28 episodes
- What are the risks of hardening an OT environment? Are there practical hardening steps that are safe to take?
In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined by Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), Tyler Bergman (Principal Security Consultant at Rockwell Automation), and Zach Woltjer (Technical Account Manager) to discuss the risks of implementing different hardening strategies and standards within OT environments.
This discussion was inspired by Lee Carter's article: Device Hardening in OT: How Far Can You Go Before You Break the Plant?
Key Takeaways
Operational Technology (OT) Device Hardening Challenges: What are the complexities and risks of hardening OT devices? The team discuss real-world experiences of balancing security improvements with operational stability in industrial environments.
Importance of Institutional Knowledge in OT Cybersecurity: It's an absolute necessity for OT cybersecurity practitioners to possess deep institutional and operational knowledge, enabling them to communicate effectively with plant personnel and make informed decisions about security interventions.
Identifying and Protecting Critical Assets: What are some strategies for identifying the most critical assets in OT environments, often referred to as 'crown jewels,' and the importance of prioritizing their protection to minimize business risk.
Practical Guidance for OT Hardening: Actionable advice for OT hardening, emphasizing the need to understand the environment, start with basic controls, and avoid changes that could disrupt operations or exceed the organization's risk appetite.
Subscribe
Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
Get in Touch
🔗 LinkedIn | YouTube | X | Contact Us - Important note: this episode is part two of of a discussion that began last week on the Industrial Cybersecurity Insider podcast. Before you listen, check out that episode...or watch it on YouTube!
In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined by Dino Busalachi (Director at BW Design Group), Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), and Tyler Bergman (Principal Security Consultant at Rockwell Automation) to discuss the technical challenges of OT cybersecurity, and the importance of the human element in any plant-facing cybersecurity strategy.
Key Takeaways
IT and OT Convergence Challenges: There continue to be persistent challenges and risks associated with IT and OT convergence in industrial environments, including differences in priorities, operational risks, and barriers to collaboration and domain knowledge transfer.
Human Factors and Plant Relationships: Don't underestimate the importance of building trust and relationships with plant personnel, such as electricians and operators, to gain access to critical knowledge and ensure successful cybersecurity and maintenance initiatives.
Technical Complexities in Industrial Environments: The discussion includes multiple real-world examples illustrating the technical complexities and legacy challenges in industrial environments, including outdated systems, undocumented network configurations, and the risks of human error.
Best Practices for IT Managers Transitioning to OT: Actionable advice for IT managers tasked with taking over OT maintenance, stressing the importance of relationship-building, asset inventory, and understanding plant-specific constraints and maintenance windows.
Training, Safety, and Cyber Hygiene Integration: Can cybersecurity practices be integrated into existing plant safety programs? Would it be effective to adopt 'digital safety' protocols and ongoing training to address both operational and cyber risks?
Subscribe
Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
Get in Touch
🔗 LinkedIn | YouTube | X | Contact Us - In this episode of OT After Hours, Ken Kully (Delivery Readiness at Rockwell Automation) is joined Lance Lamont (Special Projects & Protocols Team Lead at Rockwell Automation), to bid a bittersweet farewell to Natalie Kalinowski, who is leaving Rockwell after 4 years to take on a new and exciting opportunity.
But leave it to Natalie to bring up one last timely topic, in this case the importance of using layered security strategies when defending OT environments.
Key Takeaways
Layered Security Strategies in OT Environments: When consistent patching and regular hardware update cycles are unavailable, layered security approaches become a vital means of defending operational technology (OT) environments, especially practices such as network segmentation, compensating controls, and other practical approaches to securing legacy devices.
Practical Security Recommendations and Tools: What are some actionable recommendations for OT security? There are many, including the use of change detection, network monitoring, and leveraging available frameworks and tools to enhance resilience.
Device Interoperability and Undocumented Vulnerabilities: Lance's team within the SecureOT family researches device interoperability, often discovering undocumented vulnerabilities in the things that keep plants running. This underscores the importance of not relying solely on published vulnerability databases.
