Your lights are on, your car runs, because industrial systems work 24/7 to keep our lives ticking. But what happens when those systems—the very pillars of modern society—are threatened?
Hosted by Nate Nelson and Andrew Ginter, The Industrial Security Podcast takes a deep-dive into the most pressing emerging issues in SCADA technologies today. But don't just take our word for it: each new episode of the show features a leading voice in the world of industrial control systems security. You'll hear from executives, engineers, researchers and more, each with their own unique take on what's wrong with how we do things today, and how to fix it.
ICS security is complicated. Here is where it all comes together.
We've been hacked. Everything is down. Or more mundane - there was a power surge and 5% of our cyber gear is fried. How do we get back into operation fastest? Stephen Nichols of Acronis joins us to look at rapid recovery of OT systems - from the mundane to the arcane.
We know there are problems in our security systems, but we can't and shouldn't fix everything. What do we fix? Who decides? How do we explain what's reasonable to people who do decide? Kayne McGladrey, CISOIn Residence at Hyperproof, joins us to explore risk, communication, and a surprising role for insurance.
Yes the device has to be safe to use on patients, and yes it has to produce its results reliably, but patient / data confidentiality is also really important. Naomi Schwartz of Medcrypt joins us to explore the multi-faceted world of medical device cybersecurity - from MRI's to blood sugar testers.
If you can touch it, you can hack it, usually. And having hacked it, you can often more easily find exploitable vulnerabilities. Marcel Rick-Cen of Foxgrid walks us through the basics of hacking industrial hardware and software systems.
Asset inventory, networks and router / firewall configurations, device criticality - a lot of information. How can we USE this information to make useful decisions about next steps to address cyber risk? Vivek Ponada of Frenos joins us to explore a new kind of OT / industrial digital twin - grab all that data and work it to draw useful conclusions.
We don't have budget to fix the problem, so we accept the risk? Tim McCreight of TaleCraft Security in his (coming soon) book "I don't sign s**t" uses story-telling to argue that front line security leaders should not be accepting multi-billion dollar risks on behalf of the business. We need to escalate those decisions - with often surprising results when we do.
NIS2 legislation is late in many EU countries, and the new CRA applies to most suppliers of industrial / OT computerized and software products to the EU. Christina Kiefer, attorney at reuschlaw, walks us through what's new and what it means for vendors, as well as for owner / operators.
Hundreds of subsystems with the same IP addresses? Thousands of legacy devices with no modern encryption or other security? Constant, acquisitions of facilities "all over the place" network-wise and security-wise? What most of us need is "network duct tape". Tom Sego of Blastwave shows us how their "duct tape" works.
Safety defines cybersecurity - Kenneth Titlestad of Omny joins us to explore safety, risk, likelihood, credibility, and deterministic / unhackable cyber defenses - a lot of it in the context of Norwegian offshore platforms.
How did they get in? How did we find them when they got in? What can we do in future to clean up the mess faster? Chris Sistrunk reflects on a decades' industrial cyber incident response experience at Mandiant (Google).
Asset inventory tools have become almost ubiquitous as main offerings or add-ons to OT security solutions. In this episode, Brian Derrico of Trident Cyber Partners walks us through what it's like to use these tools - different kinds of tools in different environments.
Industrial incidents can be cyber attacks, or equipment failures, or physical equipment leaking product because of metal fatigue or incorrect welds. OT incident responders need to know a lot. Doug Leece of Enbridge explores what is OT incident response and what you look for recruiting people into that role.
For safety-critical operations or for critical national infrastructures, would you rather base your system on a code that people have tested as best they can, or would you rather base your system on a platform that has been proven correct? Daly Brown and Nick Foubert of Metropolitan Technologies look at a new approach to designing OT systems.
Most of us struggle to get funding for industrial cybersecurity. Ian Fleming of Deloitte explains how - because cybersecurity is essential to sustaining the value of industrial assets - how we can embed up to 20 or 30 years of cybersecurity budget into capital plans, rather than fight for budget every year.
