(CS)²AI Podcast Show: Control System Cyber Security cover image

(CS)²AI Podcast Show: Control System Cyber Security

(CS)²AI Podcast Show: Control System Cyber Security

By: Derek Harp
Listen for free

Season's Savings | 0.99 €/mo for 3 months

6.99 €/month thereafter - terms apply. Cancel monthly.
Control System Cyber Security Association International, or (CS)²AI, is the premier global non-profit workforce development organization supporting professionals of all levels charged with securing control systems. With over 34,000 members worldwide, we provide the platform for members to help members, foster meaningful peer-to-peer exchange, continue professional education, and directly support OT and ICS cyber security professional development in every way. Our founder, Derek Harp, interviews cyber security leaders and brings relevant insights to help any company handle cybersecurity effectively.Copyright 2026 Derek Harp Career Success Economics Politics & Government
Episodes
  • 135: The Cassandra Panel: OT Threat Intelligence from April to September 2026
    6 Oct 2026

    The Cassandra Panel: OT Threat Intelligence from April to Now

    Bryan Singer revisits an April threat briefing to ask what changed in six months, and the answer is a lot. Georgia Tech's Saman Zonouz shares research on thousands of internet-exposed PLCs, web-enabled controllers, shared firmware code across vendors, and exposed solar inverters. Daryl Haegley explains why threat intel has to start with knowing what's inside the fence, and Brad Willet brings the asset owner's view: stray contractor routers, insider risk, and why no newsletter replaces a trusted network. Vivek dubbed it "the Cassandra Panel" for a reason.

    Guests: Saman Zonouz (Georgia Tech); Daryl Haegley (Department of War); Brad Willet (UPS) Host / moderator: Bryan Singer

    Chapters: 00:00 April recap: nothing sophisticated about it 03:53 Georgia Tech CPSEC and anonymous incident reporting 11:35 What changed since April 13:44 Looking inside the fence 16:08 How the Iranian campaign is progressing 18:37 Internet exposure and inventory 23:27 Not fighting the last war 24:51 Capacity gaps and web-enabled PLCs 28:53 Inside-out threat intelligence 33:38 Relationships as threat intel 37:08 Contractors, modems, and insiders 41:14 SBOM and shared firmware code 43:03 Impact-first risk and wrap-up

    Recorded at the CS²AI Online Symposium, "Level Zero: Visions & Reflections."

    Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back.

    Questions: info@levelzeroconference.com · Sponsorship: sponsor@levelzeroconference.com Produced by CS²AI (Control System Cyber Security Association International).

    Show more Show less
    46 mins
  • 134: Engineers Belong at the Table: Cyber-Informed Engineering and the End of the OT/IT Boundary
    29 Sep 2026

    Three veterans of critical infrastructure security trace how the field went from arguing that infrastructure was even a target to treating digital risk as an engineering hazard. Ginger Wright, Sarah Freeman, and Marc Sachs define cyber-informed engineering in plain terms, share real examples of consequences engineered out of a system, explain why adversaries already read your engineering documentation, and make the case that engineers don't need to become hackers to belong in this conversation. They close with why engineers should come to Level Zero.

    Guests: Sarah Freeman (MITRE); Marc Sachs (Center for Internet Security) Host / moderator: Ginger Wright (Idaho National Laboratory)

    Chapters: 00:00 Welcome and panel introductions 02:52 Why engineering is up first at Level Zero 04:24 From 'not a target' to target du jour 08:03 Y2K to WannaCry: when the OT/IT boundary became fiction 12:28 Engineering out the consequence (NIST 800-82 Rev. 3) 14:31 Why engineers belong at the table 19:01 Digital risk and defining CIE / CCE 22:13 Real examples of designed-out consequences 28:34 Where CIE runs into regulation 32:40 Engineer pushback and 'fighting the scenario' 37:01 Digital risk is just another hazard 40:01 The five whys, and why come to Level Zero

    Recorded at the CS²AI Online Symposium, "Level Zero: Visions & Reflections."

    Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back.

    Questions: info@levelzeroconference.com · Sponsorship: sponsor@levelzeroconference.com Produced by CS²AI (Control System Cyber Security Association International).

    Show more Show less
    43 mins
  • Episode 133: Engineering Expertise: Core Skills for ICS/OT Cybersecurity with Marcus Sachs, Patrick Miller and Christian Harter
    18 Aug 2026

    Solving the OT Talent Puzzle: A Career Roadmap from Three Industry Veterans

    Derek Harp sits down with Marcus Sachs (Center for Internet Security), Patrick Miller (Ampyx Cyber), and Christian Harter (UPS) for a candid conversation about breaking into — and building a career in — ICS/OT cybersecurity. The panel tackles the IT/OT divide, why "dropping your ego" matters more than any certification, how AI is reshaping the skills employers want, and why old-school, face-to-face networking still beats the resume-screening algorithms. Whether you're a plant engineer eyeing cybersecurity or a security pro trying to understand the physical world, this episode is a practical roadmap for finding your way in.

    Show more Show less
    1 hr and 15 mins
adbl_web_anon_alc_button_suppression_t1
No reviews yet