@BEERISAC: OT/ICS Security Podcast Playlist
Anton Shipulin / Listen Notes

Senaste avsnittet
792 avsnitt
- Podcast: Industrial Cybersecurity Insider
Episode: When Cyber Stops the Line, Safety Is on the Line
Pub date: 2026-09-23
Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization
Safety starts with a goal. So should cybersecurity.
Craig Duckworth sits down with Shankar Somasundaram, CEO of Asimily and former head of Symantec's IoT business, to explain why plant floor cybersecurity is a safety issue, not an IT expense. They cover why industrial cybersecurity programs stall after the tool is purchased, how to start with a goal instead of a solution, and why fixing the biggest risks first beats trying to secure everything at once.
The conversation also covers network segmentation mistakes, AI as both a helper and a new threat to critical infrastructure, protecting legacy OT and IoT equipment without disrupting production, watching traffic inside the plant, what drives cybersecurity maturity, and what OT security market consolidation means for manufacturers.
Shankar's three takeaways for your next budget cycle:
Cyber risk is safety risk
Start with the goal
Visibility and fixing the problem are one program, not two
Chapters:
(00:00:00) Cybersecurity is patient safety, operational safety, plant safety
(00:00:45) Meet Shankar and the four pillars behind Asimily
(00:03:50) Why OT security projects stall after the tool is purchased
(00:06:20) Start with a goal, not a solution
(00:09:20) Exposure management and the segmentation myths that slow teams down
(00:11:45) AI as enabler and attacker inside critical infrastructure
(00:15:40) Collecting data on legacy OT and IoT without disrupting operations
(00:18:20) North south, east west, and the flow data most teams skip
(00:20:00) Does maturity come from size, budget, or management
(00:24:20) Consolidation in the OT market and the advice Shankar leaves behind
Links And Resources:
Want to Sponsor an episode or be a Guest? Reach out here.
Industrial Cybersecurity Insider on LinkedIn
Cybersecurity & Digital Safety on LinkedIn
BW Design Group Cybersecurity
Shankar Somasundaram on LinkedIn
Asimily
Dino Busalachi on LinkedIn
Craig Duckworth on LinkedIn
Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!
The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc. Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
2026-09-23 | 46 min.Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)
Episode: Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
Pub date: 2026-09-21
Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization
Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep124/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and supply chain. What does that actually change on the plant floor?
In this episode of Protect It All, host Aaron Crow talks with Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, about the shift regulation is driving in OT: responsibility moving from the server rooms into the boardrooms, and from the operator to the manufacturer.
Tobias makes the case that what gets regulated are fundamentally the basics: risk assessment, asset inventory, cyber hygiene, and detection. The industry has preached these for a decade. Now the law demands them, which makes compliance the business case that finally unlocks long-overdue modernization budget. His advice: do not treat legislation as a paper exercise. Treat it as a utility.
The second half is about recovery, the foundation most plants skip. Aaron and Tobias dig into the vendor-install backup that has never been tested, recovery targets that ignore how long a plant really takes to come back, retain values operators tuned for years that live nowhere else, redundant controllers that are not cyber resilience, and vendor SLAs that send a system engineer when you needed a cyber expert. Tobias's practical pattern: keep a replica of your critical systems, restore into the bubble, and be as intrusive as you like there, scanners and all, without touching production.
Also in this one: NIS2 Article 20 and personal liability for executives, why a cyber incident does not need a nation state (bad firmware counts), where AI belongs in the Purdue model and where it does not, AI as the daily brief for the one-person water utility, Aaron's Exchange 5.5 story about the week the executives lost their email, borrowing the safety engineers' hazard studies as risk input, and why you should never fire up a wireless pineapple on an airplane.
In this episode, you'll learn:
How NIS2, the Cyber Resilience Act, and CIRCIA move accountability to executives and manufacturers
Why 24-hour incident reporting starts with detection, and why you can't wing it
How to reframe your next modernization budget ask around compliance
What a real recovery plan needs: tested backups, plant-realistic RPO and RTO, and captured retain values
Why redundant controllers protect against failure, not compromise
How to test restores and run scanners safely in a replica instead of production
Where AI helps an understaffed operator and where it should never take control
Tune in to hear how the biggest regulatory wave in industrial cybersecurity history can become the budget unlock OT has been waiting for.
About the guest:
Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Having sat on both sides of the table, first delivering cybersecurity services to critical infrastructure operators and now shaping how legislation lands in engineering practice, he brings a combined view of policy, technology, and plant-floor reality that few in the industry carry. Tobias is based in Germany.
Important Links:
LinkedIn of Tobias Nitzsche: https://www.linkedin.com/in/tobias-nitzsche-37339735/