Nation state threats are often portrayed as the "irresistible forces" of cyber threats, with little qualification. Joseph Price of Deloitte joins us to dig deeper - what are nation states capable of, what are they up to, and how should we interpret the information that is available to the public?
Security automation needs a machine-readable vulnerability database. Carmit Yadin of Device Total joins us to look at limitations of the widely-used National Vulnerability Database (NVD), and explore a new "data science" alternative.
Tomomi Aoyama translated the book Countering Cyber Sabotage - Consequence-Driven, Cyber-Informed Engineering - to Japanese. Tomomi recalls the effort of translating CCE to Japanese and looks forward to applying CCE and OT security principles to industrial cloud systems at Cognite.
Compromise a cloud service and tens thousands of vehicles can be affected at once. Matt MacKinnon of Upstream Security walks us through the world of cloud security for connected vehicles, transport trucks, tractors, and other "stuff that moves."
The bad guys keep getting better at what they do, and so must we defenders. Gary Southwell of Aria Cyber joins us to look at using AI to get ahead of constantly-changing malware.
The CIS Top 18 is widely used in IT, and Jack Bliss of 1898 & Co. has adapted that list for OT/industrial, adding a lot of industrial context and lists of related OT-centric tools and technology.
Airports really are small cities. Eric Vautier, CISO of all 3 Paris airports looks at what is an airport and how are thousands of airports changing because of NIS2 and the regulatory environment more generally.
Ransomware is the most common cyber attack causing OT outages - all Windows machines encrypted. What if we could "press a button" and have everything working again in seconds or minutes? Alex Yevtushenko of Salvador Technologies joins us to look at new technology for rapid recovery.
The Mitre CWE - Common Weakness - database talks about kinds of problems that can show up in the future - future zero days - rather than CVE that talks about what vulnerabilities were discovered in the past. Susan Farrell walks us through the CWE and how both vendors and owners & operators use it.
AI is coming and industrial security is an issue. Join us as Leo Simonovich VP at Siemens Energy joins us to look at both in the context of the energy transition - burning fewer fuels to achieve the same industrial process goals.
How hard is it for an attacker to dig around in my network? Robin Berthier of Network Perception joins us to look at new network segmentation evaluation and visualization technology that lets us see at a glance how much trouble, or not, we're in.
Precision farming is heavily automated, as are the "food factories" essential to feeding the world's population. Marcus Sachs at the McCrary Institute at Auburn University joins us to look at the threats, the challenges and opportunities to secure our food supplies from cyber risk.
From supply chain to Active Directory to segmentation designing security into ICS products is hard. Jake Hawkes walks us through how security gets built into AVEVA Enterprise SCADA.
We have a security program, we have a risk assessment, we see gaps and we have a limited budget. How do we use that budget most effectively? Jørgen Hartig, CEO at SecuriOT joins us to look at a decision support tool to help answer the question.
https://securiot.dk/securiot-irt
You plug in a USB drive and your laptop starts smoking - nasty. Mario Prieto Sanlés of AuthUSB joins us to look at the nastiest of USB attacks, and what we can do about them.
Smart meters, smart cities and the IIoT - when thousands of systems of millions of low-power devices need to talk to each other, and talk between systems, managing trust is hard. Dr. Chris Gorog of BlockFrame walks us through the problem and the work BlockFrame and the University of Colorado have been doing to solve the problem.
Moving from IT or engineering roles into OT security is harder than it should be. Mike Holcomb of Fluor has written eBooks & provides a newsletter to help people with that transition. In this episode, Mike reflects on his own evolution into OT security and gives advice to others looking at making the move.
