@BEERISAC: OT/ICS Security Podcast Playlist

@BEERISAC: OT/ICS Security Podcast Playlist

By Anton Shipulin / Listen NotesBusinessTechnology
Download on the App Store

@BEERISAC: OT/ICS Security Podcast Playlist episodes

  • Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
    Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)
    Episode: Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
    Pub date: 2026-09-21

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization



    Work with Aaron: https://protectitallpod.com/work/

    The book: https://protectitallpod.com/book/
    This episode: https://protectitallpod.com/ep124/
    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and supply chain. What does that actually change on the plant floor?

    In this episode of Protect It All, host Aaron Crow talks with Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, about the shift regulation is driving in OT: responsibility moving from the server rooms into the boardrooms, and from the operator to the manufacturer.

    Tobias makes the case that what gets regulated are fundamentally the basics: risk assessment, asset inventory, cyber hygiene, and detection. The industry has preached these for a decade. Now the law demands them, which makes compliance the business case that finally unlocks long-overdue modernization budget. His advice: do not treat legislation as a paper exercise. Treat it as a utility.

    The second half is about recovery, the foundation most plants skip. Aaron and Tobias dig into the vendor-install backup that has never been tested, recovery targets that ignore how long a plant really takes to come back, retain values operators tuned for years that live nowhere else, redundant controllers that are not cyber resilience, and vendor SLAs that send a system engineer when you needed a cyber expert. Tobias's practical pattern: keep a replica of your critical systems, restore into the bubble, and be as intrusive as you like there, scanners and all, without touching production.

    Also in this one: NIS2 Article 20 and personal liability for executives, why a cyber incident does not need a nation state (bad firmware counts), where AI belongs in the Purdue model and where it does not, AI as the daily brief for the one-person water utility, Aaron's Exchange 5.5 story about the week the executives lost their email, borrowing the safety engineers' hazard studies as risk input, and why you should never fire up a wireless pineapple on an airplane.

    In this episode, you'll learn:
    • How NIS2, the Cyber Resilience Act, and CIRCIA move accountability to executives and manufacturers
    • Why 24-hour incident reporting starts with detection, and why you can't wing it
    • How to reframe your next modernization budget ask around compliance
    • What a real recovery plan needs: tested backups, plant-realistic RPO and RTO, and captured retain values
    • Why redundant controllers protect against failure, not compromise
    • How to test restores and run scanners safely in a replica instead of production
    • Where AI helps an understaffed operator and where it should never take control
    • Tune in to hear how the biggest regulatory wave in industrial cybersecurity history can become the budget unlock OT has been waiting for.

      About the guest:

      Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Having sat on both sides of the table, first delivering cybersecurity services to critical infrastructure operators and now shaping how legislation lands in engineering practice, he brings a combined view of policy, technology, and plant-floor reality that few in the industry carry. Tobias is based in Germany.

      Important Links:
      • LinkedIn of Tobias Nitzsche: https://www.linkedin.com/in/tobias-nitzsche-37339735/
      • ABB Energy Industries: https://global.abb/group/en/organization/energy-industries
      • Learn more about PrOTect IT All:

        Work with Aaron: https://protectitallpod.com/work/

        The book: https://protectitallpod.com/book/
        This episode: https://protectitallpod.com/ep124/
        The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
        YouTube: https://www.youtube.com/@PrOTectITAll
        X: https://twitter.com/protectitall
        Facebook: https://facebook.com/protectitallpodcast

        To be a guest or suggest a guest or episode, email [email protected].

        Please leave us a review on Apple or Spotify:

        Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
        Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4



        The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        47 min
      • 3/4 Acciones de Gobierno y coordinación de la seguridad OT en el sector eléctrico
        Podcast: Casos de Ciberseguridad Industrial
        Episode: 3/4 Acciones de Gobierno y coordinación de la seguridad OT en el sector eléctrico
        Pub date: 2026-09-21

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        En este episodio se detallan las capacidades clave que se consideran necesarias hoy en día para reducir el riesgo en instalaciones eléctricas industriales. A través de este bloque, examinaremos cómo se toman las decisiones de mitigación en aquellos casos donde no es viable intervenir o parchear determinados activos, analizando el papel que juegan tanto la […]

        The podcast and artwork embedded on this page are from Centro de Ciberseguridad Industrial, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        10 min
      • Tatyana Bolton on the OTCC and OT Cybersecurity
        Podcast: Nexus: A Claroty Podcast (LS 32 · TOP 5% what is this?)
        Episode: Tatyana Bolton on the OTCC and OT Cybersecurity
        Pub date: 2026-09-20

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        Tatyana Bolton, Executive Director of the Operational Technology Cybersecurity Coalition (OTCC), joins the Nexus Podcast to discuss a new partnership between OTCC and the International Society of Automation (ISA), alongside a joint position paper advocating for the ISA/IEC 62443 standard as the definitive global benchmark for operational technology (OT) cybersecurity.

