@BEERISAC: OT/ICS Security Podcast Playlist

@BEERISAC: OT/ICS Security Podcast Playlist

By Anton Shipulin / Listen NotesBusinessTechnology
Download on the App Store

@BEERISAC: OT/ICS Security Podcast Playlist episodes

  • Is Your Cybersecurity Plan Ready for Your Plant Floor?
    Podcast: Industrial Cybersecurity Insider
    Episode: Is Your Cybersecurity Plan Ready for Your Plant Floor?
    Pub date: 2026-10-07

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    You passed the audit. The tools are installed. None of it means your plant is secure.

    Most industrial cybersecurity plans are written far from the equipment they're meant to protect. The tools are purchased but never fully operationalized. Critical equipment stays unseen. And the plant teams who know it best are the last to see the data.

    In this compilation episode, Craig Duckworth, Dino Busalachi, and Ian Bramson of Black & Veatch cover:

    • Why security tools sit unused, and what that costs
    • Why plant teams need access to security data
    • What real IT and OT collaboration looks like
    • Who responds first when something goes wrong
    • Why compliance isn't security
    • How to prioritize risk while protecting safety and uptime

    Strong security programs are built with the people closest to the equipment. Is yours?

    Chapters:

    • (00:00:00) The hidden gap in OT asset visibility
    • (00:04:00) Why plant teams need access to security data
    • (00:08:00) The cost of an unoperationalized cybersecurity tool
    • (00:10:00) What IT and OT convergence really means
    • (00:14:00) Bringing system integrators into the conversation
    • (00:18:00) Who responds first when an industrial incident happens
    • (00:22:00) Compliance, residual risk, and real world security
    • (00:26:00) Risk prioritization for utilities and industrial operators
    • (00:30:00) Build security into new projects from the start

    Links And Resources:

    • Want to Sponsor an episode or be a Guest? Reach out here.
    • Industrial Cybersecurity Insider on LinkedIn
    • Cybersecurity & Digital Safety on LinkedIn
    • BW Design Group Cybersecurity
    • Dino Busalachi on LinkedIn
    • Craig Duckworth on LinkedIn

    Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!



    The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    32 min
  • 135: The Cassandra Panel: OT Threat Intelligence from April to September 2026
    Podcast: (CS)²AI Podcast Show: Control System Cyber Security
    Episode: 135: The Cassandra Panel: OT Threat Intelligence from April to September 2026
    Pub date: 2026-10-06

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    The Cassandra Panel: OT Threat Intelligence from April to Now

    Bryan Singer revisits an April threat briefing to ask what changed in six months, and the answer is a lot. Georgia Tech's Saman Zonouz shares research on thousands of internet-exposed PLCs, web-enabled controllers, shared firmware code across vendors, and exposed solar inverters. Daryl Haegley explains why threat intel has to start with knowing what's inside the fence, and Brad Willet brings the asset owner's view: stray contractor routers, insider risk, and why no newsletter replaces a trusted network. Vivek dubbed it "the Cassandra Panel" for a reason.

    Guests: Saman Zonouz (Georgia Tech); Daryl Haegley (Department of War); Brad Willet (UPS) Host / moderator: Bryan Singer

    Chapters: 00:00 April recap: nothing sophisticated about it 03:53 Georgia Tech CPSEC and anonymous incident reporting 11:35 What changed since April 13:44 Looking inside the fence 16:08 How the Iranian campaign is progressing 18:37 Internet exposure and inventory 23:27 Not fighting the last war 24:51 Capacity gaps and web-enabled PLCs 28:53 Inside-out threat intelligence 33:38 Relationships as threat intel 37:08 Contractors, modems, and insiders 41:14 SBOM and shared firmware code 43:03 Impact-first risk and wrap-up

    Recorded at the CS²AI Online Symposium, "Level Zero: Visions & Reflections."

    Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back.

    Questions: [email protected] · Sponsorship: [email protected] Produced by CS²AI (Control System Cyber Security Association International).