Our enemies cooperate, and so must we. Aurelio Blanquet walks us through the activities of the European Energy ISAC, with a focus on building the trust that is essential to enabling the cooperation that we need to work together. Aurelio Blanquet - EE-ISAC Nov 21
The industrial security initiative was triggered by the 9/11 attack on the World Trade Center. Aaron Turner, on the faculty at IANS Research, helped investigate laptop computers used by 9/11 attackers and joined up with Michael Assante to persuade government authorities to launch what has become today's industrial cybersecurity industry. Aaron takes us through the formative years - from 9/11 to the Aurora generator demonstration.
Cybersecurity and IEC 62443 are increasingly relevant to building automation. Parking garages contain safety-critical CO2 sensors that control fans, the MGM breach is in the news and standards bodies are debating minimum security levels for different kinds of systems. Kyle Peters of Intelligent Buildings joins us to look at IEC 62443-2-1 style security assessments of modern buildings and what we can learn from those assessments.
Adversaries who can physically touch a target have a huge advantage when it comes to compromising that target. Mike Almeyda of Force5 joins us to look at tools for physical security that support cybersecurity, especially for the North American NERC CIP standards.
From aging equipment to regulators who must approve every patch, securing safety-critical rail systems is hard, but has to be done. Miki Shifman, CTO and Co-Founder at Cylus, joins us to talk about the problem and what many owners and operators are doing solution-wise.
Job seekers say there are no OT security job postings. Hiring managers say nobody is applying to their posts. Amanda Theel and Eddy Mullins of Argonne National Labs walk us through recruiting issues, especially for fresh grads.
Data centers are critical information infrastructures, with a lot of associated physical infrastructure. Vlad-Gabriel Anghel of Data Center Dynamics Academy walks us through these very recent additions to critical infrastructures, and digs into industrial / OT security needs and solutions for the space.
Active defense or "intrusion prevention" deep into industrial networks has long been thought of as not workable. Youssef Jad - CTO at CyVault - joins us to talk about a new approach to OT active defense that is designed for sensitive OT / industrial environments.
Patching is hard in many industrial / OT systems - the risk the new code poses to operations is comparable to the risk of a cyber attack. But - the vulnerability does not go away just because patching is hard. Rick Kaun, VP Solutions at Verve Industrial joins us to look at what to patch, when to patch, and automation to help make the whole process faster, easier and cheaper.
Modern automobiles contain hundreds of CPUs and a CANbus network or three connecting these devices. Thieves are hacking the CANbus to steal cars. Worse is possible. Ken Tindell, CTO at Canis joins us to look at the problem and at what the automobile industry is doing about these embedded control systems.
NERC CIP, the new TSA pipeline and rail directives and other regulations can be very expensive - to comply with and to prove to an auditor that you comply. Kathryn Wagner of Assurx joins us to look at what and how we can automate this process to save time and money.
All physical processes involve risk - sometimes very big risk. Dr. Janaka Ruwanpura from the University of Calgary joins us to look at where cyber risks fit into the big picture of risk at industrial organizations, and at roles and responsibilities for managing risk throughout an organization.
OT systems are critical to mining safety. Rob Labbe, the chair of the Metals and Mining ISAC joins us to look at six steps to integrating IT & OT networks and security programs in this very sensitive environment.
Risk assessments are a staple of industrial security programs. Paul Piotrowski, a Principal OT Cybersecurity Engineer at Shell, walks us through a deep dive into his experience using IEC 62443-3-2 risk assessments and the lessons he's learned, with lots of examples.
Getting an industrial site started on the cybersecurity road can be hard. Matthew Malone of Yokogawa joins us to look at strategies to shake loose funding, trigger conditions that can jump-start investments, and stumbling blocks and how to address them.
SSVC is a new standard decision process for deciding what to do about new vulnerabilities and patches. Thomas Schmidt of the German BSI joins us to look at how SSVC decision trees work, and where and why to use them.
Different kinds of organizations in different stages of their cybersecurity evolution need to look for different kinds of people to contribute to their industrial security programs. Jason Rivera a Director at Security Risk Advisors joins us to look at workforce capability gaps and different approaches needed to fill those gaps in different scenarios.