        Read more about the partnership

        Read the position paper on a unified approach to OT cybersecurity

        Subscribe and listen to the Nexus Podcast here. 



        The podcast and artwork embedded on this page are from Claroty, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        34 min
      • Why Industrial Cyber Risk Is Escalating (And How To Stop It)
        Podcast: Industrial Cybersecurity Insider
        Episode: Why Industrial Cyber Risk Is Escalating (And How To Stop It)
        Pub date: 2026-09-16

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        This highlight episode pulls the sharpest moments from past conversations into one continuous argument about why industrial cyber risk keeps escalating and why so many programs stall before they start.

        Craig Duckworth and Dino Busalachi open with a number that should stop any executive team cold: one manufacturer lost roughly $500 million in valuation inside 60 hours, and that loss had nothing to do with lost production.

        From there the conversation gets practical. They explain why a plant floor security program cannot be run entirely from the data center, why asset inventory and communication flow mapping must come before any discussion of segmentation, and what distinguishes warranted traffic from unwarranted traffic within a control system environment.

        Jim Cook joins to break down the difference between a flat network and what the team calls a super flat network, where drives, flow meters, robots, and business systems all share the same space. Together, they make the case that zero trust in operational technology must be built from the bottom of the stack upward, using what they describe as the bucket approach, rather than layered over the plant with enterprise tooling that nobody on site knows how to operate.

        The episode closes on ownership: who is accountable, who the plant manager actually trusts, and why the people who design and build the machines belong in the room from day one. If you are responsible for production uptime and for protecting the assets that create it, this one is a fast tour of the decisions that matter most.

        Chapters:

        • (00:00:00) A $500 Million Valuation Loss In 60 Hours
        • (00:01:00) Why Industrial Cyber Risk Is More Urgent Right Now
        • (00:03:00) Why IT Cannot Secure The Plant Floor Alone
        • (00:05:00) Asset Inventory And Communication Flows Come First
        • (00:07:00) Building A Defensible Architecture In OT Environments
        • (00:09:00) Flat Networks Versus Super Flat Networks
        • (00:11:00) The Bucket Approach To Segmentation
        • (00:14:00) Vetting A Cybersecurity Partner The Right Way
        • (00:16:00) Tabletop Exercises With The Executive Team
        • (00:19:00) Who Actually Owns Industrial Cybersecurity

        Links And Resources:

        • Want to Sponsor an episode or be a Guest? Reach out here.
        • Industrial Cybersecurity Insider on LinkedIn
        • Cybersecurity & Digital Safety on LinkedIn
        • BW Design Group Cybersecurity
        • Dino Busalachi on LinkedIn
        • Craig Duckworth on LinkedIn

        Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!



        The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        21 min
      • #135: Mastering OT Cybersecurity Countermeasures in the Power Grid │ Part 1
        Podcast: Energy Talks
        Episode: #135: Mastering OT Cybersecurity Countermeasures in the Power Grid │ Part 1
        Pub date: 2026-09-17

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        Discover essential grid defenses with OMICRON expert Simon Rommer.

        In this episode of Energy Talks, OMICRON Cybersecurity Expert Simon Rommer launches an essential new mini-series focused on operational technology (OT) cybersecurity countermeasures in the power industry. Instead of just chasing the latest tech trends or treating security like a generic checklist, this series takes a step back to ask a fundamental question: Countermeasures—what for, and against what?

        Through a mix of solo deep-dives and expert guest interviews, the series explores how to bridge the gap between theoretical security and the messy reality of utility operations.

        To help utilities navigate their own security journeys, Simon introduces a structured, six-question framework that will guide every upcoming episode. This framework shifts the conversation away from superficial bullet points and toward measurable, sustainable risk reduction. It also introduces a three-tiered maturity model designed to help teams identify exactly when a countermeasure makes sense to implement, preventing organizations from building on a weak foundation.

        Whether you are an OT architect, a protection engineer, or a utility manager, this kick-off episode sets the stage for a practical, field-tested roadmap to true operational resilience. Tune in to discover how to maximize your security impact, evaluate your current maturity level, and learn how you can submit your own real-world challenges to be featured in upcoming episodes.

