Critical Infrastructure Risks
Easy Prey11 Feb

Critical Infrastructure Risks

Most cybersecurity conversations focus on stolen data, breached accounts, and attacks that live entirely on screens. This episode looks at a far more consequential threat: what happens when cyberattacks target the physical systems that keep society running. Power, water, transportation, and manufacturing. When those systems fail, the consequences aren't just digital. They're immediate, visible, and sometimes dangerous.

My guest is Lesley Carhart, Technical Director of Incident Response at Dragos, a cybersecurity firm focused exclusively on protecting critical infrastructure. Lesley specializes in industrial control systems and operational technology, investigating real-world attacks against power plants, water systems, transportation networks, and industrial facilities built on aging, irreplaceable technology.

We talk about why these environments are uniquely vulnerable, how ransomware groups and nation-state actors quietly gain long-term access, and why many compromises go undetected for years. The conversation also explores the limits of traditional cybersecurity thinking, the real-world constraints operators face, and what organizations can realistically do to improve security when failure isn't an option.

Show Notes:
  • [01:30] Lesley Carhart is here and explains what operational technology is and why industrial systems are uniquely vulnerable
  • [03:40] How decades-old computers still run power plants, water systems, and transportation infrastructure
  • [06:10] Why industrial environments can't simply patch, upgrade, or shut systems down
  • [08:25] The mindset shift required when safety and continuity matter more than stopping an intrusion
  • [10:40] Why air-gapped systems are mostly a myth in modern critical infrastructure
  • [13:15] How remote access became unavoidable—and one of the biggest risk factors
  • [16:05] The three main threat categories facing industrial systems: ransomware, insiders, and nation-state actors
  • [18:45] Why ransomware is especially damaging in power, water, and manufacturing environments
  • [21:30] How nation-state attackers quietly establish footholds years before taking action
  • [24:20] Why many industrial compromises go undetected for months—or even years
  • [27:10] What incident response looks like when you can't just "pull the plug"
  • [30:05] The most common causes of industrial failures: human error, maintenance issues, and environment
  • [32:40] A surprising incident that looked like a nation-state attack—but wasn't
  • [34:55] Why critical infrastructure organizations often feel pressure to pay ransoms
  • [37:00] Practical starting steps for organizations with aging, mission-critical systems
  • [39:20] Advice for people interested in industrial cybersecurity and working with legacy technology
  • [42:10] Why mentorship matters and why Lesley chooses to give back to the field

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

Links and Resources:

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(329)

Job Recruiter Scams

Job Recruiter Scams

Job hunting is hard enough without having to stop and ask whether the recruiter in your inbox is even real. My guest today, Jay Jones, ran into that problem firsthand after being laid off in December ...

24 Juni 35min

Bail Bonds Scams

Bail Bonds Scams

Getting a call that someone you love has been arrested is scary enough. Getting that call from someone who sounds official, knows just enough to seem credible, and says you have to send money right aw...

17 Juni 36min

Confessions of a Fraudster

Confessions of a Fraudster

Technology keeps changing, but many of the most effective scams still come down to something very human: trust. My guest today is Tony Sales, co-founder of We Fight Fincrime and Underworld TV. Tony ha...

10 Juni 54min

Personal Safety

Personal Safety

Scams and safety threats don't always announce themselves. Sometimes they start quietly, with a moment of distraction, a strange feeling you ignore, or a situation that shifts just enough to test whet...

3 Juni 43min

Data For Sale

Data For Sale

Everyday conveniences ask for tiny pieces of information all the time like a phone number at checkout, a zip code at the register, an email address for a receipt, or a loyalty account for a small disc...

27 Maj 43min

Exploiting Psychology

Exploiting Psychology

Scams are often explained as a failure of judgment, but the truth is far more human. People are not fooled because they are foolish. They are manipulated at the exact moment emotion overrides logic, w...

20 Maj 45min

Investment Traps

Investment Traps

Investment losses can be confusing because they do not always tell the whole story. Sometimes money is lost because the market has changed. Other times, an investor was sold something they did not und...

13 Maj 47min

Elder Exploitation

Elder Exploitation

Aging parents often rely on the people closest to them for help, but what happens when that help becomes a way to take control? For Charles Wallace, the warning signs started small. His mother's fridg...

6 Maj 39min

Populärt inom Politik & nyheter

svenska-fall
motiv
p3-krim
aftonbladet-krim
de-fyras-gang
spar
tv4-nyheterna-story
rss-expressen-dok
flashback-forever
aftonbladet-daily
rss-sanning-konsekvens
svd-dokumentara-berattelser-2
rss-vad-fan-hande
svd-ledarredaktionen
kungligt
rss-flodet
rss-krimreportrarna
rss-frandfors-horna
olyckan-inifran
grans