IEC 62443 is considered the global framework for operational technology (OT) cybersecurity, yet in the United States, that’s not necessarily the case. OT security standards and frameworks are very much fragmented in the U.S. for a handful of reasons, including the dominance of the federally created NIST Cybersecurity Framework (CSF), NIST’s competing 800-82 guidance document for industrial control systems (ICS), sector-specific frameworks and standards, and that ISA/IEC 62443 is a proprietary, paid standard. Access to the entire 62443 series is expensive, while NIST frameworks are free and public-domain.
The Operational Technology Cybersecurity Coalition (OTCC) is trying to change that. Tatyana Bolton, the Executive Director of the OTCC, recently joined the Nexus Podcast to discuss a partnership with 62443’s governing body, the International Society of Automation (ISA). Announced Aug. 25, the partnership centers around an intent to collaborate to improve OT cybersecurity across critical infrastructure and encourage recognition of 62443 as the global standard.
The partnership complements a recently published OTCC position paper that calls for the establishment of 62443 as the single OT cybersecurity standard, and to eliminate the current fragmentation. Bolton said one of the biggest barriers that must be overcome is that 62443 is a paid standard.
“That creates a situation where the federal government in the U.S. is hesitant to adopt those standards,” Bolton said.
She added that some agencies such as the Department of War continue to favor creating homegrown standards.
“They do have a very unique network and a very unique responsibility. So, I can understand that. But I do think there's a lot of value in harmonizing our standards,” Bolton said. “We've been talking about harmonizing cybersecurity regulations for years across multiple administrations, and we've not been able to find anywhere where we've actually removed any kind of standard in lieu of an overarching one.”
“The OT space is one where the industry and various countries around the world have all come together to acknowledge 62443 as the baseline standard. And I think it's high time the U .S. gets on board,” Bolton added.
OT cybersecurity is an inflection point. Connectivity continues to create exposures in these once-isolated assets and introducing new risks, while old, unsolved problems persist. Critical infrastructure heavy in OT and cyber-physical assets continue to struggle with legacy technology, an intolerance for downtime that makes updating assets close to impossible, growing demands for remote access and secure data-sharing, and growing attention from threat actors exploiting internet-facing assets that are not properly secured.
"We have provided—not just from OTCC, but also from CISA, from NIST, from obviously ISA—guidelines that most people should be complying with. But unfortunately, most of those are voluntary."
—Tatyana Bolton
“So I would say it’s a tale of two cities, if you will, the haves and have nots,” Bolton said.
Bolton added that regulated industries such as energy and financial services have stronger baseline protections, while other sectors such as water and healthcare, continue to struggle—especially where resources are needed for smaller businesses in those industries.
“I think the maturity across those sectors is unfortunately poor,” Bolton said, citing the recent string of attacks against water systems in the U.S. “The vendor space and the OEMs, I think, have provided a lot of the security controls and tools that we need. The technology is absolutely there. I'd also argue that on the policy side, we know what to do. And we have provided—not just from OTCC, but also from CISA, from NIST, from obviously ISA—guidelines that most people should be complying with. But unfortunately, most of those are voluntary.
"We don't have strict compliance rules across most sectors in the U.S. and so what we have is a patchwork of compliance across these sectors and the one thing we are missing is the resources for some of these state and local entities to pick up these guidelines, run with them, and actually implement the technology and the policies that are necessary.”
MIMOSO 0:15
Alright, welcome back to the Nexus Podcast. Tatiana Bolton is my guest today. She is the executive director of the Operational Technology Cybersecurity Coalition, and I am glad she's here today because the OTCC has made some news recently announcing a partnership with ISA that is intent on improving OT cybersecurity, as well as the recent publication of a position paper advocating for 62443 as the global OT security standard. So very relevant, important stuff to talk about. Before we get going, my usual reminder to subscribe to the podcast. We've had a big year so far, and I can't tell you how much I appreciate everyone for the support and for obviously listening to the podcast. Best way to keep up with the show is to subscribe. You can find us on all of the major platforms, including Apple, Spotify, Audible, iHeart, you name it, we are there. So uh let's get started with today's episode. Hi, Tatiana. Nice to meet you.
BOLTON 1:14
Hi, thanks for having me.
