Security Breach

Eric Sorensen

A weekly discussion of new developments and the latest cybersecurity threats, including ransomware, malware, phishing schemes, DDoS attacks and more, facing the U.S. industrial sector.

  1. Sep 23

    Water Treatment Hacks Reflect Larger OT Threats

    Send us Fan Mail Although the need to defend the networks, data and endpoints of critical infrastructure dates back to the first time a PLC was connected to an HMI, the realization of how damaging such a compromise could be was probably Stuxnet. And while we’ve progressed enough to typically spot an unknown or malicious player armed with a suspicious USB, the threat landscape has expanded, and the bad actors have evolved. Combining those factors with a lack of funds, training, expertise and resources has opened the doors to ransomware groups and state-sponsored hackers to infiltrate, shutdown or compromise infrastructure operations across the globe, and more recently, across the United States. These growing threats were recently on display when over 100 water treatment facilities across 12 states experienced temporary shutdowns due to breeches believed to have been carried out by Iranian hacking groups. Here to discuss the rise in these attacks, and what they mean in the broader scope of industrial cybersecurity is Jen Sovada, General Manager for Public Sector initiatives at Claroty. Listen as we discuss: The blocking and tackling of OT security that has become vital in defending critical assets on any plant floor.How Watershed 250 is working to help utilities protect their OT infrastructure.How the ongoing IT/OT divide is hurting new cybersecurity initiatives.The proper implementation of strategies like microsegmentation, artificial intelligence tools.How, despite all the challenges facing industrial cybersecurity, she can still sleep at night.To catch up on past episodes, you can go to Manufacturing.net, IEN.com  or  MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com. As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    Water Treatment Hacks Reflect Larger OT Threats
  2. Sep 10

    Shadow AI Is Amplifying OT Threats

    Send us Fan Mail Name a prominent AI company, and chances are they’ve been in the news for the wrong reasons over the last couple of months. Anthropic, OpenAI and Meta have all made headlines as their AI agents have escaped the testing sandbox and either exposed vulnerabilities or performed outright hacks of other systems. The underlying engine driving these attacks is fueled by both competitive pressures and consumer demands. In manufacturing the use of AI has escalated at a furious pace, as enterprise stakeholders are encouraging everyone from the plant floor to payroll to embrace the technology in finding ways to optimize any and all tasks. While this had led to a number of positive use cases, the implementation of AI without proper checks and balances has also created a new monster called Shadow AI. In the rush to seek forgiveness instead of asking permission, AI is being implemented throughout the manufacturing sector without letting key IT, operations or security personnel know what is being used. This creates huge security concerns, along with cost overruns and internal confusion on the best ways to leverage AI. In this episode we talk to Julie Brunias, Cybersecurity Expert at Videotron. Watch/listen as we discuss: Preventing the villanization of artificial intelligence.The importance of having a man-in-the-loop for all AI integrations.The role of regulatory bodies when it comes to AI.Understanding the right AI tools for your environment.Here's a link to the information Julie shared. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com .  You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com. As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    Shadow AI Is Amplifying OT Threats
  3. Aug 28

    AI is Fueling, Killing Ransomware

    Send us Fan Mail In this episode, we’re doubling up on a couple of topics that continue to be at the top of industrial cybersecurity’s critical issue list – ransomware and artificial intelligence. The confluence of these two topics is interesting to break down in considering how AI has contributed to the speed and scale of ransomware attacks, while the growth of these extortion campaigns has led to more enterprises seeking out AI solutions to bolster their cyber defenses. To discuss these intertwining facets of industrial cybersecurity, we’ll first hear from Rob T. Lee, the Chief AI Officer and Chief of Research at the SANS Institute, then from Eric Herzog, the Chief Marketing Officer at Infinidat before getting some closing remarks from Rob. Listen/watch as they discuss: • The growing threat landscape and what is feeding it. • How data storage strategies can help mitigate attacks. • The growing importance of response plans. • How AI is generating both concern and excitement for cybersecurity strategies. • The rise of autonomous attack schemes. • Why experimentation should be a key element of cybersecurity training. • A copy of the report Rob mentioned can be found here. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or  MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com. #Cybersecurity #Ransomware #ArtificialIntelligence #AI #IndustrialCybersecurity #Manufacturing #OTSecurity #CyberThreats #CyberDefense #ManufacturingCybersecurity As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    AI is Fueling, Killing Ransomware
  4. Aug 12

