エピソード

  • Remote Access in OT: Securing Industrial Systems with IEC 62443
    2026/07/28

    Series 3 - Episode 5


    In this episode of Cyber Brews, we explore how Remote Access fits into the IEC 62443 standard and discuss the different approaches organisations are using to securely connect to their OT environments.


    We cover topics including:

    ▪️ The different types of OT remote access and why it's much more than simply using Remote Desktop (RDP)
    ▪️ The advantages and disadvantages of common remote access technologies
    ▪️ How secure remote access supports maintenance, vendors and operational teams
    ▪️ Where remote access fits within the principles of IEC 62443
    ▪️ Practical considerations for reducing cyber risk while maintaining operational availability


    Whether you're an engineer, asset owner, system integrator or cybersecurity professional, understanding how to implement secure remote access is becoming increasingly important in today's connected industrial environments.


    ☕ Grab a brew and join us as we explore one of the most critical topics in OT cybersecurity.

    続きを読む 一部表示
    49 分
  • IEC 62443-2-1 Cyber Security Program
    2026/06/01

    Series 3 - Episode 4


    In this episode of Cyber Brews, we dive into IEC 62443-2-1 Edition 2 and explore what the updated standard means for organisations building and managing cybersecurity programs within industrial and OT environments.


    We discuss the difference between a Cybersecurity Management System (CSMS) and a broader Security Program (SP), why the terminology matters, and how the latest edition of the standard is evolving beyond traditional compliance thinking.


    The episode also covers:

    ▪️ What the IEC 62443-2-1 security program is designed to achieve

    ▪️ The biggest changes introduced in Edition 2

    ▪️ How the standard impacts different stakeholders across industry

    ▪️ What engineers, site owners, OT teams, and process safety professionals should be thinking about moving forward


    As industrial cyber security continues to mature, organisations are increasingly being asked to demonstrate not just technical controls, but governance, ownership, and long-term resilience.

    続きを読む 一部表示
    51 分
  • AI and OT Security: The Future of Industrial Cybersecurity?
    2026/04/22

    Series 3 - Episode 3!

    Artificial Intelligence is rapidly becoming part of the industrial cyber landscape but is it strengthening critical infrastructure, or introducing entirely new risks?

    In this episode we explore the growing relationship between AI and OT security, discussing how organisations are beginning to rely on AI-driven technologies within critical infrastructure environments.


    We dive into topics including:▪️ AI as a new dependency in critical infrastructure▪️ AI-assisted defence for OT environments▪️ How attackers are beginning to use AI against operational technology▪️ The emerging cyber “arms race” between defenders and adversaries▪️ New vulnerabilities and attack vectors introduced by AI systems▪️ Risks such as malicious data poisoning and the growing concern around AI model collapse caused by AI-generated training data


    As AI adoption accelerates, understanding both the opportunities and the unintended consequences becomes increasingly important for organisations operating industrial systems.

    So grab a brew and join us as we explore whether AI is becoming the future of industrial cybersecurity or the next major challenge.

    続きを読む 一部表示
    57 分
  • OG86 to IEC 62443…what’s really changing?
    2026/03/09

    Series 3 - Episode 2!

    The landscape of industrial cybersecurity guidance in the UK is evolving, and many organisations are now navigating the transition from HSE’s OG86 guidance to the more comprehensive IEC 62443 standard.

    In this episode of Cyber Brews, we explore what that shift really means for engineers, operators, and organisations responsible for industrial control systems and operational technology.

    We discuss why OG86 existed, the role it played in protecting safety-related systems, and how the growing cyber threat landscape has driven the move toward IEC 62443’s broader, lifecycle-based approach to cybersecurity.

    Along the way, we unpack key differences between the two approaches, the expectations emerging from regulators, and some of the practical challenges organisations face when applying these concepts to real-world OT environments.

    So grab a brew and join us as we break down the journey from OG86 to IEC 62443 and what it means for the future of industrial cyber security!

    続きを読む 一部表示
    43 分
  • OT Cyber Stories 2025: Lessons from the Front Lines
    2026/02/04

    Series 3 – Episode 1!2025 has been a year full of remarkable OT cybersecurity stories, and in this episode of Cyber Brews, we take you behind the scenes of the most impactful events in the industrial cyber world.

    From Jaguar Land Rover incidents to human-factor challenges in incident response planning, AI ransomware and defence-in-depth strategies, zero-day threats, and attackers embedding infostealers in PyPI packages, we cover the stories that shaped the year.

    We also discuss the wider regulatory and geopolitical landscape, including the Cyber Security and Resilience (Network and Information Systems) Bill, CISA alerts, FBI advisories, and global collaboration to defend critical infrastructure against pro-Russia hacktivist threats.

    Join us as we unpack the lessons learned from 2025, explore the evolving threat landscape, and highlight what it takes to protect critical industrial systems in a world where cyber risks are ever-present.

    So grab a brew and tune in to the front lines of OT cybersecurity.

    続きを読む 一部表示
    43 分
  • Cyber Brews - CAF 4 Is Here: What’s New and What’s Changed
    2025/12/16

    Series 2 - Episode 8

    CAF 4.0 – What’s Changed Since CAF 3.2?


    In this episode of Cyber Brews, we take a closer look at Cyber Assessment Framework (CAF) version 4 and explore how it differs from CAF 3.2.

    We talk through the key changes, what they mean in practice for organisations operating in ICS and OT environments, and how teams should start thinking about alignment, evidence, and assurance under the updated framework.

    Whether you’re already working with CAF or preparing for future assessments, this episode helps break down what’s new, what’s evolved, and what really matters moving forward.


    So grab a brew and join us as we navigate the latest changes in the CAF landscape.

    続きを読む 一部表示
    41 分
  • Cyber Brews - OT Incident Response & Recovery Plans
    2025/11/13

    Series 2 – Episode 7!When something goes wrong in the OT world, every second counts....but whatever happens, don’t panic.

    This months episode we take a look into incident response and recovery plans. We break down the essentials of Incident Response in Operational Technology environments — what it is, who needs to know about it, and why it matters — towel is optional.

    We discuss what makes a strong Incident Response Plan (IRP), the key components every organisation should include, and how even well-prepared plans can fail when theory meets reality.

    Along the way, we share real examples and lessons learned from the front lines of OT security and we talk a little about our latest published cyber security paper on using critical task analysis to understand the human element of incident response plans.

    So grab a brew, keep calm, and join us as we hitchhike through the world of OT incident response.

    続きを読む 一部表示
    52 分