OT Office Hours | Hacktivists, Nation-States & OT Security Fundamentals | Mike Holcomb

OT Office Hours | Hacktivists, Nation-States & OT Security Fundamentals | Mike Holcomb

🎙 Mike Holcomb, Dan Gunter, Sam Becker 👥 2K 📅 September 18, 2025 ⏱ 56 min 👁 83 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityICShacktivistsnation-stateBAS

Summary

In this OT Office Hours session, Mike Holcomb and Dan Gunter discuss the current OT threat landscape, emphasizing the difference between high-volume/low-impact and low-volume/high-impact threats. They highlight that attackers often aim to simply disrupt operations (‘I just want you off the network’). The conversation covers historical incidents like Stuxnet, SQL Slammer, and WannaCry, illustrating how IT malware can impact OT environments. Mike shares his background and stresses the importance of mastering fundamentals: Backups, Asset Management, Secure Infrastructure, Incident Response, and Continuous Vulnerability Management (BAS). He argues that these basics are cost-effective and can significantly reduce risk, especially for smaller organizations. The discussion also touches on the lack of monitoring and segmentation in many OT environments, the role of hacktivists and nation-state actors, and the need for proper firewall configuration between IT and OT. The session concludes with practical advice on starting an OT security program, prioritizing the BAS fundamentals, and leveraging firewall logs for monitoring.

155 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in the practical, experience-based insights from a seasoned OT security professional. Mike provides a clear framework (BAS) for prioritizing security measures, which is actionable for organizations with limited resources. The argumentation is solid, grounded in real-world examples and industry knowledge. However, some claims lack specific data or citations, and the discussion occasionally veers into anecdotal territory. The emphasis on fundamentals is well-argued and aligns with industry best practices.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the speakers rely on their professional experience and well-known incidents rather than formal research. Sources mentioned include the book ‘Sandworm’ by Andy Greenberg and references to Rob Lee’s presentations, but no direct URLs or studies are cited. The title accurately reflects the content, and the discussion is coherent and focused. The lack of formal citations is a limitation, but the practical expertise adds credibility.

158 words

Title / Content Match

The title accurately reflects the content: the session covers hacktivists, nation-state threats, and OT security fundamentals.

Quality & Reliability

7/10

The discussion is based on the speakers' extensive practical experience in OT cybersecurity, with references to well-known incidents (Stuxnet, SQL Slammer, WannaCry, Colonial Pipeline) and industry best practices. However, it lacks formal citations or data sources, and some claims (e.g., 65% unsecured remote access) are mentioned without specific references.

Key Moments

Cited Sources

Concurring Sources

  • NIST SP 800-82 — Aligns with the emphasis on asset management, network segmentation, and incident response.

Contribution & Novelties

The session provides a practical, experience-based perspective on OT security, emphasizing the BAS framework as a cost-effective starting point. It bridges the gap between theoretical knowledge and real-world implementation, particularly for resource-constrained organizations. The discussion of hacktivists and nation-state actors offers current insights into the threat landscape.

Pour aller plus loin :

95 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical expertise shared. The technical level is moderate, suitable for a broad audience, while reliability is good but not exceptional due to the lack of formal citations.

Reliability 7/10

💬 No comments were provided for analysis.