Skip to content
PodcastsBusiness@BEERISAC: OT/ICS Security Podcast Playlist

@BEERISAC: OT/ICS Security Podcast Playlist

Anton Shipulin / Listen Notes
@BEERISAC: OT/ICS Security Podcast Playlist
Latest episode

794 episodes

  • @BEERISAC: OT/ICS Security Podcast Playlist

    Own Your Industrial Airspace: Wireless, Vendors, and the Parking Lot Crane Hack with Scott McNeil

    29/09/2026 | 1h 5 mins.
    Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)
    Episode: Own Your Industrial Airspace: Wireless, Vendors, and the Parking Lot Crane Hack with Scott McNeil
    Pub date: 2026-09-28

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization

    Work with Aaron: https://protectitallpod.com/work/

    The book: https://protectitallpod.com/book/

    This episode: https://protectitallpod.com/ep125/

    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    A wireless engineer sat in a parking lot, connected to a plant's crane anti-collision network, and had everything he needed to stop the cranes inside 20 minutes. Nobody inside the fence ever knew he was there.

    In this episode of Protect It All, host Aaron Crow talks with Scott McNeil, Industrial Network and Security Architect II at Global Process Automation (GPA), about the part of the OT network most plants never look at: the airspace. Scott has spent more than 20 years in networking and wireless, the last ten of them entirely in OT, and he sits in the integrator's seat, working across every manufacturer's gear without a product to sell.

    The conversation starts where most plants actually are: one flat network, off the shelf gear on the floor, and no budget. Scott's argument is that the low hanging fruit costs time and effort, not money, and that a stable network is the foundation for everything security asks for later: segmentation, inventory, monitoring, then a firewall between OT and IT. He walks through war driving your own plant, why a hidden SSID is not security, the wild west of industrial wireless protocols, wireless that was abandoned in power plants years ago and is still on the air, and where wireless earns its place.

    The second half is about vendors and access. Do not take the vendor's word for it, ask the questions before the gear ships, and treat every third party connection as your own exposure. Scott's rule for remote access is simple: this is my house, vendors connect on my terms, every session logged, with an approve or deny button before anyone gets in. Aaron adds the zip tie in the fan story, a backup switch that had silently failed months earlier and nobody knew until monitoring went on, and the two close on shrinking the wireless footprint that leaves your site and on Scott's podcast, The Industrial Wi-Fi Shop.

    In this episode, you'll learn:

    Why a stable network comes before any security project, and what to fix first

    How to war drive your own plant and what a passive scan of your airspace tells an attacker

    Why hiding the SSID and relying on obscurity is not a control

    Which industrial wireless protocols are standards based and which are proprietary risk

    The questions to ask a wireless vendor before you sign

    How to run vendor remote access on your terms: logged sessions, approve or deny, no standing tunnels

    Why monitoring finds failures you did not know you had

    Tune in to hear why your industrial airspace deserves the same design, monitoring, and ownership as any wired connection.

    About the guest:

    Scott McNeil is an Industrial Network and Security Architect II at Global Process Automation (GPA), where he helps manufacturers design, secure, and modernize the OT networks that keep critical processes running: architecture, IT/OT convergence, segmentation, resilient connectivity, and industrial wireless. A longtime wireless engineer, he created and co-hosts The Industrial WiFi Shop Podcast with Jeremy Baker, speaks regularly at OT and industrial cybersecurity events, holds a bachelor's degree in Industrial Technology from East Carolina University with multiple wireless and network certifications, and serves on the UNC Wilmington Cybersecurity Advisory Board.

    Important Links:

    LinkedIn of Scott McNeil: https://www.linkedin.com/in/americanmcneil/

    The Industrial Wi-Fi Shop Podcast: https://industrialwifishop.com/

    The Industrial Wi-Fi Shop on YouTube: https://www.youtube.com/@IndustrialWi-FiShop

    Scott on X: https://x.com/americanmcneil

    Global Process Automation (GPA): https://www.globalprocessautomation.com/

    Learn more about PrOTect IT All:

    Work with Aaron: https://protectitallpod.com/work/

    The book: https://protectitallpod.com/book/

    This episode: https://protectitallpod.com/ep125/

    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    YouTube: https://www.youtube.com/@PrOTectITAll

    Email: info@protectitall.co

    X: https://twitter.com/protectitall

    Facebook: https://facebook.com/protectitallpodcast

    To be a guest or suggest a guest or episode, email info@protectitall.co.

