
Hosted by Klaus Mochalski
OT Security Made Simple is about OT security from practice for practice, hosted by Rhebo CEO Klaus Mochalski. The podcast invites experts from the forefront of OT security at energy suppliers, distribution system operators, manufacturing companies and critical infrastructures to share their experiences and best…
61 episodes · publishes fortnightly · latest 2026-06-23 · ~26 min/episode
Rank
#902
Substance
73.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#902 of 6183
Substance
Top 15%
outscores 85% of the index
OT Security Made Simple ranks #902 on The B2B Podcast Index with a substance score of 73.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and originality. Ehrenreich has genuine long-tenure practitioner credentials - 46 years in engineering, 36 in ICS/SCADA, a Siemens background during Stuxnet - but he is now primarily a self-employed trainer and conference speaker rather than an active operator at scale, which limits the depth of current operational insight.
Averaged across 1 recently scored episode, with cited evidence.
The episode contains a handful of genuinely non-obvious arguments - particularly the OT ransomware logic and the OT SOC intervention critique - but large stretches are filled with discursive meandering, repetitive qualifications, and the closing advice ('start with training') is thoroughly generic.
“OT ransomware never happened. Why? Because ransomware is a hostile act where you expect to get money.”
“by the definition of the SOC for it, you allow intervention into the system in order to stop the attack...For industrial control systems you are not allowed to do that.”
The reframing of Colonial Pipeline as a management decision rather than an OT attack, and the argument that professional ransomware actors won't target OT because they know no operator will trust a decryption key for a safety-critical system, are genuinely contrarian positions worth hearing; the rest of the episode recycles standard ICS security discourse.
“the famous, uh, colonial pipeline. Still, many people call it OT cyber attack. And I said no, it was a classic IT ransomware...it was interrupted as a management decision.”
“Can I be confident that, uh, Industrial Control System PLC HMI Control server, which were encrypted, can be returned to a safe operation after conducting the decrypting process using the key that I purchased from the attacker?”
Ehrenreich has genuine long-tenure practitioner credentials - 46 years in engineering, 36 in ICS/SCADA, a Siemens background during Stuxnet - but he is now primarily a self-employed trainer and conference speaker rather than an active operator at scale, which limits the depth of current operational insight.
“I'm active in the field of engineering about 46 years. In the past 36 years I'm involved with industrial control systems, SCADA”
“At that time I was working for Siemens and we got all we got but a major instruction from now on, you need to quickly learn cybersecurity for industrial control systems.”
The transcript names real figures (Langner, Weiss, Peterson), real events (Stuxnet, Colonial Pipeline, Oldsmar), and offers a few concrete procedural details, but almost no hard data, no named vendors, no incident metrics, and anonymised anecdotes ('a major company in my country') where specifics would matter most.
“I heard one major company in my country said we receive 100,000 attacks Ah, per day. And I said no, no, no, you get all kind of uh, pinks and scan.”
“There are about, I believe about 10 vendors who different type of uh, solutions to allow secure, we call it sra Secure Remote Access.”
The host asks reasonable directional questions and occasionally sharpens the frame (distinguishing safety-critical vs. non-critical systems), but largely accepts claims without challenge, lets the guest self-promote without redirection, and closes with the boilerplate 'where do I start?' question rather than probing the more interesting threads opened earlier.
“Would you argue that, uh, it should be still today's best practices to not have remote access on the shop floor in critical infrastructures? Or would you differentiate”
“So what are the professional attackers doing? Uh, when we look at OT infrastructures and uh, what tools are they using if it's not ransomware?”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/ot-security-made-simple" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/ot-security-made-simple/badge.svg" alt="Ranked #78 on The B2B Podcast Index" width="360" height="136" />
</a>Track OT Security Made Simple's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.