Skip to content
PodcastsTechnologyOT After Hours

OT After Hours

Rockwell Automation
OT After Hours
Latest episode

29 episodes

  • OT After Hours

    The EU CRA and OEMs

    16/09/2026 | 48 mins.
    How can industrial device OEMs comply with the new EU CRA and its requirements for digital devices sent to the European market?
    In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined by Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), Tyler Bergman (Principal Security Consultant at Rockwell Automation), Zach Woltjer (Technical Account Manager), and by special guests Maria Else (Global Product Manager for Industrial Cybersecurity) and Stefan Turi (EMEA Cybersecurity Lead for OEMs) to discuss the EU Cyber Resilience Act (CRA), its implications for industrial device original equipment manufacturers (OEMs), and how the SecureOT™ solution suite can help drive both compliance and security in response.
    Key Takeaways
    EU Cyber Resilience Act Scope: The CRA applies broadly to products with digital elements placed on the EU market, including industrial machines. These responsibilities extend across manufacturers, OEMs, system integrators, importers, distributors, and end users.
    OEM Compliance And Product Lifecycle: CRA obligations include having a secure-by-design processes, vulnerability handling, documentation, risk analysis, and support throughout the product lifecycle. OEMs must establish repeatable processes rather than simply purchase security technology.
    Asset Inventory And Vulnerability Traceability: Under the CRA, maintaining a durable record of shipped equipment, its configuration, ownership, location, and software or firmware versions so OEMs can identify affected customers and respond to newly disclosed vulnerabilities across their installed base.
    Vulnerability Remediation And Patching: Vulnerability findings should be prioritized and remediated without disrupting industrial production, including update limitations for embedded devices, vendor dependencies, maintenance windows, and the need for tested procedures.
    Digital Twins And Security Validation: Digital twins can be used to model manufacturing lines and test patches before deployment. Rockwell's Emulate3D and associated consulting capabilities provide a solution for validating dependencies and developing secure operational procedures.
    Cybersecurity Governance And Safety: CRA compliance requires sustained organizational ownership and collaboration, while cybersecurity must be treated as part of machine safety because exploitation can affect operators, equipment, production, and the surrounding environment.
    Subscribe
    Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
    Get in Touch
    🔗 LinkedIn | YouTube | X | Contact Us
  • OT After Hours

    Device Hardening in OT Systems

    22/07/2026 | 48 mins.
    What are the risks of hardening an OT environment? Are there practical hardening steps that are safe to take?
    In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined by Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), Tyler Bergman (Principal Security Consultant at Rockwell Automation), and Zach Woltjer (Technical Account Manager) to discuss the risks of implementing different hardening strategies and standards within OT environments.
    This discussion was inspired by Lee Carter's article: Device Hardening in OT: How Far Can You Go Before You Break the Plant?
    Key Takeaways
    Operational Technology (OT) Device Hardening Challenges: What are the complexities and risks of hardening OT devices? The team discuss real-world experiences of balancing security improvements with operational stability in industrial environments.
    Importance of Institutional Knowledge in OT Cybersecurity: It's an absolute necessity for OT cybersecurity practitioners to possess deep institutional and operational knowledge, enabling them to communicate effectively with plant personnel and make informed decisions about security interventions.
    Identifying and Protecting Critical Assets: What are some strategies for identifying the most critical assets in OT environments, often referred to as 'crown jewels,' and the importance of prioritizing their protection to minimize business risk.
    Practical Guidance for OT Hardening: Actionable advice for OT hardening, emphasizing the need to understand the environment, start with basic controls, and avoid changes that could disrupt operations or exceed the organization's risk appetite.
    Subscribe
    Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
    Get in Touch
    🔗 LinkedIn | YouTube | X | Contact Us
  • OT After Hours

