
Sign up to save your podcasts
Or


Work with Aaron: https://protectitallpod.com/work/
NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and supply chain. What does that actually change on the plant floor?
In this episode of Protect It All, host Aaron Crow talks with Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, about the shift regulation is driving in OT: responsibility moving from the server rooms into the boardrooms, and from the operator to the manufacturer.
Tobias makes the case that what gets regulated are fundamentally the basics: risk assessment, asset inventory, cyber hygiene, and detection. The industry has preached these for a decade. Now the law demands them, which makes compliance the business case that finally unlocks long-overdue modernization budget. His advice: do not treat legislation as a paper exercise. Treat it as a utility.
The second half is about recovery, the foundation most plants skip. Aaron and Tobias dig into the vendor-install backup that has never been tested, recovery targets that ignore how long a plant really takes to come back, retain values operators tuned for years that live nowhere else, redundant controllers that are not cyber resilience, and vendor SLAs that send a system engineer when you needed a cyber expert. Tobias's practical pattern: keep a replica of your critical systems, restore into the bubble, and be as intrusive as you like there, scanners and all, without touching production.
Also in this one: NIS2 Article 20 and personal liability for executives, why a cyber incident does not need a nation state (bad firmware counts), where AI belongs in the Purdue model and where it does not, AI as the daily brief for the one-person water utility, Aaron's Exchange 5.5 story about the week the executives lost their email, borrowing the safety engineers' hazard studies as risk input, and why you should never fire up a wireless pineapple on an airplane.
Tune in to hear how the biggest regulatory wave in industrial cybersecurity history can become the budget unlock OT has been waiting for.
Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Having sat on both sides of the table, first delivering cybersecurity services to critical infrastructure operators and now shaping how legislation lands in engineering practice, he brings a combined view of policy, technology, and plant-floor reality that few in the industry carry. Tobias is based in Germany.
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Tatyana Bolton, Executive Director of the Operational Technology Cybersecurity Coalition (OTCC), joins the Nexus Podcast to discuss a new partnership between OTCC and the International Society of Automation (ISA), alongside a joint position paper advocating for the ISA/IEC 62443 standard as the definitive global benchmark for operational technology (OT) cybersecurity.
Read more about the partnership
Read the position paper on a unified approach to OT cybersecurity
Subscribe and listen to the Nexus Podcast here.
This highlight episode pulls the sharpest moments from past conversations into one continuous argument about why industrial cyber risk keeps escalating and why so many programs stall before they start.
Craig Duckworth and Dino Busalachi open with a number that should stop any executive team cold: one manufacturer lost roughly $500 million in valuation inside 60 hours, and that loss had nothing to do with lost production.
From there the conversation gets practical. They explain why a plant floor security program cannot be run entirely from the data center, why asset inventory and communication flow mapping must come before any discussion of segmentation, and what distinguishes warranted traffic from unwarranted traffic within a control system environment.
Jim Cook joins to break down the difference between a flat network and what the team calls a super flat network, where drives, flow meters, robots, and business systems all share the same space. Together, they make the case that zero trust in operational technology must be built from the bottom of the stack upward, using what they describe as the bucket approach, rather than layered over the plant with enterprise tooling that nobody on site knows how to operate.
The episode closes on ownership: who is accountable, who the plant manager actually trusts, and why the people who design and build the machines belong in the room from day one. If you are responsible for production uptime and for protecting the assets that create it, this one is a fast tour of the decisions that matter most.
Chapters:
Links And Resources:
Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!
In this episode of Energy Talks, OMICRON Cybersecurity Expert Simon Rommer launches an essential new mini-series focused on operational technology (OT) cybersecurity countermeasures in the power industry. Instead of just chasing the latest tech trends or treating security like a generic checklist, this series takes a step back to ask a fundamental question: Countermeasures—what for, and against what?
Through a mix of solo deep-dives and expert guest interviews, the series explores how to bridge the gap between theoretical security and the messy reality of utility operations.
