Discover(CS)²AI Podcast Show: Control System Cyber Security
(CS)²AI Podcast Show: Control System Cyber Security
Claim Ownership

(CS)²AI Podcast Show: Control System Cyber Security

Author: Derek Harp

Subscribed: 35Played: 449
Share

Description

Control System Cyber Security Association International, or (CS)²AI, is the premier global non-profit workforce development organization supporting professionals of all levels charged with securing control systems. With over 34,000 members worldwide, we provide the platform for members to help members, foster meaningful peer-to-peer exchange, continue professional education, and directly support OT and ICS cyber security professional development in every way. Our founder, Derek Harp, interviews cyber security leaders and brings relevant insights to help any company handle cybersecurity effectively.
137 Episodes
Reverse
The Cassandra Panel: OT Threat Intelligence from April to NowBryan Singer revisits an April threat briefing to ask what changed in six months, and the answer is a lot. Georgia Tech's Saman Zonouz shares research on thousands of internet-exposed PLCs, web-enabled controllers, shared firmware code across vendors, and exposed solar inverters. Daryl Haegley explains why threat intel has to start with knowing what's inside the fence, and Brad Willet brings the asset owner's view: stray contractor routers, insider risk, and why no newsletter replaces a trusted network. Vivek dubbed it "the Cassandra Panel" for a reason.Guests: Saman Zonouz (Georgia Tech); Daryl Haegley (United States Department of the Air Force); Brad Willet (UPS) Host / moderator: Bryan Singer (Accenture)Chapters: 00:00 April recap: nothing sophisticated about it 03:53 Georgia Tech CPSEC and anonymous incident reporting 11:35 What changed since April 13:44 Looking inside the fence 16:08 How the Iranian campaign is progressing 18:37 Internet exposure and inventory 23:27 Not fighting the last war 24:51 Capacity gaps and web-enabled PLCs 28:53 Inside-out threat intelligence 33:38 Relationships as threat intel 37:08 Contractors, modems, and insiders 41:14 SBOM and shared firmware code 43:03 Impact-first risk and wrap-upRecorded at the (CS)²AI Online Symposium, "Level Zero: Visions & Reflections."Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back.Questions: [email protected]: [email protected] by CS²AI (Control System Cyber Security Association International).
Three veterans of critical infrastructure security trace how the field went from arguing that infrastructure was even a target to treating digital risk as an engineering hazard. Ginger Wright, Sarah Freeman, and Marc Sachs define cyber-informed engineering in plain terms, share real examples of consequences engineered out of a system, explain why adversaries already read your engineering documentation, and make the case that engineers don't need to become hackers to belong in this conversation. They close with why engineers should come to Level Zero.Guests: Sarah Freeman (MITRE); Marc Sachs (Center for Internet Security) Host / moderator: Ginger Wright (Idaho National Laboratory)Chapters: 00:00 Welcome and panel introductions 02:52 Why engineering is up first at Level Zero 04:24 From 'not a target' to target du jour 08:03 Y2K to WannaCry: when the OT/IT boundary became fiction 12:28 Engineering out the consequence (NIST 800-82 Rev. 3) 14:31 Why engineers belong at the table 19:01 Digital risk and defining CIE / CCE 22:13 Real examples of designed-out consequences 28:34 Where CIE runs into regulation 32:40 Engineer pushback and 'fighting the scenario' 37:01 Digital risk is just another hazard 40:01 The five whys, and why come to Level ZeroRecorded at the CS²AI Online Symposium, "Level Zero: Visions & Reflections."Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back.Questions: [email protected] · Sponsorship: [email protected] Produced by CS²AI (Control System Cyber Security Association International).
Solving the OT Talent Puzzle: A Career Roadmap from Three Industry VeteransDerek Harp sits down with Marcus Sachs (Center for Internet Security), Patrick Miller (Ampyx Cyber), and Christian Harter (UPS) for a candid conversation about breaking into — and building a career in — ICS/OT cybersecurity. The panel tackles the IT/OT divide, why "dropping your ego" matters more than any certification, how AI is reshaping the skills employers want, and why old-school, face-to-face networking still beats the resume-screening algorithms. Whether you're a plant engineer eyeing cybersecurity or a security pro trying to understand the physical world, this episode is a practical roadmap for finding your way in.
Kenny Mesker, OT Cybersecurity Strategist and Distinguished Engineer at Chevron, joins Derek Harp to share his remarkable journey from growing up on a farm in West Texas to becoming one of the industry's leading voices in operational technology (OT) cybersecurity.With more than 30 years of experience spanning electric utilities, SCADA systems, industrial control systems, and cybersecurity, Kenny reflects on the evolution of OT security from the days of air-gapped networks to today's interconnected digital environments. He discusses how a passion for problem-solving led him from electrical engineering into industrial operations and ultimately into cybersecurity strategy.Kenny offers practical advice for professionals looking to enter the OT cybersecurity field, explaining why hands-on operational experience remains one of the most valuable foundations for success. He also explores the challenges of IT/OT convergence, the importance of risk assessment, and how cybersecurity leaders must think beyond individual systems to protect entire organizations and critical infrastructure.Looking ahead, Kenny shares his perspective on artificial intelligence, cloud technologies, and the future of OT architectures, highlighting both the opportunities and challenges these emerging technologies will bring to industrial environments.Whether you're an engineer, cybersecurity professional, student, or industry leader, this episode provides valuable insights into building a successful OT cybersecurity career while helping protect the systems that power modern society.
In this episode of the (CS)²AI Podcast, host Derek Harp is joined by Jonathan Pollet, Marc Visser, and Bryan Singer for a deep-dive Q&A discussion following CS2AI’s January 21st community event on OT Monitoring & SOC and Incident Response. Drawing on decades of hands-on experience across industrial environments worldwide, the panel expands on questions that couldn’t be fully addressed during the live sessions.The conversation explores why OT monitoring and SOC capabilities must come before incident response, and how poor network architecture, lack of visibility, and organizational silos continue to undermine response efforts when incidents occur. Jonathan outlines the architectural foundations required to support effective detection, response, and recovery, while Marc emphasizes the practical realities of implementing OT monitoring—from working with factory engineers to reducing alert fatigue and building usable SOC workflows.Bryan brings the incident responder’s perspective, sharing real-world insights from global OT incidents, including prolonged dwell times, ransomware impacts on production, and why organizations without proper segmentation and monitoring often experience the most severe and prolonged outages. The discussion also tackles common questions around Fusion SOCs vs. dedicated OT SOCs, the human challenges of translating OT data into actionable intelligence, and what asset owners should realistically expect from incident response retainers.This episode is a must-listen for OT practitioners, security leaders, and asset owners looking to move beyond theory and understand what actually works in the field. Whether you are just beginning your OT monitoring journey or refining mature SOC and IR capabilities, this discussion offers practical guidance rooted in real operational experience.
loading
Comments