        Get more information about OT Cybersecurity for the Power Grid.



        The podcast and artwork embedded on this page are from OMICRON electronics GmbH, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        16 min
      • AI in OT: Hype, Opportunities, and Risk-Free Integration in Industrial Plants | OT Security Made Simple
        Podcast: OT Security Made Simple
        Episode: AI in OT: Hype, Opportunities, and Risk-Free Integration in Industrial Plants | OT Security Made Simple
        Pub date: 2026-09-15

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        Klaus Mochalski and OT expert Daniel Ehrenreich discuss the integration of Artificial Intelligence in Industrial Control Systems (ICS). Discover why AI already delivers value in predictive maintenance and PLC programming, the physical risks of real-time process control, and why a "human-in-the-loop" approach backed by deep domain expertise remains essential.

        You can find more information on OT Security Made Simple at rhebo.com or send us your ideas, questions, or guest suggestions at [email protected].



        The podcast and artwork embedded on this page are from Klaus Mochalski, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
        29 min
      • AI in OT: Why Humans Stay in the Loop and the Junior Problem with Jori VanAntwerp
        Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)
        Episode: AI in OT: Why Humans Stay in the Loop and the Junior Problem with Jori VanAntwerp
        Pub date: 2026-09-14

        Get Podcast Transcript →
        powered by Listen411 - fast audio-to-text and summarization



        Work with Aaron: https://protectitallpod.com/work/

        The book: https://protectitallpod.com/book/
        This episode: https://protectitallpod.com/ep123/
        The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

        AI is a consensus engine, and consensus on the internet is frequently wrong. So what does that mean for the people defending power plants, water systems, and factories with it?

        In this episode of Protect It All, host Aaron Crow welcomes back Jori VanAntwerp, CEO and founder of EmberOT, for a completely unscripted conversation on AI in OT. Two practitioners who use AI aggressively every day make the case for restraint in exactly the places that matter.

        Jori explains why human in the loop is non-negotiable: AI shapes a junior's output to look senior without the understanding underneath, so you have to be able to interrogate it. Aaron walks through his own sandbox discipline, where AI gets a folder and not the keys, and nothing goes in that he would not publish on the internet.

        The conversation then turns to the OT reality behind AI-found vulnerabilities, why an attacker who can reach your HMI or PLC does not need your unpatched CVE, teaching AI your voice with markdown primers, the build-versus-buy MVP trap, the submarine principle for modular defense, and why an operator flipping to manual is still the save of last resort.

        Underneath all of it is the workforce math nobody is doing on air: if one person plus AI does the work of five, nobody is training juniors, and no juniors today means no seniors in ten years. OT's aging-out workforce is the preview.

        In this episode, you'll learn:
        • Why AI is a consensus engine, and why that framing predicts where it fails
        • Why human in the loop is not optional for anything that matters
        • How to sandbox AI in real workflows: a folder, not the keys
        • How to rank AI-found vulnerabilities against what an attacker in your OT network can actually do
        • How primers teach AI your voice, brand, and rules
        • The build versus buy trap: if a power company builds its own software, it is now a software company
        • The submarine principle: compartments, modular tooling, and swapping tools without ripping out the estate
        • Why analog fallbacks and operators keep saving critical infrastructure
        • The junior pipeline problem: no juniors today means no seniors in ten years
        • Why the entry-level job for OT cybersecurity is IT
        • Tune in for the most honest AI conversation the show has had, from the people who actually run it in OT.

          About the guest:

          Jori VanAntwerp is a two-time cybersecurity founder and CEO who has spent over two decades helping industrial and IT/OT organizations reduce risk, strengthen compliance, and mature the way they defend critical infrastructure. He has held executive and leadership roles at McAfee, FireEye, CrowdStrike, Dragos, and Gravwell before stepping into the founder seat, first at SynSaber and now as the Founder and CEO at EmberOT. The result is a vantage point that runs from the boardroom to the packet capture, from silicon to the cloud. At EmberOT, he is focused on bringing visibility, security, and risk quantification to the critical infrastructure the rest of the world takes for granted.

          From EmberOT:

          Want to see what is really happening in your OT environment? EmberOT provides flow-first, passive OT visibility and threat detection without requiring proprietary hardware.