    Please leave us a review on Apple or Spotify:

    Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

    Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

    The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
  • @BEERISAC: OT/ICS Security Podcast Playlist

    Kiss of Death

    28/09/2026 | 36 mins.
    Podcast: mnemonic security podcast
    Episode: Kiss of Death
    Pub date: 2026-09-28

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization

    What does a 30-year-old timekeeping protocol have to do with taking down a phone network? 
    In this episode of the mnemonic security podcast, Robby welcomes OT security specialist Mikael Vingaard back to the podcast to share some war stories from the world of industrial security. 
    They start off talking about the Network Time Protocol (NTP), a decades-old protocol that still plays a fundamental role in keeping systems synchronised. Mikael shares the story of how renting three servers in Albania accidentally made him one of the country's main sources of NTP traffic, and how shutting them down disrupted an ISP's IP telephony. They discuss what the story reveals about dependencies we may not even know exist, and what incorrect time can mean for industrial systems.
    They also explore configuration drift in OT environments, where small and often undocumented changes accumulate over long device lifecycles. Mikael shares findings from passive network assessments, including supposedly air-gapped networks that turned out to be connected and discusses how periodic verification can help organisations understand what is actually running in their environments.
    Finally, they discuss approaches to securely scanning OT environments, testing guardrails around AI and Denmark's push for digital sovereignty.
    Send us Fan Mail

    The podcast and artwork embedded on this page are from mnemonic, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
  • @BEERISAC: OT/ICS Security Podcast Playlist

    When Cyber Stops the Line, Safety Is on the Line

    24/09/2026 | 31 mins.
    Podcast: Industrial Cybersecurity Insider
    Episode: When Cyber Stops the Line, Safety Is on the Line
    Pub date: 2026-09-23

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization

    Safety starts with a goal. So should cybersecurity.
    Craig Duckworth sits down with Shankar Somasundaram, CEO of Asimily and former head of Symantec's IoT business, to explain why plant floor cybersecurity is a safety issue, not an IT expense. They cover why industrial cybersecurity programs stall after the tool is purchased, how to start with a goal instead of a solution, and why fixing the biggest risks first beats trying to secure everything at once.
    The conversation also covers network segmentation mistakes, AI as both a helper and a new threat to critical infrastructure, protecting legacy OT and IoT equipment without disrupting production, watching traffic inside the plant, what drives cybersecurity maturity, and what OT security market consolidation means for manufacturers.
    Shankar's three takeaways for your next budget cycle:
    Cyber risk is safety risk
    Start with the goal
    Visibility and fixing the problem are one program, not two

    Chapters:
    (00:00:00) Cybersecurity is patient safety, operational safety, plant safety
    (00:00:45) Meet Shankar and the four pillars behind Asimily
    (00:03:50) Why OT security projects stall after the tool is purchased
    (00:06:20) Start with a goal, not a solution
    (00:09:20) Exposure management and the segmentation myths that slow teams down
    (00:11:45) AI as enabler and attacker inside critical infrastructure
    (00:15:40) Collecting data on legacy OT and IoT without disrupting operations
    (00:18:20) North south, east west, and the flow data most teams skip
    (00:20:00) Does maturity come from size, budget, or management
    (00:24:20) Consolidation in the OT market and the advice Shankar leaves behind

    Links And Resources:
    Want to Sponsor an episode or be a Guest? Reach out here.
    Industrial Cybersecurity Insider on LinkedIn
    Cybersecurity & Digital Safety on LinkedIn
    BW Design Group Cybersecurity
    Shankar Somasundaram on LinkedIn
    Asimily
    Dino Busalachi on LinkedIn
    Craig Duckworth on LinkedIn

    Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

    The podcast and artwork embedded on this page are from Industrial Cybersecurity Insider, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
  • @BEERISAC: OT/ICS Security Podcast Playlist

    Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche

    23/09/2026 | 46 mins.
    Podcast: PrOTect It All (LS 27 · TOP 10% what is this?)
    Episode: Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
    Pub date: 2026-09-21

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization

    Work with Aaron: https://protectitallpod.com/work/

    The book: https://protectitallpod.com/book/

    This episode: https://protectitallpod.com/ep124/

    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and supply chain. What does that actually change on the plant floor?