MIMOSO 1:16
Yeah, I've been uh looking forward to this one for a while. Um so before we get into kind of the discussion, I'd I'd love to hear a little bit about how you landed in OT cybersecurity. It's not the most conventional career destination in security for sure.
BOLTON 1:29
What do you mean? It's top for everyone. Critical infrastructure everybody's favorite job. Um so my background is mostly federal government. So I was at uh the Department of Defense, I was at CISA, I then went to the Cyberspace Solarium Commission, uh, and most recently was at Google uh doing cyber policy. But I'll say that throughout the majority of my career, I've touched on ICS security, critical infrastructure security in any number of different ways uh in all of those roles. I think it's incredibly important and I think increasingly recognized as a top issue, both uh in the administration and the Hill. You see more and more folks focusing on it, you see more funding and resourcing going to it uh in the Department of War. So, you know, I think it's it uh it's really a great place to be working right now. I think obviously we still have a lot of work to do, which is obviously what the OTCC does. But um, yeah, that's that's kind of how I landed here, you know, have done a lot of stuff, but uh, you know, it's it's fun to work on issues most critical to national security.
MIMOSO 2:46
So I I'm just curious, what do you what's your characterization of the state of OT security right now? It's obviously getting a lot more attention than seemingly ever before, yet we're still kind of running headfirst in some of the same legacy technology issues, remediation issues seem to be getting in the way of overall protection of critical infrastructure. I uh, you know, what's your elevator pitch on on OT security in 2026?
BOLTON 3:10
So I'd say that it's a tale of like two cities, if you will. It's the haves and have nots. I mean, I I think everyone is fairly familiar with the breakdown, right? There's the regulated funded industries, finance, energy, et cetera, right, that have the um that have the stronger baseline protections. And then you've got basically everybody else. Um, and I think the maturity across those sectors is uh unfortunately poor. I think we are in a position where we are seeing increased attacks. Uh we just had a month, or well, I guess the last couple months, where Iran has targeted our water systems and we've seen the outcomes of that, right? And given it wasn't uh as um as sort of affecting of life and property as it could have been, I think it's still incredibly important for us to take that as a lesson in how bad our security is. I mean, if you look at the ways in which the Iranians were getting in, you could have been a high schooler and could have broken into that network. Some of them, some of the ways the hackers were getting those systems, they were adding passwords. They were adding passwords to the systems, and that's how they were locking out the operators. So, you know, if you ask me how what's the state of our critical infrastructure, I would say it is desperately in need of support.
MIMOSO 4:45
Yeah, it's it's absolutely more of a resources issue than necessarily throwing more technology at the problem at this point, right?
BOLTON 4:54
I mean, the you know, the vendor space and the OEMs, I think, have provided a lot of the security, uh, a lot of the security controls and tools that we need. The technology is absolutely there. I don't I'd also argue that on the policy side, we know what to do. And we have provided uh not just from OTCC, but also from SISA, from NIST, from obviously ISA, um, guidelines, right, that most people should be uh complying with. But unfortunately, most of those, most of those are voluntary, right? We don't have uh strict uh compliance rules across most uh sectors in the US. And so what we have is a patchwork of compliance across these um across these sectors. And the one thing we are missing is the resources for some of these state and local entities to pick up these guidelines, run with them, and actually implement the the technology and the policies that are necessary. Um it feels like the policy could be easier to be, could be easier to uh implement, but it still runs into uh it still runs into resource constraints, especially when if you take a look at um if you take a look at some of the states, their local budget for cyber is zero. And that's one of the things that actually the state and local cyber grant program was trying to address, right? That was a significant pot of money that it granted the states uh over the course of five years to improve their cybersecurity. Um last week at Billington, we actually had a conversation with one of those state CISOs and how they were implementing that program because we're actively trying to encourage the adoption of SLCGP or the reauthorization of SLCGP, because it's up for um uh uh it's about to expire at the end of this week. So in two weeks, SLCGP will expire. Um, and it's run out of money. So we're at a place where uh the the CISO was telling us that you know they're in a position where they either give more service, they they continue to give these services to the state and locals where all a lot of our critical infrastructure sits, or um they they don't, they stop because it's not like those state and locals can actually pick up the pick up the tools and run with them. They, you know, a lot of a lot of tools require maintenance, they require patching, they require um, you know, obviously patching is a separate issue within OT, obviously, but uh they require people who know how to run them. And you know, that's a significant uh significant problem.