          Learn more about EmberOT: https://emberot.com/

          Request a demo: https://www.emberot.com/request-a-demo/
          Want to explore your own OT network traffic right now? Download the free EmberOT PCAP Analyzer: https://www.emberot.com/ot-pcap-analyzer/

          Important Links:
          • Jori VanAntwerp on LinkedIn: https://www.linkedin.com/in/jvanantwerp/
          • EmberOT: https://emberot.com/
          • Jori's previous episodes: Ep 49, The Intersection of IT and OT: Highlights from S4 Conference: https://youtu.be/OuocvnZsKwU and Ep 29, Bridging IT and OT in Cybersecurity for Power Plants: https://youtu.be/0stFEr6krbY
          • Learn more about PrOTect IT All:

            Work with Aaron: https://protectitallpod.com/work/

            The book: https://protectitallpod.com/book/
            This episode: https://protectitallpod.com/ep123/
            The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
            YouTube: https://www.youtube.com/@PrOTectITAll
            X: https://twitter.com/protectitall
            Facebook: https://facebook.com/protectitallpodcast

            To be a guest or suggest a guest or episode, email [email protected].

            Please leave us a review on Apple or Spotify:

            Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
            Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4



            The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
            1 hr 6 min
          • 2/4 Análisis de Gobierno y coordinación de la seguridad OT en el sector eléctrico
            Podcast: Casos de Ciberseguridad Industrial
            Episode: 2/4 Análisis de Gobierno y coordinación de la seguridad OT en el sector eléctrico
            Pub date: 2026-09-14

            Get Podcast Transcript →
            powered by Listen411 - fast audio-to-text and summarization



            Este episodio analiza las principales fragilidades estructurales que presenta actualmente el ecosistema eléctrico desde una perspectiva OT. Se examinan las tensiones existentes entre la continuidad operativa, los avances en digitalización, las exigencias de la regulación y las necesidades de ciberseguridad.

            The podcast and artwork embedded on this page are from Centro de Ciberseguridad Industrial, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
            23 min
          • Can Humans and Robots Safely Work Side by Side?
            Podcast: Advanced Manufacturing Now (LS 35 · TOP 3% what is this?)
            Episode: Can Humans and Robots Safely Work Side by Side?
            Pub date: 2026-09-08

            Get Podcast Transcript →
            powered by Listen411 - fast audio-to-text and summarization



            On this episode of Advanced Manufacturing Live, Ole Marius Hoel Rindal, PhD, co-founder of Sonair, will explain why most industrial robots are still caged even with increasing development of AI. Sonair has created what it says is the world's first safety-certified ultrasonic sensor. The technology may allow robots out of their cages while helping ensure human coworkers remain safe.



            The podcast and artwork embedded on this page are from SME Media, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
            42 min
          • Ben Gardiner on Hacking Truck Brake Controllers
            Podcast: Nexus: A Claroty Podcast (LS 32 · TOP 5% what is this?)
            Episode: Ben Gardiner on Hacking Truck Brake Controllers
            Pub date: 2026-09-13

            Get Podcast Transcript →
            powered by Listen411 - fast audio-to-text and summarization



            Ben Gardiner, senior cybersecurity research engineer for the National Motor Freight Traffic Association (NMFTA), joins the Nexus Podcast to discuss research he published on a silent patch released by vendor Bendix addressing serious cybersecurity vulnerabilities in brake controllers found on tractor trailers. The vulnerabilities—which were updated as part of a safety recall—posed safety risks to drivers and others on the road. 

            Ben explains how and why he chose to reverse-engineer the safety recall and how the vulnerabilities impact the security of any trailer-connected telematics devices, and also how they could be exploited at close range. 

            Subscribe and listen to the Nexus Podcast here. 



            The podcast and artwork embedded on this page are from Claroty, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
            26 min

          About @BEERISAC: OT/ICS Security Podcast Playlist

          From the publisher's feed

          A curated playlist of Operational Technology (OT) and Industrial Control Systems (ICS) cybersecurity podcast episodes in any language, compiled by ICS security enthusiasts. Missing something? Contact…

          More shows like @BEERISAC: OT/ICS Security Podcast Playlist

          Hacked by Hacked

          Hacked

          192 Listeners

          Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

          Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

          373 Listeners

          CyberWire Daily by N2K Networks

          CyberWire Daily

          1,028 Listeners

          Darknet Diaries by Jack Rhysider

          Darknet Diaries

          8,055 Listeners

          Cybersecurity Headlines by CISO Series

          Cybersecurity Headlines

          138 Listeners

          PrOTect It All by Aaron Crow | Operational Technology & Cybersecurity Host

          PrOTect It All

          7 Listeners