, and the real-world implications of relying too heavily on scoring systems like CVSS.The conversation covers CISA’s Known Exploited Vulnerabilities (KEV) catalog, exploring how it’s being used (and possibly misused) in prioritization workflows, and where the disconnects lie between policy directives and operational feasibility. Kylie also critiques the current state of vendor responsiveness, machine-readable vulnerability disclosure (CSAF), and the importance of asset and exposure awareness.This episode is essential listening for practitioners wrestling with patching fatigue, program prioritization, and the tradeoffs between theoretical vulnerability data and applied security outcomes in critical infrastructure environments.Links:CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilitiesCISA vulnrichment: https://github.com/cisagov/vulnrichmentVulnrichment, Year One: https://www.youtube.com/watch?v=g5pSVMnWD7kCISA SSVC: https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvcCarnegie Mellon SSVC: https://certcc.github.io/SSVC/CSAF: https://www.csaf.io/VulnCheck KEV: https://vulncheck.com/kevKylie McLanahan on LinkedIn: https://www.linkedin.com/in/kyliemcclanahan/Bastazo: https://bastazo.com -
From CISO to Startup: OT Security, Leadership, and Lessons from the Field 13.04.2025 44минIn this episode of the Critical Assets Podcast, Patrick Miller interviews Darren Highfill, former CISO of Norfolk Southern, for a candid look behind the curtain of life as a security executive. Darren shares hard-won lessons from building and leading a cybersecurity program in a critical infrastructure environment, including how to gain executive buy-in, scale a team, and align security with business priorities. He reflects on the challenges of translating cyber risk into business risk, managing real-world incidents, and the evolving expectations of the CISO role. Whether you're in the chair now or working toward it, this conversation is packed with practical insights for anyone navigating cybersecurity leadership.Show links:Darren Highfill LinkedIn Profile - https://www.linkedin.com/in/darrenhighfill/NIST Cyber Security Framework (CSF) - https://www.nist.gov/cyberframeworkAnkrd website - https://www.ankrd.com/ -
Critical Conversations: IR, Forensics, and Regulation in OT 04.01.2025 44минIn this episode, we sit down with Lesley Carhart (@hacks4pancakes), a renowned expert in OT/ICS incident response and forensics, to explore the unique challenges of defending critical infrastructure against cyber threats. Lesley shares insights into how internal OT teams can better support external IR teams, evaluates global and sector-specific preparedness, and discusses the impact of regulations on effective incident response. We delve into the complexities of defining and reporting incidents, the potential for improved approaches, and actionable advice for those looking to enhance their IR and forensics skills. Lesley also gives a glimpse into the future of their work and their continued mission to strengthen cybersecurity in critical infrastructure.Show Links:https://www.linkedin.com/in/lcarhart/https://www.threads.net/@hacks4pancakeshttps://bsky.app/profile/hacks4pancakes.comhttps://infosec.exchange/@hacks4pancakes -
Energizing Cybersecurity Careers: Workforce Development in OT/ICS 03.03.2024 1ч 8минJoin us for a discussion on Energizing Cybersecurity Careers: Workforce Development in the OT/ICS Community. Guests Cynthia Hsu and Erin Owens dive into the cybersecurity challenges facing Industrial Control Systems and Operational Technology asset owners. Through open conversations, we explore everything from skill gaps and career pathways to diversity, continuous learning, and the impact of new technologies. This session aims to provide insights into developing a skilled, diverse cybersecurity workforce – starting from the ground up – with a focus on practical strategies for professionals, educators, and anyone interested in the future of ICS/OT security.Show links:Cynthia Hsu LinkedIn profile https://www.linkedin.com/in/cynthiahsu33/Erin Owens LinkedIn profile https://www.linkedin.com/in/erinowens/DOE CESER Cybersecurity Training for the Utility Workforce, free 3-day ICS Cybersecurity training for electric and ONG utility staff. Next training event: Buffalo, NY, April 23-25, Register at: Eventleaf | Event Registration Software and Mobile Event Apps DOE CESER CyberStrikeTM professional cybersecurity training for operational technology environments: https://inl.gov/cyberstrike/· LIGHTS OUT – focus on Ukraine attacks· NEMESIS – focus on nation-state TTPs· STORMCLOUD – focus on renewable energy DOE CESER CyberForce® workforce development program for college students focused on building a pipeline of cyber professional candidates in operational technology cybersecurity: https://cyberforce.energy.gov/ Sandia National LaboratoryTracer FIRE (Forensic Incident Response Exercise): https://github.com/sandialabs/Tracer-FIRECenter for Cyber Defenders: https://www.sandia.gov/careers/career-possibilities/students-and-postdocs/internships-co-ops/institute-programs/titans-technical-internships-to-advance-national-security/titans-cyber/ Cyber Defense Center https://www.cyberdefensecenter.org/ -
CIE: Architecting Infrastructure Immunity 09.11.2023 53минIn this episode, we take a deep dive into the world of Cyber Informed Engineering (CIE), joined by Ginger Wright, Program Manager at Idaho National Laboratory. This episode unpacks CIE's strategic efforts to integrate cybersecurity into the very fabric of engineering critical infrastructure. We discuss the evolution of CIE and how it's transforming the approach to system design. We cover the synergy between engineers and cybersecurity experts and the implementation of engineering-based mitigations. Get insights on building resilience into critical systems from the ground up. -
One Rule to Rule Them All 05.09.2023 59минJoin Patrick Miller, CEO of Ampere Industrial Security and his guest Danielle Jablanski, OT Cybersecurity Strategist at Nozomi Networks as they continue their debate on the topic: "If you could have only one cybersecurity regulation, what should that be?" They cover everything from threat hunting, vulnerability management, attack surface management, incident response, breach notification, risk quantification, cybersecurity insurance, NIS2, NERC CIP, and what's best for corporate vs. public good. -
