PLAY PODCASTS
The Industrial Security Podcast

The Industrial Security Podcast

148 episodes — Page 2 of 3

Living at the Edge - Visibility into Edge Devices [The Industrial Security Podcast]

Industrial network monitoring and intrusion detection tend to start at the highest level networks - the ones closest to the IT network. Ron Fabella, CTO and Co-Founder of Synsaber joins us to look at the problem the other way around - at how important and how useful it is to monitor our lowest level networks - the edge networks closest to the physical process.

Jan 16, 202353 min

Secure Software Development and a Zero Trust Supply Chain [The Industrial Security Podcast]

How does secure software development work for industrial products (SDLC) and what is a zero-trust supply chain? Gonda Lamberink of Fortress Information Security leads us on a deep dive of what's new in secure software development, and especially how supply chain security is impacting that lifecycle.

Jan 2, 202350 min

Consequences Matter [The Industrial Security Podcast]

Worst-case consequences of compromise determine government and societal policies, so consequences matter, especially for critical infrastructure security. Danielle Jablanski, OT Cybersecurity Strategist at Nozomi Networks joins us to look at threats, consequences and policies for critical infrastructure security.

Dec 12, 202245 min

Really Committing to Supply Chain Security [The Industrial Security Podcast]

Supply chain security is bigger than one standard or one approach. Supply chain has fingers into remote access and cloud services and many other things beyond SBOMs and vendor questionnaires. Pedro Fernandes of Accenture joins us to look at the big picture and at what it takes to really commit to supply chain security.

Nov 14, 202247 min

ROI Mistakes for Cybersecurity Investments [The Industrial Security Podcast]

Cybersecurity investments, like safety investments, involve ROI calculations. But unlike safety, security ROI is not baked into engineering practice. Wally Magda - a senior standards and security instructor, advisor and former NERC CIP auditor joins us to look at today's ROI problems and what to do about them.

Oct 31, 202249 min

Set and Forget - is not cyber resiliency [The Industrial Security Podcast]

Complex networks "drift" over time - maintaining an original security vision is hard. Robin Berthier, CEO and Co-Founder of Network Perception joins us to look at a new technology for understanding what's happening to our networks.

Oct 17, 202244 min

56 OT Vulnerabilities - do they matter? [The Industrial Security Podcast]

Forescout's recent Icefall report documents 56 new OT vulnerabilities, many in certified "secure" industrial equipment. Daniel Dos Santos, Head of Security Research, joins us to look at the vulnerabilities and at what they mean for industrial security.

Oct 3, 202240 min

Why and Who - Not Just How [The Industrial Security Podcast]

The big picture of industrial security programs is why we do security, who does what, and to what standards or risk tolerances. Darren Conway of Capula joins us to look at documenting industrial security policies and programs, not just technology.

Sep 20, 202244 min

Moving Target Defence [The Industrial Security Podcast]

Moving target defence is increasingly used for remote access systems and other high risk connections between and into systems. Ian Schmertzler, President and Co-Founder of Dispel joins us to dig into the technology.

Sep 7, 202237 min

DNP3 Crypto - Harder Than It Looks [The Industrial Security Podcast]

Many people ask "why can't we just encrypt all those industrial protocols?" It turns out it's harder than it looks. Andrew West of Subnet Solutions and the Technical Chair of the DNP User group looks at Secure DNP3 - take three.

Aug 24, 202249 min

Relationships, Not Creepiness - Marketing Industrial Security [The Industrial Security Podcast]

Relationships, humour and a complete lack of creepiness - Laura Torres and Sarah Jennings of FoxGuard join us to look at the art of marketing industrial security solutions.

Aug 8, 202231 min

Like industrial security a decade ago [The Industrial Security Podcast]

Building automation cybersecurity is starting to happen, but most buildings are way back of their industrial peers. Mirel Sehic, Cyber Practice GM for Honeywell Building Technology, joins us to look at security for building automation, smart cities, and the results of a recent survey re: state of the practice.The full survey report is available at https://buildings.honeywell.com/us/en/solutions/healthy-buildings/trends-report

Jul 11, 202243 min

Legislation demands state of the art [The Industrial Security Podcast]

Jens Wiesner of the German BSI joins us - new German critical infrastructure laws demand immediate reporting and certified state-of-the-art attack detection.

