Who Actually Owns OT Cybersecurity? Not Who You Think

Who Actually Owns OT Cybersecurity? Not Who You Think

🎙 Dino Busalaki and Craig Duckworth 👥 192 📅 April 7, 2026 ⏱ 30 min 👁 105 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityICSasset inventoryremote accessPurdue model

Summary

In this episode, Dino Busalaki and Craig Duckworth discuss the current state of OT cybersecurity, highlighting that 60% of OT environments are still in the unaware-to-awareness phase, 30% have started some initiatives, and only 10% have operationalized their programs. They emphasize that ownership of remediation typically falls to plant-floor teams and their OEM/integrator partners, not IT. The conversation covers the limitations of visibility at Purdue Level 3, the importance of accurate asset inventory and remote access control, and the challenges of flat networks, legacy switches, and warranty concerns. They share a cautionary example of an EDR deployment that caused significant operational costs and production downtime. The hosts stress the need for local tribal knowledge and argue that OT cybersecurity requires a ’think globally, act locally’ approach. They conclude by identifying safety, quality, and cybersecurity as the three priorities that leaders will fund, and highlight the importance of change management and monitoring PLC edits.

153 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, field-based insights into OT cybersecurity challenges. The hosts provide concrete examples, such as the EDR deployment that cost $1 million in capex but resulted in $8 million in opex and potential $25 million in total impact, illustrating the risks of IT-first approaches. They also discuss the ‘oh wow’ moment after initial pilots and the difficulty of achieving visibility at lower Purdue levels. The argumentation is coherent and grounded in their experience, though it relies heavily on anecdotal evidence rather than formal studies. They effectively argue that ownership and execution must reside with OT teams and their partners, and that accurate asset inventory and remote access control are foundational. The discussion on the 3:1 cost difference between IT and OT assessments adds a practical dimension. However, the lack of citations to external sources weakens the overall rigor.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the hosts are experienced practitioners, but they do not cite specific studies or standards. They reference industry players like Cisco, Armis, and Claroty for market statistics, but these are not formally verified. The title accurately reflects the content, focusing on ownership and responsibility. The description and chapters align well with the discussion. No external sources are provided in the video description, so the analysis relies solely on the hosts’ expertise. The adequacy between title and content is strong, as the episode directly addresses the question of who owns OT cybersecurity.

255 words

Title / Content Match

The title accurately reflects the central theme of the episode, which focuses on the ownership and responsibility for OT cybersecurity in industrial environments.

Quality & Reliability

7/10

The hosts are experienced practitioners in OT cybersecurity, providing practical insights and real-world examples. However, the discussion is largely anecdotal and lacks formal citations or references to specific studies or standards.

Key Moments

Contribution & Novelties

The episode provides a practitioner’s perspective on the ownership and execution of OT cybersecurity, emphasizing the critical role of plant-floor teams and OEM/integrator partnerships. It highlights the gap between IT and OT approaches and the need for local knowledge. The discussion on the cost implications of IT-first tools like EDR is particularly insightful.

Pour aller plus loin :

  • Purdue Model — Reference architecture for industrial control systems, relevant to the discussion on network segmentation.
  • IEC 62443 — International standards for industrial cybersecurity, providing a framework for OT security.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, offering best practices for securing OT environments.

106 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the hosts' extensive practical knowledge. The technical level is moderate, suitable for a general audience, while reliability is slightly lower due to the lack of formal citations. Overall, the content is informative and credible for practitioners.

Reliability 6/10