The new US Department of Energy Cyber Informed Engineering Strategy includes unhackable safeties, manual operations, and other engineering-grade protections, in addition to traditional cybersecurity. Join Cheri Caddy, USA Deputy Assistant Cyber Director as we look at a strategy to develop a discipline of security engineering.
Windows and Linux operating systems provide a lot of detail as to what software & versions of the operating system, applications & libraries are installed. Most firmware provides almost nothing - only a single firmware version number. Thomas Pace, Co-Founder and CEO of Netrise joins us to look at gaining visibility into industrial device firmware and vulnerabilities.
Industrial network monitoring and intrusion detection tend to start at the highest level networks - the ones closest to the IT network. Ron Fabella, CTO and Co-Founder of Synsaber joins us to look at the problem the other way around - at how important and how useful it is to monitor our lowest level networks - the edge networks closest to the physical process.
How does secure software development work for industrial products (SDLC) and what is a zero-trust supply chain? Gonda Lamberink of Fortress Information Security leads us on a deep dive of what's new in secure software development, and especially how supply chain security is impacting that lifecycle.
Worst-case consequences of compromise determine government and societal policies, so consequences matter, especially for critical infrastructure security. Danielle Jablanski, OT Cybersecurity Strategist at Nozomi Networks joins us to look at threats, consequences and policies for critical infrastructure security.
Supply chain security is bigger than one standard or one approach. Supply chain has fingers into remote access and cloud services and many other things beyond SBOMs and vendor questionnaires. Pedro Fernandes of Accenture joins us to look at the big picture and at what it takes to really commit to supply chain security.
Cybersecurity investments, like safety investments, involve ROI calculations. But unlike safety, security ROI is not baked into engineering practice. Wally Magda - a senior standards and security instructor, advisor and former NERC CIP auditor joins us to look at today's ROI problems and what to do about them.
Complex networks "drift" over time - maintaining an original security vision is hard. Robin Berthier, CEO and Co-Founder of Network Perception joins us to look at a new technology for understanding what's happening to our networks.
Forescout's recent Icefall report documents 56 new OT vulnerabilities, many in certified "secure" industrial equipment. Daniel Dos Santos, Head of Security Research, joins us to look at the vulnerabilities and at what they mean for industrial security.
The big picture of industrial security programs is why we do security, who does what, and to what standards or risk tolerances. Darren Conway of Capula joins us to look at documenting industrial security policies and programs, not just technology.
Moving target defence is increasingly used for remote access systems and other high risk connections between and into systems. Ian Schmertzler, President and Co-Founder of Dispel joins us to dig into the technology.
Many people ask "why can't we just encrypt all those industrial protocols?" It turns out it's harder than it looks. Andrew West of Subnet Solutions and the Technical Chair of the DNP User group looks at Secure DNP3 - take three.
Relationships, humour and a complete lack of creepiness - Laura Torres and Sarah Jennings of FoxGuard join us to look at the art of marketing industrial security solutions.
Building automation cybersecurity is starting to happen, but most buildings are way back of their industrial peers. Mirel Sehic, Cyber Practice GM for Honeywell Building Technology, joins us to look at security for building automation, smart cities, and the results of a recent survey re: state of the practice.
The full survey report is available at https://buildings.honeywell.com/us/en/solutions/healthy-buildings/trends-report
Jens Wiesner of the German BSI joins us - new German critical infrastructure laws demand immediate reporting and certified state-of-the-art attack detection.
"Silent" cyber coverage has vanished in most insurance policies, and you can't get cyber insurance any more without cyber security. Georgina Williams, Senior Cyber Underwriter at Murich RE joins us to look at how insurers are digging deep into both engineering and security aspects of industrial cyber risk.
A lot can go wrong - Enrique Martinez Technical Solutions Architect for OT Security at WWT joins us to look at common mistakes when deploying OT asset inventory, IDS and other visibility solutions - and how to avoid them.
