Перейти к содержимому

Regulation Is the Budget Unlock OT Needs | Tobias Nitzsche | Ep 124

PrOTect IT All

0:00 / 0:00

Regulation Is the Budget Unlock OT Needs | Tobias Nitzsche | Ep 124

47 просмотров · 2 дня назад
PrOTect IT All
477 подписчиков
47 просмотров · 2 дня назад
Work with Aaron: https://protectitallpod.com/work/ The book: https://protectitallpod.com/go/book/yt This episode: https://protectitallpod.com/ep124/ The OT Security Starter Kit: https://protectitallpod.com/go/kit/yt NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and the supply chain. Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, explains what that changes on the plant floor: responsibility moves from the server rooms into the boardrooms, and from the operator to the manufacturer. Host Aaron Crow and Tobias make the case that what gets regulated are fundamentally the basics, why 24-hour reporting starts with detection (you can't wing it), and why compliance is the business case that finally unlocks modernization budget. Then they go deep on recovery: the vendor-install backup nobody has tested, RPO and RTO in plant terms, retain values, redundant controllers that are not cyber resilience, restoring in a bubble so you can scan the copy instead of production, and where AI belongs in the Purdue model. 🎧 Episode page & full transcript: https://protectitallpod.com/ep124/ 🧰 Free OT Security Starter Kit: https://protectitallpod.com/go/kit/yt 📘 The book (Kindle, paperback, hardcover): https://protectitallpod.com/go/book/yt 🤝 Sponsor the show: https://protectitallpod.com/go/sponso... Key Learnings: • What gets regulated are the basics: risk assessment, asset inventory, cyber hygiene, detection. Treat legislation as a utility, not a paper exercise. • 24-hour reporting starts at detection. If you cannot tell what happened and whether it is an incident, the clock beats you. • Compliance is the budget unlock. Map the modernization you already wanted to the requirement it satisfies. • The vendor-install backup is not a backup until you have restored it. Know your RPO and RTO in plant terms, and capture retain values. • Redundant controllers protect against failure, not compromise. A bad firmware push counts as a cyber incident, no nation state required. • Restore in a bubble. Be as intrusive as you like on the copy, never on production. • AI belongs at level 3, not at level 0 or 1: the daily brief for the one-person water utility, not the operator. Key Moments: 0:00 You can't wing this (cold open) 0:32 Back from DEF CON, and OT still gets missed 3:55 From the server rooms into the boardrooms 7:31 Legislation as the modernization unlock 9:26 NIS2 and the CRA: who is in scope now 11:39 You can't wing 24 hour reporting 13:49 Be prepared to restore, not just to plan 16:23 The vendor install backup problem 18:37 Redundant controllers are not resilience 22:19 Water: one person, fifty jobs 24:16 No nation state required 25:38 Restore in a bubble, scan the copy 29:16 The week the executives lost their email 31:55 NIS2 Article 20: personal liability 33:42 What was hot at DEF CON: AI on both sides 36:58 AI as the daily brief, not the operator 39:49 The pineapple on the plane 42:07 Borrow the safety engineers 44:12 Legislation is a utility, not paperwork About the Guest: Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Tobias is based in Germany. Connect with Tobias:   / tobias-nitzsche-37339735   ABB Energy Industries: https://global.abb/group/en/organizat... Protect It All: All Things Cybersecurity, from IT to OT Hosted by Aaron Crow (about: https://protectitallpod.com/#about) Website: https://protectitallpod.com Blog: https://protectitallpod.com/blog/ Apple Podcasts: https://podcasts.apple.com/us/podcast... Spotify: https://open.spotify.com/show/1Vvi0eu... X:   / protectitall   Facebook:   / protectitallpodcast   Be a guest or suggest a topic: info@protectitall.co #otsecurity #nis2 #cybersecurity #criticalinfrastructure #protectitall