Regulation Is the Budget Unlock OT Needs | Tobias Nitzsche | Ep 124
PrOTect IT All
0:00 / 0:00
Regulation Is the Budget Unlock OT Needs | Tobias Nitzsche | Ep 124
47 просмотров · 2 дня назад
PrOTect IT All
477 подписчиков
47 просмотров · 2 дня назад
Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/go/book/yt
This episode: https://protectitallpod.com/ep124/
The OT Security Starter Kit: https://protectitallpod.com/go/kit/yt
NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and the supply chain. Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, explains what that changes on the plant floor: responsibility moves from the server rooms into the boardrooms, and from the operator to the manufacturer.
Host Aaron Crow and Tobias make the case that what gets regulated are fundamentally the basics, why 24-hour reporting starts with detection (you can't wing it), and why compliance is the business case that finally unlocks modernization budget. Then they go deep on recovery: the vendor-install backup nobody has tested, RPO and RTO in plant terms, retain values, redundant controllers that are not cyber resilience, restoring in a bubble so you can scan the copy instead of production, and where AI belongs in the Purdue model.
🎧 Episode page & full transcript: https://protectitallpod.com/ep124/
🧰 Free OT Security Starter Kit: https://protectitallpod.com/go/kit/yt
📘 The book (Kindle, paperback, hardcover): https://protectitallpod.com/go/book/yt
🤝 Sponsor the show: https://protectitallpod.com/go/sponso...
Key Learnings:
• What gets regulated are the basics: risk assessment, asset inventory, cyber hygiene, detection. Treat legislation as a utility, not a paper exercise.
• 24-hour reporting starts at detection. If you cannot tell what happened and whether it is an incident, the clock beats you.
• Compliance is the budget unlock. Map the modernization you already wanted to the requirement it satisfies.
• The vendor-install backup is not a backup until you have restored it. Know your RPO and RTO in plant terms, and capture retain values.
• Redundant controllers protect against failure, not compromise. A bad firmware push counts as a cyber incident, no nation state required.
• Restore in a bubble. Be as intrusive as you like on the copy, never on production.
• AI belongs at level 3, not at level 0 or 1: the daily brief for the one-person water utility, not the operator.
Key Moments:
0:00 You can't wing this (cold open)
0:32 Back from DEF CON, and OT still gets missed
3:55 From the server rooms into the boardrooms
7:31 Legislation as the modernization unlock
9:26 NIS2 and the CRA: who is in scope now
11:39 You can't wing 24 hour reporting
13:49 Be prepared to restore, not just to plan
16:23 The vendor install backup problem
18:37 Redundant controllers are not resilience
22:19 Water: one person, fifty jobs
24:16 No nation state required
25:38 Restore in a bubble, scan the copy
29:16 The week the executives lost their email
31:55 NIS2 Article 20: personal liability
33:42 What was hot at DEF CON: AI on both sides
36:58 AI as the daily brief, not the operator
39:49 The pineapple on the plane
42:07 Borrow the safety engineers
44:12 Legislation is a utility, not paperwork
About the Guest:
Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Tobias is based in Germany.
Connect with Tobias: / tobias-nitzsche-37339735
ABB Energy Industries: https://global.abb/group/en/organizat...
Protect It All: All Things Cybersecurity, from IT to OT
Hosted by Aaron Crow (about: https://protectitallpod.com/#about)
Website: https://protectitallpod.com
Blog: https://protectitallpod.com/blog/
Apple Podcasts: https://podcasts.apple.com/us/podcast...
Spotify: https://open.spotify.com/show/1Vvi0eu...
X: / protectitall
Facebook: / protectitallpodcast
Be a guest or suggest a topic: info@protectitall.co
#otsecurity #nis2 #cybersecurity #criticalinfrastructure #protectitall