Billede af showet The OT Podcast: A CISO’s Guide to OT

The OT Podcast: A CISO’s Guide to OT

Podcast af Chris McLaughlin

engelsk

Videnskab & teknologi

Begrænset tilbud

2 måneder kun 19 kr.

Derefter 99 kr. / månedOpsig når som helst.

  • 20 lydbogstimer pr. måned
  • Podcasts kun på Podimo
  • Gratis podcasts
Kom i gang

Læs mere The OT Podcast: A CISO’s Guide to OT

Welcome to the ”OT Security Podcast,” a podcast dedicated to bridging the gap between IT and OT security.  This podcast offers a practical guide for IT professionals who are new to the world of manufacturing and critical infrastructure security. We will provide valuable insights, practical examples, and actionable advice to help you navigate the complexities of securing industrial environments. Whether you’re looking to enhance your knowledge or seeking practical solutions, The OT ”OT Security Podcast” is your go-to resource for mastering OT security.

Alle episoder

4 episoder

episode Four Common OT Attack Points cover

Four Common OT Attack Points

In Episode 4 of the CISO's Guide to OT Security, Chris McLaughlin drills into the primary vulnerabilities attackers exploit in operational technology (OT) systems and explains why many historic incidents share the same weak points. Chris outlines the four most common OT attack vectors: insecure remote access and internet-exposed devices; poor network segmentation and IT–OT bridges; software vulnerabilities, missing patches and misconfigurations; and human risks including phishing and insider threats. He illustrates each with real incidents such as water and pipeline breaches, Ukraine grid outages, and ransomware impacts on energy operations. The episode also explains why these vulnerabilities persist — contractor and vendor access, legacy VPNs, forgotten remote tools, and risky contractual arrangements — and emphasizes collaboration between IT, OT and procurement to inventory and secure access. Practical steps include mapping all remote access points, applying zero-trust and MFA, prioritizing OT-aware patching and testing, improving user awareness and insider-threat controls, and updating contracts to require secure remote solutions. Listeners will take away a clear sense of where OT systems are most exposed and what immediate actions can reduce risk. The episode closes by pointing to resources for ongoing threat intelligence and previews the next episode, Step 2: Hire a translator, which will help bridge communications between IT and OT teams.

22. mar. 2026 - 26 min
episode OT threats that every CISO should know about cover

OT threats that every CISO should know about

In this episode of The CISO’s Guide to OT Security, host Chris McLaughlin takes listeners on a twenty‑year journey through some of the most significant cyber incidents to ever impact industrial control systems. He frames the discussion around four major categories of threats—nation‑state attacks, ransomware spillover, supply‑chain compromises, and insider threats—each revealing how vulnerable operational technology environments have become. He begins with nation‑state operations, recounting landmark events such as the Stuxnet sabotage of Iran’s Natanz facility, the coordinated attacks against Ukraine’s power grid in 2015 and 2016, and the TRITON malware targeting safety systems at a Saudi petrochemical plant. He also highlights long‑term infiltration campaigns by Russian and Chinese groups seeking persistent access to U.S. critical infrastructure. The narrative then shifts to ransomware, illustrating how criminal groups—initially focused on IT—started causing widespread OT outages. Incidents like NotPetya, LockerGoga at Norsk Hydro, and the DarkSide attack that led Colonial Pipeline to halt fuel operations show how tightly IT and OT environments are intertwined. These events underscore how even indirect IT compromises can ripple into physical operations. McLaughlin also explores the growing risk of third‑party and supply‑chain compromises. From the Dragonfly campaign’s Trojanized ICS software updates to attacks on vendors supporting utilities and wind energy operators, he describes how adversaries increasingly exploit trusted relationships to bypass strong perimeters and reach industrial environments. Finally, he walks through real‑world insider incidents—cases where employees, contractors, or former staff misused privileged access to damage systems, manipulate processes, or profit personally. These stories serve as a reminder that not all threats originate outside the organization. The episode closes by emphasizing the importance of recognizing these major threat trends and understanding how attackers gain initial access. This sets the stage for the next installment, where he will break down attacker methods and the controls that OT teams can put in place to reduce risk.

