
Security Breach · 2026-06-24 · 31 min
Key moments - from our scoring
Substance score
38 / 100
Five dimensions, 20 points each
Manufacturing remains the most targeted industry for ransomware and IP theft, facing a complex threat landscape where attackers combine encryption, data theft, and DDoS attacks simultaneously. Nick Lantu breaks down two critical pain points: supply chain security and ransomware attacks, both rooted in the false belief that smaller manufacturers are too insignificant to target. The conversation covers how larger manufacturers are conducting supply chain audits while smaller players increasingly adopt managed detection and response (MDR) and managed extended detection and response (XDR) services to compensate for budget and expertise constraints. Cyber Proof's threat-led approach starts with identifying which nation states, cybercriminals, and campaigns most likely target your organization, then maps those threats to the MITRE ATT&CK framework to prioritize defensive actions. For ransomware preparedness, Lantu emphasizes incident response planning, network segregation between IT and OT systems, continuous monitoring, offline backups, and employee training. AI adoption is accelerating as a force multiplier for detection at machine speeds, though governance and data quality remain critical considerations when deploying these tools.
Rather than trying to procure a full stack of expensive tools, small manufacturers should prioritize adopting managed services like MDR or XDR, which provide external talent, technology, and processes for protecting complex OT environments without major capital investment.
It depends on preparation: if you have strong backups and failover systems, you may avoid payment; if not, you're at the mercy of the adversary. The best mitigation is having comprehensive incident response plans, regularly scheduled offline backups, and network segregation in place before an attack occurs.
Request audit and dashboard capabilities from your provider that show your actual security posture, what needs to be done, and what is being done - allowing a gap analysis rather than trusting implicitly that they're optimizing for your security rather than their bottom line.
It starts by identifying the specific nation states, criminal campaigns, and active threats most likely to target organizations like yours, then works backward to determine required defenses, visibility, detection logic, and compensating controls mapped to the MITRE ATT&CK framework.
AI-driven detection tools that identify anomalies and behavior changes at machine speeds, combined with threat intelligence to understand who is targeting you and what vulnerabilities you have, provide the best entry point for manufacturing environments lacking resources.
Our reviewer’s read on each dimension, with quotes from the episode.
A handful of non-trivial points appear - simultaneous encrypt/steal/DDoS attack chains, machine-speed attack democratisation beyond nation states, and employee IP leakage into public AI tools - but they're buried under repetitive generic advice (backups, segmentation, training) and heavy verbal filler that pads the runtime.
Now they're encrypting, they're stealing the Data, they're launching DDoS attacks all simultaneously
maybe 10% of the OT networks are being continuously monitored
The episode recycles well-worn frameworks - zero trust, defense in depth, MDR/MSSP adoption, incident response basics - with no contrarian or first-principles arguments. Even the 'make it painful enough where they pack up and go' framing is a cybersecurity cliché.
You want to make it painful enough where they pack up and go, this isn't worth it
you've got to have a really fleshed out incident, uh, response plan, right. To jump into action as soon as something happens
Nick Landu is a legitimate practitioner at CyberProof (a real managed-SOC firm), and his threat-led methodology tied to Mitre ATT&CK shows genuine operational grounding, but his answers are heavily hedged and generic, and a significant portion of the episode functions as a CyberProof sales pitch rather than practitioner insight.
we tie that back to the ttps, we marry that up to the, to the Mitre, ATT and CK framework and we're able to show what needs to be done from a prioritization standpoint
we can actually put up a dashboard and show you, hey, you know, here's, here's what they're doing. This is your security, you know, this is your actual security posture. Here's what needs to be done, and this is what's being done
The episode almost entirely avoids concrete data: the one quantitative claim about OT monitoring is immediately disclaimed as unverified hearsay, industry-targeting rank is hedged with 'I think,' and no named breach cases, ransomware dollar figures, or customer examples are provided.
I don't even know what the exact number is, uh, but what I've heard is that, you know, there's maybe 10% of the OT networks are being continuously monitored
manufacturing is the most targeted industry for I think, three or four years running right now
The host poses a few legitimately interesting questions - the pay-or-not-pay ransomware dilemma, the prioritisation of tools vs. talent - but consistently accepts non-answers without follow-up, prefixes his own questions with 'absolutely,' and lets the guest deliver an extended company pitch unchallenged.
