Industrial Cybersecurity Insider

Industrial Cybersecurity Insider

Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

  1. 2 days ago

    Supply Chain Risk: Your Vendors Have Vendors You've Never Heard Of

    Craig Duckworth sits down with Jowanza Joseph, CEO of Parakeet Risk, to unpack why third-party risk has become one of the most urgent challenges facing manufacturers and critical infrastructure operators. Jowanza spent 15 years in engineering roles at Adobe, Pluralsight, and MasterCard before founding Parakeet Risk to serve an industrial sector he saw as the most underserved when it comes to technology. Together they address why simply knowing who your vendors are is harder than it sounds, how insurers are moving past checkbox questionnaires and demanding real evidence of controls, and what happens when contracts require you to identify a new asset in your OT environment within five minutes. They also get honest about the organizational problem few want to own: security leaders who carry responsibility for the plant floor without the authority to change anything on it. Jowanza closes with a practical, low-cost starting point for any organization and a look at where vendor attestation is headed over the next five years. Chapters: (00:00:00) Why industrial companies must become cybersecurity companies(00:02:08) Cataloging and prioritizing your most dangerous vendors(00:04:37) The hidden layers of subcontractors in your supply chain(00:06:42) Cyber insurance moves past the checkbox era(00:10:47) Contracts that demand new asset identification in five minutes(00:12:58) AI is multiplying vulnerabilities faster than solutions(00:16:31) Three hallmarks of a strong third party risk program(00:21:14) Incident response, game days, and who falls on the sword(00:23:42) Responsibility without authority across the IT and OT divide(00:28:31) Where to start today and the future of vendor attestation Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  2. 28 Jul

    Supply Chain Risk: What Manufacturers Need to Know

    Two global dairy producers made headlines this week after breaches that started with third party vendors. Dino and Craig break down how it happened and why it keeps happening. They walk through the reality of remote access on the plant floor, from cellular modems to TeamViewer installs nobody remembers approving, and explain why a single sensor in a plant might show you 25 percent of your assets at best. The conversation gets to the root of the problem: people, not technology. OT teams still lock IT out of critical systems, CISOs carry responsibility without authority, and incident response plans rarely account for the integrators working across multiple plants at any given moment. If you lead security for a manufacturing organization, this episode arms you with the tough questions to bring back to leadership before your company is the one filing with the SEC. Chapters: (00:00:00) - The CISO gets hung out to dry, not the third-party vendor(00:01:02) - Two global dairy producers breached through third-party vendors(00:02:12) - The messy reality of remote access on the plant floor(00:03:47) - Why IT has no visibility into what's connected in manufacturing(00:05:29) - North-south versus east-west traffic monitoring(00:06:41) - The culture problem of OT locking IT out(00:08:14) - Responsibility versus authority for CISOs(00:10:47) - The budget excuse and the real cost of downtime(00:14:32) - Incident response plans that leave system integrators out(00:18:56) - SEC filings, brand damage, and the tough questions to ask Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  3. 22 Jul

    Plant Floor Cybersecurity Starts at the Top. Not the Server Room, with Robert Maxwell

    For industrial leaders responsible for keeping plants productive, connected, and secure, cybersecurity cannot sit only with IT. Robert Maxwell joins Dino to address the leadership and operational gaps that leave OT environments exposed, especially when aging control systems, diverse automation platforms, and decentralized plant operations are part of the picture. They discuss what it takes to move beyond fragmented ownership and point solutions: giving an accountable leader the authority to coordinate security across IT, OT, engineering, operations, and outside partners. The conversation covers practical priorities for building a durable cyber program, including organization-wide awareness, stronger visibility into industrial assets, and a security strategy that can keep pace with AI adoption. The takeaway is clear: cybersecurity is an operational investment that protects uptime, production, and long-term business resilience. Chapters: (00:00:00) Cybersecurity is a management responsibility(00:01:00) Robert Maxwell’s journey into cybersecurity(00:04:35) Why organizations need a clear cybersecurity owner(00:08:40) Building a long-term security strategy across the business(00:12:00) What happens when companies ignore cybersecurity(00:14:10) Why vendor-led security programs fall short(00:17:05) The IT and OT divide in manufacturing(00:20:00) AI, data protection, and the growing security challenge(00:23:25) Visibility gaps across manufacturing plants(00:26:20) Why leaders should view cybersecurity as an investment Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityRobert Maxwell on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  4. 14 Jul