    The podcast and artwork embedded on this page are from Derek Harp, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    47 min
  • 1/4 Contexto de la estratgia global de ciberseguridad industrial
    Podcast: Casos de Ciberseguridad Industrial
    Episode: 1/4 Contexto de la estratgia global de ciberseguridad industrial
    Pub date: 2026-10-05

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    En este episodio se examinan las diferencias fundamentales entre aquellas organizaciones industriales con un alto nivel de madurez y las que todavía operan de forma reactiva ante las amenazas. Asimismo, contrastaremos el escenario de hace un lustro con el actual para identificar los cambios estratégicos que están transformando de raíz el panorama de la protección […]

    The podcast and artwork embedded on this page are from Centro de Ciberseguridad Industrial, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    12 min
  • The Air Gap Myth: Why Your Plant Is More Exposed Than You Think
    Podcast: Industrial Cybersecurity Insider
    Episode: The Air Gap Myth: Why Your Plant Is More Exposed Than You Think
    Pub date: 2026-09-30

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    Dino sits down with Matt Pike of Rockwell Automation for an honest conversation about why industrial cybersecurity still stalls out inside so many plants, and it has very little to do with technology. Matt walks through his path from onsite IT support at a large automotive manufacturer into OT security, and explains why modern security principles keep colliding with legacy systems that were built to run untouched for fifteen or twenty years. The two dig into the real reason the IT and OT gap has not closed, why CISOs often reach for a familiar tool instead of a strategy, and how Rockwell approaches visibility in a fully vendor agnostic way across Siemens, Honeywell, Emerson and everything else sitting on a plant floor. They also get practical about the pieces most teams skip: secure by design language inside RFQs and integrator contracts, response and recovery plans that almost nobody has written, and the funding question of who actually pays for security when a capital project lands. Matt shares what he is seeing from attackers using AI to speed up reconnaissance and rewrite ransomware around detection, and why the air gap most plants believe in disappears the moment data reaches a historian. His closing advice cuts through the noise: stop buying tools and start with an asset visibility strategy, because you cannot secure what you have never actually seen.

    Chapters:
    • (00:00:00) Matt Pike's path from IT support into OT security
    • (00:03:00) Why the IT and OT gap still has not closed
    • (00:06:00) When leadership thinks a tool will fix a people problem
    • (00:09:30) Vendor agnostic visibility down to the asset layer
    • (00:11:00) Secure by design on greenfield and brownfield projects
    • (00:14:00) The incident response plan nobody wrote
    • (00:17:30) AI on the plant floor and what it actually requires
    • (00:20:00) How attackers are already using AI
    • (00:22:30) The air gap myth and east/west blind spots
    • (00:27:30) Funding security through the capital project

    Links And Resources:

    • Want to Sponsor an episode or be a Guest? Reach out here.
    • Industrial Cybersecurity Insider on LinkedIn
    • Cybersecurity & Digital Safety on LinkedIn
    • BW Design Group Cybersecurity
    • Dino Busalachi on LinkedIn
    • Craig Duckworth on LinkedIn

    Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!



    The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    32 min
  • Robert Jackson of Moxa Talks CRA Regulations and OT Cybersecurity
    Podcast: Digital Transformation Viewpoints
    Episode: Robert Jackson of Moxa Talks CRA Regulations and OT Cybersecurity
    Pub date: 2026-09-29

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    In this episode, ARC Advisory Group Vice President of Research Larry O'Brien sits down with Robert Jackson, Manager of Corporate Strategic Marketing at Moxa, to examine the rapidly changing landscape of operational technology (OT) cybersecurity and industrial network security. Their conversation centers on the European Union's Cyber Resilience Act (CRA) and what its connection to CE marking could mean for automation suppliers, OEMs, system integrators, and industrial end users worldwide. Jackson breaks down key expectations, including secure-by-design product development, the elimination of default usernames and passwords, software bills of materials (SBOMs), vulnerability management, and long-term security patch support.