Do you pay that ransom? Do you try, do you hold off on it? What, what has been your experience in trying to advise people in those types of situations?
No, couldn't agree more. I mean there's a lot of challenges out there
Computed from the transcript - who did the talking, and the words that came up most.
Send us Fan Mail Perhaps you’re familiar with the phrase, “ignorance is bliss.” It was first written by English poet Thomas Gray in 1742. He was reflecting on the carefree aspect of childhood, and how, "In knowing nothing, life is most delightful." Well, I have to admit, he’s got a point. Not recognizing or dealing with problems does eliminate them from your day-to-day. Unfortunately, that doesn’t mean they fail to exist. The reality is that choosing to remain ignorant about ongoing problems is far from delightful, especially for all those who continue to operate with their heads above sand level and beneath the clouds. Our guest for today’s episode, CyberProof’s Nick Lantuh , illustrates this pretty plainly when discussing two of industrial cybersecurity’s biggest pain points - supply chain security and the surge in ransomware attacks. Both seem to share the same underlying causality - industrial organizations simply think they’re too small or too unimportant to be attacked - something that is repeatedly, and painfully, being realized as ignorant, and far from blissful. Listen as Nick and I discuss: The surge in foreign threat actors.
Transcribed and scored by The B2B Podcast Index.
Speaker A: While connected technology is essential for unlocking new efficiencies on the production floor, it's also presented hackers with new opportunities to seal valuable IP and data. To support OT professionals in their battle with cybercriminals, we launched the Security Breach Podcast. In each of our over 100 episodes, we've brought in cybersecurity specialists to provide valuable insights and break down critical topics. As a go to podcast for our listeners, we want to help you align your brand with our expertise. By sponsoring our podcast, your brand will build trust and your message will stand out to an audience searching for tools to assist their cybersecurity efforts. Secure your share in this rapidly growing segment by sponsoring Security Breach. Contact us today to learn more. Hi, I'm Jeff Reinke, editorial director of manufacturing.net and manufacturing business technology. Welcome to Security Breach. Um, perhaps you're familiar with the phrase ignorance is bliss. It was first written by English poet Thomas Gray in 1742. The poet was reflecting on the carefree aspect of childhood and how in Knowing nothing, life is most delightful. Well, have to admit, he does have a point. Not recognizing or dealing with problems does eliminate them from your day to day. Unfortunately, that doesn't mean they fail to exist. The reality is that choosing to remain ignorant about ongoing problems is far from delightful, especially for all of those who have to continue to operate with their heads above sand level and beneath the clouds. Our guest for today's episode, Cyber Proust, Nick Lantu, illustrates this pretty plainly when discussing two of industrial cybersecurity's biggest pain points, supply chain security and the surge in ransomware attacks. Both seem to share the same underlying causality. Industrial organizations simply think they're too small or too unimportant to be attacked, something that is repeatedly and painfully being realized as ignorant and far from blissful. Nick, thanks for taking the time to join us today and welcome to Security Breach. Jumping right into it in here, we had a really interesting conversation out at rsa. One of the things that you kind of talked a lot about, you made some interesting comments about some of the threats from China. I think even made a comment about Russia along the lines of if the Russians want in, they're going to get in. And it just kind of gets me thinking about the threat landscape in total right now. There's a lot of different variables, a lot of different things going on. But but when we look at trying to prioritize things, do you put some of these foreign actors or some of these state sponsored actors at the top of the threat list right now or what do you see there going on?
Speaker B: Well, I think you always have to be cognizant of the nation states. Obviously, um, you know, there's reasons for them to be looking at our manufacturing capabilities. Uh, but then there's also, you know, just criminal activities that are happening. Right. From obviously a ransomware standpoint that are just as important. I would say that, uh, organizations need to protect themselves against.
Speaker A: Absolutely. I think one of the areas right now with manufacturing that's getting much more priority in terms of things that we're trying to defend against are the supply chains in particular. We see stuff going on, obviously, before it was Ukraine, now it's Iran. It's always been issues with North Korea and China. Are supply chains a bigger priority right now? Or what are some of the bigger threats that you're seeing specific to that particular area?
