Cybersecurity Under Pressure. Real Attacks, Real Lessons podcast artwork

PODCAST · technology

Cybersecurity Under Pressure. Real Attacks, Real Lessons

This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business teams. Topics covered: OT security, ICS cybersecurity, industrial control systems, critical infrastructure protection, NIS2 compliance, Zero Trust architecture, operational technology resilience, railway cybersecurity, automotive security, and cyber-physical systems.

Publisher-supplied feed metadata · PodParley refreshed Apr 13, 2026 · Source feed

  1. 29

    The Restart Bottleneck Is Not the Backup. It Is the Evidence.

    After an OT cyber incident, restoring systems is only the visible part of recovery. The harder question comes next: who can prove that production is safe to restart?In this episode of Cybersecurity Under Pressure: real attacks, real lessons, we look at why OT recovery is different from IT recovery. A backup may exist. The PLC logic may appear unchanged. The virtual machine may boot. But in automotive and high-cadence manufacturing, restarting without trusted evidence can create a second crisis.We discuss engineering workstations, SCADA-related Windows servers, virtualised OT environments, dwell-time assessed baselines, out-of-band evidence, tamper-evident logs and pre-agreed IT/OT go/no-go criteria.The real challenge is not only technical recovery. It is building enough operational confidence for plant management, cybersecurity, quality and product safety to make a defensible restart decision under pressure.Because in OT, the strongest recovery teams are not the ones with the longest backup catalogue. They are the ones that can answer one question with evidence:Why is it safe to restart now?Listen now and subscribe to Cybersecurity Under Pressure for practical lessons on OT cybersecurity, industrial resilience and real-world cyber risk.

  2. 28

    Zero Trust Meets Twenty Year Old Code

    What happens when a twenty-year-old industrial control system meets the latest Zero Trust security protocols, and the two just can't seem to get along? In this episode we break down the challenges of implementing Zero Trust in industrial environments, where legacy devices don't speak the language of modern identity and security. We walk through real-world examples of how to design a Zero Trust architecture that works with, not against, these older systems. We argue that strong authentication and mediation are key to reducing exposure without disrupting production.The distinction between a good and a bad Zero Trust design can be the difference between a secure and a breached industrial system, with very real consequences for the people and processes that rely on it.Subscribe to our podcast for more insights into the intersection of security and industrial technology, and join the conversation about what it takes to protect our most critical systems.#ZeroTrust #OTSecurity #IndustrialCybersecurity

  3. 27

    Beyond Backup Recovery

    What happens when a production line grinds to a halt, not because of a technical failure, but because trust in the engineering environment has been lost?In this episode we break down the real cost of an OT cyber incident, and explore the complexities of recovery in operational technology environments. We walk through a real case where the question is no longer just about restoring systems, but about proving that the process can be trusted again. We argue that many organisations are weaker than they think when it comes to validating engineering workstation integrity and confirming PLC logic.The ability to quickly and effectively respond to an OT cyber incident can mean the difference between a minor disruption and a six-figure business problem, making it a critical consideration for anyone working in operational technology.Subscribe to our podcast for more insights on the intersection of technology and business, and join the conversation on the real-world implications of OT cyber incidents.#OTcybersecurity #operationaltechnology #industrialcontrolsystems

  4. 26

    Cyber Gaps in Automotive Supply

    What happens when a vulnerability is discovered in a car's system after production has started, and nobody knows who's responsible for fixing it?In this episode we break down the messy world of automotive cybersecurity, where gaps in responsibility between companies can put entire systems at risk. We walk through real-world scenarios where the lack of clear agreements and ownership can lead to major problems. We argue that these gaps are not just technical issues, but also governance problems that need to be addressed.The consequences of these gaps can be severe, from compromised vehicle safety to significant financial losses, making it essential for companies to rethink their approach to cybersecurity and liability.Subscribe to our podcast to dive deeper into the complex world of automotive cybersecurity and learn how to navigate these critical issues.#automotivecybersecurity #cybersecuritymatters #supplychainrisk

  5. 25

    When Patches Stop Production

    What happens when a security patch intended to protect your system ends up being the cause of a catastrophic operational incident?In this episode we break down the nuances of patch management in industrial environments, where the stakes are high and the consequences of a mistake can be devastating. We walk through real-world scenarios where a simple patch can bring down an entire production line, and explore the delicate balance between cybersecurity and operational continuity. We argue that a one-size-fits-all approach to patching is no longer tenable.The ability to manage vulnerabilities in industrial environments has a direct impact on the bottom line, as a single misstep can result in costly downtime and damaged equipment.Subscribe to our podcast to hear more about the complexities of OT vulnerability management and how to navigate the treacherous landscape of patching and cybersecurity.#IndustrialCybersecurity #PatchManagement #OTVulnerabilityManagement

