Episode 91

Responsibility Without Authority: The CISO's Industrial Cybersecurity Dilemma

Published on: 16th September, 2025

In this episode, Craig and Dino address one of the most pressing challenges in industrial cybersecurity: the gap between responsibility and authority for CISOs and their ability to protect manufacturing and critical infrastructure plant floors.

While executives are tasked with ensuring resilience and reporting to the board, they often hit resistance at the plant floor where production uptime and safety KPIs take priority.

The conversation explores IT/OT convergence, asset visibility blind spots, OEM restrictions, and the risks of relying on remote-only deployments.

With insights from decades of hands-on experience in industrial environments, Craig and Dino outline practical steps for building bridges between IT and OT, aligning financial risk with security strategy, and equipping CISOs with the authority they need to succeed.

Chapters:

  • 00:00:00 - Welcome to the Industrial Cybersecurity Insider Podcast
  • 00:01:11 - The CISO's Core Conflict of Responsibility Without Authority
  • 00:02:45 - Why Security Efforts Get "Kneecapped at the Front Door"
  • 00:04:04 - Understanding the OT Environment and Its Unique Technology
  • 00:05:36 - Building Bridges Between IT and OT as the Solution
  • 00:07:44 - Overcoming OT's "Skittish" Resistance to IT
  • 00:09:43 - The Scaling Problem of Too Few Engineers for Too Many Plants
  • 00:10:57 - Why a Remote-First Approach Fails in Manufacturing
  • 00:14:44 - The "Epiphany" of Uncovering Operational Benefits for OT Teams
  • 00:17:24 - Navigating OEM Warranties and Equipment Restrictions
  • 00:19:14 - The "Trust but Verify" Mandate for a CISO
  • 00:20:56 - The Danger of Hidden Networks and the "Air Gap" Myth
  • 00:23:16 - Speaking the Language of Business in Dollars and Cents
  • 00:24:43 - Aligning Security with the Plant's Capital Master Plan
  • 00:27:24 - How Company Ownership Affects Security Investment
  • 00:28:16 - How to Give the CISO Real Authority

Links And Resources:

Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

All Episodes Previous Episode

Listen for free

Show artwork for Industrial Cybersecurity Insider

About the Podcast

Industrial Cybersecurity Insider
Everything You Need to Know to 'Get Safer Sooner'
Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

About your host

Profile picture for Hector Santiesteban

Hector Santiesteban