Speaker B: Um, you know, from, from a supply chain standpoint, obviously for us, um, you know, and, you know, defending manufacturing organizations is, you know, the attackers are really going after now the, the smaller, less secure suppliers in those chains. And so I think that that's one of the things that, you know, need to, you know, need to be. Needs to be recognized. Uh, and, you know, there was a huge increase in 2025 of, you know, attacks going after smaller, less secure supply chain, you know, gains. Uh, and, you know, in addition to that, obviously there's the issue of, uh, the software supply chain, uh, in the manufacturing environment, a lot of code is, uh, is open source. Um, so, you know, some of that source code is, uh, you know, you know, very, uh, uh, fraught with vulnerabilities. Uh, and so there's a lot of issues around that that need to obviously be addressed and thought through when you're implementing it.
Speaker A: Absolutely. So what's the typical dynamic there? What are you seeing? Is it more of the larger manufacturers trying to reach out and educate some of their smaller suppliers? Do the suppliers need to take more of that responsibility on themselves? Or what have you seen in terms of that dynamic, in terms of rate trying to work together? Because it is so interrelated right now.
Speaker B: Yeah, it's actually both. You know, I think, you know, there's certainly, you know, some of the larger suppliers are reaching down into their supply chain, um, you know, conducting audits, you know, from a, uh, you know, defensive readiness standpoint. But also these smaller players, these smaller manufacturers obviously don't have the budgets, um, you know, to go and do this properly. But I think there is definitely a movement towards, uh, the smaller players adopting, uh, you know, MDR service and MSSP like services, uh, you know, to bring them in to be able to provide the talent and the, you know, the know how of uh, how to protect them a little bit better than what they currently are.
Speaker A: Yeah, we know that both there's issues in terms of investment levels and the different tools. There's also issues in terms of manpower and expertise. If you had to categorize them, what do you think is the bigger issue right now or what should maybe take priorities for some of these small to medium sized manufacturers? Is it getting the tools, is it getting the folks that understand it better what the are, where should they maybe put uh, things first?
Speaker B: Yeah, from the smaller side, I mean it's hard for them to procure a full stack of tools. Right. That's a very expensive uh, undertaking and it's hard to attract the type of talent that is needed. So what we're seeing is that there's certainly a movement towards um, acquiring managed services and managed detection and response and XDR services from the outside, from organizations that have the capability to lend both the people, the technology, the procedures, the processes, um, on how to protect those environments. And they're complex environments, they're certainly not easy environments to protect.
Speaker A: Well, is this a place where AI comes in? I mean we talk about artificial intelligence and cybersecurity all the time, but is this a place where maybe we see the adoption levels pick up or the pace of adoption pick up a little bit, that it could be a solution for some of these folks who are struggling in terms of investment, manpower, expertise?
Speaker B: Uh, yeah, look, I think that the AI adoption is certainly coming. It's being used uh, by the adversaries and to counterbalance that, to be able to respond at machine speeds. Then there's certainly a need for uh, AI driven defenses and that part of the market is um, maturing rapidly right now. Uh, and there's a lot of great uh, players out there that are, that are augmenting their existing solutions with AI based capabilities. But yeah, I do believe that there is a place for um, AI defenses. Uh, it's rapidly, rapidly, uh, evolving here, uh, as we speak.
Speaker A: Absolutely. And again, it seems like the struggle in manufacturing is always where do we start? Where's that jumping off point from your perspective, what is the best place AI can maybe jump in there? Is it helping with some of these shrinking response times? Is it an asset inventory? Is it just becoming more aware of all your endpoints? If they were going to implement it to get started? Where do you think is a good place to go?
Speaker B: Yeah, I think part of it is kind of deploying into that um, AI driven detection tool sets and identifying anomalies and, and doing it um, in machine behaviors right at machine speeds. I think that's really important. Um, and I think that combining that with more of a threat intelligence led defensive posture where it's more proactive, where you're doing things more uh, in a proactive nature to say, okay, who are the threats that are targeting us and you know, what are the tactics, techniques and procedures that they're being, that they're using and what vulnerabilities do we have in our environment and our asset base that we need to protect? So you know, I think that you know, AI being used in that, you know, more machine speed type of environment and marrying that together with a, uh, with a defense, you know, threat defense led, you know, kind of posture is where the industry needs to go. But you know, there's also um, you know, there's also a lot of uh, uh, issues, uh, you know, from a governance standpoint and from a usage policy standpoint when you start, you know, deploying AI within your environment that you know, organizations need to be cognizant of. And you know, so I think that there's, there's a, uh, you know, needs to be a, an eyeball on that. Um, but also I think, you know, you combine that, that AI driven tool set from a detection standpoint, an anomaly, uh, identification standpoint, um, you know, you know, with you know, data loss prevention tools and others, then you know, I think that you start to have a good foundational base of how to protect those environments a little bit better.
