Industrial Security Podcasts on ICS cybersecurity


Your Human Supply Chain: Dr. Art Conklin | Podcast Episode #27

How education differs from training, with examples from Dr. Art Conklin at the University of Houston. Click PLAY. This Episode’s Page

49 min

Know more about your system than attackers do: Matt Gibson | Podcast Episode #26

Know more about your system than attackers do, and other topics such as analog control systems, IIoT at nuclear sites and control system product “labeling” for security. Join Matt Gibson from the Electric Power Research Institute (EPRI) to explore these and other applied research insights for industrial security. Click PLAY. This Episode’s Page

56 min

Product Security at GE: Kenneth Crowther | Podcast Episode #25

Pointing fingers at vendors is easy. Creating “secure” products is a real challenge, supply chain is a big part of that challenge, and vendors cannot solve the problem in isolation. Kenneth Crowther, a Product Security Leader at GE explores what a leader in this space is doing. Click PLAY.  This Episode’s Page

55 min

Cyber and industrial focus at US CISA – Rick Driggers | Podcast Episode #24

Rick Driggers of CISA describes cyber, physical and industrial security priorities at the new US DHS CISA agency. Click PLAY.  This Episode’s Page

54 min

When Numbers Are Scarce – Ron Brash | Podcast Episode #23

How do we estimate the probability of an attack that has never happened? Ron Brash of Verve Industrial explains. Click PLAY.  This Episode’s Page

41 min

Malcolm – A New (Free, INL) Tool for Network Visibility – Jens Wiesner | Podcast Episode #22

Jens Wiesner of the German BSI explores Malcolm, a new (free, open source) tool for OT network visibility, brought to us by the U.S. Idaho National Labs (INL). Click PLAY.  This Episode’s Page

39 min

Build, Break & Secure – Matthew Luallen | Podcast Episode #21

Build, break & secure with a 1000-lb portable lab – Matthew Luallen of Cybati explores modern industrial security training. Click PLAY.  This Episode’s Page

42 min


Industrial security pioneer Joe Weiss explains how there are 3 networks, not 2 – IT, OT and Engineering, with examples from the 2007 aurora test. Click PLAY. This Episode’s Page

59 min

Layer Zero Anomaly Detection – Ilan Gendelman and Hadas Levine | Episode #19

Explore out of band security and operational anomaly detection with Ilan Gendelman and Hadas Levine of SIGA OT Solutions. Click PLAY. This Episode’s Page

42 min

Where Do Your Bits Really Come From? – Eric Byres | Episode #18

Industrial security pioneer Eric Byres, CEO of Adolus, speaks to software supply chain trust issues and some of the technology his new venture Adolus Inc. is developing to help. Click PLAY. This Episode’s Page

54 min

Be Brave When Assessing Risks – Mark Fabro | Episode #17

Mark Fabro, President and Chief Security Scientist at Lofty Perch, explores how robust cyber/physical risk assessments help “stay left of boom” at industrial sites. Click PLAY. This Episode’s Page

59 min


Lyndon Hall, Senior Manager at Iron Spear Information Security, is routinely called on for the first-ever security assessment at industrial sites. On this episode of the Industrial Security Podcast, he explains how he does that and what he finds. Click PLAY. This Episode’s Page

53 min


Asset inventory is the foundation of industrial security, which is essential to IT/OT convergence. Rick Kaun, VP Solutions at Verve Industrial Protection, talks about asset inventory concepts and the Verve Industrial technology for inventory. This Episode’s Page

59 min


A wide-ranging conversation with Greg Hale, Editor and Founder of Industrial Safety and Security Source (ISSSource), about where we are today, how security relates to safety, how to sell security as improving efficiency and other topics. This Episode’s Page

52 min


Meg Duba, a recruiter at Idaho National Labs talks about techniques, tips, and challenges for industrial security recruitment and job hunting. This Episode’s Page

26 min

Munich Airport – Security Challenges and Information Security Hub | Episode #12

Mark Lindike explores industrial systems and security challenges at the Munich International Airport, as well as how the new Munich ISH training facility is helping the airport and others.

Mark Lindike – Head of cyber defense at Munich Airport and Head of Munich (ISH) Information Security Hub. This Episode’s Page

39 min

Water Services Security at the City of Calgary – Darrol Weiss | Episode #11

Industrial security insights regarding risks, programs, budgets and technology at the City of Calgary Water Services, with Darrol Weiss.