Industrial security programs have to touch all the bases. Alexandru Suditu of the Enevo Group joins us to look at - not everything - just the tricky bits.
Demand for skilled industrial / OT security people has increased dramatically over the last couple of years. Join Meg Duba, Senior Technical Recruiter at Idaho National Labs for an update on the market.
Greg Hale - Editor and Founder of ISSSource and ICSStrive joins us to look at his new OT / industrial incident repository, and a new report using the data in the repository, analyzing industrial cyber incidents with physical consequences.
Standardization and consolidation increase the consequences of cyber attacks - these are unexpected insights from applying the CCE methodology. Jodi Jensen, President of Secure SCADA Solutions joins us to look the experience of using Consequence-Driven, Cyber-Informed Engineering
The widely-used 62443-3-3 standard is being updated. One big change is making security levels risk-based. Join Alex Nicoll, co-chair of the ISA committee updating the standard, to look at what this means and how it will work.
Functional vs operational safety, profiles, deep connections to IEC 62443 and more. Tom Aubuchon, Principal Consultant at Ethosecure Consulting and Suzanne Lemieux, Director Operations Security and Emergency Response Policy at the American Petroleum Institute join us to look at API 1164 Rev 3 - a complete rewrite of a pioneering cybersecurity standard.
Which is better - security or compliance? Suzanne Black of Network Security Technologies brings a new perspective to this old question and covers a lot of other ground in the latest NERC CIP standards.
Safety, insiders, external attacks, remote access, zero trust and more. Serkan Yusuf at Applied Risk explores a new report based on a survey of over 1000 industrial security practitioners.
A special episode where Nate and Andrew look back at what we can learn from cyber attacks on industrial sites in 2021 and what we should expect to come at us in 2022 and 2023.
Graham Speake (semi-retired) reflects on a career in industrial security. He points out industrial networks were always connected and observes that we should all get more credit for material improvements in industrial security and security technologies in the last 2-3 decades.
The IEC 62443 security standards are evolving. Eric Cosman, co-chair of the ISA SP-99 committee that creates the 62443 standards joins us in this episode. Eric looks at how experience using the 62443 standards is driving change in a number of key areas.
"Lenses" are preconceived notions that limit our ability to evaluate and accept solutions. Dr. Art Conklin from the University of Houston joins us to look at lenses in industrial security and what to do about them.
Change is a risk in industrial operations, but at least on the security side of things, rapid change is the order of the day when connecting an acquisition to a new owner's infrastructures. Anthony Morrone and Marianne Swarter of Level5Cyber join us to look at issues and solutions for mergers, acquisitions and divestitures of industrial operations.
Vulnerability handling costs a lot of time and effort - finding the announcements, evaluating them, comparing to our systems, planning & managing deployment and more. Jens Wiesner of the German BSI joins us to explore a new standard that promises to automate much of this task - the Common Security Advisory Framework.
Ernie Hayden joins us to walk through the big picture of risk assessment as documented in his new book - Critical Infrastructure Risk Assessment. The book is a "how-to" for assessing risks ranging from hurricanes to safety systems to cyber attacks.
OT / industrial cyber risk is tricky. Ask questions about probabilities like we did 10 years ago and you get answers that just don't work well. Mark Fabro, President & Chief Security Scientist at Lofty Perch joins the podcast to look at the modern way to model risk.
Maritime systems are unique in some senses - eg: both having safety critical aspects and being reliant on wireless satellite communications. But these systems are familiar too - PLCs, HMIs and remote access. Marco Ayala, Director of ICS Security at 1898 & Company walks us through the space.
No one person has all the answers. Bill Lawrence, CSO at SecurityGate.io joins us to look at industrial risk assessments in modern, complex environments.
EnergySec is working with colleges & others on the world's first industrial security apprenticeship program. Join Steve Parker, president of EnergySec to see why electric utilities cannot hire the people they need, and what's being done to fix that.