    The episode also explores how Moxa has expanded its cybersecurity strategy beyond individual networking products to an organization-wide approach. We discuss IEC 62443 certification, industrial firewalls, secure routers, deep packet inspection, microsegmentation, vulnerability management, and the challenge of protecting legacy protocols such as Modbus. We also consider the shortage of OT cybersecurity talent and how secure-by-design architectures, automation, AI-assisted operations, and continuous lifecycle governance are turning industrial cybersecurity from a discretionary investment into a business and regulatory imperative.

    For more information about Moxa, check out their page here: https://www.moxa.com/en


    For more info about ARC, contact us here: https://www.arcweb.com/about/contact-us

    Would you like to be a guest on our growing podcast?

    Do you have an intriguing or thought provoking topic you'd like to discuss on our podcast? Please contact Our Producer Tom Cabot [email protected]

    View all the episodes here: https://thedigitaltransformationpodcast.buzzsprout.com



    The podcast and artwork embedded on this page are from ARC Advisory Group, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    32 min
  • Episode 134: Engineers Belong at the Table: Cyber-Informed Engineering and the End of the OT/IT Boundary
    Podcast: (CS)²AI Podcast Show: Control System Cyber Security
    Episode: Episode 134: Engineers Belong at the Table: Cyber-Informed Engineering and the End of the OT/IT Boundary
    Pub date: 2026-09-29

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    Three veterans of critical infrastructure security trace how the field went from arguing that infrastructure was even a target to treating digital risk as an engineering hazard. Ginger Wright, Sarah Freeman, and Marc Sachs define cyber-informed engineering in plain terms, share real examples of consequences engineered out of a system, explain why adversaries already read your engineering documentation, and make the case that engineers don't need to become hackers to belong in this conversation. They close with why engineers should come to Level Zero.

    Guests: Sarah Freeman (MITRE); Marc Sachs (Center for Internet Security) Host / moderator: Ginger Wright (Idaho National Laboratory)

    Chapters: 00:00 Welcome and panel introductions 02:52 Why engineering is up first at Level Zero 04:24 From 'not a target' to target du jour 08:03 Y2K to WannaCry: when the OT/IT boundary became fiction 12:28 Engineering out the consequence (NIST 800-82 Rev. 3) 14:31 Why engineers belong at the table 19:01 Digital risk and defining CIE / CCE 22:13 Real examples of designed-out consequences 28:34 Where CIE runs into regulation 32:40 Engineer pushback and 'fighting the scenario' 37:01 Digital risk is just another hazard 40:01 The five whys, and why come to Level Zero

    Recorded at the CS²AI Online Symposium, "Level Zero: Visions & Reflections."

    Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back.

    Questions: [email protected] · Sponsorship: [email protected] Produced by CS²AI (Control System Cyber Security Association International).



    The podcast and artwork embedded on this page are from Derek Harp, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    44 min
  • Cybersicherheit im Krankenhaus: Zwischen Medizintechnik und Restrisiko
    Podcast: OT Security Made Simple
    Episode: Cybersicherheit im Krankenhaus: Zwischen Medizintechnik und Restrisiko
    Pub date: 2026-09-29

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    Klaus Mochalski und Silvia Seeger (Cyber Risk Managerin bei Relyens) beleuchten die spezifischen Herausforderungen der Cybersicherheit im Gesundheitswesen. Erfahren Sie, warum Medizintechnik eine Sonderrolle zwischen IT und OT einnimmt und weshalb starre Herstellerzulassungen das Patchen von Altgeräten erschweren.

    Mehr zum Thema OT Security Made simple findet Ihr auf rhebo.com oder schreibt uns mit Euren Ideen, Fragen oder Gastvorschlägen an [email protected].  



    The podcast and artwork embedded on this page are from Klaus Mochalski, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
    27 min
  • Own Your Industrial Airspace: Wireless, Vendors, and the Parking Lot Crane Hack with Scott McNeil
    Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)
    Episode: Own Your Industrial Airspace: Wireless, Vendors, and the Parking Lot Crane Hack with Scott McNeil
    Pub date: 2026-09-28

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    Work with Aaron: https://protectitallpod.com/work/

    The book: https://protectitallpod.com/book/
    This episode: https://protectitallpod.com/ep125/
    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    A wireless engineer sat in a parking lot, connected to a plant's crane anti-collision network, and had everything he needed to stop the cranes inside 20 minutes. Nobody inside the fence ever knew he was there.

