Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention

Industrial Cybersecurity: The Gap Between Investment and Cyber Event Prevention

🎙 Craig Duckworth and Dino Busalachi 👥 192 📅 October 15, 2025 ⏱ 33 min 👁 28 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityinvestmentrisk reductionalert fatigueincident response

Summary

In this episode of Industrial Cybersecurity Insider, hosts Craig Duckworth and Dino Busalachi discuss why manufacturers continue to experience cyber incidents despite significant investments in OT security tools. They argue that buying tools is not a strategy; organizations often underutilize their capabilities, leading to alert fatigue and a false sense of security. The conversation highlights the lack of clear ownership for plant-floor cybersecurity, with CISOs, CIOs, OEMs, and system integrators often talking past each other. They emphasize the importance of defining business use cases before tuning sensors and policies. The hosts point out that OT incident response is often missing, and operators are the true first responders. They also address the reality of flat Layer 2 networks, undocumented zones, and unmanaged switches, which create visibility blind spots. Technical debt, such as end-of-life firmware and unpatched HMIs, is a major challenge, compounded by the ‘silver tsunami’ of retiring skilled workers and the ‘jack of all trades’ constraints on remaining staff. They discuss the limitations of outside partners and the need for floor-level walkthroughs to validate asset visibility. The episode concludes with a call to build a coalition of plant managers, engineering, OEMs, and SOC to align on protecting production environments.

199 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into common pitfalls in industrial cybersecurity. The hosts provide a candid assessment of why investments fail, such as underutilization of tools, lack of ownership, and poor network architecture. Their argumentation is coherent and grounded in real-world observations, though it relies heavily on anecdotal evidence rather than empirical data. They effectively argue that a holistic approach involving all stakeholders is necessary, but they do not provide a systematic framework or evidence to support their claims.

Scientific Rigor, Source Quality, Title Accuracy

The discussion is based on the hosts’ professional experience rather than cited scientific literature. The description includes links to their LinkedIn profiles and company pages, but no specific sources or studies are referenced. The title accurately reflects the content, focusing on the gap between investment and prevention. The lack of external references limits the scientific rigor, but the practical expertise of the hosts adds credibility. No comments were provided for analysis.

171 words

Title / Content Match

The title accurately reflects the core discussion about the disconnect between cybersecurity investments and actual prevention of incidents in industrial environments.

Quality & Reliability

7/10

The hosts are experienced practitioners in industrial cybersecurity, providing practical insights grounded in field experience. However, the discussion is largely anecdotal and lacks empirical data or references to specific studies, which limits its scientific rigor.

Chapters

Cited Sources

Concurring Sources

  • IEC 62443 — International standards for industrial cybersecurity, aligning with the need for structured approaches.
  • NIST Cybersecurity Framework — Framework for improving critical infrastructure cybersecurity, supporting the hosts' emphasis on risk reduction.

Contribution & Novelties

The episode provides a candid, practitioner-focused perspective on why OT security investments often fail to prevent incidents. It emphasizes the importance of aligning business goals with security strategies, validating asset visibility through floor-level walkthroughs, and building cross-functional coalitions. The discussion offers practical insights into common pitfalls such as alert fatigue, flat networks, and technical debt.

Pour aller plus loin :

  • IEC 62443 — International standards for industrial cybersecurity, relevant for understanding best practices.
  • NIST Cybersecurity Framework — Framework for improving critical infrastructure cybersecurity, applicable to OT environments.
  • MITRE ATT&CK for ICS — Knowledge base of adversary tactics and techniques specific to industrial control systems.

104 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded discussion. The slightly lower technical level suggests the content is accessible to a broad audience, while the reliability score reflects the hosts' practical expertise.

Reliability 7/10