Subscribe
Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
Get in Touch
🔗 LinkedIn | YouTube | X | Contact Us - In this episode of OT After Hours, Ken Kully (Systems Support Lead for Rockwell SecureOT) is joined by Natalie Kalinowski (Network & Cybersecurity Specialist), and Mustafa Aamir (Application Consultant Cyber-NCS), for a timely discussion about the December 2025 cyber attack on Poland's power infrastructure, a contemporaneous physical infrastructure attack in Germany, and cyber attacks that have surrounded the recent war in Iran.
But it's not all doom and gloom! Many of these attacks follow a familiar script, exploiting basic vulnerabilities like lack of MFA and reused credentials; addressing these can significantly improve security posture. And many of these "low hanging" mitigations, such as changing credentials and implementing MFA, can be undertaken internally without extensive external support, enabling quick improvements.
Key Takeaways
Asset Management and Risk Analysis: Use "crown jewels" analysis, risk assessment, and understanding operational risk versus CVSS scores to prioritize protection of critical devices and vulnerabilities.
Basic Cyber Hygiene: Implement cybersecurity controls such as network segmentation, VLAN configuration, basic hardening, and eliminating static credentials; these measures are cost-effective and provide significant risk reduction.
External Expertise and Virtual Advisors: Bring in external consultants or virtual security advisors on a flexible basis to supplement in-house expertise, especially for organizations with diverse infrastructure and limited budgets.
Incident Response and Tabletop Exercises: Perform regular review and rehearsal of incident response plans, including tabletop exercises based on real-world attack scenarios, to evaluate preparedness and identify gaps.
Leveraging Open Source Intelligence: Use available tools to proactively identify exposed assets and low-hanging fruit, enabling operators to secure their attack surface before adversaries exploit it.
Subscribe
Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
Get in Touch
🔗 LinkedIn | YouTube | X | Contact Us - In this episode of OT After Hours, Ken Kully (Systems Support Lead for Rockwell SecureOT), sits down with Rick Kaun (Global Director of Cybersecurity Sales), Natalie Kalinowski (Network & Cybersecurity Specialist), and Lance Lamont (Special Projects & Protocols Team Lead), for a lengthy discussion about IT/OT convergence, how Rockwell's SecureOT platform can enable and accelerate advanced security, asset management, and operational efficiency for Rockwell's clients, and why Verve was renamed to SecureOT late last year.
Key Takeaways
Rockwell's Secure OT Rebranding and Strategic Direction: What was behind the transition from Verve to Rockwell's SecureOT branding? What were the strategic motivations, the business strategy review process, and the implications for product positioning and market approach?
Secure OT Platform Capabilities and Value Proposition: What are the SecureOT Platform's technical capabilities? How can it serve as data repository, support advanced security, enable asset management, and drive operational efficiency for Rockwell's clients?
Secure Digital Operations (SDO) and IT/OT Convergence: What are Secure Digital Operations (SDO)? What is its organizational structure, and how can it help bridge the gap between IT and OT security practices within manufacturing environments?
Regulatory Environment and Security Program Evolution: How does SecureOT address the expanding regulatory landscape for critical infrastructure, the importance of defensible security decisions, and the shift from compliance-driven to programmatic security strategies.
Security Culture Versus Rules: What is the distinction between enforcing security through rigid rules versus fostering a culture of security?
Subscribe
Follow and subscribe for more episodes on Apple Podcasts, Spotify, YouTube, or wherever you get your podcasts.
Get in Touch
🔗 LinkedIn | YouTube | X | Contact Us
More Technology podcasts
Trending Technology podcasts
About OT After Hours
OT After Hours, a podcast about operational technology security, brings you candid conversations with ICS engineers and experts who get the unique challenges you face. Join us for unfiltered stories and advice from the front lines of industrial cybersecurity as we share best practices, lessons learned, and a few laughs along the way.
Podcast websiteListen to OT After Hours, Search Engine and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


OT After Hours
Scan code,
download the app,
start listening.
download the app,
start listening.
OT After Hours: Podcasts in Family



























