The Hidden Reason Most Manufacturing Cybersecurity Programs Fail

The Hidden Reason Most Manufacturing Cybersecurity Programs Fail

🎙 Industrial Cybersecurity Insider 👥 192 📅 December 23, 2025 ⏱ 30 min 👁 22 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securitymanufacturingIT/OT gapboard communicationsystem integrators

Summary

In this episode of Industrial Cybersecurity Insider, host Dino Busalachi interviews Wil Klusovsky, a cybersecurity expert with 26 years of experience, about the challenges of implementing effective OT security programs in manufacturing. Klusovsky shares his unconventional journey into OT security, emphasizing the importance of understanding plant operations and communicating with business leaders in terms of financial impact. The conversation highlights the frequent failure of security tools due to lack of adoption and organizational change management, the myth of air-gapped networks, and the critical role of system integrators and OEMs in maintaining OT environments. Klusovsky argues that CISOs must build relationships with these third parties and that cybersecurity should be everyone’s responsibility, not just IT’s. He also discusses the differences between IT and OT environments, such as longer asset lifecycles and the need for specialized knowledge. The episode concludes with advice on building a cybersecurity program as a continuous journey, focusing on business impact and collaboration.

155 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in the practical, experience-based insights shared by Klusovsky, who draws on decades of work in both IT and OT. He provides concrete examples, such as the 135% discrepancy in asset visibility and the prevalence of unauthorized remote access points, to illustrate common pitfalls. The argumentation is coherent and persuasive, emphasizing the need for business-oriented communication and the inclusion of system integrators and OEMs in security strategies. However, the discussion is largely anecdotal and lacks empirical data or references to industry studies, which limits its scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the guest’s expertise lends credibility, but the episode does not cite specific sources or research. The quality of sources is limited to the guest’s personal experience and mentions of industry tools and events, such as Rockwell Automation Fair. The title accurately reflects the content, which focuses on the reasons behind the failure of manufacturing cybersecurity programs. No comments were provided, so no analysis of public reception is included.

180 words

Title / Content Match

The title accurately reflects the core theme of the episode, which explores why manufacturing cybersecurity programs often fail due to communication gaps, lack of OT understanding, and missing partnerships.

Quality & Reliability

7/10

The discussion is based on the guest's 26 years of experience in IT and OT cybersecurity, providing practical insights. However, it lacks specific data, citations, or references to studies, and relies heavily on anecdotal evidence.

Key Moments

Cited Sources

Concurring Sources

  • IEC 62443 — International standards for industrial automation and control systems security, aligning with the need for OT-specific approaches.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, supporting the discussion on OT security challenges.

External References

Contribution & Novelties

The episode provides a practitioner’s perspective on the systemic issues in OT security, particularly the communication gap between IT and OT and the overlooked role of system integrators and OEMs. It offers a framework for speaking to boards in business terms, which is a practical contribution. The discussion also challenges common myths like the air gap and emphasizes the need for organizational change management.

Pour aller plus loin :

  • IEC 62443 — International standards for industrial automation and control systems security.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security.
  • MITRE ATT&CK for ICS — Knowledge base of adversary tactics and techniques specific to ICS.

107 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical insights but limited scientific depth. The technical level is moderate, suitable for a general audience, and the overall reliability is moderate due to the lack of cited sources.

Reliability 6/10