24. jan. 2026 - 27 min
episode Seven Steps to a Sustainable Industrial Security Program cover

Seven Steps to a Sustainable Industrial Security Program

Episode 2 of the CISO's Guide to OT Security with Chris McLaughlin walks through seven practical steps to build a sustainable industrial security program. This episode focuses on how to fix common OT security mistakes by bridging the gap between IT and OT and creating lasting, operationally controls. Step 1: Admit you have a problem and secure executive and engineering buy-in by showing realistic OT threats such as remote access risks, ransomware spillover, and unsafe third-party access. Step 2: Add an OT translator to your security team — an engineer or consultant who can communicate OT realities to IT and lend credibility to the program. Step 3: Understand the critical business and OT processes through plant tours and discussions so you can prioritize protections where they matter most. Step 4: Inventory OT assets carefully after you have organizational context; use passive tooling and the OT translator to avoid disrupting operations and map zones and conduits per ISA/IEC guidance. Step 5: Add value to operations (backups and failover checks, virtualization reviews, investment support, operational fixes) so OT teams welcome the security effort rather than resist it. Step 6: Implement OT governance based on standards like ISA-IEC 62443, starting with the most critical controls and improving the program iteratively. Step 7: Keep it real — involve operators, maintenance staff and contractors, tie security into safety messaging, run tabletop exercises, and provide clear, practical awareness training. The episode closes by emphasizing the importance of a cooperative IT–OT relationship and invites feedback at chris@theotpodcast.com. Tune in to episode 3 for a deep dive into common OT cyber threats and mitigation strategies.

18. jan. 2026 - 25 min
episode A CISO's Guide to OT: 5 mistakes we make in OT cover

A CISO's Guide to OT: 5 mistakes we make in OT

Welcome to the podcast version of "A CISO's Guide to OT Security" by Chris McLaughlin. This episode explains why IT-led security programs often struggle in operational technology (OT) environments and sets the stage for a practical, CISO-focused series to build industrial security programs. The episode outlines five common mistakes CISOs make when interacting with OT teams: not understanding OT priorities (safety and availability), undervaluing OT engineers' knowledge, incorrect assumptions about OT patching, excluding OT from incident response planning, and not applying OT-specific security frameworks. Listeners will learn the CIA + S concept (confidentiality, integrity, availability, plus safety), the importance of IT/OT collaboration through plant tours and tabletop exercises, risk-based patching strategies, and framework recommendations such as ISA/IEC 62443 and NIST 800-82. This is the first of a series of 12 episodes mapped to the forthcoming book due in 2026, designed for audio so you can consume individual chapters or follow the series in order. Subscribe for future episodes and practical guidance on building a sustainable industrial security program.

1. jan. 2026 - 41 min
Tilmeld dig for at lytte
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
En fantastisk app med et enormt stort udvalg af spændende podcasts. Podimo formår virkelig at lave godt indhold, der takler de lidt mere svære emner. At der så også er lydbøger oveni til en billig pris, gør at det er blevet min favorit app.
Rigtig god tjeneste med gode eksklusive podcasts og derudover et kæmpe udvalg af podcasts og lydbøger. Kan varmt anbefales, om ikke andet så udelukkende pga Dårligdommerne, Klovn podcast, Hakkedrengene og Han duo 😁 👍
Podimo er blevet uundværlig! Til lange bilture, hverdagen, rengøringen og i det hele taget, når man trænger til lidt adspredelse.

Vælg dit abonnement

Mest populære

Begrænset tilbud

Premium

20 timers lydbøger

  • Podcasts kun på Podimo

  • Ingen reklamer i podcasts fra Podimo

  • Opsig når som helst

2 måneder kun 19 kr.
Derefter 99 kr. / måned

Kom i gang

Premium Plus

100 timers lydbøger

  • Podcasts kun på Podimo

  • Ingen reklamer i podcasts fra Podimo

  • Opsig når som helst

Prøv gratis i 7 dage
Derefter 129 kr. / måned

Prøv gratis

Kun på Podimo

Populære lydbøger

Ofte stillede spørgsmål

Flere spørgsmål og svar
Kom i gang

2 måneder kun 19 kr. Derefter 99 kr. / måned. Opsig når som helst.