MIMOSO 7:39
How how much is the I guess I don't know if fragmentation is the right word, but that's just that line between private and public ownership of critical infrastructure in the US in particular? How much complexity does that add to this overall security discussion?
BOLTON 7:53
Well, I'll give you an example. You know, right now we're working on a uh a recommendation some recommendations around what CISA could put out as a binding operational directive, ABOD, to the federal civilian executive branch agencies to encourage them to do more on OT. And we think that will be very important to do. OTCC is advocating for that. We came out with a statement after the water hack saying this is one of the first and most important things that says it can do uh that's within its authority. But it still will only hit technically 15% or less of critical infrastructure in the country because most of it arguably, well, some say 85%, but I we know that number has been kind of like, you know, sure someone just came up with that in '92.
MIMOSO 8:42
It's a little flaky, yeah.
BOLTON 8:43
A little bit. Yeah, I blame Mark Montgomery for that. Kidding. Love you, Mark. But um the you know, that's that shows you how big of a problem it is, right? The federal government can only direct so much. Um, there is no regulator that will um that can that can uh require the private sector entities to take up some of this, uh, some of these things. There's no one to be able to say, hey, you should do um you should do 62443, right? You should start implementing an international standard that's been developed by over the years, so many years, and so many, um, so many uh experts. Let's use this standard. It exists, you know, we're we're arguing for that, but there's nobody to require it. Uh, and so it is a it's a it's uh it's a bit of a mishmash. Alternatively, in you know, places like uh the UK, they have 18 water systems, right? Compared to our uh, I think the estimate is 151,000, right? And theirs are all kind of directed or owned by the by the government. Um, I'm not saying we should go to a government-owned like system, that's not what I'm saying. Um, but I'm but it does absolutely add complexity, and our scale adds complexity. Um, and so I think you know, we have our work cut out for us. But you know, going back to the 6443 point, that's where I think guidelines, standards that have been developed by industry are really helpful.
MIMOSO 10:21
Such an insane number of water systems when you say it out there.
BOLTON 10:24
I know, I know. Now, I'll make you feel a little better. Apparently, only, you know, again, I'm not a water expert, but like 55,000 of those are the community water systems that you and I think about, right? It's not like trucks, truck stop 47s, you know, like well, it's the ones that are actually it's only there's only 52,000 of the ones that are that are providing water for each individual like city or you know, uh town. So a little less, but still 52,000 is not 18, right? So when you see some of these uh countries like Estonia or the UK or um you know wherever Germany taking uh particular kind of steps to protect their critical infrastructure, um, you know, they have a much different footprint. Uh and I saw that firsthand when I went over to um I was in Israel on a on a DHS uh sponsored uh fellowship, and you kind of see it. They have like one airport, they've got you know one major, one main kind of energy um uh or uh energy plant. They they you know they have a different they have a different kind of threat vector. And so it's a lot easier to kind of promulgate some of these rules. Um Singapore, right? It's like the size of DC. You know, it's a lot different than the entirety of the United States.
MIMOSO 11:52
Right. So let's talk a little bit about the the partnership, the collaboration between ISA and the OTCC. Um just tell me a little bit about what's involved, how it came together, and maybe some of the gaps that you guys are aiming to fill together on this.
BOLTON 12:08
Yeah, well, so you know, we've known ISA for a while. Um, and we participated in their conference in Prague earlier this year, spoke on a panel, uh, and have been having conversations about the ways in which we can basically work together on things where we align. And one of the major, you know, areas where we align is engagement and advocacy around the adoption of 62443 around the world. Um, our our members are strongly supportive of this international standard, and obviously ISA as the sort of creator and the host of uh this standard uh are, I think, see very much eye to eye. And so we kind of bring the policy and the advocacy piece. We're you know, we're very engaged in that area. And ISA has a lot of technical capacity and a lot of um expertise, obviously, around uh the standard and are working to uh continue to educate folks on that. And so we thought it only made sense to to partner and to uh help each other in and improve the baseline standards uh for OT security around the country.
MIMOSO 13:23
I was always under the impression that 62443 was the standard. I mean, is there something getting in the way of that?