ABB Energy Industries: https://global.abb/group/en/organization/energy-industries
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep124/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
YouTube: https://www.youtube.com/@PrOTectITAll
Email: [email protected]
X: https://twitter.com/protectitall
Facebook: https://facebook.com/protectitallpodcast
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.3/4 Acciones de Gobierno y coordinación de la seguridad OT en el sector eléctrico
2026-09-22 | 9 min.Podcast: Casos de Ciberseguridad Industrial
Episode: 3/4 Acciones de Gobierno y coordinación de la seguridad OT en el sector eléctrico
Pub date: 2026-09-21
Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization
En este episodio se detallan las capacidades clave que se consideran necesarias hoy en día para reducir el riesgo en instalaciones eléctricas industriales. A través de este bloque, examinaremos cómo se toman las decisiones de mitigación en aquellos casos donde no es viable intervenir o parchear determinados activos, analizando el papel que juegan tanto la […]
The podcast and artwork embedded on this page are from Centro de Ciberseguridad Industrial, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.- Podcast: Nexus: A Claroty Podcast (LS 32 · TOP 5% what is this?)
Episode: Tatyana Bolton on the OTCC and OT Cybersecurity
Pub date: 2026-09-20
Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization
Tatyana Bolton, Executive Director of the Operational Technology Cybersecurity Coalition (OTCC), joins the Nexus Podcast to discuss a new partnership between OTCC and the International Society of Automation (ISA), alongside a joint position paper advocating for the ISA/IEC 62443 standard as the definitive global benchmark for operational technology (OT) cybersecurity.
Read more about the partnership
Read the position paper on a unified approach to OT cybersecurity
Subscribe and listen to the Nexus Podcast here.
The podcast and artwork embedded on this page are from Claroty, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc. - Podcast: Industrial Cybersecurity Insider
Episode: Why Industrial Cyber Risk Is Escalating (And How To Stop It)
Pub date: 2026-09-16
Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization
This highlight episode pulls the sharpest moments from past conversations into one continuous argument about why industrial cyber risk keeps escalating and why so many programs stall before they start.
Craig Duckworth and Dino Busalachi open with a number that should stop any executive team cold: one manufacturer lost roughly $500 million in valuation inside 60 hours, and that loss had nothing to do with lost production.
From there the conversation gets practical. They explain why a plant floor security program cannot be run entirely from the data center, why asset inventory and communication flow mapping must come before any discussion of segmentation, and what distinguishes warranted traffic from unwarranted traffic within a control system environment.
Jim Cook joins to break down the difference between a flat network and what the team calls a super flat network, where drives, flow meters, robots, and business systems all share the same space. Together, they make the case that zero trust in operational technology must be built from the bottom of the stack upward, using what they describe as the bucket approach, rather than layered over the plant with enterprise tooling that nobody on site knows how to operate.
The episode closes on ownership: who is accountable, who the plant manager actually trusts, and why the people who design and build the machines belong in the room from day one. If you are responsible for production uptime and for protecting the assets that create it, this one is a fast tour of the decisions that matter most.
Chapters:
(00:00:00) A $500 Million Valuation Loss In 60 Hours
(00:01:00) Why Industrial Cyber Risk Is More Urgent Right Now
(00:03:00) Why IT Cannot Secure The Plant Floor Alone
(00:05:00) Asset Inventory And Communication Flows Come First
(00:07:00) Building A Defensible Architecture In OT Environments
(00:09:00) Flat Networks Versus Super Flat Networks
(00:11:00) The Bucket Approach To Segmentation
(00:14:00) Vetting A Cybersecurity Partner The Right Way
(00:16:00) Tabletop Exercises With The Executive Team
(00:19:00) Who Actually Owns Industrial Cybersecurity
Links And Resources:
Want to Sponsor an episode or be a Guest? Reach out here.
Industrial Cybersecurity Insider on LinkedIn
Cybersecurity & Digital Safety on LinkedIn
BW Design Group Cybersecurity
Dino Busalachi on LinkedIn
Craig Duckworth on LinkedIn
Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!
The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Fler podcasts i Näringsliv
Trendiga poddar i Näringsliv
Om @BEERISAC: OT/ICS Security Podcast Playlist
A curated playlist of Operational Technology (OT) and Industrial Control Systems (ICS) cybersecurity podcast episodes in any language, compiled by ICS security enthusiasts. Missing something? Contact Anton Shipulin on LinkedIn. Subscribe for updates!
Podcast-webbplatsLyssna på @BEERISAC: OT/ICS Security Podcast Playlist, Avanzapodden och många andra poddar från världens alla hörn med radio.se-appen

Hämta den kostnadsfria radio.se-appen
- Bokmärk stationer och podcasts
- Strömma via Wi-Fi eller Bluetooth
- Stödjer Carplay & Android Auto
- Många andra appfunktioner
Hämta den kostnadsfria radio.se-appen
- Bokmärk stationer och podcasts
- Strömma via Wi-Fi eller Bluetooth
- Stödjer Carplay & Android Auto
- Många andra appfunktioner


@BEERISAC: OT/ICS Security Podcast Playlist
Skanna koden,
ladda ner appen,
börja lyssna.
ladda ner appen,
börja lyssna.



















