Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Eric Sorensen. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Eric Sorensen or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Avoiding a 'Chicken Little' Cybersecurity Strategy

39:55
 
Share
 

Manage episode 408208163 series 3352216
Content provided by Eric Sorensen. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Eric Sorensen or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

Threat intelligence is important, but why manufacturers should focus on risk factors first.
When it comes to the industrial sector’s ongoing cybersecurity challenges, we all know that there's more to defend, but what is most concerning is that we’re not responding quickly enough to the expanding threat landscape. In case you needed proof, here are some of the recent stats from Dragos 2023 Year in Review Report. It found that:

  • 80 percent of industrial sector vulnerabilities reside deep within the ICS network, making them difficult to see and harder to kick out.
  • 53 percent of the advisories Dragos analyzed could cause both a loss of visibility and control.
  • Ransomware attacks against industrial organizations increased by 50 percent last year, and Dragos tracked 28 percent more ransomware groups focused on the ICS/OT environment.
  • Attacks were confirmed in 33 unique manufacturing sectors.
  • 74 percent of all vulnerability advisories had no mitigation strategy.

I’m not going to promise solutions for all of these challenges, but we’ve definitely found a guy interested in trying. Scott Sarris is an Information Security, Compliance and Privacy Solutions Advisor at Aprio, a leading advisory and business consulting firm. Watch/listen as we discuss:

  • Why OT could affectionately be known as "Old Tech".
  • The political factors impacting IT/OT divisiveness in the industrial sector, but why Scott is optimistic about the progress being made in bringing the two segments together.
  • Why cybersecurity planning and investments needs to start with assessing and prioritizing risk.
  • How slowing down can help ramp up security efforts.
  • Why dwelling or living-off-the-land attacks will escalate.

As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts.
Click Here to Become a Sponsor.

Promoguy Talk Pills
Agency in Amsterdam dives into topics like Tech, AI, digital marketing, and more drama...
Listen on: Apple Podcasts Spotify

To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast.
If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at [email protected].

To download our latest report on industrial cybersecurity, The Industrial Sector’s New Battlefield, click
here.

  continue reading

Chapters

1. Avoiding a 'Chicken Little' Cybersecurity Strategy (00:00:00)

2. [Ad] Promoguy Talk Pills (00:11:47)

3. (Cont.) Avoiding a 'Chicken Little' Cybersecurity Strategy (00:12:20)

132 episodes

Artwork
iconShare
 
Manage episode 408208163 series 3352216
Content provided by Eric Sorensen. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Eric Sorensen or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://staging.podcastplayer.com/legal.

Threat intelligence is important, but why manufacturers should focus on risk factors first.
When it comes to the industrial sector’s ongoing cybersecurity challenges, we all know that there's more to defend, but what is most concerning is that we’re not responding quickly enough to the expanding threat landscape. In case you needed proof, here are some of the recent stats from Dragos 2023 Year in Review Report. It found that:

  • 80 percent of industrial sector vulnerabilities reside deep within the ICS network, making them difficult to see and harder to kick out.
  • 53 percent of the advisories Dragos analyzed could cause both a loss of visibility and control.
  • Ransomware attacks against industrial organizations increased by 50 percent last year, and Dragos tracked 28 percent more ransomware groups focused on the ICS/OT environment.
  • Attacks were confirmed in 33 unique manufacturing sectors.
  • 74 percent of all vulnerability advisories had no mitigation strategy.

I’m not going to promise solutions for all of these challenges, but we’ve definitely found a guy interested in trying. Scott Sarris is an Information Security, Compliance and Privacy Solutions Advisor at Aprio, a leading advisory and business consulting firm. Watch/listen as we discuss:

  • Why OT could affectionately be known as "Old Tech".
  • The political factors impacting IT/OT divisiveness in the industrial sector, but why Scott is optimistic about the progress being made in bringing the two segments together.
  • Why cybersecurity planning and investments needs to start with assessing and prioritizing risk.
  • How slowing down can help ramp up security efforts.
  • Why dwelling or living-off-the-land attacks will escalate.

As a go-to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust, and your message will stand out to an audience searching for tools to assist their cybersecurity efforts.
Click Here to Become a Sponsor.

Promoguy Talk Pills
Agency in Amsterdam dives into topics like Tech, AI, digital marketing, and more drama...
Listen on: Apple Podcasts Spotify

To catch up on past episodes, you can go to Manufacturing.net, IEN.com or MBTmag.com. You can also check Security Breach out wherever you get your podcasts, including Apple, Amazon and Overcast.
If you have a cybersecurity story or topic that you’d like to have us explore on Security Breach, you can reach me at [email protected].

To download our latest report on industrial cybersecurity, The Industrial Sector’s New Battlefield, click
here.

  continue reading

Chapters

1. Avoiding a 'Chicken Little' Cybersecurity Strategy (00:00:00)

2. [Ad] Promoguy Talk Pills (00:11:47)

3. (Cont.) Avoiding a 'Chicken Little' Cybersecurity Strategy (00:12:20)

132 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play