Your SIs and OEMs Already Have the Access, the Context, and the Knowledge. Now Put It to Work.

Your SIs and OEMs Already Have the Access, the Context, and the Knowledge. Now Put It to Work.

🎙 Dino Busalacchi 👥 192 📅 April 22, 2026 ⏱ 25 min 👁 42 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securitysystem integratorsasset inventoryremote accessmanufacturing

Summary

In this episode of Industrial Cybersecurity Insider, host LuRae Lumpkin interviews Dino Busalacchi, an expert in industrial automation and cybersecurity. They discuss why manufacturers often overlook their system integrators (SIs) and OEMs as valuable cybersecurity resources. Dino argues that IT leaders frequently lack visibility into plant floor operations and may not include OT assets in their cybersecurity strategies. He emphasizes that SIs and OEMs, who already work inside plants, possess the access, context, and knowledge to help secure control systems. The conversation covers the importance of starting with an accurate asset inventory, understanding network communications, and implementing governance measures like change control and auditing for remote access. Dino criticizes the ‘check-the-box’ compliance approach and stresses the need for operationalized security. He advises manufacturers to build strong partnerships with their SIs and OEMs, rather than treating them as transactional vendors, and to leverage their expertise to address resource constraints. The episode concludes with practical advice on budgeting, calculating ROI based on downtime costs, and acting proactively before an incident occurs.

169 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into leveraging existing partnerships for OT security, highlighting a commonly overlooked resource. The argumentation is coherent and grounded in real-world experience, with concrete examples like the WannaCry incident and the dairy company anecdote. However, it relies heavily on anecdotal evidence and personal opinion rather than empirical data or case studies, which limits its scientific rigor. The speaker makes a compelling case for the importance of asset inventory and visibility, but the discussion remains at a high level without delving into specific technical details or best practices.

Scientific Rigor, Source Quality, Title Accuracy

The video does not cite specific sources or provide references to studies, standards, or frameworks. The information is presented as expert opinion based on decades of experience, which adds credibility but lacks verifiability. The title accurately reflects the content, focusing on the untapped potential of SIs and OEMs. The discussion is practical and actionable, but the lack of citations and data weakens its scientific foundation. No comments were provided for analysis.

177 words

Title / Content Match

The title accurately reflects the core message: leveraging existing relationships with system integrators and OEMs for OT cybersecurity. It is engaging and directly aligned with the content.

Quality & Reliability

6/10

The video presents expert opinions and practical advice based on decades of experience in industrial automation and cybersecurity. It lacks formal citations, data, or references to specific studies, but the arguments are coherent and grounded in real-world scenarios. The credibility is moderate, relying on the speaker's authority rather than verifiable evidence.

Key Moments

Contribution & Novelties

The video offers a fresh perspective on OT cybersecurity by emphasizing the untapped potential of existing ecosystem partners (SIs and OEMs). It provides practical steps for manufacturers to leverage these relationships, such as starting with asset inventory and building governance around remote access. The discussion highlights the gap between IT and OT and the need for collaboration.

Pour aller plus loin :

  • NIST Cybersecurity Framework — A widely adopted framework for improving cybersecurity, including for OT environments.
  • IEC 62443 — International standards for industrial automation and control systems security.
  • MITRE ATT&CK for ICS — A knowledge base of adversary tactics and techniques specific to industrial control systems.

107 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher values in information quantity and quality, indicating a solid but not exceptional presentation. The technical level is moderate, suitable for a broad audience, while reliability is adequate given the reliance on expert opinion.

Reliability 6/10