  6. 24

    Ransomware Beyond Encryption

    What if a single login credential was all a hacker needed to bring your entire production line to a grinding halt, without even touching your industrial control systems?In this episode we break down the grey zone where ransomware attacks on operational technology can have devastating consequences, and explore the often-overlooked vulnerabilities that can allow attackers to move undetected between IT and OT systems. We walk through real-world scenarios where a simple login can enable access to sensitive areas of your operation, and discuss the importance of understanding the trust, exposure, and consequence of your assets.The reality is that many organizations are unaware of the risks lurking in the spaces between their IT and OT systems, and the consequences of a breach can be catastrophic, resulting in lost production time, damaged equipment, and compromised safety.Subscribe to our podcast to stay ahead of the threats and learn how to protect your operation from these emerging risks.#IndustrialCyberSecurity #Ransomware #OperationalTechnology

  7. 23

    Beyond Asset Coverage

    Can a single overlooked device really bring down your entire network, and are you unwittingly leaving the door open to cyberattacks by focusing on the wrong security strategy?In this episode we break down the flaws in traditional network visibility programs and explore how microsegmentation can limit the damage of unseen assets. We walk through real-world examples of how IT dependencies and vendor access have led to devastating breaches, and discuss the importance of structuring conversations around asset risk and function.By the end of this episode, you'll understand why treating inventory as a containment strategy is a recipe for disaster, and how a different approach can save you from costly disruptions.Subscribe to our podcast for more insights on how to secure your network and stay one step ahead of emerging threats.#cybersecurity #networkvisibility #microsegmentation

  8. 22

    When Containment Fails Recovery

    What if your team contained a cyber incident, but the real damage was only just beginning?In this episode we break down the disconnect between IT and engineering timelines, and explore how the NIS2 directive is raising the bar for incident recovery and accountability. We walk through the implications of Articles 20, 21, and 34, and what they mean for management bodies and cybersecurity teams. We argue that a single incident command model is the key to true recovery.The ability to recover from a cyber incident quickly and effectively is no longer a nice-to-have, but a critical component of business continuity and risk management.Subscribe to our podcast for more insights on cybersecurity and operational risk, and join the conversation on how to stay ahead of emerging threats.#cybersecurity #NIS2 #incidentrecovery #operationalrisk #businesscontinuity

  9. 21

    Exposed Paths in OT Networks

    What if the biggest security risk to your industrial control systems isn't a malicious hacker, but rather a simple disconnect between when a work order closes and when network access is actually shut off?In this episode we break down the hidden dangers of insecure remote access conditions and explore why PAM is not failing in OT, but rather being asked to enforce a physical work state it cannot see. We walk through real-world examples of exposed engineering paths and unpatched VPNs, and discuss the consequences of a visibility gap between operations and network access. We argue that the problem lies not with the tools, but with the disconnection between different states that never converge.The reality is that this gap can have devastating consequences, from allowing attackers to gain access to sensitive systems to putting entire operations at risk.Subscribe to our podcast to learn more about the intersection of industrial control systems and cybersecurity, and to stay up to date on the latest threats and solutions.#OTSecurity #ZeroTrust #IndustrialCybersecurity

  10. 20

    Shipping the Code That Security Rejected

    Your vehicle's biggest security threat might be arriving with a perfectly valid digital signature and your company's own stamp of approval.In this episode, we break down why the shift to software-defined vehicles is currently failing at the release gate. We walk through the uncomfortable reality of SOP pressure and argue that current security assessments are often treated as advisory rather than hard controls.It is time to stop asking for attention and start controlling the release, because a "safe" binary that your organization doesn't actually understand is just a liability waiting to happen.Drop your take in the comments or share this episode with a colleague who is fighting against weak provenance and unrealistic deadlines right now.#AutomotiveCybersecurity #SDV #SupplyChainSecurity #CyberSecurity #AutomotiveSoftware

  11. 19

    When a Patch Reopens the Safety Case

    A simple security patch can fix a vulnerability and still become a total operational nightmare that brings an entire railway network to a standstill.In this episode, we break down the high-stakes collision between the new Cyber Resilience Act and the rigid, uncompromising world of railway safety certification. We walk through why architectural perfection is a myth for brownfield systems and how to use protocol-aware filtering to keep your network secure without triggering a massive, budget-breaking reassessment.We argue that the strongest cyber programs are not the ones with the fastest patch cycles, but the ones that know how to improve risk posture while keeping the trains moving. This conversation is about making security maintenance survivable in a sector where you simply cannot afford to touch the binary.Subscribe to the show and share this episode with anyone currently trying to navigate the impossible tension between rapid response and safety-critical stability.#RailCybersecurity #CyberResilienceAct #CriticalInfrastructure #OTSecurity