Speaker A: Yeah, let's talk about some of those pitfalls a little bit. You know, you've worked with a number of manufacturers and just companies overall who I'm sure I'm trying to get on board with AI and maybe, maybe go too fast, maybe they're not going too slow. But there's definitely areas where that pace can be an issue. The way that it's implemented, the way it's introduced to employees can be a problem, problematic. What have you seen as maybe some of the biggest issues when it comes to implement AI where folks have fallen down a little bit or we can learn from it?
Speaker B: Well, I think we're in the beginning stages of those implementations and so right now there's a lot of the big players in the space, uh, the platform players, the tool set providers, um, are coming out with really solid uh, AI strategies and how to blend that together with their existing stack of solutions. Um, and I think that Right now it's relying on those large players, um, you know, and the tool providers, uh, you know, for that AI enablement. Um, so I think that, you know, there's, there's a lot of great solutions that are out there and it's coming at it from a lot of different angles. It's coming at it from the detection and response side. It's coming at it from, you know, the, the threat hunt side is coming at it from, you know, numerous angles, the vulnerability side. So, um, you know, it's being, it's being adopted and used by these, you know, by the vendors that are being deployed in these environments as we speak. So it's not so much that, you know, the manufacturing base is going to have to stand up and say, hey, you know, what specific AI tools am I going to have? It's, you know, it's being incorporated into the way defenders are, you know, and vendors and product providers are doing it today.
Speaker A: No, makes sense. And I mean, every, every environment's a little bit different. Every enterprise is a little bit unique. So there's, there's really trying to figure out that sort of that magic formula that works for everyone involved. And a lot of that, as you've alluded to a couple of times, it comes back to what you're trying to defend and who you're defending against. When you look at those two dynamics here, what have you seen as some of the biggest evolutions over time in terms of the threat landscape? Has it just been the speed? Have you seen changes in tactics or attackers or what have been some of the biggest things that folks have had to adjust to?
Speaker B: Yeah, I mean, it's quite a bit. Right. I mean, I think that, uh, as you know. Right, manufacturing is the most targeted industry for I think, three or four years running right now. And it's really focusing in on the fact that that environment is really dealing with an IT and an OT environment, uh, and they're blended together now. And so the whole idea of the risks that manufacturers are now facing, I would say probably ransomware and operational disruption are probably top of mind, uh, on everyone's thoughts. And obviously the adversaries are targeting downtime, um, especially large environments where, you know, every hour is millions of dollars of lost productivity. But they're also advancing how they're doing this. Right. It's not a simple encrypt environment anymore. Now they're encrypting, they're stealing the Data, they're launching DDoS attacks all simultaneously. The nation states that we talked about earlier are obviously Looking for IP related, uh, proprietary information processes, blueprints. Certain industries like aerospace and semiconductor are especially under duress right now. Um, I think that this whole convergence of the IT and OT environment, where you've got legacy systems and legacy PLCs that are lacking encryption and security and MFA, it's just difficult to patch in those environments. And so, you know, uh, there's a constant overhang of how do we secure both of those types of environments. And now that we've opened up the OT side to the Internet, um, it becomes really difficult to go ahead and protect those environments. And you blend that together with a lot of the AI driven phishing and social engineering attacks that are coming at these organizations. Um, you know, it's, it's very difficult. You know, it's a, it's a difficult environment.
Speaker A: No, absolutely. I mean, you laid out all, all the challenges there pretty clearly. And I think some of the bigger ones, especially the patching, finding time to figure out when to do that with all the older technology that's in place and that kind of leads to, you know, you also mentioned ransomware. It's, it's manufacturing is just a prime target and it continues to escalate in terms of the much, that's, how much that's being paid out. So let me throw kind of a. And there's no right answer to this. I understand it depends on a lot of variables, but just generally speaking, when a manufacturer is facing a ransomware attack and they're giving that demand, what's your initial gut feeling or advice? Do you pay that ransom? Do you try, do you hold off on it? What, what has been your experience in trying to advise people in those types of situations?
