Who Actually Owns OT Cybersecurity? Not Who You Think

Who Actually Owns OT Cybersecurity? Not Who You Think

🎙 Dino Busalacchi and Craig Duckworth 👥 192 📅 April 7, 2026 ⏱ 30 min 👁 23 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT cybersecurityownershipplant floorOEMasset inventoryremote accessPurdue modelIT/OT convergenceEDRchange management

Summary

In this episode of Industrial Cybersecurity Insider, hosts Dino Busalacchi and Craig Duckworth discuss the current state of OT cybersecurity adoption, noting that 60% of organizations are still in the ‘unaware to awareness’ phase, 30% have started some initiatives, and only 10% have operationalized their programs. They emphasize that the responsibility for remediation often falls to plant-floor teams and their OEM/integrator partners, rather than IT, due to the specialized nature of industrial environments. The conversation covers the limitations of visibility at Purdue Level 3, the importance of accurate asset inventory and remote access control, and the challenges posed by flat networks, legacy switches, and warranty concerns. They share a cautionary example of an EDR deployment that caused significant operational costs and downtime. They conclude with advice to ’think globally, act locally’ and to build defensible OT programs that align with how plants actually operate, highlighting that safety, quality, and cybersecurity are the three areas leaders are willing to fund.

159 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, field-based insights into the challenges and realities of OT cybersecurity implementation. The hosts draw on their extensive experience to highlight common pitfalls, such as the misconception that IT tools can be directly applied to OT environments, and the importance of understanding plant-floor operations. Their argumentation is coherent and grounded in real-world examples, such as the EDR case study and the roofing company incident, which illustrate the potential consequences of inadequate OT security measures. However, the discussion is largely anecdotal and lacks empirical data or formal references, which somewhat weakens the scientific rigor. The hosts’ perspective is clear and consistent, advocating for a localized, plant-centric approach to OT security, but they do not engage with counterarguments in depth.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the hosts are credible practitioners, but they do not cite specific studies, standards, or external sources to support their claims. The quality of sources is limited to their own experience and anecdotal evidence, which, while valuable, is not verifiable. The title accurately reflects the content, which focuses on the question of ownership in OT cybersecurity. The description provides links to the hosts’ LinkedIn profiles and the podcast’s social media, but these are not substantive sources. No comments were provided for analysis.

227 words

Title / Content Match

The title accurately reflects the central theme of the episode, which focuses on the ownership and execution of OT cybersecurity responsibilities.

Quality & Reliability

7/10

The hosts are experienced practitioners in OT cybersecurity, providing practical insights and real-world examples. However, the discussion is largely anecdotal and lacks formal citations or references to specific studies or standards, which limits its scientific rigor.

Key Moments

Cited Sources

Concurring Sources

  • NIST SP 800-82 — Provides guidance on securing ICS, aligning with the episode's emphasis on asset inventory and remote access.
  • IEC 62443 — International standards for industrial cybersecurity, supporting the need for defense-in-depth and segmentation.

Dissenting Sources

  • IT-centric approaches to OT security — The episode argues against relying solely on IT tools and approaches for OT security, which some IT professionals might disagree with.

Contribution & Novelties

The episode provides a practitioner’s perspective on the ownership and execution challenges in OT cybersecurity, emphasizing the critical role of plant-floor teams and OEMs. It offers practical advice on asset inventory, remote access control, and the importance of understanding the operational environment. The discussion of the EDR failure and the roofing company incident illustrates real-world consequences, adding valuable context.

Pour aller plus loin :

  • Purdue Model — Foundational reference for ICS network segmentation.
  • IEC 62443 — International standards for industrial cybersecurity.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security.

92 words

Radar Profile

The radar profile shows balanced scores across all dimensions, indicating a well-rounded discussion with moderate technical depth and reliability. The highest score is in 'quantite_information' and 'niveau_technique', reflecting the hosts' expertise, while 'fiabilite_globale' is slightly lower due to the lack of formal citations.

Reliability 7/10