A tool for more secure layer 1 devices is available - The Top 20 Secure PLC Coding Practices. Sarah Fluchs and Vivek Ponnada, two leaders of the initiative, join us to talk about the practices and how to use them.
''Repost (sound problems repaired) Explore how to work with boards of directors on industrial security issues with Level5Cyber industry veterans Anthony Morrone (former CISO @ DuPont) and Michael Piccalo (former Director @ Forescout)
Commodity vs specialty chemical manufacturing is different in kind, not just quantity. Sameer Koranne, Global OT Lead for IBMs X-Force incident response team talks about manufacturing, safety and security.
https://www.ibm.com/security/services/ibm-x-force-incident-response-and-intelligence
In boxing, amateurs get hit and go down. Professionals get hit and keep fighting. Join us as Ofir Hason of CyberGym explores how to turn entire organizations from amateurs into professionals when it comes to cyber attacks.
The new cyber rules for sites in Israel handling hazardous materials are the strongest in the world. Join Yosi Shavit, Head of the ICS Cybersecurity Department in Israel's Ministry of Environmental Protection to see what's new and different.
Encryption is everywhere, but making it work in industrial settings is harder than it looks. Join Sam Elsner, Senior Manager for the Kepware-focused applications engineering team at PTC to do the deep dive on how modern systems are connected and encrypted.
Measuring future security costs is easier than measuring today's security benefits. Donovan Tindill, Senior Cybersecurity Strategist at Honeywell Connected Enterprise joins us to explore how to manage industrial cybersecurity spend over the life of industrial automation projects.
Yosi Shneck, long, time CSO at Israel Electric Company, talks about his experience leading cybersecurity efforts in a very difficult threat environment, and about Israel Electric's new initiative to share the company's expertise with other utilities and industrial enterprises.
Sarah Freeman at Idaho National Laboratories and co-author of the new book Countering Cyber Sabotage joins us to discuss the CCE methodology, attacker requirements and "unhackable" mitigations.
So very much about mining and about automation in mining is about safety. Greg Jones, an industrial security specialist at PPLTEK takes us through some unique physical processes and security challenges.
The SolarWinds supply chain breach is arguably the biggest hack in history. OSIsoft's Security Architect, Bryan Owen, joins us to explore the breach and what it means for industrial security.
Like civil engineers building bridges, security engineers should have quantitative goals: How secure must the system be when commissioned? (How much load must the bridge carry?) How long must the system maintain that security level without major maintenance? (How long must the bridge carry that load reliably between major repairs?) Join Terry Ingoldsby to explore the science of security.
CIP-013 is intended to reduce supply chain risks. What are the rules? What are they costing? Are they working? Dr. Joseph Baugh, Managing Consultant at Guidehouse joins us to explore CIP-013, the executive order and other timely NERC CIP topics.
Ed Amoroso of Tag Cyber, former CSO of AT&T talks about the IT perspective & approach for OT security - where to start and what to watch for.
There are those who say that "Industrial" and "Cloud" and "Security" really don't fit together - but is this really true? Our guest today is Andrea Carcano from Nozomi Networks explaining how cloud-based security systems really do improve industrial and IoT security.
Markus Braendle, head of Airbus Cybersecurity, and Falk Lindner, lead architect for Industrial Cybersecurity at Airbus Manufacturing join us to talk about industrial security monitoring and management at one of the most complex industrial enterprises on the planet.
Breaking into tenant enterprise networks via building automation networks, say from a public coffee shop: Barry Coflan, a Strategy Consultant at Tower Hill Analytics, provides a perspective on the growing attack surface in modern buildings.
Patrick Coyle - long-time blogger at Chemical Facility Security News explores the state of CFATS regulations, new cybersecurity spending bills in the pipe, and his new blog: Future ICS Security News
Cybersecurity for rolling stock (trains) is trickier and even more safety critical than we imagine. Join Shannon Ramsaywak, Managing Partner at Nathanial Rand as we explore automation, security and safety issues for passenger rails.
