Listen to the full episode.
What this episode examines
In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we look at a uncomfortable shift in industrial cybersecurity: the attacker does not always need deep OT knowledge to create operational impact.
As factories become more software-defined, the attack surface moves beyond PLCs, HMIs and plant networks. Identity, remote access, cloud services, engineering workstations, supplier connections and software deployment pipelines become part of the production risk model.
The episode explores how young, highly organised attackers can use social engineering, credential theft and weak access paths to move from IT compromise toward factory disruption, data exposure or loss of trust in the software loaded into industrial systems and vehicles.
The key lesson is clear: protecting the plant now means protecting the full chain of trust. Identity controls, supplier access governance, OT segmentation, engineering station hardening, change monitoring, CSMS, PSIRT and incident response must work together before the pressure arrives.