Jun 27, 202242 min

OT Cyber insurance is changing fast [The Industrial Security Podcast]

"Silent" cyber coverage has vanished in most insurance policies, and you can't get cyber insurance any more without cyber security. Georgina Williams, Senior Cyber Underwriter at Murich RE joins us to look at how insurers are digging deep into both engineering and security aspects of industrial cyber risk.

Jun 14, 202249 min

Common mistakes in OT visibility deployments [The Industrial Security Podcast]

A lot can go wrong - Enrique Martinez Technical Solutions Architect for OT Security at WWT joins us to look at common mistakes when deploying OT asset inventory, IDS and other visibility solutions - and how to avoid them.

May 30, 202239 min

Just the tricky bits [The Industrial Security Podcast]

Industrial security programs have to touch all the bases. Alexandru Suditu of the Enevo Group joins us to look at - not everything - just the tricky bits.

May 16, 202233 min

Exploding demand [The Industrial Security Podcast]

Demand for skilled industrial / OT security people has increased dramatically over the last couple of years. Join Meg Duba, Senior Technical Recruiter at Idaho National Labs for an update on the market.

May 2, 202235 min

Industrial cyber attacks, consequences & trends [The Industrial Security Podcast]

Greg Hale - Editor and Founder of ISSSource and ICSStrive joins us to look at his new OT / industrial incident repository, and a new report using the data in the repository, analyzing industrial cyber incidents with physical consequences.

Apr 19, 202245 min

Standardization and other risks - experience using CCE [The Industrial Security Podcast]

Standardization and consolidation increase the consequences of cyber attacks - these are unexpected insights from applying the CCE methodology. Jodi Jensen, President of Secure SCADA Solutions joins us to look the experience of using Consequence-Driven, Cyber-Informed Engineering

Mar 29, 202249 min

Risk-based Security Levels - updating ISA/IEC 62443-3-3 [The Industrial Security Podcast]

The widely-used 62443-3-3 standard is being updated. One big change is making security levels risk-based. Join Alex Nicoll, co-chair of the ISA committee updating the standard, to look at what this means and how it will work.

Mar 15, 202251 min

Complete Rewrite - API 1164 Rev 3 [The Industrial Security Podcast]

Functional vs operational safety, profiles, deep connections to IEC 62443 and more. Tom Aubuchon, Principal Consultant at Ethosecure Consulting and Suzanne Lemieux, Director Operations Security and Emergency Response Policy at the American Petroleum Institute join us to look at API 1164 Rev 3 - a complete rewrite of a pioneering cybersecurity standard.

Feb 22, 202246 min

Security vs Compliance & other NERC CIP insights [The Industrial Security Podcast]

Which is better - security or compliance? Suzanne Black of Network Security Technologies brings a new perspective to this old question and covers a lot of other ground in the latest NERC CIP standards.

Feb 7, 202253 min

Architecting Next Gen OT Security [The Industrial Security Podcast]

Safety, insiders, external attacks, remote access, zero trust and more. Serkan Yusuf at Applied Risk explores a new report based on a survey of over 1000 industrial security practitioners.

Jan 24, 202239 min

2021 Attacks & Predictions for 2022 [The Industrial Security Podcast]

A special episode where Nate and Andrew look back at what we can learn from cyber attacks on industrial sites in 2021 and what we should expect to come at us in 2022 and 2023.

Jan 10, 202241 min

We Were Always Connected [The Industrial Security Podcast]

Graham Speake (semi-retired) reflects on a career in industrial security. He points out industrial networks were always connected and observes that we should all get more credit for material improvements in industrial security and security technologies in the last 2-3 decades.

