The Hidden Reason Most Manufacturing Cybersecurity Programs Fail

The Hidden Reason Most Manufacturing Cybersecurity Programs Fail

🎙 Dino Busalachi 👥 192 📅 December 22, 2025 ⏱ 30 min 👁 43 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securitymanufacturingcybersecurityICSboard communication

Summary

In this episode of Industrial Cybersecurity Insider, host Dino Busalachi interviews cybersecurity veteran Wil Klusovsky, who has 26 years of experience in IT and OT security. They discuss the fundamental gaps between IT security practices and operational technology (OT) realities in manufacturing environments. Key topics include the communication breakdown between CISOs and plant operations, the critical role of system integrators and OEMs often overlooked by IT leaders, and the persistent myth of the ‘air gap’ that leaves facilities vulnerable. Wil emphasizes the importance of speaking to boards in business terms, such as revenue loss and downtime costs, rather than technical jargon. He also highlights the high failure rate of security tools that become ‘shelfware’ due to lack of organizational change management and adoption. The conversation covers challenges like MFA implementation in OT, why patching isn’t always feasible, and the need for asset visibility tools that often miss a significant portion of equipment. They stress that cybersecurity must be a shared responsibility across the organization, not just IT’s problem, and that building a successful OT security program is a continuous journey requiring collaboration with third-party vendors and a deep understanding of plant floor operations.

193 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of this episode lies in its practical, experience-based insights into OT cybersecurity, a field often misunderstood by IT-centric approaches. Wil Klusovsky provides concrete examples, such as the 135% asset visibility discrepancy and the $50,000 investment scenario, to illustrate the importance of aligning security investments with business impact. The argumentation is coherent and persuasive, emphasizing the need for organizational change management, board-level communication in business language, and the inclusion of system integrators and OEMs as essential partners. However, the discussion is largely anecdotal and lacks empirical data or formal case studies, which limits its scientific rigor. The speakers’ expertise lends credibility, but the absence of references to industry frameworks or standards (e.g., NIST, ISA/IEC 62443) is a notable gap.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the episode is an expert opinion discussion without formal citations. The sources cited are limited to LinkedIn profiles and a Linktree, which are not academic or industry-standard references. The title accurately reflects the content, focusing on the systemic reasons why manufacturing cybersecurity programs fail. The discussion touches on real-world challenges but does not provide verifiable data or references to support claims. The lack of citations to standards like ISA/IEC 62443 or NIST SP 800-82 is a weakness for viewers seeking authoritative guidance. The title is appropriate and not misleading.

229 words

Title / Content Match

The title accurately reflects the core theme of the episode, which focuses on the systemic failures in manufacturing cybersecurity programs.

Quality & Reliability

7/10

The discussion is based on 26 years of professional experience in cybersecurity and OT, providing practical insights. However, it is an opinion-based podcast without formal citations or empirical data, limiting its scientific rigor.

Key Moments

Cited Sources

  • Wil Klusovsky on LinkedIn — Guest's professional profile, mentioned as a point of contact.
  • Industrial Cybersecurity Insider on LinkedIn — Podcast's official LinkedIn page, mentioned for further engagement.
  • Dino Busalachi on LinkedIn — Host's professional profile, mentioned for connection.

Concurring Sources

  • ISA/IEC 62443 — International standard for IACS security, aligning with the episode's emphasis on OT-specific security practices.
  • NIST SP 800-82 — Guide to ICS security, supporting the need for specialized OT security approaches.

Dissenting Sources

  • No discordant sources found — The episode does not reference any sources that contradict its claims.

Contribution & Novelties

This episode provides a practitioner’s perspective on the systemic failures in manufacturing cybersecurity, emphasizing the importance of business-aligned communication and the often-overlooked role of system integrators and OEMs. It offers actionable advice for CISOs and IT leaders to improve OT security programs.

Pour aller plus loin :

  • ISA/IEC 62443 — The international standard for industrial automation and control systems security, directly relevant to the discussion on OT security frameworks.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, providing foundational guidance for securing OT environments.
  • CyberX acquisition by Microsoft — Context on the acquisition of CyberX, mentioned in the episode as an example of IT vendors entering the OT space.

112 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the depth of practical insights. The technical level is moderate, indicating accessibility for a broad audience. Overall reliability is strong due to the speaker's experience, though the lack of formal citations slightly reduces the score.

Reliability 7/10

💬 No comments were provided for analysis.