PLAY PODCASTS
The Industrial Security Podcast

The Industrial Security Podcast

148 episodes — Page 1 of 3

Rapid Recovery - When Security Fails [The Industrial Security Podcast]

We've been hacked. Everything is down. Or more mundane - there was a power surge and 5% of our cyber gear is fried. How do we get back into operation fastest? Stephen Nichols of Acronis joins us to look at rapid recovery of OT systems - from the mundane to the arcane.

Dec 13, 202543 min

We can't - and shouldn't - fix everything [The Industrial Security Podcast]

We know there are problems in our security systems, but we can't and shouldn't fix everything. What do we fix? Who decides? How do we explain what's reasonable to people who do decide? Kayne McGladrey, CISOIn Residence at Hyperproof, joins us to explore risk, communication, and a surprising role for insurance.

Nov 21, 202554 min

Ep 210Medical Device Cybersecurity Is Tricky [The Industrial Security Podcast]

Yes the device has to be safe to use on patients, and yes it has to produce its results reliably, but patient / data confidentiality is also really important. Naomi Schwartz of Medcrypt joins us to explore the multi-faceted world of medical device cybersecurity - from MRI's to blood sugar testers.

Oct 28, 20251h 3m

Ep 218Hardware Hacking - Essential OT Attack Knowledge [the industrial security podcast]

If you can touch it, you can hack it, usually. And having hacked it, you can often more easily find exploitable vulnerabilities. Marcel Rick-Cen of Foxgrid walks us through the basics of hacking industrial hardware and software systems.

Oct 6, 202543 min

Ep 212Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]

Asset inventory, networks and router / firewall configurations, device criticality - a lot of information. How can we USE this information to make useful decisions about next steps to address cyber risk? Vivek Ponada of Frenos joins us to explore a new kind of OT / industrial digital twin - grab all that data and work it to draw useful conclusions.

Sep 8, 202545 min

I don't sign s**t [The Industrial Security Podcast]

We don't have budget to fix the problem, so we accept the risk? Tim McCreight of TaleCraft Security in his (coming soon) book "I don't sign s**t" uses story-telling to argue that front line security leaders should not be accepting multi-billion dollar risks on behalf of the business. We need to escalate those decisions - with often surprising results when we do.

Aug 11, 202549 min

NIS2 and the Cyber Resilience Act (CRA) [The Industrial Security Podcast]

NIS2 legislation is late in many EU countries, and the new CRA applies to most suppliers of industrial / OT computerized and software products to the EU. Christina Kiefer, attorney at reuschlaw, walks us through what's new and what it means for vendors, as well as for owner / operators.

Jul 28, 202553 min

Network Duct Tape [The Industrial Security Podcast]

Hundreds of subsystems with the same IP addresses? Thousands of legacy devices with no modern encryption or other security? Constant, acquisitions of facilities "all over the place" network-wise and security-wise? What most of us need is "network duct tape". Tom Sego of Blastwave shows us how their "duct tape" works.

Jul 11, 20251h 4m

Credibility, not Likelihood [The Industrial Security Podcast]

Safety defines cybersecurity - Kenneth Titlestad of Omny joins us to explore safety, risk, likelihood, credibility, and deterministic / unhackable cyber defenses - a lot of it in the context of Norwegian offshore platforms.

Jun 17, 202553 min

Lessons Learned From Incident Response [The Industrial Security Podcast]

How did they get in? How did we find them when they got in? What can we do in future to clean up the mess faster? Chris Sistrunk reflects on a decades' industrial cyber incident response experience at Mandiant (Google).

May 20, 202550 min

Experience & Challenges Using Asset Inventory Tools [The Industrial Security Podcast]

Asset inventory tools have become almost ubiquitous as main offerings or add-ons to OT security solutions. In this episode, Brian Derrico of Trident Cyber Partners walks us through what it's like to use these tools - different kinds of tools in different environments.

Apr 21, 202536 min

Needles in Haystacks - Recruiting OT Incident Responders [The Industrial Security Podcast]

Industrial incidents can be cyber attacks, or equipment failures, or physical equipment leaking product because of metal fatigue or incorrect welds. OT incident responders need to know a lot. Doug Leece of Enbridge explores what is OT incident response and what you look for recruiting people into that role.