Dec 20, 202140 min

Stronger & Faster - ISA/IEC 62443 [The Industrial Security Podcast]

The IEC 62443 security standards are evolving. Eric Cosman, co-chair of the ISA SP-99 committee that creates the 62443 standards joins us in this episode. Eric looks at how experience using the 62443 standards is driving change in a number of key areas.

Dec 1, 202146 min

How Lenses Blind Us [The Industrial Security Podcast]

"Lenses" are preconceived notions that limit our ability to evaluate and accept solutions. Dr. Art Conklin from the University of Houston joins us to look at lenses in industrial security and what to do about them.

Nov 17, 202149 min

Mergers & Acquisitions - Rapid Change [The Industrial Security Podcast]

Change is a risk in industrial operations, but at least on the security side of things, rapid change is the order of the day when connecting an acquisition to a new owner's infrastructures. Anthony Morrone and Marianne Swarter of Level5Cyber join us to look at issues and solutions for mergers, acquisitions and divestitures of industrial operations.

Oct 31, 202147 min

Automating Vulnerability Handling - a Promising New Standard: CSAF [The Industrial Security Podcast]

Vulnerability handling costs a lot of time and effort - finding the announcements, evaluating them, comparing to our systems, planning & managing deployment and more. Jens Wiesner of the German BSI joins us to explore a new standard that promises to automate much of this task - the Common Security Advisory Framework.

Oct 12, 202145 min

Big Picture Risk - A How-To [The Industrial Security Podcast]

Ernie Hayden joins us to walk through the big picture of risk assessment as documented in his new book - Critical Infrastructure Risk Assessment. The book is a "how-to" for assessing risks ranging from hurricanes to safety systems to cyber attacks.

Sep 29, 20211h 2m

Capabilities vs Probabilities: Ask Different Questions & you get Different Answers [The Industrial Security Podcast]

OT / industrial cyber risk is tricky. Ask questions about probabilities like we did 10 years ago and you get answers that just don't work well. Mark Fabro, President & Chief Security Scientist at Lofty Perch joins the podcast to look at the modern way to model risk.

Sep 14, 202156 min

Maritime Systems: Incidents, Issues and What to do About Them [The Industrial Security Podcast]

Maritime systems are unique in some senses - eg: both having safety critical aspects and being reliant on wireless satellite communications . But these systems are familiar too - PLCs, HMIs and remote access. Marco Ayala, Director of ICS Security at 1898 & Company walks us through the space.

Sep 2, 202145 min

Kill the Spreadsheet [The Industrial Security Podcast]

No one person has all the answers. Bill Lawrence, CSO at SecurityGate.io joins us to look at industrial risk assessments in modern, complex environments.

Aug 18, 202131 min

Building Your Own Workforce [The Industrial Security Podcast]

EnergySec is working with colleges & others on the world's first industrial security apprenticeship program. Join Steve Parker, president of EnergySec to see why electric utilities cannot hire the people they need, and what's being done to fix that.

Aug 4, 202147 min

Secure PLC Coding Practices [The Industrial Security Podcast]

A tool for more secure layer 1 devices is available - The Top 20 Secure PLC Coding Practices. Sarah Fluchs and Vivek Ponnada, two leaders of the initiative, join us to talk about the practices and how to use them.

Jul 20, 202158 min

It's All About Risk - Working With the Board [The Industrial Security Podcast]

''Repost (sound problems repaired) Explore how to work with boards of directors on industrial security issues with Level5Cyber industry veterans Anthony Morrone (former CISO @ DuPont) and Michael Piccalo (former Director @ Forescout)

Jul 7, 202153 min

Petrochemical Manufacturing Cybersecurity [The Industrial Security Podcast]

Commodity vs specialty chemical manufacturing is different in kind, not just quantity. Sameer Koranne, Global OT Lead for IBMs X-Force incident response team talks about manufacturing, safety and security.https://www.ibm.com/security/services/ibm-x-force-incident-response-and-intelligence

Jun 21, 202142 min

Training the Organization, not the Individual [The Industrial Security Podcast]

In boxing, amateurs get hit and go down. Professionals get hit and keep fighting. Join us as Ofir Hason of CyberGym explores how to turn entire organizations from amateurs into professionals when it comes to cyber attacks.

