Cybersecurity Under Pressure. Real Attacks, Real Lessons

When VEX Becomes a Bureaucratic Shield

30 min · 15. maj 2026
episode When VEX Becomes a Bureaucratic Shield cover

Description

Your SBOM is probably useless, and it is time we talked about why. In this episode, we look past the hype of vulnerability scanning to the uncomfortable reality of the software-defined vehicle. We walk through how suppliers are using VEX as a bureaucratic shield to dodge patches and why your security program is likely just a mountain of expensive noise. We argue that if you are not prepared to challenge a supplier's claim with technical evidence, you are not doing security—you are just doing paperwork. This conversation is about moving from a flood of findings to actual, defensible risk management that protects the driver, not just the budget. Subscribe and share this with a security lead who is tired of chasing ghosts in their supply chain. #cybersecurity #automotive #supplychain #SBOM #VEX

Comments

0

Be the first to comment

Sign up now and become a member of the Cybersecurity Under Pressure. Real Attacks, Real Lessons community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

56 episodes

episode When ECUs Meet Malice artwork

When ECUs Meet Malice

What if the most vulnerable point in automotive cybersecurity isn't the car itself, but the station that gives it its software identity, setting the stage for a potential disaster that could put lives at risk. In this episode we break down the critical intersection of product cybersecurity and factory cybersecurity, and explore the potential consequences of a compromised ECU flashing station. We walk through a real-world scenario where a flaw in the flashing process could lead to a supply chain crisis, and discuss the importance of bridging the gap between corporate and vehicle security teams. By the end of this episode, you'll understand the urgent need for a unified approach to automotive cybersecurity. The reality is that a breach at the flashing station could have far-reaching consequences, from safety issues to reputational damage, and could change the way you think about the entire automotive supply chain. Subscribe to our podcast for more insights into the latest cybersecurity threats and trends, and join the conversation on the most critical issues facing the industry today. #automotivecybersecurity #cybersecuritymatters #supplychainrisk

Yesterday33 min
episode Zero Trust Meets Twenty Year Old Code artwork

Zero Trust Meets Twenty Year Old Code

What happens when a twenty-year-old industrial control system meets the latest Zero Trust security protocols, and the two just can't seem to get along? In this episode we break down the challenges of implementing Zero Trust in industrial environments, where legacy devices don't speak the language of modern identity and security. We walk through real-world examples of how to design a Zero Trust architecture that works with, not against, these older systems. We argue that strong authentication and mediation are key to reducing exposure without disrupting production. The distinction between a good and a bad Zero Trust design can be the difference between a secure and a breached industrial system, with very real consequences for the people and processes that rely on it. Subscribe to our podcast for more insights into the intersection of security and industrial technology, and join the conversation about what it takes to protect our most critical systems. #ZeroTrust #OTSecurity #IndustrialCybersecurity

10. juni 202644 min
episode Beyond Backup Recovery artwork

Beyond Backup Recovery

What happens when a production line grinds to a halt, not because of a technical failure, but because trust in the engineering environment has been lost? In this episode we break down the real cost of an OT cyber incident, and explore the complexities of recovery in operational technology environments. We walk through a real case where the question is no longer just about restoring systems, but about proving that the process can be trusted again. We argue that many organisations are weaker than they think when it comes to validating engineering workstation integrity and confirming PLC logic. The ability to quickly and effectively respond to an OT cyber incident can mean the difference between a minor disruption and a six-figure business problem, making it a critical consideration for anyone working in operational technology. Subscribe to our podcast for more insights on the intersection of technology and business, and join the conversation on the real-world implications of OT cyber incidents. #OTcybersecurity #operationaltechnology #industrialcontrolsystems

8. juni 202630 min
episode Cyber Gaps in Automotive Supply artwork

Cyber Gaps in Automotive Supply

What happens when a vulnerability is discovered in a car's system after production has started, and nobody knows who's responsible for fixing it? In this episode we break down the messy world of automotive cybersecurity, where gaps in responsibility between companies can put entire systems at risk. We walk through real-world scenarios where the lack of clear agreements and ownership can lead to major problems. We argue that these gaps are not just technical issues, but also governance problems that need to be addressed. The consequences of these gaps can be severe, from compromised vehicle safety to significant financial losses, making it essential for companies to rethink their approach to cybersecurity and liability. Subscribe to our podcast to dive deeper into the complex world of automotive cybersecurity and learn how to navigate these critical issues. #automotivecybersecurity #cybersecuritymatters #supplychainrisk

5. juni 202631 min
episode When Patches Stop Production artwork

When Patches Stop Production

What happens when a security patch intended to protect your system ends up being the cause of a catastrophic operational incident? In this episode we break down the nuances of patch management in industrial environments, where the stakes are high and the consequences of a mistake can be devastating. We walk through real-world scenarios where a simple patch can bring down an entire production line, and explore the delicate balance between cybersecurity and operational continuity. We argue that a one-size-fits-all approach to patching is no longer tenable. The ability to manage vulnerabilities in industrial environments has a direct impact on the bottom line, as a single misstep can result in costly downtime and damaged equipment. Subscribe to our podcast to hear more about the complexities of OT vulnerability management and how to navigate the treacherous landscape of patching and cybersecurity. #IndustrialCybersecurity #PatchManagement #OTVulnerabilityManagement

3. juni 202641 min