BOLTON 13:29
Or it is the standard, but I will say, and obviously we're very much in partnership with ISA, and so you know, very much um applaud all of their work. Uh I will say one of the biggest barriers is that it is a paid standard still, and so creates uh creates a situation where um the federal government in the US is hesitant to adopt those standards. And some agencies, like, you know, I'm not gonna lie, but like DOW is not uh jumping up and down to adopt other people's uh standards. They want to create their own. Um which, you know, they do have very unique, um, sort of a very unique network and a very unique um uh responsibility. So, you know, I can understand that, but I do think there's a lot of value in harmonizing our standards. I mean, we've been talking about, we've been talking about harmonizing cybersecurity regulations for years, right? Like across multiple administrations, and we've not been able to find anywhere where we've actually removed any kind of um any kind of standard in lieu of uh an overarching one. Even Circia, uh, that says it's about to promulgate, right? Uh, or that is about to come into effect, uh, you know, is having struggles because there are still sorts you know upwards of 50 different, upwards of 50 different state and federal uh reporting uh uh regulations. But the OT space is one where the industry, various countries around the world have all come around come together to acknowledge 62443 as the baseline standard. And I think it's high time the US gets on board.
MIMOSO 15:19
Right.
BOLTON 15:21
And uh again, but what is getting in the way is it some of the sector-specific mandates that kind of some of it is that, but I think yeah, I I think more than anything, it's that the United States likes to design their own stuff.
unknown 15:36
Yeah.
BOLTON 15:36
And the United States doesn't like anything that's um, you know, it I think we we have a we have a fair skepticism of European standards, international standards, participating in international standards bodies. I mean, we do participate, of course, but um, you know, as Americans, we we are, you know, first and best. We want to set the standard. But I think in this particular scenario, it is causing friction and creating compliance headaches. It's costing the Americans uh and the critical infrastructure community specifically um money. Uh, I you know, there's uh from our uh from our members, I mean, we see that like you know they have to keep track of not only what is required to match or uh comply with 62443, but they also have to keep track of, you know, what California has design decided is important, or what CISA has uh promulgated that is critical, or you know, or a DOE standard through NURC SIP, right? So it it's it's a sometimes sector specific, but sometimes just you know, um lack of standard adoption that's that's kind of harming the uh 62443.
MIMOSO 16:58
Yeah. But I mean, if this can reduce the compliance burden or make it a little less expensive, I mean I would imagine that's a pretty strong argument in favor.
BOLTON 17:07
I I mean when I talk to people one-on-one, I don't, and and this is including policymakers at the various, you know, agencies that are relevant to this discussion, I think nobody is opposed to streamlining regulations. I think when you start talking details, you know, there's there's questions about, well, what about NIST? And you know, how does NIST play into that? What about um 853? What about um what about everything else? And I think our point is that we um we don't uh we don't disagree that like um NIST 882, which is the um OT standard, is irrelevant here. We're just saying that if there's an international standard that's been adopted by you know 80% of the community, maybe we should just go with that, right? And it's been developed by experts for you know for many, many years. And is, and if we if you don't like the standard, let's work with it, right? Let's let's engage with the standard, let's work through the standard that through the uh the body to um to make amendments. That's happening right now. I know a number of OEMs and and countries are are working through that process to add various um various pieces uh to the standard to make sure that it is uh relevant to sort of today's landscape. But that's the right way to do it rather than create either creating new standards or not adopting the standard at all. Um and so I think that, you know, I think even NIST would agree that it is much better to have one overarching standard rather than many.
MIMOSO 18:49
Yeah. So as part of the partnership, is there kind of like a day-to-day technical collaboration, or is it strictly kind of on the on the standards development and and implementation side?
BOLTON 19:02
Well, it's both. So we we absolutely helped uh our members participate in the standards development um uh conversations, uh, but we participate in each other's uh meetings, so it's not daily, but it's weekly or bi-weekly. Um and so we we share information and we discuss strategy and things like that. And so it's a um it's a it's a it's a robust partnership that we are eager to develop as the years go on.
MIMOSO 19:33
And with respect to 62443 specifically, uh I mean, there's so much connectivity that's been introduced uh to OT to cyber physical systems. How good of a job is the standard done in keeping up with just how rapidly modernized these environments are becoming?