    In this episode of Protect It All, host Aaron Crow talks with Scott McNeil, Industrial Network and Security Architect II at Global Process Automation (GPA), about the part of the OT network most plants never look at: the airspace. Scott has spent more than 20 years in networking and wireless, the last ten of them entirely in OT, and he sits in the integrator's seat, working across every manufacturer's gear without a product to sell.

    The conversation starts where most plants actually are: one flat network, off the shelf gear on the floor, and no budget. Scott's argument is that the low hanging fruit costs time and effort, not money, and that a stable network is the foundation for everything security asks for later: segmentation, inventory, monitoring, then a firewall between OT and IT. He walks through war driving your own plant, why a hidden SSID is not security, the wild west of industrial wireless protocols, wireless that was abandoned in power plants years ago and is still on the air, and where wireless earns its place.

    The second half is about vendors and access. Do not take the vendor's word for it, ask the questions before the gear ships, and treat every third party connection as your own exposure. Scott's rule for remote access is simple: this is my house, vendors connect on my terms, every session logged, with an approve or deny button before anyone gets in. Aaron adds the zip tie in the fan story, a backup switch that had silently failed months earlier and nobody knew until monitoring went on, and the two close on shrinking the wireless footprint that leaves your site and on Scott's podcast, The Industrial Wi-Fi Shop.

    In this episode, you'll learn:
    • Why a stable network comes before any security project, and what to fix first
    • How to war drive your own plant and what a passive scan of your airspace tells an attacker
    • Why hiding the SSID and relying on obscurity is not a control
    • Which industrial wireless protocols are standards based and which are proprietary risk
    • The questions to ask a wireless vendor before you sign
    • How to run vendor remote access on your terms: logged sessions, approve or deny, no standing tunnels
    • Why monitoring finds failures you did not know you had
    • Tune in to hear why your industrial airspace deserves the same design, monitoring, and ownership as any wired connection.

      About the guest:

      Scott McNeil is an Industrial Network and Security Architect II at Global Process Automation (GPA), where he helps manufacturers design, secure, and modernize the OT networks that keep critical processes running: architecture, IT/OT convergence, segmentation, resilient connectivity, and industrial wireless. A longtime wireless engineer, he created and co-hosts The Industrial WiFi Shop Podcast with Jeremy Baker, speaks regularly at OT and industrial cybersecurity events, holds a bachelor's degree in Industrial Technology from East Carolina University with multiple wireless and network certifications, and serves on the UNC Wilmington Cybersecurity Advisory Board.

      Important Links:
      • LinkedIn of Scott McNeil: https://www.linkedin.com/in/americanmcneil/
      • The Industrial Wi-Fi Shop Podcast: https://industrialwifishop.com/
      • The Industrial Wi-Fi Shop on YouTube: https://www.youtube.com/@IndustrialWi-FiShop
      • Scott on X: https://x.com/americanmcneil
      • Global Process Automation (GPA): https://www.globalprocessautomation.com/
      • Learn more about PrOTect IT All:

        Work with Aaron: https://protectitallpod.com/work/

        The book: https://protectitallpod.com/book/
        This episode: https://protectitallpod.com/ep125/
        The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
        YouTube: https://www.youtube.com/@PrOTectITAll
        X: https://twitter.com/protectitall
        Facebook: https://facebook.com/protectitallpodcast

        To be a guest or suggest a guest or episode, email [email protected].

        Please leave us a review on Apple or Spotify:

        Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
        Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4



        The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        1 hr 6 min
      • Kiss of Death
        Podcast: mnemonic security podcast
        Episode: Kiss of Death
        Pub date: 2026-09-28

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        What does a 30-year-old timekeeping protocol have to do with taking down a phone network? 

        In this episode of the mnemonic security podcast, Robby welcomes OT security specialist Mikael Vingaard back to the podcast to share some war stories from the world of industrial security. 

