Building OT Cybersecurity That Works in the Real World

Building OT Cybersecurity That Works in the Real World

🎙 Dino Busalachi 👥 192 📅 October 1, 2025 ⏱ 37 min 👁 23 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityinterdependence mappingtool rationalizationgovernanceincident response

Summary

In this episode, Dino Busalachi interviews Danielle ‘DJ’ Jablanski about practical approaches to OT cybersecurity. They discuss why OT maturity often stalls, emphasizing the need to focus on competence and capacity before capabilities. Key topics include asset management, segmentation, and access controls as foundational measures. They highlight governance gaps where frameworks exist on paper but are not implemented in practice, citing a DOE OIG report on NIST CSF shortcomings. Interdependence mapping is presented as a critical method to understand system dependencies beyond ‘crown jewels’, including human knowledge and vendor relationships. Operators are identified as first responders, and the importance of safe-state procedures is stressed. The conversation covers vendor and OEM ecosystems, questioning who owns the response plan. They critique threat intelligence’s limitations, advocating for effects-based security over means-based noise. Incident readiness requires plans, practice, and clear ownership. Supply chain fragility and concentration risk in manufacturing are discussed. Finally, they address tool rationalization, measuring ROI, coverage, and usability to avoid overinvestment in point solutions.

163 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners, offering actionable insights on prioritizing OT security efforts. The argumentation is solid, grounded in real-world experience and references to specific reports and frameworks. The discussion on interdependence mapping and the critique of over-reliance on threat intelligence are particularly valuable. However, some claims lack detailed evidence, and the conversation is more conversational than rigorously analytical.

72 words

Title / Content Match

The title accurately reflects the content, which focuses on practical approaches to OT cybersecurity in real-world industrial settings.

Quality & Reliability

7/10

The discussion is grounded in practical experience and references specific reports (e.g., DOE OIG on NIST CSF) and frameworks (NIST 800-82), but lacks detailed citations and relies heavily on anecdotal evidence and personal opinions.

Chapters

Cited Sources

Concurring Sources

External References

Contribution & Novelties

The episode provides a practitioner’s perspective on OT cybersecurity, emphasizing the importance of interdependence mapping and the need to move beyond compliance checklists. It offers a fresh angle on tool rationalization and the limitations of threat intelligence. The discussion on vendor ecosystems and the role of operators as first responders adds practical value.

Pour aller plus loin :

  • NIST SP 800-82 Rev. 3 — Official guide to OT security, referenced in the episode.
  • NIST Cybersecurity Framework — Framework discussed in the context of governance gaps.
  • DOE Office of Inspector General Reports — Source of the report on NIST CSF implementation gaps mentioned in the episode.

105 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded discussion. The slightly lower technical level suggests the content is accessible to a broader audience, while the reliability score reflects the use of practical experience and references.

Reliability 7/10