@BEERISAC: OT/ICS Security Podcast Playlist

Vulnerability Overload: Making Prioritization Work in the Real World


Listen Later

Podcast: Critical Assets Podcast
Episode: Vulnerability Overload: Making Prioritization Work in the Real World
Pub date: 2025-07-20

Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization



In this episode, Patrick Miller speaks with Kylie McClanahan, CTO at Bastazo, about the practical (and often messy) realities of patch and vulnerability management in operational technology (OT) environments. Kylie shares grounded insights into patching challenges, the gaps between IT and OT remediation cycles, and the real-world implications of relying too heavily on scoring systems like CVSS.

The conversation covers CISA’s Known Exploited Vulnerabilities (KEV) catalog, exploring how it’s being used (and possibly misused) in prioritization workflows, and where the disconnects lie between policy directives and operational feasibility. Kylie also critiques the current state of vendor responsiveness, machine-readable vulnerability disclosure (CSAF), and the importance of asset and exposure awareness.

This episode is essential listening for practitioners wrestling with patching fatigue, program prioritization, and the tradeoffs between theoretical vulnerability data and applied security outcomes in critical infrastructure environments.

Links:

CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities

CISA vulnrichment: https://github.com/cisagov/vulnrichment

Vulnrichment, Year One: https://www.youtube.com/watch?v=g5pSVMnWD7k

CISA SSVC: https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc

Carnegie Mellon SSVC: https://certcc.github.io/SSVC/

CSAF: https://www.csaf.io/

VulnCheck KEV: https://vulncheck.com/kev

Kylie McLanahan on LinkedIn: https://www.linkedin.com/in/kyliemcclanahan/

Bastazo: https://bastazo.com



The podcast and artwork embedded on this page are from Patrick Miller, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
...more
View all episodesView all episodes
Download on the App Store

@BEERISAC: OT/ICS Security Podcast PlaylistBy Anton Shipulin / Listen Notes

  • 4.5
  • 4.5
  • 4.5
  • 4.5
  • 4.5

4.5

8 ratings


More shows like @BEERISAC: OT/ICS Security Podcast Playlist

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

229,169 Listeners

WSJ What’s News by The Wall Street Journal

WSJ What’s News

4,349 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,022 Listeners

The Daily by The New York Times

The Daily

112,408 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,039 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

181 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

92 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

138 Listeners

Cyber Uncut by Momentum Media

Cyber Uncut

0 Listeners

Industrial Cybersecurity Insider by Industrial Cybersecurity Insider

Industrial Cybersecurity Insider

0 Listeners

PrOTect It All by Aaron Crow

PrOTect It All

7 Listeners