  12. 18

    The Trap of the Trusted Engineering Session

    Your VPN is lying to you about how safe your plant actually is.In this episode, we break down why relying on MFA and session monitoring is just giving you a front-row seat to your own incident. We walk through the reality of session hijacking in brownfield OT and argue why the network should never be the one deciding who gets to touch the control layer.This is about the high-stakes shift from letting the network decide your fate to putting the power back into the hands of the operators on the floor. It is the only way to withdraw digital authority before a trusted session becomes a physical catastrophe.Subscribe to the show and share this with someone who still thinks a secure tunnel is a silver bullet for industrial safety.#OTSecurity #Cybersecurity #CriticalInfrastructure #IndustrialAutomation

  13. 17

    When VEX Becomes a Bureaucratic Shield

    Your SBOM is probably useless, and it is time we talked about why.In this episode, we look past the hype of vulnerability scanning to the uncomfortable reality of the software-defined vehicle. We walk through how suppliers are using VEX as a bureaucratic shield to dodge patches and why your security program is likely just a mountain of expensive noise.We argue that if you are not prepared to challenge a supplier's claim with technical evidence, you are not doing security—you are just doing paperwork. This conversation is about moving from a flood of findings to actual, defensible risk management that protects the driver, not just the budget.Subscribe and share this with a security lead who is tired of chasing ghosts in their supply chain.#cybersecurity #automotive #supplychain #SBOM #VEX

  14. 16

    Why FRMCS Cannot Trust the Mobile Carrier

    Your 5G service level agreement is not a safety case, and confusing the two is a dangerous mistake for the future of rail.In this episode, we break down why FRMCS cannot depend on the goodwill of a mobile operator, regardless of how low the latency claims are. We explore the logic of EN 50159 and explain why the only way to build a truly resilient railway architecture is to assume the network is already hostile, degraded, or failing.Understanding this distinction is the difference between a system that works on paper and one that actually keeps passengers safe when the transport layer inevitably breaks.Subscribe to the show and share this episode with an engineer who needs a reality check on 5G.#FRMCS #RailCybersecurity #ETCS #CriticalCommunications #OTSecurity

  15. 15

    The Token That Bypassed the Jump Host

    Most industrial security teams are betting their entire plant floor on a jump server that an attacker can bypass in seconds.In this episode, we break down why your current MFA strategy is failing to stop session theft and what it actually takes to secure the engineering zone. We walk through the technical steps of removing NTLM and binding sessions to device posture so a compromised corporate credential never touches your controllers.It is time to face the uncomfortable truth that real OT maturity requires redesigning how we handle third-party access before a hijacked session makes the decision for you.Subscribe to the show and share this with the person in your organization who still thinks a VPN is a silver bullet.#OTSecurity #CyberSecurity #IndustrialAutomation #IdentityManagement

  16. 14

    Poisoning the Software Defined Vehicle at Birth

    Your vehicle’s security might be dead on arrival if the very network that birthed it was already compromised.In this episode, we challenge the industry obsession with supplier code and shift the focus to the high-stakes world of cryptographic provisioning on the plant floor. We break down why a verifiable SBOM is only half the battle and how to implement fleet-scale monitoring that actually filters out the noise before it hits your cloud.The hard truth is that if the manufacturing environment isn't trustworthy, every security layer you add later is just a house of cards.Subscribe to the show and share this with anyone building the next generation of software-defined vehicles.#automotivecybersecurity #supplychain #infosec #softwaredefinedvehicle #iotsecurity

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business teams. Topics covered: OT security, ICS cybersecurity, industrial control systems, critical infrastructure protection, NIS2 compliance, Zero Trust architecture, operational technology resilience, railway cybersecurity, automotive security, and cyber-physical systems.

HOSTED BY

Antonio González

CATEGORIES

Frequently Asked Questions

How many episodes does Cybersecurity Under Pressure. Real Attacks, Real Lessons have?

Cybersecurity Under Pressure. Real Attacks, Real Lessons currently has 16 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Cybersecurity Under Pressure. Real Attacks, Real Lessons about?

This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business...

How often does Cybersecurity Under Pressure. Real Attacks, Real Lessons release new episodes?

Cybersecurity Under Pressure. Real Attacks, Real Lessons has 16 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Cybersecurity Under Pressure. Real Attacks, Real Lessons?

You can listen to Cybersecurity Under Pressure. Real Attacks, Real Lessons on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Cybersecurity Under Pressure. Real Attacks, Real Lessons?

Cybersecurity Under Pressure. Real Attacks, Real Lessons is created and hosted by Antonio González.
URL copied to clipboard!