EPISODE · Jun 1, 2026 · 57 MIN
Iran Came for US Dams and We Got Lucky: Frontline Insights from the OT Fight
from The GIST of Govt IT
When Iranian-linked cyber actors hit U.S. water, energy, and government facilities through internet-exposed Rockwell Allen-Bradley PLCs during the sixth week of the U.S.–Iran military campaign, they did it with attacks that were eightfold above baseline and got within 30 to 40 minutes of opening dam gates. In Episode 7 of The GIST of Govt IT, Brian and Sean sit down with Matthew Shalbetter, Director of Strategy for Civilian Agencies at Armis Federal and a 16-year HHS veteran, to unpack what's really happening at the convergence of IT and OT. Matthew breaks down why cyber has become the great equalizer for nation-state actors, the difference between Iranian "disrupt and distract" tactics, and Chinese prepositioning ahead of a potential Taiwan invasion. The conversation digs into the cultural chasm between IT and OT teams, what the Ukrainians taught a roomful of Western OT practitioners at RSA about why red teaming beats paperwork, and the basics that still aren't done. Trump's seven-page cyber strategy and what ServiceNow's $7.75B acquisition of Armis — closed April 20 — means for federal customers. Plus: Matthew's Hacker Name...DirtTrackRESOURCES MENTIONED IN THIS EPISODEFeatured Guest- Matthew Shallbetter, Director of Strategy for Civilian Agencies, Armis Federal- Armis FederalThe Iranian PLC Attacks- CISA Joint Advisory AA26-097A — Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure- Rockwell Automation security advisories- CyberAv3ngers / IRGC threat actor backgroundOT Discovery & Exposure Research- Shodan — internet-exposed device search engine- Censys — internet asset discovery- Armis State of Cyberwarfare ReportOT/ICS Frameworks & Government Guidance- NIST SP 800-82 — Guide to Operational Technology Security- CISA Cross-Sector Cybersecurity Performance Goals (CPGs)- DoD Zero Trust Overlays (including OT guidance)- NERC CIP Standards (electric sector OT)Federal Cyber Policy- White House National Cyber Strategy (the seven-page version)- CDM Program (Continuous Diagnostics and Mitigation)- CISA Industrial Control Systems resourcesThe ServiceNow + Armis Deal- ServiceNow completes Armis acquisition (April 20, 2026)Threat Actor Tracking Partners Referenced- Armis Centrix Threat Intelligence- DragosRelated Episodes- Episode 5: Vibe Hacking” and Nation State Cyber Threats - Episode 6: Cupcakes & OODA Loops: Inside(r) Insights Into The New Federal AI Cyber PlaybookUpcoming Event- GIST 360 Breakfast Briefing at the National Press Club, July 14 - When the Perimeter Disappears Securing the Converged Federal Enterprise Across IT, OT and IoT Environments The Hosts & Show- Swish- GIST 360CONNECT WITH USGot an idea for a future episode? Want to be a guest? Let us know.Brian Lake - [email protected] Applegate - [email protected] wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.
Embed this episode
What this episode covers
When Iranian-linked cyber actors hit U.S. water, energy, and government facilities through internet-exposed Rockwell Allen-Bradley PLCs during the sixth week of the U.S.–Iran military campaign, they did it with attacks that were eightfold above baseline and got within 30 to 40 minutes of opening dam gates. In Episode 7 of The GIST of Govt IT, Brian and Sean sit down with Matthew Shalbetter, Director of Strategy for Civilian Agencies at Armis Federal and a 16-year HHS veteran, to unpack ...
NOW PLAYING
Iran Came for US Dams and We Got Lucky: Frontline Insights from the OT Fight
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.