    In this episode of Protect It All, host Aaron Crow talks with Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, about the shift regulation is driving in OT: responsibility moving from the server rooms into the boardrooms, and from the operator to the manufacturer.

    Tobias makes the case that what gets regulated are fundamentally the basics: risk assessment, asset inventory, cyber hygiene, and detection. The industry has preached these for a decade. Now the law demands them, which makes compliance the business case that finally unlocks long-overdue modernization budget. His advice: do not treat legislation as a paper exercise. Treat it as a utility.

    The second half is about recovery, the foundation most plants skip. Aaron and Tobias dig into the vendor-install backup that has never been tested, recovery targets that ignore how long a plant really takes to come back, retain values operators tuned for years that live nowhere else, redundant controllers that are not cyber resilience, and vendor SLAs that send a system engineer when you needed a cyber expert. Tobias's practical pattern: keep a replica of your critical systems, restore into the bubble, and be as intrusive as you like there, scanners and all, without touching production.

    Also in this one: NIS2 Article 20 and personal liability for executives, why a cyber incident does not need a nation state (bad firmware counts), where AI belongs in the Purdue model and where it does not, AI as the daily brief for the one-person water utility, Aaron's Exchange 5.5 story about the week the executives lost their email, borrowing the safety engineers' hazard studies as risk input, and why you should never fire up a wireless pineapple on an airplane.

    In this episode, you'll learn:

    How NIS2, the Cyber Resilience Act, and CIRCIA move accountability to executives and manufacturers

    Why 24-hour incident reporting starts with detection, and why you can't wing it

    How to reframe your next modernization budget ask around compliance

    What a real recovery plan needs: tested backups, plant-realistic RPO and RTO, and captured retain values

    Why redundant controllers protect against failure, not compromise

    How to test restores and run scanners safely in a replica instead of production

    Where AI helps an understaffed operator and where it should never take control

    Tune in to hear how the biggest regulatory wave in industrial cybersecurity history can become the budget unlock OT has been waiting for.

    About the guest:

    Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Having sat on both sides of the table, first delivering cybersecurity services to critical infrastructure operators and now shaping how legislation lands in engineering practice, he brings a combined view of policy, technology, and plant-floor reality that few in the industry carry. Tobias is based in Germany.

    Important Links:

    LinkedIn of Tobias Nitzsche: https://www.linkedin.com/in/tobias-nitzsche-37339735/

    ABB Energy Industries: https://global.abb/group/en/organization/energy-industries

    Learn more about PrOTect IT All:

    Work with Aaron: https://protectitallpod.com/work/

    The book: https://protectitallpod.com/book/

    This episode: https://protectitallpod.com/ep124/

    The OT Security Starter Kit: https://protectitallpod.com/starter-kit/

    YouTube: https://www.youtube.com/@PrOTectITAll

    Email: info@protectitall.co

    X: https://twitter.com/protectitall

    Facebook: https://facebook.com/protectitallpodcast

    To be a guest or suggest a guest or episode, email info@protectitall.co.

    Please leave us a review on Apple or Spotify:

    Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

    Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

    The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
  • @BEERISAC: OT/ICS Security Podcast Playlist

    3/4 Acciones de Gobierno y coordinación de la seguridad OT en el sector eléctrico

    22/09/2026 | 9 mins.
    Podcast: Casos de Ciberseguridad Industrial
    Episode: 3/4 Acciones de Gobierno y coordinación de la seguridad OT en el sector eléctrico
    Pub date: 2026-09-21

    Get Podcast Transcript →
    powered by Listen411 - fast audio-to-text and summarization

    En este episodio se detallan las capacidades clave que se consideran necesarias hoy en día para reducir el riesgo en instalaciones eléctricas industriales. A través de este bloque, examinaremos cómo se toman las decisiones de mitigación en aquellos casos donde no es viable intervenir o parchear determinados activos, analizando el papel que juegan tanto la […]

    The podcast and artwork embedded on this page are from Centro de Ciberseguridad Industrial, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
More Business podcasts
About @BEERISAC: OT/ICS Security Podcast Playlist
A curated playlist of Operational Technology (OT) and Industrial Control Systems (ICS) cybersecurity podcast episodes in any language, compiled by ICS security enthusiasts. Missing something? Contact Anton Shipulin on LinkedIn. Subscribe for updates!
Podcast website

Listen to @BEERISAC: OT/ICS Security Podcast Playlist, Prof G Markets and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features