OT Security Isn't an IT Problem: What it Takes to Get it Right

OT Security Isn't an IT Problem: What it Takes to Get it Right

🎙 Industrial Cybersecurity Insider 👥 192 📅 May 19, 2026 ⏱ 27 min 👁 33 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityasset visibilityrisk quantificationbusiness riskCISO

Summary

In this podcast episode, host Greg Duckworth interviews Will Klusovsky, a 26-year cybersecurity veteran and CRO at viLogics, about OT security challenges in manufacturing. They discuss the importance of asset visibility as the foundation of OT security, debunking the air-gap myth, and translating cyber risk into financial terms. Klusovsky emphasizes that cybersecurity risk is business risk, and that executives, not CISOs, own the risk. They explore how to quantify downtime costs, use compensating controls, and prioritize remediation based on business impact rather than raw vulnerability scores. The conversation also covers the need for programmatic cybersecurity, the role of the CISO as a ‘chief inside selling officer,’ and the importance of aligning incentives across IT and operations teams. They conclude by teasing a part two focused on business impact analysis.

129 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into OT security, particularly the emphasis on framing cyber risk in business terms. The argumentation is solid, as Klusovsky uses concrete examples and analogies to illustrate his points, such as the air-gap myth and the story of 600 critical vulnerabilities that were not exploitable. He effectively argues that cybersecurity should be presented as a business decision, not a technical one, and that risk quantification is key to gaining executive buy-in. The discussion is coherent and well-structured, though it lacks empirical data or references to specific studies.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the content is based on expert opinion and anecdotal evidence, with no citations of specific studies or reports. The title accurately reflects the content, which focuses on the distinction between IT and OT security. The discussion is well-informed and practical, but the lack of verifiable sources limits its scientific robustness. No comments were provided for analysis.

173 words

Title / Content Match

The title accurately reflects the content, which focuses on the distinction between IT and OT security and the need for a business-oriented approach.

Quality & Reliability

7/10

The discussion is based on the expert's 26-year experience in cybersecurity, with practical insights and references to industry concepts. However, no specific studies or sources are cited, and the claims are anecdotal.

Key Moments

Contribution & Novelties

The video provides a practical perspective on OT security, emphasizing the need to frame cyber risk as business risk and to quantify it in financial terms. It offers actionable advice for CISOs and security professionals on how to communicate with executives and align incentives across teams. The discussion on using context over CVE counts is particularly valuable.

Pour aller plus loin :

103 words

Radar Profile

The radar profile shows a balanced score across all dimensions, with slightly higher scores in information quality and reliability, reflecting the expert's experience. The technical level is moderate, making the content accessible to a broad audience.

Reliability 7/10