Episode 99

The Nation-State Attacks Hiding in Your OT Network

Published on: 12th November, 2025

In this episode of the Industrial Cybersecurity Insider, Craig Duckworth sits down with Matthew Carr, co-founder of Atumcell and OT penetration testing expert with fifteen years of experience securing operational technology systems.

Matthew shares his journey from vulnerability research to specializing in cyber-physical security, recounting the pivotal moment when his exploit code stopped a production line at a major car manufacturer.

The conversation addresses the critical gaps in OT security, including why most organizations are unaware of what's actually on their networks, the dangers of default passwords on IoT devices, and how attackers often use espionage rather than ransomware to remain undetected.

Matthew reveals how his team safely conducts pentests in production environments, develops proprietary detection rule sets, and helps organizations understand their infrastructure through network mapping.

The discussion encompasses a range of topics, from the risks associated with smart TVs in conference rooms to the motivations behind nation-states targeting critical infrastructure, culminating in practical advice on developing a cybersecurity roadmap for cyber-physical systems.

Chapters:

  • (00:00:00) - Welcome and Introduction to Matthew Carr's OT Security Journey
  • (00:02:30) - The Moment Exploit Code Stopped a Production Line at a Major Car Manufacturer
  • (00:06:15) - Why Most Organizations Don't Know What's Actually on Their OT Networks
  • (00:09:45) - The Three Pillars of Adamzsel: Pentesting, Monitoring, and Tabletop Exercises
  • (00:14:20) - How Attackers Know Your Infrastructure Better Than You Do
  • (00:18:50) - Smart TVs in Conference Rooms: The Hidden Security Risk with Root Access
  • (00:22:30) - Espionage vs Ransomware: The Cyber Attacks No One Is Talking About
  • (00:26:45) - Why Default Passwords on IoT Devices Are an Attacker's Favorite Entry Point
  • (00:30:20) - Building a Cybersecurity Roadmap for Cyber-Physical Systems
  • (00:33:15) - Closing Thoughts and Free OT Security White Paper from Adamzsel

Links And Resources:

Thanks so much for joining us this week. Want to subscribe to Industrial Cybersecurity Insider? Have some feedback you’d like to share? Connect with us on Spotify, Apple Podcasts, and YouTube to leave us a review!

All Episodes Previous Episode

Listen for free

Show artwork for Industrial Cybersecurity Insider

About the Podcast

Industrial Cybersecurity Insider
Everything You Need to Know to 'Get Safer Sooner'
Industrial Cybersecurity Insider offers a thorough look into the field of industrial cybersecurity for manufacturing and critical infrastructure. The podcast delves into key topics, including industry trends, policy changes, and groundbreaking innovations. Each episode will feature insights from key influencers, policy makers, and industry leaders. Subscribe and tune in weekly to stay in the know on everything important in the industrial cybersecurity world!

About your host

Profile picture for Hector Santiesteban

Hector Santiesteban