Darrol Weiss is the Control Systems Services Leader for the City of Calgary Water Services. Darrol manages a team of automation staff responsible for OT operational technology process control systems for Calgary’s Wastewater Facilities. This Episode’s Page

48 min


Patrick Miller discusses how technology advances in Industrial Control Systems are out-pacing existing industrial cybersecurity and business risk management programs and what needs to change to keep pace. This Episode’s Page

46 min

Israeli Cybersecurity – Dr. Gabi Siboni | Episode #9

Gabi Siboni joins us to talk about standards, challenges and current initiatives in Israel – perhaps most thoroughly-cyber-protected nation on the planet. This Episode’s Page

42 min


The differences between IT and OT teams and approaches both make life difficult and represent opportunities to improve industrial operations. This Episode’s Page

32 min


The need for a standard way to classify the criticality of industrial control systems – eg: safety-critical vs. equipment-critical vs. reliability-critical systems, and what implications such classification should have for industrial security programs. This Episode’s Page

32 min

ICS Penetration Testing – Jonathan Pollet | Episode #6

In this pilot episode, Jonathan walks us through how his crew does control system penetration testing, often with live, running systems as a target, with examples of findings and how customers use those findings. This Episode’s Page

38 min

Critical Infrastructure Security In Israel – Buki Carmeli | Episode #5

Buki Carmeli walks us through the evolution of government programs and legislation for securing Israel’s critical infrastructure. This Episode’s Page

55 min

German Initiatives & Progress in Cybersecurity – Jens Weisner | Episode #4

We caught Jens Weisner at S4 and he talks about cybersecurity in Germany – progress, challenges and a little comparing of the German approach to what he sees happening in North America. This Episode’s Page

34 min

Cybersecurity Governance – Paul Feldman | Episode #3

Paul Feldman joins us to explore cybersecurity governance topics for boards of directors in the North American electric sector: what are their responsibilities and more. This Episode’s Page

32 min

OSIsoft & EPRI Methodology – Harry Paul | Episode #2

Join us for an introduction to the EPRI approach and an overview of what OSIsoft is doing, and what other product vendors can do, to support the effort. This Episode’s Page

36 min

IIoT Security – Sven Shrecker | Episode #1

In this pilot episode, Sven takes us through the emerging field of industrial IoT and how connecting the grid to the cloud presents new problems, and new solutions, for security professionals. This Episode’s Page

54 min

The future of OT security in modern industrial operationsTHE FUTURE OF OT SECURITY IN

How new approaches are needed to gain defensive advantage over already-capable cyber adversaries, to keep up with new OT/ICS technologies, and to serve business risk management needs in increasingly-demanding, competitive environments. Listen Here

Safe IT/OT Integration with unidirectional security gatewaysSAFE IT/OT INTEGRATION WITH

The reason SCADA security is so controversial stems primarily from the intense consequences that come from a compromise in this area. Unidirectional security gateways allow to digitize without compromise.  Listen Here

Vulnerabilities and architectural considerations in ICS

In this podcast, Andrew Ginter, VP of Industrial Security at Waterfall Security Solutions, and Edward Amoroso, CEO of TAG Cyber, talk about SCADA vulnerabilities in Industrial Control Systems architectures.  Listen Here

Malicious hacking activity increasingly
targeting critical infrastructure

As operational technology (OT) and industrial control system (ICS) infrastructure have become much more prominent components of national critical infrastructure, malicious hacking activity is increasingly targeted in this direction.  Listen Here

A closer look at the IT/OT Landscape
for infosec professionals

The challenge for modern cyber security engineers working in the OT/ICS area involves modernizing the weak or missing protection controls in existing infrastructure toward more advanced and effective solutions that will stop malicious actors.  Listen Here

Why Unidirectional Security Gateways
can replace firewalls

Unidirectional Security Gateways can replace firewalls in industrial network environments, providing absolute protection to control systems and operations networks from attacks originating on external networks.  Listen Here

Seal the integrity of your logs
with Waterfall BlackBox

Logs are the baseline information required for quality incident response and forensics. They consist of tracks and hints of the attack and the attacker. How do you keep log repositories more secure than the attacked network?  Listen Here

Unidirectional communications
in a bidirectional world

Modern enterprises transmit control system information to business networks continuously, and need to send information from business networks into operations networks occasionally. How do you do it securely?  Listen Here

Remote access options for
unidirectionally protected networks

Remote control is the modern attack method. While unidirectional gateways are designed to defeat remote control, that doesn’t mean we have to give up remote access. Learn about few practical options.  Listen Here

The difference between
IT security and ICS security

On IT networks, the focus of a security program is generally preventing the theft of information. The primary focus on control system networks is safety and reliability, and preventing sabotage of those elements.  Listen Here