Industrial Cybersecurity Insider

Industrial Cybersecurity Insider

Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

  1. 1d ago

    Supply Chain Risk: What Manufacturers Need to Know

    Two global dairy producers made headlines this week after breaches that started with third party vendors. Dino and Craig break down how it happened and why it keeps happening. They walk through the reality of remote access on the plant floor, from cellular modems to TeamViewer installs nobody remembers approving, and explain why a single sensor in a plant might show you 25 percent of your assets at best. The conversation gets to the root of the problem: people, not technology. OT teams still lock IT out of critical systems, CISOs carry responsibility without authority, and incident response plans rarely account for the integrators working across multiple plants at any given moment. If you lead security for a manufacturing organization, this episode arms you with the tough questions to bring back to leadership before your company is the one filing with the SEC. Chapters: (00:00:00) - The CISO gets hung out to dry, not the third-party vendor(00:01:02) - Two global dairy producers breached through third-party vendors(00:02:12) - The messy reality of remote access on the plant floor(00:03:47) - Why IT has no visibility into what's connected in manufacturing(00:05:29) - North-south versus east-west traffic monitoring(00:06:41) - The culture problem of OT locking IT out(00:08:14) - Responsibility versus authority for CISOs(00:10:47) - The budget excuse and the real cost of downtime(00:14:32) - Incident response plans that leave system integrators out(00:18:56) - SEC filings, brand damage, and the tough questions to ask Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  2. Jul 22

    Plant Floor Cybersecurity Starts at the Top. Not the Server Room, with Robert Maxwell

    For industrial leaders responsible for keeping plants productive, connected, and secure, cybersecurity cannot sit only with IT. Robert Maxwell joins Dino to address the leadership and operational gaps that leave OT environments exposed, especially when aging control systems, diverse automation platforms, and decentralized plant operations are part of the picture. They discuss what it takes to move beyond fragmented ownership and point solutions: giving an accountable leader the authority to coordinate security across IT, OT, engineering, operations, and outside partners. The conversation covers practical priorities for building a durable cyber program, including organization-wide awareness, stronger visibility into industrial assets, and a security strategy that can keep pace with AI adoption. The takeaway is clear: cybersecurity is an operational investment that protects uptime, production, and long-term business resilience. Chapters: (00:00:00) Cybersecurity is a management responsibility(00:01:00) Robert Maxwell’s journey into cybersecurity(00:04:35) Why organizations need a clear cybersecurity owner(00:08:40) Building a long-term security strategy across the business(00:12:00) What happens when companies ignore cybersecurity(00:14:10) Why vendor-led security programs fall short(00:17:05) The IT and OT divide in manufacturing(00:20:00) AI, data protection, and the growing security challenge(00:23:25) Visibility gaps across manufacturing plants(00:26:20) Why leaders should view cybersecurity as an investment Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityRobert Maxwell on LinkedInDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  3. Jul 14

    Trust But Verify: Why Every Air-Gap Claim Deserves Scrutiny

    This week we're bringing back one of our most requested episodes, because the problem it covers hasn't gone away. Dino and Jim break down one of the most dangerous assumptions in industrial security: that OT environments are air-gapped and therefore safe. Through real examples from actual plant floors, they show exactly how that assumption falls apart, from cellular modems inside machine centers to third-party technicians on guest Wi-Fi to VPN concentrators IT doesn't know exist, and explain why the gap between IT and OT teams is just as much an organizational problem as a technical one. They also get into why point-in-time assessments aren't enough, where zero trust runs into its limits in industrial settings, and what continuous visibility on the plant floor actually looks like. If you're responsible for securing manufacturing or critical infrastructure, this one is as relevant today as when it was first recorded. Chapters: (00:00:00) - The Air Gap Myth: Introduction(00:03:00) - How OT Devices End Up Connected Without IT Knowing(00:07:00) - Why Plant Managers Bypass IT Security(00:12:00) - The Compliance and Insurance Stakes(00:15:00) - Why Zero Trust Struggles in OT Environments(00:17:00) - Bringing in Outside Experts to Find the Truth(00:20:00) - Supply Chain and Hidden Connectivity(00:24:00) - What Visibility Tools Reveal on the Plant Floor(00:26:00) - Wrap-Up: Trust But Verify, Then Monitor Continuously Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  4. Jul 7

