Jason Edwards
Certified: The CompTIA SecOT+ Audio Course
Certified: The CompTIA SecOT Certification Audio Course is built for security practitioners and aspiring operators who need a practical, audio-first path into day-to-day security work. If you’re early career in cybersecurity, moving from IT into security operations, or stepping into a SOC-adjacent role, this course is designed to meet you where you are. You don’t need a lab rack or a perfect study schedule. You need clear explanations, realistic context, and a steady cadence that fits commutes, workouts, and the hours in between meetings. In Certified: The CompTIA SecOT Certification Audio Cou...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 63 — Learn from Indirect-Impact Events: Colonial Pipeline, SolarWinds, Maersk, AcidRain, CrowdStrike 2024, RTX 23.02.2026 18:31
This episode explains why indirect-impact events belong in OT security study, because OT outages often originate upstream in IT, suppliers, or shared services even when control networks remain technically untouched. You’ll learn how disruptions like ransomware, widespread IT compromise, supply chain tampering, or platform outages can halt operations through billing systems, scheduling, identity se...
Episode 62 — Learn from Direct-Impact OT Events: Stuxnet, TRISIS, BlackEnergy, FrostyGoop, Industroyer 23.02.2026 17:50
This episode uses major OT incidents as learning instruments, focusing on what made them directly impactful to physical processes and what lessons translate into exam-ready security reasoning. You’ll analyze how these events demonstrate common patterns such as highly tailored targeting, deep understanding of industrial environments, and exploitation of trust relationships that were never designed...
Episode 61 — Apply Threat Intelligence Frameworks: Diamond Model, ATT&CK for ICS, and Kill Chain 23.02.2026 15:31
This episode teaches how to use structured threat intelligence frameworks to organize thinking and avoid reactive, headline-driven decisions in OT environments. You’ll learn what the Diamond Model is trying to capture by relating adversary, capability, infrastructure, and victim into a repeatable analytic picture, then connect that to how you build and validate hypotheses when evidence is incompl...
Episode 60 — Use the Intelligence Life Cycle: Collection, Analysis, Dissemination, and Feedback Loops 23.02.2026 15:19
This episode explains the intelligence life cycle as a repeatable workflow that turns raw information into decisions, which helps you answer SecOT+ questions about process discipline and operationalization rather than just recognizing terms. You’ll learn the core phases of collection, analysis, dissemination, and feedback, and how each phase must be tailored for OT constraints like limited telemet...
Episode 59 — Threat Intelligence Foundations: Intelligence Types and What Each One Delivers 23.02.2026 15:41
This episode teaches threat intelligence foundations by explaining what different intelligence types deliver, how they are produced, and how to use them in OT without drowning in data that does not improve safety or resilience. You’ll learn the practical differences among strategic, operational, tactical, and technical intelligence, including who each type is for and what decisions it supports, fr...
Episode 58 — Monitor and Disposition Risk: Residuals, Audits, Reporting, Escalations, and Decisions 23.02.2026 15:15
This episode explains how to monitor and disposition risk after controls are implemented, because residual risk is never zero and the exam often tests whether you can keep decision-making disciplined over time. You’ll learn how to define residual risk in operational terms, including what remains possible despite controls, what conditions would increase exposure, and what indicators suggest that as...
Episode 57 — Operate a Controls Calendar: Scheduling, Evidence, and Sustainable Compliance 23.02.2026 14:23
This episode teaches how to operate a controls calendar so OT controls are tested, evidenced, and maintained on a predictable rhythm that supports both compliance and reliability without creating last-minute panic. You’ll learn why a calendar is more than dates on a page, because it defines who performs control checks, what evidence is collected, what systems are affected, and how activities align...
Episode 56 — Track Inherited Risk and Maturity Indicators: What You Own Versus What You Inherit 23.02.2026 14:56
This episode explains inherited risk in OT as the portion of risk you carry because of upstream dependencies and shared services, which is a frequent blind spot when teams assume “we secured our network” but rely on systems they do not fully control. You’ll learn to distinguish what you directly own, such as local segmentation rules and site access governance, from what you inherit, such as enterp...
Episode 55 — Control and Treat OT Risk: Controls Catalogs, Documentation, and Acceptance Criteria 23.02.2026 15:19
This episode teaches how to control and treat OT risk using controls catalogs, disciplined documentation, and clear acceptance criteria, which is core to making risk decisions auditable and sustainable. You’ll learn how to translate a risk statement into treatment options such as avoidance, mitigation, transfer, or acceptance, then select controls that match operational constraints and safety prio...
Episode 54 — Understand OT Pen Tests and Adversarial Emulation: Safety Constraints and Value 23.02.2026 17:55
This episode explains how penetration testing and adversarial emulation work in OT environments where safety, uptime, and vendor constraints change what “testing” can responsibly mean, a nuance that exam questions often probe. You’ll learn the difference between a traditional pen test focused on vulnerability discovery and exploitation, and adversarial emulation focused on reproducing realistic at...
Episode 53 — Conduct Architecture Reviews for OT Risk: Data Flows, Trust Boundaries, and Weak Links 23.02.2026 17:26
This episode teaches how to conduct architecture reviews for OT risk by focusing on data flows, trust boundaries, and weak links that create real-world compromise paths, which aligns closely with SecOT+ objectives around segmentation and defensible design. You’ll learn how to map functional flows such as control commands, telemetry, historian feeds, engineering changes, and remote support sessions...
Episode 52 — Choose Qualitative Versus Quantitative Risk: When Each Method Actually Helps 23.02.2026 13:15
This episode explains how to choose qualitative versus quantitative risk methods in OT without turning risk work into either hand-waving or false precision, a balance that the SecOT+ exam often tests through “best next step” decisions. You’ll learn when qualitative methods are the right tool, such as early program stages, limited data environments, and safety-driven decisions where conservative ju...