Speaker B: You know, it's difficult, right? I mean, as much as everybody says, hey, don't pay it, right, sometimes you have to. And uh, you know, there's countless cases of that happening. Um, you know, obviously if you have great backups, if you've got, you know, failover systems, that's um, fantastic. If you're prepared that way. Um, and if you're not, then you're at the mercy of the adversary.
Speaker A: Yeah, absolutely. It feels like some of the best responses to these, whether you're paying or not paying is going to depend on the response plans. And I think that's where manufacturers are still lagging. They've gotten so much better really since coolant pipeline in terms of detection and inventory and all of that. But the response is still in a tough spot. Talking to this group right now, if they're taking those initial steps in putting together those response plans. What advice might m you offer there?
Speaker B: Well, I mean, I think, you know, as you said, right, you know, you got to have great backups. Um, you know, you've got to have a really fleshed out incident, uh, response plan, right. To jump into action as soon as something happens. Uh, and it's really about speed. Uh, it's speed and comprehensiveness of what you've backed up and what you have as failovers in terms of, uh, you know, systems to keep those lines running because it's a, you know, again, it, you know, there's a lot of legacy systems out there. There's, you know, there's a ton of vulnerabilities, there's a lack of visibility in those environments, typically. Um, and you know, what, what you really need to do from a mitigation standpoint, you know, is to have a, you know, a continuous monitoring environment up, right. To detect anomalies on that plant four to be able to see what's going on. You gotta have network segregation, right. To separate out those OT and IT systems, right. To prevent lateral movements. Um, you know, you have to have the backups that are, you know, on a regularly, you know, scheduled timeline being backed up and offlined, uh, and so that you can recover properly without having to go pay. Um, and in many cases it comes down to, you know, lack of employee training. Um, so, you know, I think that there needs to be, you know, a steady drumbeat of training, right, against, you know, phishing attacks and against, you know, being able to, you know, to, uh, mitigate, uh, uh, you know, these types of avenues into the organization. Yeah.
Speaker A: You know, it's interesting the more we talk about some of these super complex problems and challenges out there, the solutions can be very basic at times. A lot of blocking and tackling, as I like to say. So it's interesting to hear that repeat repeatedly talking about backups and training people and, and things of that nature.
Speaker B: So.
Speaker A: So, Nick, maybe you can talk to us too a little bit about Cyber Proof. Your company that you work with there. Um, what are they about? What are some of the things that they offer? The industrial sector?
Speaker B: Yeah. So, you know, we offer a full host of, uh, managed services, uh, in the environment. So everything from, you know, manage detection and response to managed xdr, um, to threat hunting and detection engineering, um, and, you know, just a full host of, you know, threat intelligence services, etc. And we do it all with a threat led environment. So, you know, we, we start with the threat and we look at the threats that are most impactful to an organization. And then we back into what needs to be done from a defensive standpoint. So you know, we do a really good job of correlating together, you know, the attackers, the active campaigns that are running against organizations that look and smell and feel like you do. And then we tie that together with all of the malware being used, the CVEs associated with it, the exposed assets, the identities in your environment attached to those assets. And then we tie that back to the ttps, we marry that up to the, to the Mitre, ATT and CK framework and we're able to show what needs to be done from a prioritization standpoint in terms of visibility, in terms of detection logic, in terms of, you know, compensating controls and configurations in uh, order to best defend your organization against the threats that are most likely targeting you and most likely to impact your business. So that's how we look at the whole business and all of our services that wrap around that. Everything from pen testing and threat intelligence services and detection engineering services and purple team teaming and red teaming and blue teaming is all concentrated around that thought of, okay, let's start with the most likely threats that these organizations are facing today and make sure that we protect the known knowns as best as we can. So that's how we look at the, at the world from, you know, from you know, cyber proof as a whole.
Speaker A: Absolutely. So you know, manufacturers, more of them are working with msps, are looking to work with, with managed service providers. That first step is sometimes the toughest, the longest, the most difficult to get going. What advice would you offer? Terms of number one, getting that conversation started, maybe selecting the right MSP for you. And then what are some things that folks can do along the course of that journey to get the most out of it as opposed to just sort of it's over here, it's out of sight, out of mind. We need to continue to be engaged.
