In this video, an industrial cybersecurity expert discusses the differences between various cybersecurity standards such as ISA/IEC-62443, NIST, and NERC, emphasizing the unique advantages of the ISA/IEC-62443 standards in effectively mitigating risks. The speaker highlights the substantial costs of government regulations funded by taxes and argues for the efficiency of ISA/IEC-62443. Drawing from over a decade of experience, the expert shares insights on the importance of robust design and how a cybersecurity-focused approach has reshaped their perspective on industrial automation.
Category: Insights
Episode 2 Clip 5 – Avoiding typical errors when doing industrial risk assessments.
This clip emphasizes the critical need for proper risk assessment in IT practices, discusses common mistakes like skipping risk assessment, using the wrong methodology, and highlights the importance of a consequence-based approach for preventing incidents effectively.
Episode 2 Clip 4 – Understanding the importance of ISA/IEC-62443 series of standards.
In “Episode 2 Clip 4,” the speaker discusses the best methodologies for evaluating industrial cybersecurity risks, emphasizing adherence to the ISA/IEC-62443-3-2 standard. Key points include the need for a multidisciplinary, knowledge-based approach, the importance of integrating cybersecurity with other risk management disciplines, and the dangers of relying too heavily on IT-centric solutions. The clip stresses the necessity of long-term, rational decision-making within the plant and illustrates the risks associated with external dependencies, using the CrowdStrike incident as an example. The aim is to guide professionals toward effective and sustainable cybersecurity practices for critical infrastructures.
Episode 2 Clip 3 – The formula for calculating cyber risk.
The clip discusses the challenges of calculating industrial cybersecurity risk, emphasizing the importance of understanding and effectively implementing risk formulas, highlighting the role of system design in preventing cyber incidents, and stressing the significance of informed decision-making and proper investment in cybersecurity solutions.
Episode 2 Clip 2 – The true goals of industrial cybersecurity.
This clip discusses the importance of industrial cybersecurity in preventing consequences rather than just incidents. It emphasizes the need for strategic management of risks to ensure plant safety and longevity, highlighting the key role of correctly implemented cybersecurity measures. The video also touches on calculating return on investment and the significance of maintaining a comprehensive cybersecurity strategy for overall business success.
Episode 2 Clip 1 – The importance of Risk Assessment.
This video cast focuses on the importance of risk assessment in industrial cybersecurity. The speakers discuss the significance of identifying and mitigating intolerable risks through proper risk assessment practices. They emphasize the different disciplines of risk present in typical plants and stress the need for accurate decision-making based on sound analysis.
Episode 1 Clip 6 – What are the best training courses or programs for End Users and Providers?
Emphasizes the importance of investing in cybersecurity training programs, particularly the official ISA certificate training and the WisePlant cybersecurity program. It highlights the need for understanding and implementing cybersecurity requirements correctly, tailored to individual roles. The training aims to ensure project success by aligning all participants towards a common goal in the cybersecurity field.
Episode 1 Clip 5 – What do you think is the most difficult challenge to manage or mitigate the industrial cybersecurity risk?
Discusses the challenges of managing industrial cybersecurity effectively, emphasizing the importance of doing the right things correctly. It highlights why companies struggle with implementing standards and how viewing cybersecurity as an investment, rather than an expense, is crucial for the long-term security and success of businesses.
Episode 1 Clip 4 – What are the most common mistakes that you’ve seen in the market so far?
Outlines common mistakes in industrial cybersecurity, including skipping risk assessments, copying IT security policies without adaptation, and relying solely on employee training. Practical advice is given on how to prevent these errors and improve cybersecurity practices.
Episode 1 Clip 3 – What is the best approach to address industrial cybersecurity?
Emphasizes the necessity of a continuous cultural change towards cybersecurity in industrial operations for end users, service providers, and manufacturers. It highlights the importance of implementing cybersecurity management programs, conducting risk assessments, mitigating risks, and maintaining long-term security measures across the entire supply chain.