Industrial Cybersecurity Insider

Industrial Cybersecurity Insider

Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

  1. 3d ago

    Is Your Cybersecurity Plan Ready for Your Plant Floor?

    You passed the audit. The tools are installed. None of it means your plant is secure. Most industrial cybersecurity plans are written far from the equipment they're meant to protect. The tools are purchased but never fully operationalized. Critical equipment stays unseen. And the plant teams who know it best are the last to see the data. In this compilation episode, Craig Duckworth, Dino Busalachi, and Ian Bramson of Black & Veatch cover: Why security tools sit unused, and what that costsWhy plant teams need access to security dataWhat real IT and OT collaboration looks likeWho responds first when something goes wrongWhy compliance isn't securityHow to prioritize risk while protecting safety and uptime Strong security programs are built with the people closest to the equipment. Is yours? Chapters: (00:00:00) The hidden gap in OT asset visibility(00:04:00) Why plant teams need access to security data(00:08:00) The cost of an unoperationalized cybersecurity tool(00:10:00) What IT and OT convergence really means(00:14:00) Bringing system integrators into the conversation(00:18:00) Who responds first when an industrial incident happens(00:22:00) Compliance, residual risk, and real world security(00:26:00) Risk prioritization for utilities and industrial operators(00:30:00) Build security into new projects from the start Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  2. Sep 30

    The Air Gap Myth: Why Your Plant Is More Exposed Than You Think

    Dino sits down with Matt Pike of Rockwell Automation for an honest conversation about why industrial cybersecurity still stalls out inside so many plants, and it has very little to do with technology. Matt walks through his path from onsite IT support at a large automotive manufacturer into OT security, and explains why modern security principles keep colliding with legacy systems that were built to run untouched for fifteen or twenty years. The two dig into the real reason the IT and OT gap has not closed, why CISOs often reach for a familiar tool instead of a strategy, and how Rockwell approaches visibility in a fully vendor agnostic way across Siemens, Honeywell, Emerson and everything else sitting on a plant floor. They also get practical about the pieces most teams skip: secure by design language inside RFQs and integrator contracts, response and recovery plans that almost nobody has written, and the funding question of who actually pays for security when a capital project lands. Matt shares what he is seeing from attackers using AI to speed up reconnaissance and rewrite ransomware around detection, and why the air gap most plants believe in disappears the moment data reaches a historian. His closing advice cuts through the noise: stop buying tools and start with an asset visibility strategy, because you cannot secure what you have never actually seen. Chapters:(00:00:00) Matt Pike's path from IT support into OT security(00:03:00) Why the IT and OT gap still has not closed(00:06:00) When leadership thinks a tool will fix a people problem(00:09:30) Vendor agnostic visibility down to the asset layer(00:11:00) Secure by design on greenfield and brownfield projects(00:14:00) The incident response plan nobody wrote(00:17:30) AI on the plant floor and what it actually requires(00:20:00) How attackers are already using AI(00:22:30) The air gap myth and east/west blind spots(00:27:30) Funding security through the capital project Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  3. Sep 23

    When Cyber Stops the Line, Safety Is on the Line

    Safety starts with a goal. So should cybersecurity. Craig Duckworth sits down with Shankar Somasundaram, CEO of Asimily and former head of Symantec's IoT business, to explain why plant floor cybersecurity is a safety issue, not an IT expense. They cover why industrial cybersecurity programs stall after the tool is purchased, how to start with a goal instead of a solution, and why fixing the biggest risks first beats trying to secure everything at once. The conversation also covers network segmentation mistakes, AI as both a helper and a new threat to critical infrastructure, protecting legacy OT and IoT equipment without disrupting production, watching traffic inside the plant, what drives cybersecurity maturity, and what OT security market consolidation means for manufacturers. Shankar's three takeaways for your next budget cycle: Cyber risk is safety riskStart with the goalVisibility and fixing the problem are one program, not two Chapters: (00:00:00) Cybersecurity is patient safety, operational safety, plant safety(00:00:45) Meet Shankar and the four pillars behind Asimily(00:03:50) Why OT security projects stall after the tool is purchased(00:06:20) Start with a goal, not a solution(00:09:20) Exposure management and the segmentation myths that slow teams down(00:11:45) AI as enabler and attacker inside critical infrastructure(00:15:40) Collecting data on legacy OT and IoT without disrupting operations(00:18:20) North south, east west, and the flow data most teams skip(00:20:00) Does maturity come from size, budget, or management(00:24:20) Consolidation in the OT market and the advice Shankar leaves behind Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityShankar Somasundaram on LinkedInAsimilyDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  4. Sep 16