Join us to explore building automation for skyscrapers, cybersecurity, and attack examples with Fred Gordy of Intelligent Buildings.
A timely and insightful exploration of supply chain security issues with Spencer Wilcox, the CSO and Executive Director of Technology at PNM Resources.
Daniel Ehrenreich joins us to explore practitioner experience of IT/OT Integration, 62443 training and the ICS CyberSec conference every year in Israel.
P&I diagrams connect process engineering to control engineering. Sarah Fluchs of Admeritia explains what we need to connect control engineers with security engineers.
Ransomware continues to evolve and sophisticated phishing attacks are the most popular attack vector. James McQuiggan of KnowBe4 explores ransomware, phishing and what we can do about it.
️
Internet communications are creeping into electric distribution systems. James McCarthy and Don Faatz join us from the NIST NCCoE to talk about this project & others where they provide detailed “how to” industrial security documentation
️
Learn about the Beer ISAC movement, the Beer ISAC Podcast, the Russian industrial security community and other initiatives with Anton Shipulin and Vladimir Dashchenko of Kaspersky
️
Explore a targeted ransomware attack at a pharmaceuticals plant, the incident response and how hard it is to just "restore from backup" with Ofer Shaked, Co-Founder & Chief Technology Officer at SCADAfence.
Author, researcher and industrial security pioneer Jake Brodsky explores the security and operational benefits of configuring self-consistency checks into industrial control systems. He argues that these checks quickly pay for themselves through operational benefits, and substantially improve our ability to detect the most sophisticated of cyber attacks as well.
Derek Harp, CEO and Co-Founder of CS2AI and Founder of The Cyber List speaks to the history and future of CS2AI, and provides some insights into cyber security training for non-cyber-savvy audiences.
Roman Arutyunov, Co-Founder of Xage Security, explores intrinsically-distributed, authority-based blockchains for industrial security in the form of the Xage Security Fabric
️
Marco Blume, Product Manager for Embedded at WIBU Systems introduces discrete manufacturing and explores how intellectual property protection, safety and cybersecurity work in that vertical and others.
️
Phil Neray, VP Industrial Security of CyberX reviews findings, remediations and C-level responses for security assessments at 1800 industrial sites
️
Industrial Defender was a pioneer of Industrial Security, but the brand dropped off the radar for several years. As of January though, Industrial Defender has returned. Phil Dunbar, CTO of the new Industrial Defender joins us to explore the significance of the firm's historical contributions, and where the new Industrial Defender is headed today.
Andy Bochman of Idaho National labs describes CCE, a new methodology for industrial security with a focus on mission assurance, which means different things in different industries
️
Robert Pitcher of Public Safety Canada explores Canadian industrial security, including very popular attack training/awareness sessions and the annual industrial security symposium.
Security PHA Review - a new methodology for protecting safe operations. Join our discussion with one of the authors of the new ISA book describing a robust connection between safety and cybersecurity.