Jun 7, 202135 min

The World's Strongest HazMat Cyber Rules [The Industrial Security Podcast]

The new cyber rules for sites in Israel handling hazardous materials are the strongest in the world. Join Yosi Shavit, Head of the ICS Cybersecurity Department in Israel's Ministry of Environmental Protection to see what's new and different.

May 24, 202154 min

In the Trenches - Cryptosystems & Connectivity [The Industrial Security Podcast]

Encryption is everywhere, but making it work in industrial settings is harder than it looks. Join Sam Elsner, Senior Manager for the Kepware-focused applications engineering team at PTC to do the deep dive on how modern systems are connected and encrypted.

May 3, 202153 min

Managing Future Cost for Security [The Industrial Security Podcast]

Measuring future security costs is easier than measuring today's security benefits. Donovan Tindill, Senior Cybersecurity Strategist at Honeywell Connected Enterprise joins us to explore how to manage industrial cybersecurity spend over the life of industrial automation projects.

Apr 19, 202149 min

Cybersecurity In A Harsh Environment [The Industrial Security Podcast]

Yosi Shneck, long, time CSO at Israel Electric Company, talks about his experience leading cybersecurity efforts in a very difficult threat environment, and about Israel Electric's new initiative to share the company's expertise with other utilities and industrial enterprises.

Apr 5, 202157 min

CCE: Changing How People Think About Cybersecurity [The Industrial Security Podcast]

Sarah Freeman at Idaho National Laboratories and co-author of the new book Countering Cyber Sabotage joins us to discuss the CCE methodology, attacker requirements and "unhackable" mitigations.

Mar 22, 202151 min

Safety and Security in Mining [The Industrial Security Podcast]

So very much about mining and about automation in mining is about safety. Greg Jones, an industrial security specialist at PPLTEK takes us through some unique physical processes and security challenges.

Mar 8, 202156 min

Learnings from the SolarWinds Breach [The Industrial Security Podcast]

The SolarWinds supply chain breach is arguably the biggest hack in history. OSIsoft's Security Architect, Bryan Owen, joins us to explore the breach and what it means for industrial security.

Feb 22, 202153 min

[The Industrial Security Podcast] The Science of Security

Like civil engineers building bridges, security engineers should have quantitative goals: How secure must the system be when commissioned? (How much load must the bridge carry?) How long must the system maintain that security level without major maintenance? (How long must the bridge carry that load reliably between major repairs?) Join Terry Ingoldsby to explore the science of security.

Feb 8, 20211h 6m

[The Industrial Security Podcast] Addressing "Weak Link" Vendors in the Power Grid

CIP-013 is intended to reduce supply chain risks. What are the rules? What are they costing? Are they working? Dr. Joseph Baugh, Managing Consultant at Guidehouse joins us to explore CIP-013, the executive order and other timely NERC CIP topics.

Jan 25, 202148 min

[The Industrial Security Podcast] The Enterprise Perspective on OT Security

Ed Amoroso of Tag Cyber, former CSO of AT&T talks about the IT perspective & approach for OT security - where to start and what to watch for.

Jan 12, 202147 min

[The Industrial Security Podcast] Industrial Cloud Security

There are those who say that "Industrial" and "Cloud" and "Security" really don't fit together - but is this really true? Our guest today is Andrea Carcano from Nozomi Networks explaining how cloud-based security systems really do improve industrial and IoT security.

Dec 21, 202056 min

[The Industrial Security Podcast] Security Monitoring & Management at Airbus

Markus Braendle, head of Airbus Cybersecurity, and Falk Lindner, lead architect for Industrial Cybersecurity at Airbus Manufacturing join us to talk about industrial security monitoring and management at one of the most complex industrial enterprises on the planet.

Dec 7, 20201h 4m