Episode 51 — Use Failure Mode and Criticality Thinking: Safety, Reliability, and Cascading Effects 23.02.2026 14:28
This episode teaches failure mode and criticality thinking in OT as a practical way to predict how small faults become large incidents, which is essential for SecOT+ questions that revolve around safe prioritization under uncertainty. You’ll learn how to break a system into components, identify plausible failure modes, and connect each failure to effects on safety, reliability, product quality, an...
Episode 50 — Evaluate Third-Party Risk: Integrators, Remote Support, and Shared Responsibility 23.02.2026 15:32
This episode teaches how to evaluate third-party risk in OT, because integrators and remote support providers often have the access and authority that determines whether controls are enforceable or merely aspirational. You’ll learn how to identify third-party roles, what systems they touch, what credentials and pathways they use, and what shared responsibility actually means when something fails,...
Episode 49 — Assess Supply Chain Risk in OT: Hardware, Software, and Vendor Dependencies 23.02.2026 17:06
This episode explains how to assess supply chain risk in OT with a focus on dependencies that can affect safety and uptime long before an organization realizes the risk is “cyber.” You’ll learn to evaluate hardware and firmware provenance, software update channels, licensing and activation dependencies, and the operational risk of vendor-only tools and proprietary protocols that can create single...
Episode 48 — Apply Scenario-Based Risk Methods: Realistic Failure Paths and Meaningful Mitigations 23.02.2026 13:04
This episode teaches scenario-based risk methods that focus on believable failure paths, because OT risk work is strongest when it mirrors how systems actually fail and how people actually respond under pressure. You’ll learn how to build a scenario from an initiating event, enabling conditions, and a path to impact, then identify where controls can break the chain without relying on perfect dete...
Episode 47 — Identify OT Threat Surface: Vectors, Exposure, and Threat Actors in Context 23.02.2026 14:43
This episode explains how to identify the OT threat surface by combining technical exposure with operational context, because OT risk is shaped as much by access pathways and habits as it is by vulnerabilities. You’ll learn to separate vectors, such as remote access, removable media, vendor connections, wireless links, and IT-to-OT pivot paths, from exposure, such as weak authentication, flat netw...
Episode 46 — Scope OT Risk Assessments: Assets, Networks, and Boundaries You Can Defend 23.02.2026 14:01
This episode teaches how to scope OT risk assessments so the results are defensible, actionable, and aligned to how the plant actually works, which is a common weak spot in both real programs and exam scenarios. You’ll learn how to define scope using operational boundaries like units, cells, lines, sites, and shared services, then map those to network zones, conduits, remote access paths, and vend...
Episode 45 — Model Likelihood and Consequence: Risk Variables That Drive Real Decisions 23.02.2026 14:25
This episode explains how to model likelihood and consequence in OT without pretending you have perfect data, because good risk decisions come from disciplined reasoning, not false precision. You’ll learn what “likelihood” means when incidents can be rare but impactful, and how to account for exposure, threat capability, existing controls, and operational conditions that make certain failures mor...
Episode 44 — Explain OT Risk Assessment Frameworks: NIST and ISA/IEC Approaches in Practice 23.02.2026 14:22
This episode teaches how OT risk assessment frameworks are applied in practice, so you can recognize what a scenario is asking for when it references structured risk work rather than ad hoc judgment. You’ll learn how NIST-style approaches emphasize repeatability, documented controls, and evidence-driven decision paths, while ISA/IEC approaches emphasize zones, conduits, and security levels aligned...
Episode 43 — Produce OT Documentation That Works: Policies, Processes, Standards, and SOPs 23.02.2026 15:16
This episode explains how to create OT security documentation that people can actually use under pressure, because unreadable policies and vague procedures fail exactly when incidents and outages happen. You’ll learn the difference between policies that set intent, standards that define requirements, processes that describe repeatable workflows, and SOPs that guide step-by-step execution, then see...
Episode 42 — Determine Asset Criticality: What Fails First, What Hurts Most, and Why 23.02.2026 13:59
This episode teaches how to determine OT asset criticality using operational reality rather than guesswork, because risk decisions depend on knowing what truly matters first. You’ll learn how to rank assets based on safety impact, production dependency, environmental consequence, recoverability, and the time sensitivity of control functions, so “critical” means something measurable. We connect cri...
Episode 41 — Build Training and Awareness for OT Teams: Competence Without Chaos 23.02.2026 16:16
This episode explains how to build OT security training that improves competence without turning daily operations into a compliance exercise that people avoid. You’ll learn how to distinguish awareness from skill, and how to tailor training to roles like operators, engineers, maintenance, and vendors so content matches what each group can actually influence. We connect training design to exam-rele...
Episode 40 — Measure OT Security With Purpose: Metrics, Measures, and What They Really Signal 23.02.2026 15:03
This episode teaches how to measure OT security in a way that supports decisions, because poor metrics create false confidence, misdirect resources, and frustrate operations with reporting that does not reflect reality. You’ll learn the difference between metrics and measures, and why the most useful indicators tie directly to risk reduction, such as improved asset visibility, reduced unmanaged ac...
Episode 39 — Use MOUs and SOWs Correctly: Scope, Responsibilities, and Deliverable Discipline 23.02.2026 13:52
This episode explains how Memoranda of Understanding and Statements of Work support disciplined OT security execution by defining scope and deliverables clearly enough that operations are not surprised midstream. You’ll learn how an MOU typically frames collaboration and shared intent across organizations or internal groups, while an SOW specifies exactly what work will be performed, what artifact...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.