Responsibility Without Authority: The CISO's Industrial Cybersecurity Dilemma

Responsibility Without Authority: The CISO's Industrial Cybersecurity Dilemma

🎙 Craig Duckworth and Dino Busalachi 👥 192 📅 September 16, 2025 ⏱ 30 min 👁 28 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

CISOOT SecurityIT/OT ConvergenceAsset VisibilityRisk Management

Summary

In this episode of the Industrial Cybersecurity Insider podcast, hosts Craig Duckworth and Dino Busalachi discuss the challenge faced by CISOs in industrial environments: they have the responsibility for cybersecurity but lack the authority to implement necessary measures on the plant floor. They explain that plant managers prioritize production uptime and safety KPIs, often resisting security initiatives that could disrupt operations. The hosts emphasize the need for IT and OT teams to build bridges and collaborate, as well as the importance of understanding the unique technologies and constraints of OT environments. They highlight the pitfalls of remote-only deployments, the necessity of on-site presence to gain visibility into assets, and the challenges posed by OEM restrictions and the myth of air-gapped networks. The conversation also covers the importance of communicating security risks in financial terms to align with business objectives, and the role of capital master plans in addressing obsolescence. Finally, they discuss how company ownership structures (e.g., private equity vs. family-owned) influence security investment, and suggest ways to equip CISOs with real authority, such as involving them in plant-level planning and fostering a culture of trust but verify.

188 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, field-based insights into the real-world challenges of industrial cybersecurity. The hosts draw on decades of experience to illustrate the disconnect between IT and OT, the difficulties of asset visibility, and the importance of building relationships with plant teams and OEMs. The argumentation is coherent and persuasive, relying on anecdotal evidence and common industry observations rather than formal data or case studies. While this limits its scientific rigor, it provides actionable advice for practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the discussion is based on expert opinion and practical experience, but lacks formal citations to standards, studies, or frameworks. The sources cited in the description are primarily promotional (LinkedIn profiles, company pages) and do not provide direct references to external research. The title accurately reflects the content, which focuses on the CISO’s dilemma of responsibility without authority. The episode is well-structured with clear chapters, and the hosts maintain a consistent focus on the topic.

176 words

Title / Content Match

The title accurately reflects the core theme of the episode, which is the CISO's challenge of having responsibility without corresponding authority in industrial environments.

Quality & Reliability

7/10

The hosts are experienced practitioners in industrial cybersecurity, providing practical insights grounded in field experience. However, the discussion is anecdotal and lacks formal citations or references to specific studies or standards, which limits its scientific rigor.

Chapters

Cited Sources

Concurring Sources

  • NIST SP 800-82 Rev.2 — Guidelines for securing industrial control systems, supporting the need for asset visibility and risk management.

Contribution & Novelties

The episode provides a practitioner’s perspective on the often-overlooked challenge of CISO authority in industrial settings. It offers practical advice on bridging IT/OT gaps, emphasizing the need for on-site presence and relationship-building. The discussion on aligning security with capital master plans and communicating in financial terms is particularly valuable for CISOs.

Pour aller plus loin :

  • IT/OT Convergence — Overview of the integration of information and operational technology.
  • Purdue Model — Reference architecture for industrial control systems.
  • NIST SP 800-82 — Guide to Industrial Control Systems Security.

87 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical insights provided. The lower scores in technical depth and reliability indicate the lack of formal citations and the anecdotal nature of the discussion.

Reliability 6/10

💬 No comments were provided for analysis.