    Trust But Verify: Why Every Air-Gap Claim Deserves Scrutiny

    This week we're bringing back one of our most requested episodes, because the problem it covers hasn't gone away. Dino and Jim break down one of the most dangerous assumptions in industrial security: that OT environments are air-gapped and therefore safe. Through real examples from actual plant floors, they show exactly how that assumption falls apart, from cellular modems inside machine centers to third-party technicians on guest Wi-Fi to VPN concentrators IT doesn't know exist, and explain why the gap between IT and OT teams is just as much an organizational problem as a technical one. They also get into why point-in-time assessments aren't enough, where zero trust runs into its limits in industrial settings, and what continuous visibility on the plant floor actually looks like. If you're responsible for securing manufacturing or critical infrastructure, this one is as relevant today as when it was first recorded. Chapters: (00:00:00) - The Air Gap Myth: Introduction(00:03:00) - How OT Devices End Up Connected Without IT Knowing(00:07:00) - Why Plant Managers Bypass IT Security(00:12:00) - The Compliance and Insurance Stakes(00:15:00) - Why Zero Trust Struggles in OT Environments(00:17:00) - Bringing in Outside Experts to Find the Truth(00:20:00) - Supply Chain and Hidden Connectivity(00:24:00) - What Visibility Tools Reveal on the Plant Floor(00:26:00) - Wrap-Up: Trust But Verify, Then Monitor Continuously Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  5. 7 Jul

    The Real Cost of Delaying OT Cybersecurity Investment

    Craig and Jim revisit one of their most practical conversations: how to build a compelling business case for OT cybersecurity budget. They break down the IT/OT ownership gap that leaves manufacturers exposed, explain how to frame liability, physical risk, and financial impact in language executives actually care about, and walk through the options every organization faces. From doing nothing to running a proof-of-concept pilot site that generates real, quantifiable data. They also tackle the role of cybersecurity insurance, why every company needs OT on its risk register, and how the concept of technology debt can finally help leadership understand the cost of decades of deferred OT security investment. Whether you're approaching this from the IT side, the OT side, or somewhere in between, this episode gives you the framework to start the budget conversation before a breach forces it. Chapters: (00:00:00) - Introduction: The High Stakes of OT Cybersecurity(00:01:00) - Why Budgeting for OT Security Is So Difficult(00:04:00) - How to Get Executives to Actually Listen(00:06:00) - Liability: Speaking the Language of Leadership(00:11:00) - Building Your OT Cybersecurity Business Case(00:13:00) - Ownership and Visibility: The First Questions to Ask(00:17:00) - Proof of Concept: Using Real Data to Drive Decisions(00:20:00) - Cybersecurity Insurance and the Third Leg of the Stool(00:26:00) - Risk Management, Roadmaps, and Playing the Long Game(00:31:00) - Technology Debt and Final Takeaways Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInJim Cook on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  6. 30 Jun

    Your Organization Says It's 'Green' on Manufacturing Security: Here's Why That's Dangerous