Mar 17, 202556 min

Would You Rather Use a Control System That's Proven Correct? [The Industrial Security Podcast]

For safety-critical operations or for critical national infrastructures, would you rather base your system on a code that people have tested as best they can, or would you rather base your system on a platform that has been proven correct? Daly Brown and Nick Foubert of Metropolitan Technologies look at a new approach to designing OT systems.

Feb 24, 202552 min

How to Embed 30 Years of Security Funding into Capital Budgets [The Industrial Security Podcast]

Most of us struggle to get funding for industrial cybersecurity. Ian Fleming of Deloitte explains how - because cybersecurity is essential to sustaining the value of industrial assets - how we can embed up to 20 or 30 years of cybersecurity budget into capital plans, rather than fight for budget every year.

Jan 27, 202556 min

Insights into Nation State Threats [The Industrial Security Podcast]

Nation state threats are often portrayed as the "irresistible forces" of cyber threats, with little qualification. Joseph Price of Deloitte joins us to dig deeper - what are nation states capable of, what are they up to, and how should we interpret the information that is available to the public?

Dec 9, 20241h 7m

OT Security Data Science - A better vulnerability database [The Industrial Security Podcast]

Security automation needs a machine-readable vulnerability database. Carmit Yadin of Device Total joins us to look at limitations of the widely-used National Vulnerability Database (NVD), and explore a new "data science" alternative.

Nov 20, 202434 min

Driving Change - Cloud Systems and Japanese CCE [The Industrial Security Podcast]

Tomomi Aoyama translated the book Countering Cyber Sabotage - Consequence-Driven, Cyber-Informed Engineering - to Japanese. Tomomi recalls the effort of translating CCE to Japanese and looks forward to applying CCE and OT security principles to industrial cloud systems at Cognite.

Oct 21, 202442 min

Hitting Tens of Thousands of Vehicles At Once [The Industrial Security Podcast]

Compromise a cloud service and tens thousands of vehicles can be affected at once. Matt MacKinnon of Upstream Security walks us through the world of cloud security for connected vehicles, transport trucks, tractors, and other "stuff that moves."

Sep 23, 202435 min

AI takes on polymorphic malware [The Industrial Security Podcast]

The bad guys keep getting better at what they do, and so must we defenders. Gary Southwell of Aria Cyber joins us to look at using AI to get ahead of constantly-changing malware.

Aug 5, 202448 min

New Resource: Adapting IT Advice for OT [The Industrial Security Podcast]

The CIS Top 18 is widely used in IT, and Jack Bliss of 1898 & Co. has adapted that list for OT/industrial, adding a lot of industrial context and lists of related OT-centric tools and technology.

Jul 22, 202444 min

Their own rail system, water treatment and more [The Industrial Security Podcast]

Airports really are small cities. Eric Vautier, CISO of all 3 Paris airports looks at what is an airport and how are thousands of airports changing because of NIS2 and the regulatory environment more generally.

Jul 2, 202452 min

Rapid Recovery After an Attack [The Industrial Security Podcast]

Ransomware is the most common cyber attack causing OT outages - all Windows machines encrypted. What if we could "press a button" and have everything working again in seconds or minutes? Alex Yevtushenko of Salvador Technologies joins us to look at new technology for rapid recovery.

May 27, 202447 min

CWE for Zero Days - not CVE [The Industrial Security Podcast]

The Mitre CWE - Common Weakness - database talks about kinds of problems that can show up in the future - future zero days - rather than CVE that talks about what vulnerabilities were discovered in the past. Susan Farrell walks us through the CWE and how both vendors and owners & operators use it.

May 8, 202449 min

AI and Industrial Security in the Energy Transition [The Industrial Security Podcast]

AI is coming and industrial security is an issue. Join us as Leo Simonovich VP at Siemens Energy joins us to look at both in the context of the energy transition - burning fewer fuels to achieve the same industrial process goals.

Apr 3, 202446 min

Evaluating network segmentation strength [The Industrial Security Podcast]

How hard is it for an attacker to dig around in my network? Robin Berthier of Network Perception joins us to look at new network segmentation evaluation and visualization technology that lets us see at a glance how much trouble, or not, we're in.

Mar 12, 202451 min

Tractors to Table Tops - Industrial Security in the Industry of Human Consumables [The Industrial Security Podcast]

Precision farming is heavily automated, as are the "food factories" essential to feeding the world's population. Marcus Sachs at the McCrary Institute at Auburn University joins us to look at the threats, the challenges and opportunities to secure our food supplies from cyber risk.