    Why Industrial Cyber Risk Is Escalating (And How To Stop It)

    This highlight episode pulls the sharpest moments from past conversations into one continuous argument about why industrial cyber risk keeps escalating and why so many programs stall before they start. Craig Duckworth and Dino Busalachi open with a number that should stop any executive team cold: one manufacturer lost roughly $500 million in valuation inside 60 hours, and that loss had nothing to do with lost production. From there the conversation gets practical. They explain why a plant floor security program cannot be run entirely from the data center, why asset inventory and communication flow mapping must come before any discussion of segmentation, and what distinguishes warranted traffic from unwarranted traffic within a control system environment. Jim Cook joins to break down the difference between a flat network and what the team calls a super flat network, where drives, flow meters, robots, and business systems all share the same space. Together, they make the case that zero trust in operational technology must be built from the bottom of the stack upward, using what they describe as the bucket approach, rather than layered over the plant with enterprise tooling that nobody on site knows how to operate. The episode closes on ownership: who is accountable, who the plant manager actually trusts, and why the people who design and build the machines belong in the room from day one. If you are responsible for production uptime and for protecting the assets that create it, this one is a fast tour of the decisions that matter most. Chapters: (00:00:00) A $500 Million Valuation Loss In 60 Hours(00:01:00) Why Industrial Cyber Risk Is More Urgent Right Now(00:03:00) Why IT Cannot Secure The Plant Floor Alone(00:05:00) Asset Inventory And Communication Flows Come First(00:07:00) Building A Defensible Architecture In OT Environments(00:09:00) Flat Networks Versus Super Flat Networks(00:11:00) The Bucket Approach To Segmentation(00:14:00) Vetting A Cybersecurity Partner The Right Way(00:16:00) Tabletop Exercises With The Executive Team(00:19:00) Who Actually Owns Industrial Cybersecurity Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  5. Sep 9

    The “Don’t Touch It” Problem Hiding on Your Plant Floor

    Most plants are running production on infrastructure nobody wants to touch. Somebody installed it years ago, that person is long gone, and the standing rule is to leave it alone so it keeps working. In this episode, Dino sits down with Jeff Slapp, cofounder, CTO and head of produduct development at SteelDome, to talk about what it would take to change that. Jeff has spent almost 30 years building and running data centers, starting with VMware back in 1998, and he admits that until recently he couldn't have properly defined OT, even though control systems, safety systems, and fire suppression were around him the entire time. They dig into why so many manufacturers still have hundreds of standalone HMIs, why a capital project is the real moment to think about security, and why IT/OT convergence rarely shows up in practice the way everyone talks about it. Jeff also walks through what it means to stand up a full production platform, complete with secure remote access, in about 90 seconds instead of nine months. They close on the reality that this is a people problem more than a technology problem, and why AI on the plant floor will only be as good as the foundation it runs on. Chapters: (00:00:00) If technology is not saving time, money, or mistakes, what is the point?(00:01:12) Jeff Slapp's 30-year journey from early VMware to co-founding SteelDome(00:04:35) What a universal infrastructure operating system means for the plant(00:06:24) An IT veteran admits OT was around him the whole time, and he never saw it(00:10:03) Legacy plants, standalone HMIs, and the "nobody touches it" problem(00:13:22) Kasm and secure application delivery: the missing third layer(00:18:04) Time to value: a full production platform in 90 seconds, not nine months(00:21:56) Democratizing infrastructure and where AI meets industrial security(00:25:14) Secure by design: build cybersecurity into the capital project(00:28:38) Asset inventory gaps, the IT/OT convergence myth, and closing thoughts Links And Resources: SteelDome WebsiteJeffrey Slapp on LinkedInWant to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  6. Sep 1