    The Real Cost of Delaying OT Cybersecurity Investment

    Craig and Jim revisit one of their most practical conversations: how to build a compelling business case for OT cybersecurity budget. They break down the IT/OT ownership gap that leaves manufacturers exposed, explain how to frame liability, physical risk, and financial impact in language executives actually care about, and walk through the options every organization faces. From doing nothing to running a proof-of-concept pilot site that generates real, quantifiable data. They also tackle the role of cybersecurity insurance, why every company needs OT on its risk register, and how the concept of technology debt can finally help leadership understand the cost of decades of deferred OT security investment. Whether you're approaching this from the IT side, the OT side, or somewhere in between, this episode gives you the framework to start the budget conversation before a breach forces it. Chapters: (00:00:00) - Introduction: The High Stakes of OT Cybersecurity(00:01:00) - Why Budgeting for OT Security Is So Difficult(00:04:00) - How to Get Executives to Actually Listen(00:06:00) - Liability: Speaking the Language of Leadership(00:11:00) - Building Your OT Cybersecurity Business Case(00:13:00) - Ownership and Visibility: The First Questions to Ask(00:17:00) - Proof of Concept: Using Real Data to Drive Decisions(00:20:00) - Cybersecurity Insurance and the Third Leg of the Stool(00:26:00) - Risk Management, Roadmaps, and Playing the Long Game(00:31:00) - Technology Debt and Final Takeaways Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedInJim Cook on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  5. Jun 30

    Your Organization Says It's 'Green' on Manufacturing Security: Here's Why That's Dangerous

    Who actually owns OT cybersecurity? And when something breaks, who's accountable? In this episode, Craig and Dino tackle a question most manufacturing organizations still haven't answered. They address why CISOs are often handed responsibility for OT security without the authority to act on it, and how plants can score "green" on a compliance dashboard while remaining blind to 80% of their actual assets. They also dig into the role OEMs and system integrators should be playing in building security into project proposals from day one, and why most still aren't. From virtual patching for legacy systems that can't be touched, to the fast-growing OT security market, this is a grounded conversation for plant leaders, engineers, and security teams trying to close the gap between IT and OT. Chapters: (00:00:00) - Who Really Owns OT Cybersecurity?(00:02:00) - Asset Owners Bear the Ultimate Responsibility(00:04:00) - Responsibility Without Authority: The CISO's Dilemma(00:06:00) - Why OEMs and SIs Aren't Including Cybersecurity in Their Proposals(00:08:00) - The False Sense of Security Driving Dangerous Blind Spots(00:10:00) - How Organizations Claim "Green" While Missing 80% of Their Assets(00:13:00) - Half Measures vs. a Real OT Cybersecurity Strategy(00:16:00) - The Growing OT Security Market and Why Some Still Aren't Paying Attention(00:18:00) - Incident Response Drills and AI Accelerating the Threat Landscape(00:20:00) - Breaking Down the IT/OT Trust Barrier for Good Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  6. Jun 24

    It's Control System Integrity not just OT Cybersecurity

    Many manufacturers don't realize that an investment in OT Cybersecurity also enhances Control System Integrity. In this rewind episode, Craig and Dino dig into why so many OT intrusion detection platforms get installed but never become truly operational. They address what gets lost when IT owns the tool while OT owns the equipment, and why the word “cybersecurity” itself can stall progress the moment it lands on the plant floor. They land on a question every CISO, plant leader, and engineering director should be asking right now: who at your sites actually knows how to use the tools you have already paid for, and how do you bring the OT ecosystem into the room before the next outage forces you to? Chapters: (00:00:00) Cold Open: The Diagnostic Tool Sitting Unused in Your Plant(00:01:00) Shadow OT Versus Shadow IT and Why the Distinction Matters(00:02:30) Why IT Gets Left Out of Industrial Lifecycle Decisions(00:04:00) Reframing Cybersecurity as Control System Integrity(00:05:00) The 8:10 AM Production Shutdown Mystery(00:07:00) Three Rogue Servers Hiding in Plain Sight(00:08:00) A Brewery, a Misconfigured Module, and a Network No One Could Diagnose(00:10:00) Buying an MRI Machine and Refusing to Turn It On(00:12:00) Bringing the OT Ecosystem to the Table(00:15:00) Why IT Needs New Friends in Manufacturing Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  7. Jun 15

    Is AI Becoming Your Plant Floor's Biggest Vulnerability?