Paul Feldman joins us to explore cybersecurity governance topics for boards of directors in the North American electric sector. Paul is a former director of WECC and MISO, among many other roles. He talks to us about what are the responsibilities of boards of directors for cybersecurity and what kinds of cybersecurity discussions he sees taking place at the board level.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Sven Shrecker is not just an expert in the internet of things—he's a well-versed, experienced public speaker. A Chief Architect at IBM, Sven is not only at the cutting-edge of IoT security, but someone who can magically make the work he does sound both engaging and understandable to just about anyone. In this pilot episode of The Industrial Security Podcast, Sven will be taking us through the emerging field of IoT in ICS, and how connecting the grid to the grid presents new problems, and new solutions, for security professionals.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Harry Paul's product is, well, complicated. His company produces what are called “data sheets”, addressing threat assessment and vulnerability mitigation for industrial cyber systems…and that's just about the simplest, most basic part of it. Andrew's got a big task in today's show—to take on some of the very highest-concept work going on in the SCADA private sector today, and translating it for the rest of us.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Jonathan Pollet, CEO of Red Tiger Security, walks us through how his crew does control system penetration testing, often with live, running systems as a target, with examples of findings and how customers use those findings.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
We caught Jens Weisner at S4 and he talks about cybersecurity in Germany – progress, challenges and a little comparing of the German approach to what he sees happening in North America.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Buki Carmeli walks us through the evolution of government programs and legislation for securing Israel's critical infrastructure.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Marty Edwards discusses the need for a standard way to classify the criticality of industrial control systems – eg: safety-critical vs. equipment-critical vs. reliability-critical systems, and what implications such classification should have for industrial security programs.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
The differences between IT and OT teams and approaches both make life difficult and represent opportunities to improve industrial operations.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Gabi Siboni joins us to talk about standards, challenges and current initiatives in Israel – perhaps most thoroughly-cyber-protected nation on the planet.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Patrick Miller discusses how technology advances in Industrial Control Systems are out-pacing existing industrial cybersecurity and business risk management programs and what needs to change to keep pace.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Industrial security insights regarding risks, programs, budgets and technology at the City of Calgary Water Services, with Darrol Weiss.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
A wide-ranging conversation with Greg Hale, Editor and Founder of Industrial Safety and Security Source (ISSSource), about where we are today, how security relates to safety, how to sell security as improving efficiency and other topics.
Mark Lindike explores industrial systems and security challenges at the Munich International Airport, as well as how the new Munich ISH training facility is helping the airport and others.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
About this episodes guest: Mark Lindike - Head of cyber defense an Munich Airport and Head of Munich (ISH) Information
Meg Duba, a recruiter at Idaho National Labs talks about techniques, tips and challenges for industrial security recruitment and job hunting.
Guest: Meg Duba, Recruiter, Idaho National Laboratories
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Asset inventory is the foundation of industrial security, which is essential to IT/OT convergence. Rick Kaun talks about asset inventory concepts and the Verve Industrial technology for inventory.
Guest: Rick Kaun – VP Solutions at Verve Industrial Protection
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Lyndon is routinely called on for the first-ever security assessment at industrial sites. He explains how he does that and what he finds.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Mark Fabro explores how robust cyber/physical risk assessments help "stay left of boom" at industrial sites.
Guest: Mark Fabro, President and Chief Security Scientist at Lofty Perch
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Industrial security pioneer Eric Byres speaks to software supply chain trust issues and some of the technology his new venture Adolus Inc. is developing to help.
Guest: Eric Byres – CEO of Adolus
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Explore out of band security and operational anomaly detection with Ilan Gendelman and Hadas Levine of SIGA OT Solutions.
Industrial security pioneer Joe Weiss explains how there are 3 networks, not two – IT, OT and Engineering, with examples from the 2007 aurora test.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Build, break & secure with a 1000-lb portable lab – Matthew Luallen of Cybati explores modern industrial security training.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Jens Wiesner of the German BSI explores Malcolm, a new (free, open source) tool for OT network visibility, brought to us by the U.S. Idaho National Labs (INL).
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
How do we estimate the probability of an attack that has never happened? Ron Brash of Verve Industrial explains.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Rick Driggers of CISA describes cyber, physical and industrial security priorities at the new US DHS CISA agency.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
Pointing fingers at vendors is easy. Creating "secure" products is a real challenge, supply chain is a big part of that challenge, and vendors cannot solve the problem in isolation. Kenneth Crowther, a Product Security Leader at GE to explores what a leader in the space is doing.
This podcast is produced by P.I. Media for Waterfall Security Solutions.
Theme music: Waterfall by Headshock Music
How education differs from training, with examples from Dr. Art Conklin at the University of Houston.
And other topics such as analog control systems, IIoT at nuclear sites and control system product "labeling" for security. Join Matt Gibson from the Electric Power Research Institute (EPRI) to explore these and other applied research insights for industrial security.