EPISODE · Jul 29, 2026 · 32 MIN
The 6-Step Supply Chain Bleed: When Your Safety Blueprints Leak and the Lifeboats Catch Fire
from Cybersecurity Under Pressure. Real Attacks, Real Lessons · host Antonio Gonzalez
In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we follow the evidence into one of the most consequential architectural debates in industrial cybersecurity today: Should Safety Instrumented Systems (SIS) be strictly segregated from Basic Process Control Systems (BPCS)?The conversation is no longer theoretical. CISA Advisory AA-2026-2697 details Iranian-linked actors actively targeting internet-exposed PLCs, and the threat landscape has shifted from opportunistic ransomware to deliberate, physics-aware attacks. Adversaries are no longer just locking screens—they are hunting for PLC project files, logic diagrams, and network maps to understand your process before they break it.We map the six-stage Supply Chain Bleed in forensic detail:Classification – sensitive engineering assets locked in a fortified central repository.Distribution – access granted to a vetted prime contractor.Delegation – specialized tasks farmed out to tier-3 and tier-4 subcontractors.Export beyond the trust boundary – files converted to PDF, CAD, or raw logic and pulled onto unmanaged endpoints.Peripheral exposure – those files sit on personal laptops, consumer cloud drives, and vulnerable small-business networks.Delayed detection – the plant operator remains completely blind while attackers quietly exfiltrate the blueprints they need to craft a targeted strike.Then we confront the architectural nightmare: common mode failure. When BPCS and SIS share engineering workstations, network switches, or Active Directory credentials, a single compromise collapses both control and safety simultaneously. The ship loses its bridge and its lifeboats.We debate the standards and the reality:IEC 61511 demands safety-oriented independence.IEC 62443 mandates zones and conduits.NIST SP 800-82 Rev. 2 warns that true air-gaps are operational myths in modern facilities.We explore the tension between strict physical segregation (data diodes, isolated workstations) and the operational need for visibility, predictive maintenance, and remote diagnostics. And we draw a critical parallel to the automotive sector—where ISO/SAE 21434 and UN R155 are forcing hardware-level isolation between infotainment and braking ECUs—to show why industrial OT must evolve beyond flat networks.The episode closes with a live Pressure Test: A self-propagating ransomware strain has fully encrypted your BPCS. Your operators are locked out. Reactor pressure is building. The SIS must autonomously initiate a safe shutdown without any human intervention, any shared credential, or any network bridge to the compromised control layer. You have incomplete evidence, no live-fire test history, and terrifying uncertainty about hidden network bridges installed during past maintenance windows. What is your reversible move?What you’ll take away:Why the six-step supply chain bleed is the most overlooked attack surface in OT.How shared infrastructure between BPCS and SIS creates fatal common mode failures.The difference between visibility through integration and safety through isolation—and why data diodes may be the only defensible compromise.A concrete crisis escalation trigger: when to pull the plug, trigger an ungraceful shutdown, and prioritize life safety over production.Why your SIS must be capable of autonomous safe shutdown without relying on the BPCS, shared AD services, or remote command.Thank you so much for spending part of your Wednesday with us, diving deep into these critical and complex issues. We know how valuable your time is, and we truly appreciate you choosing to explore these hard questions alongside us. The stakes for our industry have never been higher, and conversations like this are exactly what move us forward. We will be back tomorrow with a shorter, highly focused follow-up episode diving even deeper into this topic—so please stay with us, and we will see you in the next episode.
Embed this episode
Ready to play
The 6-Step Supply Chain Bleed: When Your Safety Blueprints Leak and the Lifeboats Catch Fire
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.