OT Security Isn't an IT Problem: What it Takes to Get it Right

OT Security Isn't an IT Problem: What it Takes to Get it Right

🎙 Industrial Cybersecurity Insider 👥 192 📅 May 18, 2026 ⏱ 27 min 👁 69 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityasset visibilitycyber risk quantificationcompensating controlsbusiness risk

Summary

In this podcast episode, host Greg Duckworth interviews Will Klusovsky, a 26-year cybersecurity veteran and CRO at viLogics, about the unique challenges of OT security in manufacturing. They discuss the importance of asset visibility as the foundation of OT security, debunking the air gap myth, and translating cyber risk into financial terms. Klusovsky emphasizes that cybersecurity risk is business risk, and that quantifying potential downtime costs (e.g., $1.2 million per 8-hour outage) helps executives make informed decisions. They explore the need for programmatic cybersecurity, the role of compensating controls, and the importance of context over raw CVE counts. The conversation highlights the CISO’s role as ‘Chief Inside Selling Officer’ to gain buy-in, and the necessity of aligning incentives across IT, operations, and executive teams. They also touch on remote access risks and the need for business impact analysis to prioritize remediation. The episode concludes with a promise of a part two focusing on business impact analysis.

156 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into OT security, particularly the emphasis on translating cyber risk into financial terms and the importance of asset visibility. The argumentation is solid, built on real-world examples and a clear logical flow: starting with the problem of visibility, moving to quantification, and then to decision-making and programmatic approaches. The guest’s expertise adds credibility, and the discussion avoids fear-based selling, instead advocating for data-driven risk management. However, some claims (e.g., 50% of breaches due to human error) are not precisely sourced, and the conversation remains at a high level without deep technical detail.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the discussion is based on professional experience rather than formal research, and specific statistics are mentioned without precise citations. The quality of sources is not explicitly addressed, but the guest’s background and the podcast’s focus lend some credibility. The title accurately reflects the content, which is a discussion of OT security as distinct from IT security. The podcast does not provide a formal bibliography, but the content aligns with industry frameworks like NIST. No comments were provided for analysis.

202 words

Title / Content Match

The title accurately reflects the core message that OT security requires a different approach than IT, focusing on business risk and operational priorities.

Quality & Reliability

7/10

The discussion is based on the guest's 26 years of experience in cybersecurity, providing practical insights. However, specific data points (e.g., 50% of breaches due to human error) are mentioned without precise citations, and the podcast format limits depth. The content is coherent and aligns with industry best practices.

Key Moments

Cited Sources

Concurring Sources

  • NIST Cybersecurity Framework — The podcast's emphasis on programmatic cybersecurity and risk management aligns with NIST's framework for improving critical infrastructure cybersecurity.

Contribution & Novelties

The podcast provides a practical perspective on OT security, emphasizing the need to frame cyber risk in financial terms and to align security efforts with business objectives. It offers actionable advice for CISOs and operations teams, such as using compensating controls and focusing on business impact rather than raw vulnerability scores. The discussion on the ‘Chief Inside Selling Officer’ role is a memorable insight.

Pour aller plus loin :

  • NIST Cybersecurity Framework — Relevant for understanding a structured approach to managing cybersecurity risk.
  • IEC 62443 — International standards for industrial automation and control systems security.
  • FAIR Model — A framework for quantifying cyber risk in financial terms, aligning with the podcast’s emphasis on risk quantification.

115 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in quality and reliability, reflecting the expert-driven discussion. The technical level is moderate, suitable for a professional audience, and the information is presented with practical relevance.

Reliability 7/10