Feb 26, 20241h 10m

Cybersecurity in the AVEVA Enterprise SCADA Product - Going Deep [The Industrial Security Podcast]

From supply chain to Active Directory to segmentation designing security into ICS products is hard. Jake Hawkes walks us through how security gets built into AVEVA Enterprise SCADA.

Feb 12, 20241h 1m

What's Next? A decision support tool for industrial security [The Industrial Security Podcast]

We have a security program, we have a risk assessment, we see gaps and we have a limited budget. How do we use that budget most effectively? Jørgen Hartig, CEO at SecuriOT joins us to look at a decision support tool to help answer the question.https://securiot.dk/securiot-irt

Jan 29, 202436 min

USB Firmware Attacks [The Industrial Security Podcast]

You plug in a USB drive and your laptop starts smoking - nasty. Mario Prieto Sanlés of AuthUSB joins us to look at the nastiest of USB attacks, and what we can do about them.

Jan 15, 202443 min

Managing Trust in Massive IIoT Systems [The Industrial Security Podcast]

Smart meters, smart cities and the IIoT - when thousands of systems of millions of low-power devices need to talk to each other, and talk between systems, managing trust is hard. Dr. Chris Gorog of BlockFrame walks us through the problem and the work BlockFrame and the University of Colorado have been doing to solve the problem.

Jan 1, 202451 min

Making the Move into OT Security [The Industrial Security Podcast]

Moving from IT or engineering roles into OT security is harder than it should be. Mike Holcomb of Fluor has written eBooks & provides a newsletter to help people with that transition. In this episode, Mike reflects on his own evolution into OT security and gives advice to others looking at making the move.

Dec 12, 202348 min

Building Trust to Cooperate - at the EE-ISAC [The Industrial Security Podcast]

Our enemies cooperate, and so must we. Aurelio Blanquet walks us through the activities of the European Energy ISAC, with a focus on building the trust that is essential to enabling the cooperation that we need to work together. Aurelio Blanquet - EE-ISAC Nov 21

Nov 30, 202345 min

Failures of Imagination - from 9-11 to the Aurora test [The Industrial Security Podcast]

The industrial security initiative was triggered by the 9/11 attack on the World Trade Center. Aaron Turner, on the faculty at IANS Research, helped investigate laptop computers used by 9/11 attackers and joined up with Michael Assante to persuade government authorities to launch what has become today's industrial cybersecurity industry. Aaron takes us through the formative years - from 9/11 to the Aurora generator demonstration.

Nov 14, 202355 min

Safety, Security and IEC 62443 in Building Automation [The Industrial Security Podcast]

Cybersecurity and IEC 62443 are increasingly relevant to building automation. Parking garages contain safety-critical CO2 sensors that control fans, the MGM breach is in the news and standards bodies are debating minimum security levels for different kinds of systems. Kyle Peters of Intelligent Buildings joins us to look at IEC 62443-2-1 style security assessments of modern buildings and what we can learn from those assessments.

Oct 30, 202335 min

Physical Security Supports Cybersecurity [The Industrial Security Podcast]

Adversaries who can physically touch a target have a huge advantage when it comes to compromising that target. Mike Almeyda of Force5 joins us to look at tools for physical security that support cybersecurity, especially for the North American NERC CIP standards.

Oct 18, 202346 min

Cybersecurity for Rail Systems - Harder than it sounds [The Industrial Security Podcast]

From aging equipment to regulators who must approve every patch, securing safety-critical rail systems is hard, but has to be done. Miki Shifman, CTO and Co-Founder at Cylus, joins us to talk about the problem and what many owners and operators are doing solution-wise.

Oct 3, 202350 min

Demystifying Cyber Jobs - In the Energy Sector [The Industrial Security Podcast]

Job seekers say there are no OT security job postings. Hiring managers say nobody is applying to their posts. Amanda Theel and Eddy Mullins of Argonne National Labs walk us through recruiting issues, especially for fresh grads.

Sep 18, 202347 min

Large Data Centers - more than just protecting information [The Industrial Security Podcast]

Data centers are critical information infrastructures, with a lot of associated physical infrastructure. Vlad-Gabriel Anghel of Data Center Dynamics Academy walks us through these very recent additions to critical infrastructures, and digs into industrial / OT security needs and solutions for the space.

