All Episodes

January 13, 2025 58 mins

In this episode, host Aaron Crow converses with Lesley Carhart, Technical Director at Dragos, who brings over 15 years of experience in incident response and forensics within critical infrastructure sectors.

The episode dives deep into the standard practices in industrial settings, such as operators shutting down power plants for safety and the lack of forensic investigation into equipment failures. Lesley emphasizes the importance of integrating cybersecurity into these environments, pointing out that many failures are due to maintenance or human error, though a notable portion does involve cyber threats.

Listeners will learn about the challenges and necessary collaborations between operational technology (OT) and information technology (IT) teams. The discussion addresses cultural and trust barriers that hinder effective cybersecurity measures and advises on how organizations can improve their defenses regardless of size and resources.

Lesley also highlights the evolving landscape of cyber threats, including the increasing sophistication of adversaries and the vulnerabilities caused by standardizations in industrial systems. Real-world examples underscore the complexity of securing these environments, emphasizing the need for proactive and informed cybersecurity practices, such as "cyber-informed engineering."

Tune in to better understand the critical intersections of cybersecurity and industrial operations, and learn practical strategies to safeguard essential services.



Key Moments: 

05:00 IT-OT miscommunication leads to cybersecurity risks.

09:23 IT processes are too slow; bypassing is required for solutions.

11:36 Leaving an outdated system may pose less risk.

15:09 Slow changes in OT due to unforeseen impacts.

19:17 Include cybersecurity in root cause analysis discussions.

20:31 Nation-states analyze and bypass industrial control systems.

25:40 Cybersecurity is essential to combat potential system threats.

29:27 Communication, champions, and leadership crucial for cybersecurity.

31:37 Cybersecurity struggle due to resources community helps.

35:03 OT vs. IT language differences affect incident classification.

38:08 Empowered safety culture prevents accidents and retribution.

40:22 Few people have diverse cybersecurity skills and experience.

45:05 Experience across all 17 critical infrastructure verticals.

48:29 Evading detection in the nuclear enrichment process.

51:25 Identify industrial devices, build security program.

About the guest : 

Lesley Carhart is a renowned cybersecurity expert specializing in industrial control systems (ICS) security. With a keen understanding of the convergence between traditional IT and operational technology (OT), Lesley has been at the forefront of safeguarding critical infrastructures. Her work emphasizes the vulnerabilities of human-machine interfaces (HMIs) and programming devices, which are increasingly resembling typ

Mark as Played

Advertise With Us

Popular Podcasts

Stuff You Should Know
Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

On Purpose with Jay Shetty

On Purpose with Jay Shetty

I’m Jay Shetty host of On Purpose the worlds #1 Mental Health podcast and I’m so grateful you found us. I started this podcast 5 years ago to invite you into conversations and workshops that are designed to help make you happier, healthier and more healed. I believe that when you (yes you) feel seen, heard and understood you’re able to deal with relationship struggles, work challenges and life’s ups and downs with more ease and grace. I interview experts, celebrities, thought leaders and athletes so that we can grow our mindset, build better habits and uncover a side of them we’ve never seen before. New episodes every Monday and Friday. Your support means the world to me and I don’t take it for granted — click the follow button and leave a review to help us spread the love with On Purpose. I can’t wait for you to listen to your first or 500th episode!

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.