Discover@BEERISAC: OT/ICS Security Podcast PlaylistIndustrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention
Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention

Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention

Update: 2025-10-16
Share

Description

Podcast: Industrial Cybersecurity Insider
Episode: Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention
Pub date: 2025-10-14

Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization



In this episode, Craig and Dino address why manufacturers still suffer incidents after spending millions on OT security tools. They discuss how to convert those investments into measurable risk reduction.

You'll learn why buying tools isn't a strategy. Get insights into how to validate asset visibility on the floor (not just the network map), practical ways to reduce alert fatigue and assign ownership, how to close the OT incident response gap by connecting SOC to operators, the realities of flat Layer 2 networks and undocumented zones, how to handle technical debt at scale (EOL firmware, unpatched HMIs, safe upgrade paths), and why "everyone is responsible" often means no one is.

Expect candid discussion on alert fatigue, flat networks, and the human constraints driving today's gaps, plus a concrete checklist for building a coalition that actually works to protect production environments.

Chapters

00:00:00 – Why incidents still happen after major OT cyber spend

00:02:30 – Tools vs. outcomes: underusing capabilities and alert fatigue

00:05:50 – Who owns plant‑floor cyber? Why CISOs, CIOs, OEMs, and SIs talk past each other

00:08:10 – Define the use case before tuning sensors and policies

00:10:00 – OT IR is missing: operators are the first responders

00:11:20 – Network reality check: flat L2, VLAN gaps, and unmanaged switches

00:13:30 – Change management and patching in OT: risk, downtime, and technical debt

00:15:20 – Skills and staffing: the silver tsunami and "jack of all trades" constraints

00:18:00 – What outside partners can and cannot do in plants

00:21:00 – Visibility blind spots: validating coverage with floor‑level walkthroughs

00:24:00 – It won’t stick without a coalition: getting plant managers, engineering, OEMs, and SOC aligned

Links And Resources:


Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!



The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention

Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention

Industrial Cybersecurity Insider