Ghost in the Machine: a Future Look at AI and OT 26.06.2023 43минJoin Patrick Miller, CEO of Ampere Industrial Security and his guest Amanda Freick, CRO of Altruistic as they discuss the need for collaboration and breaking down cultural barriers to effectively utilize data and drive innovation in the energy sector with AI/ML. We also touch upon the importance of approaching generative AI and language models like GPT with a strategic mindset, understanding the specific needs and goals of the organization before implementation. Additionally, we talk about the importance of recognizing and leveraging the untapped skills and potential within an organization to drive transformation and democratize access to meaningful work.Show Links:Amanda Freick LinkedIn - https://www.linkedin.com/in/amandafreick/Altruistic Video Case Study - https://vimeo.com/733720685Tony Robbins Book, Life Force - https://amzn.to/3qTXRfj -
Breaking into the OT Cybersecurity Field 11.05.2023 42минHear from an experienced ICS/OT Security Manager, Gabe Agboruche, on how to enter or upskill into the ICS/OT cybersecurity field. He answers questions such as… What training is available? What are the biggest obstacles? What are some common job roles? What are the best paying job roles? We also cover the asset owner’s perspective on how they can obtain and retain new cybersecurity professionals.SHOW LINKS:Gabe Agboruche LinkedIn ProfileGabe’s YouTube channel - Struggle SecurityMalware Traffic AnalysisFree Network EmulatorsICSVillageICS Village Youtube ChannelSans ICS Free ResourcesSANS ICS ConceptsDNP3 SimulatorsScapyCompTIA (Security+ and Network+ certifications) -
Simplifying ICS Security Metrics 09.03.2023 43минGetting started with ICS and OT security metrics can be hard. What do you measure? How do you represent it? Do you even have the data? In this podcast, we talk with Erin Torruella to share her experience from building and managing metrics for multiple different sectors. She provides great advice on where to start and how to get the effort going in the right direction.ChatGPT response was…Operational Technology (OT) and Industrial Control Systems (ICS) are crucial components of critical infrastructure, and their security is essential for ensuring the safety, reliability, and availability of essential services. To measure the success or failure of an OT/ICS security program, several metrics can be considered, such as:1. Vulnerability Management Metrics: This metric measures the number of vulnerabilities identified, the number of vulnerabilities remediated, and the time it takes to remediate the vulnerabilities.2. Incident Response Metrics: This metric measures the effectiveness of the incident response process. It includes the time it takes to detect, contain, and resolve an incident, as well as the number and severity of incidents.3. Compliance Metrics: This metric measures compliance with relevant security standards, regulations, and policies. It includes the number of audits conducted, the number of non-compliances identified, and the time it takes to remediate non-compliances.4. Risk Management Metrics: This metric measures the effectiveness of the risk management program. It includes the number and severity of risks identified, the number of risks mitigated, and the time it takes to mitigate the risks.5. Awareness Metrics: This metric measures the effectiveness of the security awareness program. It includes the number of training sessions conducted, the number of employees trained, and the level of understanding demonstrated by employees.6. Asset Management Metrics: This metric measures the effectiveness of the asset management program. It includes the number and types of assets identified, the level of asset classification, and the accuracy of the asset inventory.7. Performance Metrics: This metric measures the performance of the OT/ICS infrastructure. It includes uptime, availability, and response time.Thanks for listening!Show links:Erin Torruella...LinkedIn - https://www.linkedin.com/in/erin-torruella/Twitter - https://twitter.com/LadySqrrlMastodon - https://infosec.exchange/@ladysqrrlJD Christopher SANS talk on ICS Security Metrics - https://www.youtube.com/watch?v=gIsLP_Dtv7MJD Christopher SANS blog post on ICS Security Metrics -https://www.sans.org/blog/mature-ics-security-with-metrics/S.M.A.R.T. Methodology - https://en.wikipedia.org/wiki/SMART_criteriaDHS CISA Cross-Sector Cyber Performance Goals - https://www.cisa.gov/cross-sector-cybersecurity-performance-goals -
What to do about FERC's new INSM Order 887 08.02.2023 32минFERC has issued Order 887, directing NERC to create new Critical Infrastructure Protection (CIP) cybersecurity standards for Internal Network Monitoring Systems (INSM). In this episode, Patrick Miller, CEO of Ampere Industrial Security talks with Carter Manucy, IT/OT Cybersecurity Director for Florida Municipal Power Authority (FMPA). Hear from a real electric utility asset owner, on what this Order means for the industry and what you should do next.Show links:Carter Manucy LinkedIn Profile - https://www.linkedin.com/in/cmanucy/FERC Order 887 - https://www.ferc.gov/media/e-1-rm22-3-000FERC INSM NOPR - https://www.federalregister.gov/documents/2022/01/27/2022-01537/internal-network-security-monitoring-for-high-and-medium-impact-bulk-electric-system-cyber-systemsNational Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems - https://www.amperesec.com/blog/industry-brief-national-security-memorandum-on-improving-cybersecurity-for-critical-infrastructure-control-systemsNERC INSM Practice Guide - https://www.nerc.com/pa/comp/guidance/CMEPPracticeGuidesDL/CMEP%20Practice%20Guide%20-%20Network%20Monitoring%20Sensors.pdfCorresponding Ampere Blog post - https://www.amperesec.com/blog/what-to-do-about-fercs-new-insm-order-887
Популаран у
Овај подкаст се појављује и у подкаст листама ових земаља.