Archive

All entries

ICS Advisory founder Dan Ricci explains why a list of operational technology (OT) assets is not an asset inventory. Asset inventories must be organized, updated, and physically validated. Only then can this facet of asset management support enterprise-wide risk management and cyber-physical systems protection programs.
Cyber Resilience
Operational Resilience
Operational Technology
Vulnerability Management
Risk Management

From Inventory to Insight: Turning OT Visibility into Concrete Risk Reduction

Dan Ricci
derbyshire.jpg
Cyber Resilience
Industrial
Operational Resilience
Operational Technology
Risk Management
Vulnerability Management

Nexus Podcast: Ric Derbyshire on Living-Off-the-Plant OT Cyberattacks

Michael Mimoso
AJ Eserjose, Regional Director for Operational Technology Information Sharing and Analysis Center (OT-ISAC), writes about how the information shared among members of a hub such as OT-ISAC creates a predictive resilience.  Attack, threat, and risk signals are aggregated from contributions made by different members into comprehensive intelligence that improves overall cyber and operational resilience.
Cyber Resilience
Industrial
Operational Resilience
Operational Technology
Risk Management

How Collective Intelligence Enhances Predictive Resilience

AJ Eserjose
Rapid7 Principal Security Research (IoT) lead Deral Heiland joins the Nexus Podcast to discuss work his team did on how attackers might weaponize cellular-based IoT.  Rapid7 conducted three phases of this research, with the most recent digging into how attackers with access to these systems can abuse them to gain unauthorized access, potentially exfiltrate critical data, or pivot into backend network infrastructure.
Internet of Things
Vulnerability Management
Risk Management
Operational Resilience

Nexus Podcast: Deral Heiland on Weaponizing Cellular-Based IoT

Michael Mimoso
nexus_samir.jpg
Industrial
Cyber Resilience
Operational Resilience
Operational Technology
Risk Management

Nexus Podcast: MITRE on Caldera for OT Adversary Emulation

Michael Mimoso
Former Pfizer global head of automation engineering Jim LaBonty is featured in Episode 2 of Nexus Digest. Jim discusses a recent article he wrote on the interlock between data centers and modern manufacturing facilities. He describes their dependencies and how cybersecurity fits in these relationships.
Vulnerability Management
Risk Management

Nexus Digest: Jim LaBonty on Data Center and Manufacturing Cybersecurity

Former Pfizer global head of automation engineering Jim LaBonty is featured in Episode 2 of Nexus Digest. Jim discusses a recent article he wrote on the…
Michael Mimoso
Tiffany Wilson, the founder of Wilson Inclusive Solutions (WINS), a disability accessibility consulting firm, joins the Nexus Podcast to discuss the proliferation of consumer technology into healthcare infrastructure. This technology—smart speakers that help manage medications or cameras that monitor vulnerable individuals—often handles patient data and safety, and operates in a regulatory void.
Healthcare
Risk Management
Internet of Things

Nexus Podcast: Tiffany Wilson on the Security Crisis of Consumer Tech in Healthcare

Michael Mimoso
nexuspod_joe-slowik.jpeg
Operational Resilience
Operational Technology
Internet of Things
Industrial
Healthcare
Cyber Resilience
Risk Management

Nexus Podcast: Joe Slowik on Securing Exposed Internet-Facing Assets

Michael Mimoso
On this episode of the Nexus Podcast, Health-ISAC VP of Medical Device Cybersecurity Phil Englert discusses the cybersecurity risks introduced by legacy technology in healthcare and how it impacts patient care and safety. He also brought context and insight into the U.S. Food and Drug Administration's (FDA) updated guidance on cybersecurity requirements for medical devices aimed at manufacturers and premarket product submissions.
Healthcare
Cyber Resilience
Vulnerability Management
Risk Management
Technical Debt

Nexus Podcast: Health-ISAC's Phil Englert on Medical Device Cybersecurity

Michael Mimoso
ASL Roma 1 CISO Stefano Scaramuzzino and Deloitte’s Fabio Battelli explain the next evolution of cybersecurity and risk governance at Italy’s largest public health authority: canonical risk. The hospital's HOPE framework is the decision layer for this concept, a governed, explainable, and auditable synthesis of technical signals, operational context, and explicit priority logic that inform remediation and mitigation actions.
Healthcare
Cyber Resilience
Operational Resilience
Risk Management

At ASL Roma 1, Canonical Risk Informs Governance, Remediation Actions

Stefano Scaramuzzino
Fabio Battelli
On this episode of the Nexus Podcast, Rafael Arakelian, the OT/IoT Cybersecurity Manager for Accenture, joins to discuss the inner workings of Operation Grim Beepeer, a 2024 Israeli operation that used booby-trapped pagers and walkie talkies to injure or kill Hezbollah members. Raphael studied the technical, cybersecurity, and supply-chain risks involved in this operation, and shares how those lessons can be applied to operational technology.
Industrial
Cyber Resilience
Operational Technology
Operational Resilience
Risk Management

Nexus Podcast: Raphael Arakelian on Operation Grim Beeper

Michael Mimoso
Adm. Michael S. Rogers, USN (Ret.) joins the Nexus podcast to discuss the Biden administration's National Cybersecurity Strategy, and its themes of cyber resilience and critical infrastructure protection.
Risk Management
Cyber Resilience

Nexus Podcast: Adm. Michael Rogers on the Job of NSA Director

Michael Mimoso
Latest on Nexus Podcast