    Good Guys Also Use AI

    Send us Fan Mail The pace of technological advancement and the evolution of hacker behaviors makes recording episodes of this podcast well in advance a bit or a risk. There’s always the worry that whatever we discuss could become less relevant by the time it goes live. Today’s episode, however, bucks that trend. The number of AI programs that have made headlines recently for busting out of their developmental sandboxes has generated some justified scrutiny of AI-based security solutions. And while all of these developers deserve the heat they’re getting, it’s also important to not let these missteps serve as an excuse to delay your use of AI in strengthening cyber defenses. I’m excited to have you listen to a conversation I had recently with AirMDR’s CEO Kumar Saurabh. His unbridled enthusiasm about how AI can help the good guys keep pace with evolving threats and implement solutions far more quickly and cost-effectively than even months ago, serves as a critical reminder to continue moving forward with AI implementations, albeit at possibly a more measured pace. Watch/listen as we discuss: How AI also simplifies and scales things for the good guys.Why AI is only in the second inning of the game.How an AI strategy should be like "building the car around the engine."Why AI could be the solution for enterprises trying to implement cybersecurity fixes, but lack the time and resources.Where agents and humans can compliment each other.Why shrinking attack windows mean manufacturers have to pick up the pace for response.Ways to identify the right tools and platforms for your organization.A copy of the report mentioned by Kumar can be found here.  As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    Good Guys Also Use AI
  5. Jul 31

    LISTEN: The Continuing Evolution of Ransomware

    Send us Fan Mail There is perhaps no greater confluence of old and new school ideologies than the current ransomware threat landscape plaguing the industrial sector. On one hand – the motivations and avenues of attack have changed very little. Hackers are still leveraging weak log-in security or lagging parameter defenses to steal data and launch malware as they extort the enterprise. However, that malware is now being released by highly specialized hacking groups that can launch and scale their attacks more quickly with AI tools, and with malware either sourced from another specialized provider, or optimized by, again, AI tools. The overall result has been another surge in ransomware attacks against the hacking community’s favorite target – manufacturing.  Here to offer some insight on these and other trends related to ransomware in the industrial sector is Sean Nikkel. He serves as the Team Lead for Bitdefender’s Cyber Intelligence Fusion Cell. Listen as we discuss:  • The spike in living-off-the-land ransomware attacks, and how old-school detection strategies may be fueling this surge. • How a combination of ransomware group specialization and AI are helping bad actors scale their attacks in unprecedented ways. • The need to prioritize vulnerabilities in new ways. • How fewer ransomware payments could only be a temporary win for the sector. • How to build a culture where cybersecurity is more than doom and gloom, and the best ways to celebrate the wins.  A copy of the report Sean mentioned can be found here. https://www.bitdefender.com/en-us/blog/businessinsights/ransomware-attacks-targeting-us-organizations-2026  To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com. #cybersecurity, #infosec, #cybersecurityawareness, #ethicalhacking, #hacking, #cyberattack, #datasecurity, #networksecurity, #informationsecurity, #cybercrime, #tech, #technology, #ai, #ransomware, #malware, #cloudsecurity, #zerotrust, #phishing, #soc, #cyberdefense, #itsecurity, #cybernews, #security, #penetrationtesting, #digitalsecurity As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    LISTEN: The Continuing Evolution of Ransomware
  6. Jul 17

    LISTEN: Security Breach: 'Prevention is Damn Near Impossible'