    Who actually owns OT cybersecurity? And when something breaks, who's accountable? In this episode, Craig and Dino tackle a question most manufacturing organizations still haven't answered. They address why CISOs are often handed responsibility for OT security without the authority to act on it, and how plants can score "green" on a compliance dashboard while remaining blind to 80% of their actual assets. They also dig into the role OEMs and system integrators should be playing in building security into project proposals from day one, and why most still aren't. From virtual patching for legacy systems that can't be touched, to the fast-growing OT security market, this is a grounded conversation for plant leaders, engineers, and security teams trying to close the gap between IT and OT. Chapters: (00:00:00) - Who Really Owns OT Cybersecurity?(00:02:00) - Asset Owners Bear the Ultimate Responsibility(00:04:00) - Responsibility Without Authority: The CISO's Dilemma(00:06:00) - Why OEMs and SIs Aren't Including Cybersecurity in Their Proposals(00:08:00) - The False Sense of Security Driving Dangerous Blind Spots(00:10:00) - How Organizations Claim "Green" While Missing 80% of Their Assets(00:13:00) - Half Measures vs. a Real OT Cybersecurity Strategy(00:16:00) - The Growing OT Security Market and Why Some Still Aren't Paying Attention(00:18:00) - Incident Response Drills and AI Accelerating the Threat Landscape(00:20:00) - Breaking Down the IT/OT Trust Barrier for Good Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  7. 24 Jun

    It's Control System Integrity not just OT Cybersecurity

    Many manufacturers don't realize that an investment in OT Cybersecurity also enhances Control System Integrity. In this rewind episode, Craig and Dino dig into why so many OT intrusion detection platforms get installed but never become truly operational. They address what gets lost when IT owns the tool while OT owns the equipment, and why the word “cybersecurity” itself can stall progress the moment it lands on the plant floor. They land on a question every CISO, plant leader, and engineering director should be asking right now: who at your sites actually knows how to use the tools you have already paid for, and how do you bring the OT ecosystem into the room before the next outage forces you to? Chapters: (00:00:00) Cold Open: The Diagnostic Tool Sitting Unused in Your Plant(00:01:00) Shadow OT Versus Shadow IT and Why the Distinction Matters(00:02:30) Why IT Gets Left Out of Industrial Lifecycle Decisions(00:04:00) Reframing Cybersecurity as Control System Integrity(00:05:00) The 8:10 AM Production Shutdown Mystery(00:07:00) Three Rogue Servers Hiding in Plain Sight(00:08:00) A Brewery, a Misconfigured Module, and a Network No One Could Diagnose(00:10:00) Buying an MRI Machine and Refusing to Turn It On(00:12:00) Bringing the OT Ecosystem to the Table(00:15:00) Why IT Needs New Friends in Manufacturing Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  8. 15 Jun

    Is AI Becoming Your Plant Floor's Biggest Vulnerability?

    Craig and Dino dig into the widening gap between IT and OT and why the plant floor keeps getting left behind. They break down what Dragos ' acquisition of Phosphorus signals for the future of IoT security in manufacturing, from cameras and label printers to X-ray inspection systems that ship with default passwords and almost never get patched. The conversation gets sharp on artificial intelligence: the same models helping plants work smarter are now lowering the barrier for attackers, putting Stuxnet-style capabilities into the hands of people who lack the resources and sophistication that nation states once needed. Craig and Dino expose the everyday habits that leave operations vulnerable, including system integrators plugging personal laptops straight into production networks, locked USB ports that solve only half the problem, and remote access so wide open that a single entry point can expose an entire plant. They argue that nobody truly owns OT cyber hygiene, that frameworks like IEC 62443 and the NIST 800 82 series get named in RFPs but rarely enforced, and that leaders keep tripping over dollars to pick up nickels by choosing the cheapest bid over real protection. It's a candid, experience-driven look at why industrial security moves so slowly and what plant leaders, engineers, and security teams can actually do about it. Chapters: (00:00:00) - AI Enters the OT Battlefield(00:01:30) - Why IoT Is Creeping Onto the Plant Floor(00:03:30) - Printers, Cameras, and the Default Passwords Nobody Owns(00:06:00) - Dragos, Phosphorus, and the Managed Services Question(00:08:00) - How AI Lowers the Bar for Attacking Control Systems(00:09:40) - Stuxnet Then vs. AI-Powered Attacks Now(00:12:00) - The Laptop in the Plant: Contractors, USBs, and Open Networks(00:16:00) - Frameworks on Paper vs. Reality (IEC 62443 & NIST 800-82)(00:19:00) - Tripping Over Dollars to Pick Up Nickels(00:24:00) - Short-Tenure CISOs and Why You Shouldn't Go It Alone Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

About

Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

You Might Also Like