Speaker B: Yeah, look, I think there's a lot of great providers out there, right, With a lot of great skill sets, uh, and capabilities. And I think it's great to run a comprehensive RFP RFI process, uh, in order to determine who's the best fit for you. Some organizations are better with large enterprises, others are better in the SMB world. Some come packaged with their own black box capabilities, others just use the tooling that you already have. It's just an understanding of who the better fit is, who the best fit is for your organization. Um, but then being able to somehow um, understand what they're doing. Right. Because we also don't believe that it's smart to just trust implicitly. It's great to be able to verify it in some way as well. So there's some tooling out there, and we provide some of this tooling to our customers where you can verify that your vendor is doing what's best for you. Um, you know, it's sometimes, um, you know, you get caught in this, in this thought process of, geez, are they just doing what's best for their, you know, balance sheet or are they doing what's best for us to protect us the right way? And so we've got some, um, some audit kind of capabilities where if you've got, uh, you know, an MSSP or an MDR provider that's, that's doing the defense for you, we can actually put up a dashboard and show you, hey, you know, here's, here's what they're doing. This is your security, you know, this is your actual security posture. Here's what needs to be done, and this is what's being done. So we could show a gap analysis. Uh, but, you know, it's nice to have some way to verify that they're actually doing what's best for you because, you know, you know, it's not, it's not great to just say, okay, we trust you implicitly and not have a way to, you know, to verify it.
Speaker A: Absolutely. You know, I want to circle back a little bit on the conversation about artificial intelligence, whether it was RSA the last couple of years or just the general dynamic or just a general dialogue. Right now in cybersecurity it's AI and, and then of course it's agentic AI and what all these different agents can do and the best way to employ them. Again, we're getting, putting our, ah, dipping our toe in the water a little bit when it comes to some of these things. When you look at agentic AI specifically, are you seeing specific applications or certain areas of cybersecurity where they, they work the best? I mean, we've talked a lot about threat detection, we've talked a lot about understanding the threat landscape. Is that an area for them or are you seeing better places that they can be employed?
Speaker B: We're seeing it being employed across the board. Right. So you know, across, across the stack we're seeing, uh, AI being used. And just so, so long as the, as the data set that it's working off of is definitive, uh, yeah, it's fine. Right. Uh, you know what? You don't want to do is put it in a place where it's guessing. Um, and so, you know, we've spent a lot of time making sure that, you know, the foundational data is, you know, is the exact data set that, you know, you want to, you know, dig through. Um, and in those cases, if the data is sound, right, the solution, you know, what AI is going to kick out to you is going to be sound. But we see it across the board. Um, you know, we see it being used in every aspect. We're doing the same thing within our environment. We're using it across almost all aspects of our business. Um, you just have to. And, uh, you know, the attacks are coming at you now at machine speeds, you know, whereas before, you know, we first started seeing that kind of movement, uh, you know, back 10, 10 ish years ago. And now that from, from an attacker standpoint has kind of been democratized. So now it's not just the realm of nation states that can do that type of, you know, those types of attacks and be able to pivot, uh, you know, at machine speeds. You gotta be able to respond, uh, in order to counterbalance that properly. Um, and you got to have, you know, layered, you know, defense in depth, um, so that, you know, look, if something does happen, right, there's, there's, there's, you know, additional mitigating capabilities in your environment that are going to stop it from, you know, ultimately a data exfiltration, uh, you know, or a ransomware lockdown or, you know, whatever the end goal might be. Uh, but yeah, we're, we're seeing it really, Jeff, everywhere, um, you know, being used and being used effectively.
Speaker A: Yeah.
Speaker B: Well, it's interesting, again, we're at the early stages of this and it's a real acceleration, but we're still at the early stages.
Speaker A: Yeah, it's interesting. It still goes back to one of those basic core elements of clean data and understanding your data in order to implement these additional technologies, which I just hope more people are paying attention to, because otherwise there's going to be a lot of backtracking and a lot of lost investment, uh, just because you weren't set up right to begin with. So I think that's, that's an important part of the whole conversation as well, that maybe we'd only spend enough time on. So I'm really glad you brought that up.
