Is Your IIoT Strategy Creating More Security Risks?

Is Your IIoT Strategy Creating More Security Risks?

🎙 Craig Duckworth and Dino Busaki 👥 192 📅 June 9, 2026 ⏱ 22 min 👁 49 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityIIoTasset visibilityCVEprocess integrity

Summary

In this episode of Industrial Cybersecurity Insider, hosts Craig Duckworth and Dino Bousaki discuss the often-overlooked security risks posed by IIoT devices and other unmanaged assets in industrial control systems. They argue that while many organizations deploy OT intrusion detection systems to gain asset inventory, they frequently focus only on core control-layer assets like PLCs, missing drives, robots, HMIs, and other connected devices. The hosts emphasize that the air-gap assumption is a myth, as even supposedly isolated machines are often connected via remote access or third-party devices. They highlight how PLCs can act as gateways, hiding downstream devices from detection. They also discuss the gap between asset inventory and actual CVE exposure, especially in multi-vendor plants. The conversation covers how routine IT security scans can disrupt production, causing unplanned downtime, and draws parallels between predictive maintenance and digital anomaly detection. They stress the importance of process integrity and the need for OT teams to understand and leverage security tools to avoid shelfware and alert fatigue. Finally, they advise organizations to choose partners who understand both automation and cybersecurity, and to build relationships with engineering and OEM teams to integrate security by design.

192 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical focus on a real gap in OT security: the lack of visibility into IIoT and other non-core assets. The hosts provide a clear argument that asset inventory alone is insufficient and that organizations must extend monitoring to all connected devices. They support their points with relatable examples, such as technicians plugging in laptops, third-party cellular devices, and the impact of IT scans on production. The argumentation is coherent and builds logically from the problem of hidden assets to the consequences of unplanned downtime and the need for a holistic approach. However, the discussion is largely anecdotal and lacks quantitative evidence or references to industry reports, which would strengthen the argument. The hosts also promote their own services, which introduces a potential bias, but the core message remains valuable for practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the hosts are experienced professionals, but they do not cite specific sources, standards, or studies. The quality of sources is therefore limited to their own expertise and anecdotal evidence. The title accurately reflects the content, which focuses on the security risks of IIoT strategies. The discussion is internally consistent and aligns with common knowledge in the field, but the lack of citations reduces the overall rigor. No comments were provided, so no analysis of public reception is possible.

237 words

Title / Content Match

The title accurately reflects the content, which focuses on how IIoT devices and other unmanaged assets create security blind spots in OT environments.

Quality & Reliability

7/10

The hosts are experienced OT security practitioners, and the discussion is grounded in practical scenarios. However, the episode is largely anecdotal and lacks concrete data or references to specific studies, standards, or incidents. The claims about air-gap myths and visibility gaps are plausible and align with common industry knowledge, but the lack of citations and the promotional tone for their services reduce the overall reliability.

Key Moments

Contribution & Novelties

The episode provides a practical perspective on the often-neglected IIoT security blind spots, emphasizing that asset inventory is not equivalent to risk management. It draws an analogy between predictive maintenance and digital anomaly detection, which is a useful framework for OT teams. The discussion on PLC gateways hiding assets is particularly insightful. However, the content is not groundbreaking and aligns with existing industry knowledge.

Pour aller plus loin :

  • IEC 62443 — International standards for industrial automation and control systems security, relevant to the discussed security practices.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, providing foundational guidance.
  • MITRE ATT&CK for ICS — Knowledge base of adversary tactics and techniques specific to ICS, useful for understanding threats.

120 words

Radar Profile

The radar profile shows a balanced but moderate performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical insights provided. The lower score in technical depth indicates that the content is accessible but not highly technical, and the overall reliability is moderate due to the lack of citations.

Reliability 7/10