    Craig and Dino dig into the widening gap between IT and OT and why the plant floor keeps getting left behind. They break down what Dragos ' acquisition of Phosphorus signals for the future of IoT security in manufacturing, from cameras and label printers to X-ray inspection systems that ship with default passwords and almost never get patched. The conversation gets sharp on artificial intelligence: the same models helping plants work smarter are now lowering the barrier for attackers, putting Stuxnet-style capabilities into the hands of people who lack the resources and sophistication that nation states once needed. Craig and Dino expose the everyday habits that leave operations vulnerable, including system integrators plugging personal laptops straight into production networks, locked USB ports that solve only half the problem, and remote access so wide open that a single entry point can expose an entire plant. They argue that nobody truly owns OT cyber hygiene, that frameworks like IEC 62443 and the NIST 800 82 series get named in RFPs but rarely enforced, and that leaders keep tripping over dollars to pick up nickels by choosing the cheapest bid over real protection. It's a candid, experience-driven look at why industrial security moves so slowly and what plant leaders, engineers, and security teams can actually do about it. Chapters: (00:00:00) - AI Enters the OT Battlefield(00:01:30) - Why IoT Is Creeping Onto the Plant Floor(00:03:30) - Printers, Cameras, and the Default Passwords Nobody Owns(00:06:00) - Dragos, Phosphorus, and the Managed Services Question(00:08:00) - How AI Lowers the Bar for Attacking Control Systems(00:09:40) - Stuxnet Then vs. AI-Powered Attacks Now(00:12:00) - The Laptop in the Plant: Contractors, USBs, and Open Networks(00:16:00) - Frameworks on Paper vs. Reality (IEC 62443 & NIST 800-82)(00:19:00) - Tripping Over Dollars to Pick Up Nickels(00:24:00) - Short-Tenure CISOs and Why You Shouldn't Go It Alone Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

  8. Jun 9

    Is Your IIoT Strategy Creating More Security Risks?

    Craig and Dino address one of the most overlooked problems in OT security: the IIoT devices your security tools don't automatically detect. Most OT intrusion detection platforms do a reasonable job of identifying core control-layer assets such as PLCs, drives, and motor control centers. The problem is everything else. Laptops plugged into the network, third-party devices brought in by contractors, and a growing range of connected IIoT equipment often go completely undetected. Those are the gaps where risk accumulates. Craig and Dino explain why the belief that machines are air-gapped is a dangerous myth, how PLCs acting as gateways prevent intrusion detection platforms from seeing the devices behind them, and why an asset inventory is not the same as knowing your real risk and CVE exposure in multi-vendor environments. They reframe OT cybersecurity as a process-integrity problem and show how unmanaged network activity, third-party remote access, and even routine IT security scans can quietly degrade OEE and trigger unplanned downtime that costs millions. Using predictive-maintenance analogies such as thermal, harmonics, and vibration sensing, they make the case for treating digital anomalies the same way mature plants already treat mechanical ones. They close by examining why so many OT detection tools become shelfware, how to escape alert fatigue, and the two practical paths to real IT/OT convergence: building the right relationships with OEMs, system integrators, and AEC partners, and designing security-ready facilities from the ground up. It's a practical listen for CISOs, plant and engineering leaders, and OT/IT teams responsible for securing manufacturing and critical infrastructure. Chapters: (00:00:00) - Why No Industrial Asset Is Truly Air-Gapped(00:01:08) - IoT vs. IIoT: How OT Assets Get Classified(00:03:15) - The Control-Layer Blind Spot: Drives, Robots, and Motor Controls(00:05:25) - How PLC Gateways Hide Assets From Intrusion Detection(00:07:30) - Asset Inventory Isn't Risk: The CVE Gap in Multi-Vendor Plants(00:08:55) - When Cyber Blind Spots Become Costly Downtime(00:10:05) - Process Integrity: How Security Scans Disrupt Production(00:11:35) - Predictive Maintenance Meets Digital Anomaly Detection(00:17:45) - Avoiding OT Shelfware and Alert Fatigue(00:19:45) - IT/OT Convergence: Choosing a Partner and Building Secure-by-Design Links And Resources: Want to Sponsor an episode or be a Guest? Reach out here.Industrial Cybersecurity Insider on LinkedInCybersecurity & Digital Safety on LinkedInBW Design Group CybersecurityDino Busalachi on LinkedInCraig Duckworth on LinkedIn Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

Ratings & Reviews

5
out of 5
2 Ratings

About

Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

You Might Also Like