Your Organization Says It's 'Green' on Manufacturing Security: Here's Why That's Dangerous

Your Organization Says It's 'Green' on Manufacturing Security: Here's Why That's Dangerous

🎙 Craig Duckworth and Dino Busaki 👥 192 📅 June 30, 2026 ⏱ 22 min 👁 109 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityCISOasset inventoryIT/OT convergenceindustrial cybersecurity

Summary

In this episode of the Industrial Cybersecurity Insider podcast, hosts Craig Duckworth and Dino Busaki discuss the critical issue of OT cybersecurity ownership and accountability. They argue that while OT security is often considered everyone’s responsibility, in practice it becomes nobody’s responsibility, leading to dangerous gaps. The asset owner is ultimately accountable, but there is a clear delineation between IT and OT systems, with OT teams often resisting IT involvement due to concerns about production and safety. The conversation highlights the CISO’s dilemma of having responsibility without authority, and how this leads to a false sense of security when compliance metrics are met despite missing up to 80% of assets. They emphasize the need for OEMs and system integrators to include cybersecurity safeguards in their proposals, and for organizations to move beyond half measures to a comprehensive OT security strategy. The hosts also discuss the growing OT security market, the importance of incident response drills, and the need to break down the IT/OT trust barrier.

165 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into the challenges of OT cybersecurity ownership. The hosts provide concrete examples, such as the CISO who claims ‘green’ on compliance while missing 80% of assets, and the resistance from OT teams to implement visibility tools. The argumentation is coherent and grounded in real-world scenarios, though it relies heavily on anecdotal evidence rather than empirical data. The discussion effectively highlights the systemic issues of responsibility without authority and the false sense of security that can arise from incomplete asset visibility.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the hosts are industry experts, but they do not cite specific studies or standards. The quality of sources is limited to their professional experience and references to industry trends, such as acquisitions in the OT security market (e.g., Draos, Armis). The title accurately reflects the content, focusing on the danger of a false sense of security in manufacturing security. The discussion is relevant and timely, but the lack of formal citations reduces its scientific credibility.

186 words

Title / Content Match

The title accurately reflects the core message about the dangers of a false sense of security in OT cybersecurity, though it is somewhat sensationalized.

Quality & Reliability

7/10

The hosts are experienced professionals in industrial cybersecurity, providing practical insights and real-world examples. However, the discussion is largely anecdotal and lacks formal citations or data, which limits its scientific rigor.

Key Moments

Contribution & Novelties

The podcast provides a candid, practitioner-level perspective on the often-overlooked issue of OT cybersecurity ownership and accountability. It offers actionable insights for CISOs, plant managers, and engineers, emphasizing the need for clear delineation of responsibilities and the importance of involving OEMs and system integrators in security planning. The discussion on the false sense of security from incomplete asset visibility is particularly valuable.

Pour aller plus loin :

  • Purdue Model — The Purdue model is a reference architecture for industrial control systems, relevant to understanding IT/OT network segmentation.
  • IEC 62443 — This international standard provides guidelines for cybersecurity in industrial automation and control systems, directly related to the podcast’s themes.
  • NIST Cybersecurity Framework — The NIST CSF offers a structured approach to managing cybersecurity risk, applicable to OT environments.

128 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the podcast's practical insights. The technical level is moderate, suitable for a professional audience, and the overall reliability is solid due to the hosts' expertise.

Reliability 7/10