
Hosted by PI Media
Your lights are on, your car runs, because industrial systems work 24/7 to keep our lives ticking. But what happens when those systems - the very pillars of modern society - are threatened?
148 episodes · publishes fortnightly · latest 2025-12-13 · ~48 min/episode
Rank
#80
Substance
84.4
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#80 of 6182
Substance
Top 1%
outscores 99% of the index
The Industrial Security Podcast ranks #80 on The B2B Podcast Index with a substance score of 84.4 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Kane McGladery is a 30-year cybersecurity veteran, two-time CISO, IEEE senior member, and currently CISO in residence at Hyperproof. He has advised across three continents and is actively writing a book on risk frameworks. He speaks from deep operational experience, not theory. His credibility as a practicing executive who has navigated board-level risk conversations is evident throughout.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers substantial, non-obvious insights about risk communication and framing. Key ideas - cyber risk as a business problem not a technical one, the insurance-as-quantifier approach, the risk tolerance framework, and the intelligence cycle applied to threat assessment - are concrete and actionable. However, there are stretches of throat-clearing (weather/umbrella analogy, book publishing tangent) and some repetition of the core thesis that dilute density.
“CISOs who have longevity in the space, who succeed in the space, really tie it back to business impacts and consequences. And CISOs who find themselves popping jobs every two years and changing their spending a lot of time on LinkedIn. I think they talk about technical vulnerabilities or they talk about technical capabilities that don't necessarily resonate.”
“We need to stop doing security for security's sake. Like I mentioned with the Alaskan gold Russian analogy, the folks who are making money in here, those tools vendors, they're not guaranteeing outcomes.”
McGladery's core argument - that 'cyber risk is a myth' and operators should frame security around business outcomes, not technical vulnerabilities - is contrarian and refreshing against the typical vendor-driven, vulnerability-centric narrative. The insurance-premium-as-liability-accounting mechanism is genuinely novel. However, the underlying risk frameworks (NIST RMF, stakeholder buy-in, documented decisions) are standard practice, and much of the advice overlaps with established security governance.
“The premise of the book is that cyber risk is a myth and that it actually does not exist.”
“if you do nothing, we're going to go out to an insurer. We're going to get a quote for insurance. Whatever that money is, we're not going to spend it...we're going to deduct that amount of insurance even though we didn't pay it...this is a way to keep track of that cost.”
Kane McGladery is a 30-year cybersecurity veteran, two-time CISO, IEEE senior member, and currently CISO in residence at Hyperproof. He has advised across three continents and is actively writing a book on risk frameworks. He speaks from deep operational experience, not theory. His credibility as a practicing executive who has navigated board-level risk conversations is evident throughout.
“I am a thirty year veteran of the cybersecurity industry. I've done executive advisory on three separate continents and am a senior I Triple E member. I'm a second time SISO”
“When I was at a CISO at an industrial design and manufacturing company, our number one risk on our risk register was turning a city into an uninhabitable crater.”
The episode includes concrete examples (Equifax settlement $115M + $1B control spending, Change Healthcare hospital closure, Deep Horizon $69B, Oldsmar Florida water system attack) and specific business mechanics (accounts payable 90-day window vs. accounts receivable 14-day window). However, many claims lack supporting data: threat intel claims about nation-state motivations are asserted without citations, and the insurance-accounting mechanism is illustrated conceptually but without real case studies showing its implementation or results.
“That hospital somewhere in the middle of the country of the United States that basically couldn't get any money for reimbursement for medical procedures, and they consequently went out of business because of a third party data breach.”
“Equafax also had to put in one billion, that's with a B on it, one billion dollars of additional security controls over a decade as part of a negotiated settlement”
Andrew Ginter asks solid follow-up questions (clarifying non-technical framing, probing the insurance mechanism, asking about high-consequence scenarios) and occasionally pushes back productively. However, many follow-ups are gentle summaries rather than sharp challenges. McGladery is given long uninterrupted segments to explain himself, and moments where Ginter could have pressed harder on assumptions (e.g., whether all low-frequency-high-impact risks *should* be mitigated with insurance accounting) are left unexplored. The closing segment with both hosts recapping feels more congratulatory than critically examining the argument.
“The question is, though, if we're not going to talk technical, what do we talk? I mean, you've said tie it back to business impacts?”
“when you have serious consequences, given that experts disagree about what is credible, you know, how do you draw that line?”
First period on the Index - history builds from here.
10 scored on substance · 60 tracked in total.
Rapid Recovery - When Security Fails [The Industrial Security Podcast]
2025-12-13 · 44 min
We can't - and shouldn't - fix everything [The Industrial Security Podcast]
2025-11-21 · 55 min
Medical Device Cybersecurity Is Tricky [The Industrial Security Podcast]
2025-10-28 · 1h 4m
Hardware Hacking - Essential OT Attack Knowledge [the industrial security podcast]
2025-10-06 · 43 min
Managing Risk with Digital Twins - What Do We Do Next? [the industrial security podcast]
2025-09-08 · 46 min
I don't sign s**t [The Industrial Security Podcast]
2025-08-11 · 50 min
NIS2 and the Cyber Resilience Act (CRA) [The Industrial Security Podcast]
2025-07-28 · 54 min
Network Duct Tape [The Industrial Security Podcast]
2025-07-11 · 1h 4m
Credibility, not Likelihood [The Industrial Security Podcast]
2025-06-17 · 53 min
Lessons Learned From Incident Response [The Industrial Security Podcast]
2025-05-20 · 51 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/the-industrial-security-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/the-industrial-security-podcast/badge.svg" alt="Ranked #12 on The B2B Podcast Index" width="360" height="136" />
</a>Track The Industrial Security Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.