Sep 4, 202343 min

Active Defense in OT - how to make it work [The Industrial Security Podcast]

Active defense or "intrusion prevention" deep into industrial networks has long been thought of as not workable. Youssef Jad - CTO at CyVault - joins us to talk about a new approach to OT active defense that is designed for sensitive OT / industrial environments.

Aug 1, 202338 min

Risk in Context - When to Patch, When to Let It Ride [The Industrial Security Podcast]

Patching is hard in many industrial / OT systems - the risk the new code poses to operations is comparable to the risk of a cyber attack. But - the vulnerability does not go away just because patching is hard. Rick Kaun, VP Solutions at Verve Industrial joins us to look at what to patch, when to patch, and automation to help make the whole process faster, easier and cheaper.

Jul 5, 202343 min

Hacking the CANbus [The Industrial Security Podcast]

Modern automobiles contain hundreds of CPUs and a CANbus network or three connecting these devices. Thieves are hacking the CANbus to steal cars. Worse is possible. Ken Tindell, CTO at Canis joins us to look at the problem and at what the automobile industry is doing about these embedded control systems.

Jun 19, 202352 min

Saving money and effort automating compliance [The Industrial Security Podcast]

NERC CIP, the new TSA pipeline and rail directives and other regulations can be very expensive - to comply with and to prove to an auditor that you comply. Kathryn Wagner of Assurx joins us to look at what and how we can automate this process to save time and money.

May 31, 202333 min

How cyber fits into big-picture risk [The Industrial Security Podcast]

All physical processes involve risk - sometimes very big risk. Dr. Janaka Ruwanpura from the University of Calgary joins us to look at where cyber risks fit into the big picture of risk at industrial organizations, and at roles and responsibilities for managing risk throughout an organization.

May 17, 202346 min

Six steps to integrating IT & OT in mining [The Industrial Security Podcast]

OT systems are critical to mining safety. Rob Labbe, the chair of the Metals and Mining ISAC joins us to look at six steps to integrating IT & OT networks and security programs in this very sensitive environment.

May 2, 202346 min

Experience Using IEC 62443 Risk Assessments [The Industrial Security Podcast]

Risk assessments are a staple of industrial security programs. Paul Piotrowski, a Principal OT Cybersecurity Engineer at Shell, walks us through a deep dive into his experience using IEC 62443-3-2 risk assessments and the lessons he's learned, with lots of examples.

Apr 17, 202354 min

Shining a Light into the Dark [The Industrial Security Podcast]

Getting an industrial site started on the cybersecurity road can be hard. Matthew Malone of Yokogawa joins us to look at strategies to shake loose funding, trigger conditions that can jump-start investments, and stumbling blocks and how to address them.

Apr 3, 202346 min

Stakeholder-Specific Vulnerability Categorization (SSVC) [The Industrial Security Podcast]

SSVC is a new standard decision process for deciding what to do about new vulnerabilities and patches. Thomas Schmidt of the German BSI joins us to look at how SSVC decision trees work, and where and why to use them.

Mar 20, 202344 min

Bridging industrial Cybersecurity Workforce Gaps [The Industrial Security Podcast]

Different kinds of organizations in different stages of their cybersecurity evolution need to look for different kinds of people to contribute to their industrial security programs. Jason Rivera a Director at Security Risk Advisors joins us to look at workforce capability gaps and different approaches needed to fill those gaps in different scenarios.

Mar 6, 202335 min

#100 Engineering-Grade security in the US DOE Cyber Informed Engineering Strategy [The Industrial Security Podcast]

The new US Department of Energy Cyber Informed Engineering Strategy includes unhackable safeties, manual operations, and other engineering-grade protections, in addition to traditional cybersecurity. Join Cheri Caddy, USA Deputy Assistant Cyber Director as we look at a strategy to develop a discipline of security engineering.

Feb 20, 202348 min

IIoT Firmware Visibility - Under the Hood [The Industrial Security Podcast]

Windows and Linux operating systems provide a lot of detail as to what software & versions of the operating system, applications & libraries are installed. Most firmware provides almost nothing - only a single firmware version number. Thomas Pace, Co-Founder and CEO of Netrise joins us to look at gaining visibility into industrial device firmware and vulnerabilities.

Feb 1, 202347 min