Two global dairy producers made headlines this week after breaches that started with third party vendors.

Dino and Craig break down how it happened and why it keeps happening. They walk through the reality of remote access on the plant floor, from cellular modems to TeamViewer installs nobody remembers approving, and explain why a single sensor in a plant might show you 25 percent of your assets at best.

The conversation gets to the root of the problem: people, not technology.

OT teams still lock IT out of critical systems, CISOs carry responsibility without authority, and incident response plans rarely account for the integrators working across multiple plants at any given moment.

If you lead security for a manufacturing organization, this episode arms you with the tough questions to bring back to leadership before your company is the one filing with the SEC.

Chapters:

  • (00:00:00) - The CISO gets hung out to dry, not the third-party vendor
  • (00:01:02) - Two global dairy producers breached through third-party vendors
  • (00:02:12) - The messy reality of remote access on the plant floor
  • (00:03:47) - Why IT has no visibility into what's connected in manufacturing
  • (00:05:29) - North-south versus east-west traffic monitoring
  • (00:06:41) - The culture problem of OT locking IT out
  • (00:08:14) - Responsibility versus authority for CISOs
  • (00:10:47) - The budget excuse and the real cost of downtime
  • (00:14:32) - Incident response plans that leave system integrators out
  • (00:18:56) - SEC filings, brand damage, and the tough questions to ask


Links And Resources:


Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

Podden och tillhörande omslagsbild på den här sidan tillhör Industrial Cybersecurity Insider. Innehållet i podden är skapat av Industrial Cybersecurity Insider och inte av, eller tillsammans med, Poddtoppen.