Speaker B: Yeah. And to that point, right. Especially in the, you know, in the manufacturing world where you've got, you know, I don't even know what the exact number is, uh, but what I've heard is that, you know, there's maybe 10% of the OT networks are being continuously monitored. Right. And, and there's, you know, there's, there's a bunch of critical gaps that are out there. You know, we talked about the, you know, it OT convergence. Um, you know, there's, there's a, there's a certainly uh, an invisible um, kind of OT shop floor, right, where there's a bunch of assets out there that really aren't being monitored properly. Right. And there's a lack of, you know, there's a lack of monitoring capabilities. There's, there's a, you know, a ton of unpatched assets out there. There's an incomplete kind of asset inventory problem that's, you know, that's out there in the, in the manufacturing space that really does need to be addressed. Uh, but it's hard. Um, you know, and you combine that then with the whole idea of the cloud and you know, everything that, that brings from, you know, the cloud data center to the edge, devices that are, you know, a lot of unmonitored devices, but you know, there's also a lot of uh, devices in the environment that are being third party monitored right now. Right. So a lot of vendors out there that are, you know, trying to put, you know, persistent access into that production environment. Uh, and that's, that's a, you know, that, that's another avenue in for the adversary. So it's a very complicated, um, environment and it's very complicated to put, you know, a proper detection and you know, security solution in place for that type of complexity.
Speaker A: No, couldn't agree more. I mean there's a lot of challenges out there and I think what we're learning in the industrial side is yeah, we do have all this, but we, number one, we gotta do something and if we can just continue to raise the bar incrementally, it doesn't have to happen all at once to try to, you know, drink the ocean, eat the elephant, whatever you want to say, that's not going to be a good strategy because folks are going to get frustrated and, and whatever. But to do it incrementally, to take those steps, to use all the different tools and technology that's now out there, which there's never been such a, an array of different options in terms of, uh, try what you can implement too. So it is, it's understanding the situation as we've been talking about here, the basics of it, and then making good decisions to incrementally get better and hopefully just make the other, the bad guys go someplace else.
Speaker B: Yeah, yeah. You know, you want to make it painful enough where they pack up and go, this isn't worth it. Right. There's softer targets out there. There's softer underbellies that we're going to go after. Yeah.
Speaker A: So Nick, this has been awesome. Really appreciate the time here as we kind of wrap things up. Any big trends you're seeing, things that are keeping you up at night, different stuff that you think we should be aware of going forward here.
Speaker B: Yeah, look, I think, you know, I think that from a uh, manufacturer standpoint, right, this whole AI driven, you know, cyber attack, uh, you know, at scale problem is absolutely targeting this, you know, this uh, environment, right. And this market segment. So you know, I think that that's a huge issue that needs to be addressed. Uh, you know, again, this is that responding at machine speeds kind of capability. But then there's also the third parties, right, that have access to your environments, right. And you know, whether that be, um, you know, supply chain, uh, you know, as a vendor that's providing a solution or whether that's a maintenance vendor, right, that's out there that has remote access and VPN capability right into your shop floor, you know, so I think that that's a huge issue. Um, and then, you know, because of all these, um, you know, all these, and we talked about this, the adoption of these generative AI tools, you know, you've got employees out there that may be putting IP or proprietary production data or designs out into public AI tools, right? So this whole idea now that we need to start thinking about, of you know, AI tool usage, data leakage is, is a real problem. Um, so, you know, I think that, but I, and I also think that, you know, we talked about this too, is you know, there is a massive targeting of the small and mid sized manufacturing segment out there that just doesn't have the proper, you know, security posture, um, you know, to be able to protect themselves properly and, and that affects the entire supply chain. So I'd say that those are probably the, those are probably the biggest issues, um, you know, that are out there, uh, um, you know, that I see. And I also think that, you know, organizations need to put in and establish some form of continuous monitoring of those OT systems, right. To sort of mitigate this. Um, you know, I think that there needs to be a zero trust kind of network access, uh, mentality put in place, uh, where you know, you can't have, you know, you can't have permanent established connections on all the time, right? Uh, and so, you know, I think that we talked a little bit about segmenting out the networks. Um, I think that's great. You know, a great idea to do that and, and kind of break that connection between the Office IT network and the production floor. Um, and I think that, uh, ability to put in some type of DLP solution in and around your AI usage is super important.
Speaker A: Thanks, Nick. And to learn more about the work he and his colleagues are up to, you can check him out at Cyberproof. I'd also like to thank you for joining us today. And to catch up on past episodes, you can go to manufacturing.netin.com or mbtmag.com you can also check out Security Breach wherever you get your podcasts, including Apple, Amazon and Overcast. And if you have a cybersecurity story or topic that you'd like to have us explore on Security Breach, you can reach me at. Ah, jeff in.com for Nick Landu, I'm Jeff Reinke and this his Security Breach.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.