        They start off talking about the Network Time Protocol (NTP), a decades-old protocol that still plays a fundamental role in keeping systems synchronised. Mikael shares the story of how renting three servers in Albania accidentally made him one of the country's main sources of NTP traffic, and how shutting them down disrupted an ISP's IP telephony. They discuss what the story reveals about dependencies we may not even know exist, and what incorrect time can mean for industrial systems.

        They also explore configuration drift in OT environments, where small and often undocumented changes accumulate over long device lifecycles. Mikael shares findings from passive network assessments, including supposedly air-gapped networks that turned out to be connected and discusses how periodic verification can help organisations understand what is actually running in their environments.

        Finally, they discuss approaches to securely scanning OT environments, testing guardrails around AI and Denmark's push for digital sovereignty.

        Send us Fan Mail



        The podcast and artwork embedded on this page are from mnemonic, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        36 min
      • When Cyber Stops the Line, Safety Is on the Line
        Podcast: Industrial Cybersecurity Insider
        Episode: When Cyber Stops the Line, Safety Is on the Line
        Pub date: 2026-09-23

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        Safety starts with a goal. So should cybersecurity.

        Craig Duckworth sits down with Shankar Somasundaram, CEO of Asimily and former head of Symantec's IoT business, to explain why plant floor cybersecurity is a safety issue, not an IT expense. They cover why industrial cybersecurity programs stall after the tool is purchased, how to start with a goal instead of a solution, and why fixing the biggest risks first beats trying to secure everything at once.

        The conversation also covers network segmentation mistakes, AI as both a helper and a new threat to critical infrastructure, protecting legacy OT and IoT equipment without disrupting production, watching traffic inside the plant, what drives cybersecurity maturity, and what OT security market consolidation means for manufacturers.

        Shankar's three takeaways for your next budget cycle:

        1. Cyber risk is safety risk
        2. Start with the goal
        3. Visibility and fixing the problem are one program, not two

        Chapters:

        • (00:00:00) Cybersecurity is patient safety, operational safety, plant safety
        • (00:00:45) Meet Shankar and the four pillars behind Asimily
        • (00:03:50) Why OT security projects stall after the tool is purchased
        • (00:06:20) Start with a goal, not a solution
        • (00:09:20) Exposure management and the segmentation myths that slow teams down
        • (00:11:45) AI as enabler and attacker inside critical infrastructure
        • (00:15:40) Collecting data on legacy OT and IoT without disrupting operations
        • (00:18:20) North south, east west, and the flow data most teams skip
        • (00:20:00) Does maturity come from size, budget, or management
        • (00:24:20) Consolidation in the OT market and the advice Shankar leaves behind

        Links And Resources:

        • Want to Sponsor an episode or be a Guest? Reach out here.
        • Industrial Cybersecurity Insider on LinkedIn
        • Cybersecurity & Digital Safety on LinkedIn
        • BW Design Group Cybersecurity
        • Shankar Somasundaram on LinkedIn
        • Asimily
        • Dino Busalachi on LinkedIn
        • Craig Duckworth on LinkedIn

        Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!



        The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        32 min

      About @BEERISAC: OT/ICS Security Podcast Playlist

      From the publisher's feed

      A curated playlist of Operational Technology (OT) and Industrial Control Systems (ICS) cybersecurity podcast episodes in any language, compiled by ICS security enthusiasts. Missing something? Contact…

      More shows like @BEERISAC: OT/ICS Security Podcast Playlist

      Hacked by Hacked

      Hacked

      192 Listeners

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

      Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

      373 Listeners

      CyberWire Daily by N2K Networks

      CyberWire Daily

      1,028 Listeners

      Darknet Diaries by Jack Rhysider

      Darknet Diaries

      8,055 Listeners

      Cybersecurity Headlines by CISO Series

      Cybersecurity Headlines

      138 Listeners

      PrOTect It All by Aaron Crow | Operational Technology & Cybersecurity Host

      PrOTect It All

      7 Listeners