BOLTON 19:55
Well, I think any standard obviously has some lag time from the you know the um from the uh creation of a new technology and uh AI at this point is moving so quickly. I you know, I think uh we're gonna see a number of iterations uh and changes as you know the months and years go on to make sure that 62443 adapts that. But here's what I'll say, and this is gonna come out in um in a new in a new paper that we're working on around uh AI and OT specifically. Uh the biggest the biggest um and most important work that needs to be done in OT security is still not necessarily that kind of um you know most advanced uh crazy technical work. It's still the fundamentals, right? And so we I think this the standard does a great job of getting everybody to a level where we are preventing some of these attacks that are coming in that are that are targeting the least um least protected networks, right? We should not have any unprotected, un uh not password protected networks. We should not be um we should not be sending unencrypted data. Um we should acknowledge that that is a that is uh a threat factor for us. We you know, there's uh microsegmentation is possible today and should be done. Um, you know, so I think I think what we need to focus on getting to ideally a level two or three, right, of the 62443 standard for across all of our sectors before we even start to, you know, it's a crawl, walk, run. We're we're we're barely crawling. We're barely crawling in most of our sectors. So I think while it's very important for the standards development side to continue to have those conversations about how AI um how AI uh changes what the standard looks like in the years to come. Right now it is more than enough work for anybody who is running a you know a SCADA system to look at that standard and to get to get compliant with it.
MIMOSO 22:25
It's a great point you make about the the fundamentals too and and you know it's not just authentication and and secure access but so many devices, so many assets are internet facing without this basic protection, which is so contrary to you know what security people understand, but you know an operations person might has a completely different view of this and it seems like that that kind of clash is still not maybe not a clash, but that kind of dichotomy still exists out there that yeah I 100% agree.
BOLTON 22:57
I mean um and and we have to be in the policymaking community I think we have to be empathetic to the real world experience of the people that are running these systems. If you are not a cybersecurity expert and your number one priority is making sure the water continues to run to X city, right? Peoria, Illinois, you are focused entirely on that. And there's plenty enough issues in your day-to-day life to worry about without having to start thinking about like cyber and you know how do I like what's cut what's coming with AI like what's what what's you know China or Iran going to do. That's not what they're thinking about.
SPEAKER_02 23:36
Right.
BOLTON 23:36
So you know I think it's it's important that we take into account who is implementing these recommendations make sure that we keep them clear that we acknowledge realities that we don't put out and you know I am a I'm a big fan of CISA I worked at CISA very soft very big soft spot in my heart for them but I think we need to move away from recommendations around patching better, patching faster prioritizing patching quite honestly in the OT environment and I think this is one of the things that we're discussing right now in this AI working group as that I was talking about is patching the answer in OT? Or are we moving to a place where you know we need to um we need to defend defend a network that we have to assume is breached and we have to go to microsegmentation and access control, right? All of those uh all of the like identity management, all of the things that we know need to happen in so that we're not just depending on a on a you know on a firewall on the outside of these networks. And you know it's um yeah I think it's not wrong for the operators to think about the availability of of these systems as their top priority. That's not wrong. And so the policymakers really need to take that into account. And this is where I think it's really important that we focus on OT and we make policy for OT specifically that it isn't just a subset of whatever idea we've come up with for IT because those are such like such different systems with with different incentives and run by different people that you know it just it doesn't they it not sometimes the policy just doesn't translate.
MIMOSO 25:27
Yeah. Is microsegmentation and secure access the all those things that you mentioned is that the quicker path to resilience whatever that means as opposed to kind of like this mind-numbing discussion over patching that never ends and never speaks I absolutely think so I absolutely think so I think we're at this point I think we're past patching uh if let me let me put it this way um the the pat the AI uh discovery tools have gotten so good that they're coming up with um new vulnerabilities to the tune of of you know tens of thousands we have not we we have not seen a similar increase in the engineers required to build the patches for those vulnerabilities and 70% of OT systems can't be patched and on top of that even when you do have a patch only 10% of each individual patch is actually implemented.
BOLTON 26:32
So you tell me does that make a lot of sense if we are if we have too many pet if we have too many vulnerabilities to to fix and not enough people to create fixes and people aren't even implementing the fixes on only 30% of system or 30% of the systems why are we even focusing on this anymore?
MIMOSO 26:53
No it's not working.