To help utilities navigate their own security journeys, Simon introduces a structured, six-question framework that will guide every upcoming episode. This framework shifts the conversation away from superficial bullet points and toward measurable, sustainable risk reduction. It also introduces a three-tiered maturity model designed to help teams identify exactly when a countermeasure makes sense to implement, preventing organizations from building on a weak foundation.
Whether you are an OT architect, a protection engineer, or a utility manager, this kick-off episode sets the stage for a practical, field-tested roadmap to true operational resilience. Tune in to discover how to maximize your security impact, evaluate your current maturity level, and learn how you can submit your own real-world challenges to be featured in upcoming episodes.
Get more information about OT Cybersecurity for the Power Grid.
Klaus Mochalski and OT expert Daniel Ehrenreich discuss the integration of Artificial Intelligence in Industrial Control Systems (ICS). Discover why AI already delivers value in predictive maintenance and PLC programming, the physical risks of real-time process control, and why a "human-in-the-loop" approach backed by deep domain expertise remains essential.
You can find more information on OT Security Made Simple at rhebo.com or send us your ideas, questions, or guest suggestions at [email protected].
Work with Aaron: https://protectitallpod.com/work/
AI is a consensus engine, and consensus on the internet is frequently wrong. So what does that mean for the people defending power plants, water systems, and factories with it?
In this episode of Protect It All, host Aaron Crow welcomes back Jori VanAntwerp, CEO and founder of EmberOT, for a completely unscripted conversation on AI in OT. Two practitioners who use AI aggressively every day make the case for restraint in exactly the places that matter.
Jori explains why human in the loop is non-negotiable: AI shapes a junior's output to look senior without the understanding underneath, so you have to be able to interrogate it. Aaron walks through his own sandbox discipline, where AI gets a folder and not the keys, and nothing goes in that he would not publish on the internet.
The conversation then turns to the OT reality behind AI-found vulnerabilities, why an attacker who can reach your HMI or PLC does not need your unpatched CVE, teaching AI your voice with markdown primers, the build-versus-buy MVP trap, the submarine principle for modular defense, and why an operator flipping to manual is still the save of last resort.
Underneath all of it is the workforce math nobody is doing on air: if one person plus AI does the work of five, nobody is training juniors, and no juniors today means no seniors in ten years. OT's aging-out workforce is the preview.
Tune in for the most honest AI conversation the show has had, from the people who actually run it in OT.
Jori VanAntwerp is a two-time cybersecurity founder and CEO who has spent over two decades helping industrial and IT/OT organizations reduce risk, strengthen compliance, and mature the way they defend critical infrastructure. He has held executive and leadership roles at McAfee, FireEye, CrowdStrike, Dragos, and Gravwell before stepping into the founder seat, first at SynSaber and now as the Founder and CEO at EmberOT. The result is a vantage point that runs from the boardroom to the packet capture, from silicon to the cloud. At EmberOT, he is focused on bringing visibility, security, and risk quantification to the critical infrastructure the rest of the world takes for granted.
Want to see what is really happening in your OT environment? EmberOT provides flow-first, passive OT visibility and threat detection without requiring proprietary hardware.
Learn more about EmberOT: https://emberot.com/
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
On this episode of Advanced Manufacturing Live, Ole Marius Hoel Rindal, PhD, co-founder of Sonair, will explain why most industrial robots are still caged even with increasing development of AI. Sonair has created what it says is the world's first safety-certified ultrasonic sensor. The technology may allow robots out of their cages while helping ensure human coworkers remain safe.
Ben Gardiner, senior cybersecurity research engineer for the National Motor Freight Traffic Association (NMFTA), joins the Nexus Podcast to discuss research he published on a silent patch released by vendor Bendix addressing serious cybersecurity vulnerabilities in brake controllers found on tractor trailers. The vulnerabilities—which were updated as part of a safety recall—posed safety risks to drivers and others on the road.
Ben explains how and why he chose to reverse-engineer the safety recall and how the vulnerabilities impact the security of any trailer-connected telematics devices, and also how they could be exploited at close range.
Subscribe and listen to the Nexus Podcast here.
From the publisher's feed

192 Listeners

373 Listeners

1,028 Listeners

8,055 Listeners

138 Listeners

7 Listeners