    Send us Fan Mail The truth can be … brutal. The harsh realities of many situations we face on a daily basis can be tough to embrace, especially when they dictate having to adjust many long-held beliefs or established processes. This is often referred to as “breaking paradigms”, and is a situation that is simultaneously prominent in need, and typically lacking in execution throughout industrial cybersecurity.  We know the realities of addressing security concerns, but often face so many challenges in addressing them, that we choose to continue doing what we’ve always done, even if that’s not the best solution.  That’s why it’s good to hear from people like my guest for today’s episode. John Anthony Smith is the founder and chief security office of Fenix24. His company specializes in responding to breaches and he pulls no punches when it comes to the changes he feels manufacturers need to make in order to address the evolving threat landscape.  I can almost guarantee that at some point you will disagree with John, but I’d encourage you to continue listening and find the areas of your security strategies that could benefit from a more critical perspective. Watch/listen as we discuss: What he has learned from meeting clients on their worst day.Why so many organizations struggle to fully understand their data, and the bad decisions and strategies this can fuel.How over-spending on prevention tools has created a false confidence in defense posture.Why the industry needs to share more information about breeches, and why that will continue to be a challenge.The right ways to use AI.The surprising source of a growing number of hacks in the manufacturing sector. To catch up on past episodes, you can go to Manufacturing.net,IEN.com or  MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com. As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    LISTEN:  Security Breach: 'Prevention is Damn Near Impossible'
  7. Jun 24

    The Hard Realities of OT Cybersecurity

    Send us Fan Mail Perhaps you’re familiar with the phrase, “ignorance is bliss.” It was first written by English poet Thomas Gray in 1742. He was reflecting on the carefree aspect of childhood, and how, "In knowing nothing, life is most delightful." Well, I have to admit, he’s got a point. Not recognizing or dealing with problems does eliminate them from your day-to-day. Unfortunately, that doesn’t mean they fail to exist. The reality is that choosing to remain ignorant about ongoing problems is far from delightful, especially for all those who continue to operate with their heads above sand level and beneath the clouds. Our guest for today’s episode, CyberProof’s Nick Lantuh, illustrates this pretty plainly when discussing two of industrial cybersecurity’s biggest pain points – supply chain security and the surge in ransomware attacks. Both seem to share the same underlying causality – industrial organizations simply think they’re too small or too unimportant to be attacked – something that is repeatedly, and painfully, being realized as ignorant, and far from blissful. Listen as Nick and I discuss: The surge in foreign threat actors.The right approach to handling ransom demands.How a lack of response planning is making the industrial sector a favorite target of hackers.The keys to ensuring AI is deployed and operating correctly for cybersecurity applications.How smaller, and often less secure, manufacturers are the key to supply chain security, and why audits, education and regulation are so important.The importance of MDR tools being able to function at "machine speed."As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    The Hard Realities of OT Cybersecurity
  8. Jun 12

    Focus on Hitting Lower, Not Harder

    Send us Fan Mail The unsexy blocking and tacking that creates more win-win cybersecurity scenarios. It struck me in putting this episode together that working in industrial cybersecurity is kind of like playing special teams in football. Regardless of how many times you do something right, all it takes is that one blocked kick, long return, or missed field goal to get you noticed in the wrong way.  All the instances of flawless defense and precise execution is negated with one, single lapse that brings the whole operation down. I'd invite you to watch/listen as Richard Springer, Senior Director of Marketing for OT Solutions at Fortinet offers some insight on how we can build on those wins by: Embracing the "when", not "if" dynamic of being attacked.Not losing sight of the basics, despite all the challenges and potential tools and technological solutions.Continuing to build awareness of OT security challenges and priorities.Bringing IT and OT together with the shared mission of "keeping the lights on."Implementing Continuous Improvement strategies used in operations for security.Using AI to help establish priorities and assist with patching vulnerabilities.Learning from other sectors on how to identify, react and recover from attacks.The report Richard mentions can be found here. As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Click Here to Become a Sponsor. To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast. If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at jeff@ien.com.

    Focus on Hitting Lower, Not Harder

Ratings & Reviews

About

A weekly discussion of new developments and the latest cybersecurity threats, including ransomware, malware, phishing schemes, DDoS attacks and more, facing the U.S. industrial sector.