BOLTON 26:55
It's not working so it's it's microsegmentation it's assuming compromise it's identity management it's you know it like the least concept of least privilege has been around for a while zero trust is is critical and again it's not a catchphrase it's some of these controls that are important. It's the way in which you think about securing those networks and I will tell you in zero trust like patching is not number one and I think that's why it's really cut on and um I think we need to make sure that we figure out ways in which we can make zero trust and all those controls work for the work for OT environments and get all get enough resourcing to ensure that our critical infrastructure entities adopt them.
MIMOSO 27:40
Uh one more question on the partnership just how much is in there in terms of or how much work do you expect to be done on workforce training for example um and and getting you know OT cyber experience or is it a matter of kind of introducing it bringing more engineers into these discussions more asset operators is that happening um how is it happening?
BOLTON 28:01
I mean I think yeah I think it's both um we actually SANS is a member of the OTCC so we certainly talk about uh training and um and workforce development a lot ISA is also very um is is very uh supportive of workforce development um I I think you can't create new controls or uh learn new technologies without training people are people are who actually implements all this stuff so if you're not training them and you're not thinking about your workforce you've you've failed from day one. And then um you know I think we will continue we'll continue to kind of um see what that partnership looks like in terms of what we can do together um because again we're in the early days but uh but you know workforce is absolutely uh top of mind yeah um all right so before we wrap up I I wanted to ask you about kind of the the growing focus of the Department of War Department of Defense on OT um just your reaction in terms of what's driving that renewed focus and you know obviously I imagine it's a positive all around uh absolutely I mean it was a huge boon that Kirsten uh uh Kirsten Davies came from Siemens and from an OT background and I think that has uh created that has created a uh a turnaround within within the department around how they think about OT and I think they've acknowledged that OT has been forgotten for a little bit too long. I think after doing some assessments and and some um some reviews across the various um uh COCOMs and services I think they've realized the bases have a significant OT um you know uh footprint and not just on the bases but also just outside the bases and for things like military mobility OT is critical you have to have the rail lines and the roads and the airports functioning and the water to make sure that your HVAC is working and your um and your hospitals are running so that the DOD can continue to perform its functions. And so you know I uh I applaud their focus uh there they have a um defense critical infrastructure working group that's been stood up and is about to release a report which we're eagerly awaiting we had briefed them earlier this year um and then they also have uh a number of uh a number of leaders within the department including John Garska and Darryl Hagley and Rich Mason who are um very much uh uh advocating for additional resources for the DoD to really focus on this issue um as much as they focus on um mission assurance for the weapon systems uh because these are the fundamental building blocks of our weapon systems at this point, right? Um you every weapon that's up in the sky has a ground base station and guess what all of those run on electricity and sometimes water and so you know we need those and we need the we need our warfighters to be as defended as possible and so um I really I really applaud all of their effort I will say one thing which is that the CR and uh budget problems uh coming from Congress have a uh direct impact on our ability to conduct and improve our ability to improve OT security and the amount of resourcing that's going towards that because in 2027 there was supposed to be a plus up for various offices that were handling OT security and unfortunately because of the CR that money will be delayed because in a CR you only have what you had last year and just being a butter spread across the year. So you know they're not gonna get they're not gonna see that money until at least December I hope that in uh December the Congress passes our a full budget. I am skeptical so I'm worried that we're not gonna even see that plus up until March or possibly later in the year. So um I think you know it's a it's I'm hoping that um we can get our congressional leaders to get on the same page and and and fund DOW so that we can it's a bad place and a bad time to be reactive right now. Exactly.
MIMOSO 32:31
Yeah um so just a final question uh do you anticipate or even recommend any structural changes to kind of get the respective services to put more emphasis on OT security OT protection?
BOLTON 32:43
Well so I you you definitely see uh army moving forward so Brandon Pugh who's the Army PCA has really leaned into OT security and I love to see that uh Brandon actually Brandon uh and I used to work together at R Street um and uh I know that he will will do a great job of of advocating and elevating OT security critical infrastructure within the Army I think the other services uh you know are probably uh not quite as far ahead as the army uh but you know I think we can we continue to educate and discuss and and and advocate for them to um keep moving forward.
MIMOSO 33:25
All right well thank you so much for coming on the podcast I think this was a great discussion we certainly covered a lot so yeah absolutely thanks for having me all righty have a great day you too thanks so much
Michael Mimoso is Director of Influencer Marketing at Claroty and Editorial Director of Nexus.