    Human Factors and Plant Relationships

    20/05/2026 | 55 mins.
    Important note: this episode is part two of of a discussion that began last week on the Industrial Cybersecurity Insider podcast. Before you listen, check out that episode...or watch it on YouTube!
    In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined by Dino Busalachi (Director at BW Design Group), Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), and Tyler Bergman (Principal Security Consultant at Rockwell Automation) to discuss the technical challenges of OT cybersecurity, and the importance of the human element in any plant-facing cybersecurity strategy.
    Key Takeaways
    IT and OT Convergence Challenges: There continue to be persistent challenges and risks associated with IT and OT convergence in industrial environments, including differences in priorities, operational risks, and barriers to collaboration and domain knowledge transfer.
    Human Factors and Plant Relationships: Don't underestimate the importance of building trust and relationships with plant personnel, such as electricians and operators, to gain access to critical knowledge and ensure successful cybersecurity and maintenance initiatives.
    Technical Complexities in Industrial Environments: The discussion includes multiple real-world examples illustrating the technical complexities and legacy challenges in industrial environments, including outdated systems, undocumented network configurations, and the risks of human error.
    Best Practices for IT Managers Transitioning to OT: Actionable advice for IT managers tasked with taking over OT maintenance, stressing the importance of relationship-building, asset inventory, and understanding plant-specific constraints and maintenance windows.
    Training, Safety, and Cyber Hygiene Integration: Can cybersecurity practices be integrated into existing plant safety programs? Would it be effective to adopt 'digital safety' protocols and ongoing training to address both operational and cyber risks?
    Subscribe
    Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
    Get in Touch
    🔗 LinkedIn | YouTube | X | Contact Us
  • OT After Hours

    Farewell Party

    22/04/2026 | 36 mins.
    In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), to bid a bittersweet farewell to Natalie Kalinowski, who is leaving Rockwell after 4 years to take on a new and exciting opportunity.
    But leave it to Natalie to bring up one last timely topic, in this case the importance of using layered security strategies when defending OT environments.
    Key Takeaways
    Layered Security Strategies in OT Environments: When consistent patching and regular hardware update cycles are unavailable, layered security approaches become a vital means of defending operational technology (OT) environments, especially practices such as network segmentation, compensating controls, and other practical approaches to securing legacy devices.
    Practical Security Recommendations and Tools: What are some actionable recommendations for OT security? There are many, including the use of change detection, network monitoring, and leveraging available frameworks and tools to enhance resilience.
    Device Interoperability and Undocumented Vulnerabilities: Lance's team within the SecureOT family researches device interoperability, often discovering undocumented vulnerabilities in the things that keep plants running. This underscores the importance of not relying solely on published vulnerability databases.
    Subscribe
    Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
    Get in Touch
    🔗 LinkedIn | YouTube | X | Contact Us
  • OT After Hours

    Global Cyber and Physical Attacks

    27/03/2026 | 45 mins.
    In this episode of OT After Hours, Ken Kully (Systems Support Lead for Rockwell SecureOT) is joined by Natalie Kalinowski (Network & Cybersecurity Specialist), and Mustafa Aamir (Application Consultant Cyber-NCS), for a timely discussion about the December 2025 cyber attack on Poland's power infrastructure, a contemporaneous physical infrastructure attack in Germany, and cyber attacks that have surrounded the recent war in Iran.
    But it's not all doom and gloom! Many of these attacks follow a familiar script, exploiting basic vulnerabilities like lack of MFA and reused credentials; addressing these can significantly improve security posture. And many of these "low hanging" mitigations, such as changing credentials and implementing MFA, can be undertaken internally without extensive external support, enabling quick improvements.
    Key Takeaways
    Asset Management and Risk Analysis: Use "crown jewels" analysis, risk assessment, and understanding operational risk versus CVSS scores to prioritize protection of critical devices and vulnerabilities.
    Basic Cyber Hygiene: Implement cybersecurity controls such as network segmentation, VLAN configuration, basic hardening, and eliminating static credentials; these measures are cost-effective and provide significant risk reduction.
    External Expertise and Virtual Advisors: Bring in external consultants or virtual security advisors on a flexible basis to supplement in-house expertise, especially for organizations with diverse infrastructure and limited budgets.
    Incident Response and Tabletop Exercises: Perform regular review and rehearsal of incident response plans, including tabletop exercises based on real-world attack scenarios, to evaluate preparedness and identify gaps.
    Leveraging Open Source Intelligence: Use available tools to proactively identify exposed assets and low-hanging fruit, enabling operators to secure their attack surface before adversaries exploit it.
    Subscribe
    Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
    Get in Touch
    🔗 LinkedIn | YouTube | X | Contact Us
More Technology podcasts
About OT After Hours
OT After Hours, a podcast about operational technology security, brings you candid conversations with ICS engineers and experts who get the unique challenges you face. Join us for unfiltered stories and advice from the front lines of industrial cybersecurity as we share best practices, lessons learned, and a few laughs along the way.
Podcast website

Listen to OT After Hours, The AI Daily Brief: Artificial Intelligence News and Analysis and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
OT After Hours: Podcasts in Family