    The Blind Spot Between IT and OT Isn't Where or What You Think

    Manufacturing cybersecurity can't succeed when IT acts as the enforcer and OT sees security as an obstacle to production. CyberHoot founder Craig Taylor joins Dino Busalachi to explain why punishment-based awareness programs create resistance, how positive reinforcement can turn employees into an active layer of defense, and why cyber preparedness belongs beside safety, quality, uptime, and availability as a core plant metric. They discuss the overlooked role of system integrators and machine builders, the danger of unmanaged laptops and remote access, the false comfort ofair-gappedd systems, and the growing risk that AI poses to aging industrial technology. Craig also shares a simple framework called PAR, which means pause, assess, and report, and makes the case for short, practical training that rewards people for speaking up before a mistake becomes a shutdown. Chapters: (00:00:00) Why IT should empower OT(00:05:18) Connecting cyber awareness to plant uptime(00:10:04) The missing role of system integrators(00:15:07) Building a culture that rewards reporting(00:20:01) Legacy equipment, limited resources, and better incentives(00:24:06) Vulnerable plants and the air gap myth(00:29:07) Treating cybersecurity like plant safety(00:34:00) The personal value of cyber literacy Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityCraig Taylor on LinkedInFor 20% Off CyberHoot 1st Year, mention Industrial Cybersecurity InsiderDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  7. Aug 26

    Why Detection Alone Can't Stop the Next OT Attack

    Detection got fast, but remediation didn't. And that gap is exactly where attackers live. Manufacturers have spent the last decade building visibility into their plants: sensors, dashboards, alerts flying into every SOC. But knowing about a threat and fixing it are two different problems, and most industrial teams are still solving the second one at human speed. A ticket gets opened. A maintenance window gets scheduled. Three departments get looped in. Meanwhile, the attacker isn't waiting for anyone's approval. In this episode, Craig Duckworth talks with Tal Kollender, founder and CEO of Remedio, about what's actually keeping industrial environments exposed: misconfigurations left untouched for months, unnecessary services quietly giving attackers a path to move laterally, and aging systems nobody wants to be the one to touch. Tal makes the case that patching alone will never close this gap and explains why safe automated remediation is becoming essential as AI accelerates attacks faster than most security teams can keep up. They also dig into the reality of OT: uptime and safety come first, IT security tools often can't reach the controls layer, and the wrong change can cause real damage on the plant floor. It's a candid look at what it takes to align security and operations, and why building that trust is the real first step toward proactive protection instead of reactive cleanup. If you're responsible for securing a plant floor, a fleet of facilities, or the budget behind either one, this conversation gives you a clear, practical way to think about closing the gap between seeing a threat and actually stopping one. Chapters: (00:00:00) Why machine speed detection needs machine speed remediation(00:01:00) Tal’s path from teenage hacker to cybersecurity founder(00:06:00) Misconfigurations and lateral movement in industrial environments(00:11:00) Why patching and configuration changes are difficult in OT(00:15:00) Moving from reactive detection to proactive hardening(00:17:00) Aligning people, process, and technology(00:22:00) AI adoption, unmanaged risk, and doing more with less(00:25:00) Bridging the IT and OT divide without disrupting operations(00:29:00) The first practical step toward proactive industrial security Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityTal Kollender on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  8. Aug 18

    From NSA Threat Intelligence to Factory-Floor Cybersecurity

    Cybersecurity in an industrial environment isn't just an IT concern. It's a question of whether the business can keep operating, and whether people stay safe when systems fail. Craig Duckworth talks with Tim Hoffman, a former NSA director of threat intelligence whose career spans military intelligence, defense, healthcare, finance, critical infrastructure, and industrial operations. They discuss why CMMC needs to be treated as a cultural shift rather than a compliance exercise, how CISOs earn trust with plant teams, and why leaders have to translate cyber risk into terms the board actually understands. Tim explains why tools alone can't protect OT. Craig ties digital safety back to the drills and routines plants already run. And together they look at where AI helps, where it adds risk, and why two fundamentals still matter most: clear processes and the discipline to practice them. Chapters: (00:00:00) Why Security Tools Cannot Solve Operational Risk(00:01:00) Lessons from an NSA and Mission Critical Security Career(00:05:00) Why CMMC Must Be More Than a Compliance Checklist(00:08:00) Closing the Authority Gap Between IT and OT(00:12:00) Translating Cyber Risk Into Cost and Human Consequences(00:17:00) Why OT Security Demands More Than IT Tools(00:19:00) AI, Faster Attacks, and the Need for Human Judgment(00:25:00) Start With Process and Build the Discipline to Follow It(00:27:00) Treating Cyber Response Like a Plant Safety Drill(00:31:00) People and Process Come Before Technology Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityTim Hoffman on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

Ratings & Reviews

5
out of 5
2 Ratings

About

Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

You Might Also Like