Antonio González

Cybersecurity Under Pressure. Real Attacks, Real Lessons

This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business teams. Topics covered: OT security, ICS cybersecurity, industrial control systems, critical infrastructure protection, NIS2 compliance, Zero Trust architecture, operational technology resilience, railway cybersecurity, automotive security, and cyber-physical systems.

Author

Antonio González

Category

Technology

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Stopping Stealthy Radio Jamming in Industrial 5G: When the Air Interface Becomes the Attack Surface 10.07.2026

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we explore a risk that is often underestimated in industrial 5G environments: stealthy radio jamming. Industrial 5G is usually presented as a driver for uptime, low latency, automation and flexible production. But once wireless connectivity supports mobile robots, AGVs, sensors, remote operations or safety-relevant workfl...

How EV Chargers Could Crash the Grid: The Cyber Risk Behind Mass Electrification 08.07.2026

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we explore how electric vehicle chargers could become more than a mobility cybersecurity problem. As EV charging infrastructure grows, thousands of connected chargers start acting like distributed energy assets. Each charger depends on firmware, cloud platforms, payment systems, operator backends, remote maintenance, APIs...

Defending Industrial Networks from Cyber Attacks: Why Resilience Beats Perimeter Security 06.07.2026

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we look at what it really means to defend an industrial network when production, safety and uptime are part of the equation. Industrial environments are not protected by applying standard IT controls in isolation. Many plants still depend on legacy assets, flat network zones, fragile protocols, shared vendor access, engin...

Industrial 5G and the Uptime Trap: When Connectivity Becomes a Production Risk 03.07.2026

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we explore the hidden risk behind industrial 5G: the belief that better connectivity automatically means stronger resilience. Private 5G, edge computing and connected industrial assets can improve flexibility, latency and operational visibility. But they also change the risk model of the plant. The production environment...

Hacking EV Chargers to Stress the Grid: When Mobility Becomes Critical Infrastructure 01.07.2026

n this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we explore why EV chargers should no longer be treated as simple connected devices. As electric mobility scales, charging infrastructure becomes part of a wider cyber-physical system that connects vehicles, users, payment platforms, operators, cloud backends, energy providers and the grid. A weakness in one layer may not o...

Teenage Hackers and Software-Defined Factories: When Industrial Risk Starts with Identity 29.06.2026

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we look at a uncomfortable shift in industrial cybersecurity: the attacker does not always need deep OT knowledge to create operational impact. As factories become more software-defined, the attack surface moves beyond PLCs, HMIs and plant networks. Identity, remote access, cloud services, engineering workstations, suppli...

The Compliance Theater. Draining Supplier R&D and Breaking Automotive Silos. 26.06.2026

our Tier-2 supplier just spent 80,000 euros on compliance. Their product cybersecurity did not improve by a single cent. In this episode of "Cybersecurity Under Pressure: Real Attacks, Real Lessons," we look at the compliance trap the automotive industry has built for its own supply chain. A single electronic component supplier must now navigate the overlapping demands of UNR 155, TISAX,...

The Red Signal. Paralyzing a Railway Network with a Single Patch 24.06.2026

In railway signaling, an uncoordinated security patch rarely causes a fatal accident. But it can paralyze an entire network. In this episode of Cybersecurity Under Pressure Real Attacks Real Lessons, we explore the structural tension between RAMS engineering and cybersecurity in critical railway infrastructure. We operate under EN 50129, where fail-safe guarantees that an interlocking system degra...

The Shadow Corridor. Legacy VPNs and the Financial Blast Radius in OT 22.06.2026

Last month, a maintenance technician connected to a Level 1 PLC via VPN to fix a sensor. He did not know he had just opened the only door an attacker needed. In this episode of Cybersecurity Under Pressure Real Attacks Real Lessons, we look at a quiet failure in industrial architecture. The Purdue Model is not dead, but it is being bypassed from the inside. A direct VPN tunnel to OT infrastructure...

Missing Cybersecurity Evidence Can Delay Production 19.06.2026

The next production delay may not come from a missing component. It may come from missing cybersecurity evidence. In this episode of Cybersecurity Under Pressure: real attacks, real lessons, we look at a growing risk in automotive supply chains: suppliers may deliver the ECU, the software may work, and the release plan may look under control. Then a vulnerability appears, a VSOC event raises quest...

An IDPS Alert Is Not an Incident Response Capability 17.06.2026

Detecting a suspicious event in a vehicle is not the same as knowing what to do next. In this episode of Cybersecurity Under Pressure: real attacks, real lessons, we look at one of the weakest points in automotive cybersecurity: the gap between detection and decision-making. A vehicle may report suspicious diagnostic behaviour. A backend may receive telemetry. A VSOC may flag an anomaly linked to...

The Restart Bottleneck Is Not the Backup. It Is the Evidence. 15.06.2026

After an OT cyber incident, restoring systems is only the visible part of recovery. The harder question comes next: who can prove that production is safe to restart? In this episode of Cybersecurity Under Pressure: real attacks, real lessons, we look at why OT recovery is different from IT recovery. A backup may exist. The PLC logic may appear unchanged. The virtual machine may boot. But in automo...

When ECUs Meet Malice 12.06.2026

What if the most vulnerable point in automotive cybersecurity isn't the car itself, but the station that gives it its software identity, setting the stage for a potential disaster that could put lives at risk. In this episode we break down the critical intersection of product cybersecurity and factory cybersecurity, and explore the potential consequences of a compromised ECU flashing station....

Zero Trust Meets Twenty Year Old Code 10.06.2026

What happens when a twenty-year-old industrial control system meets the latest Zero Trust security protocols, and the two just can't seem to get along? In this episode we break down the challenges of implementing Zero Trust in industrial environments, where legacy devices don't speak the language of modern identity and security. We walk through real-world examples of how to design a Zero T...

Beyond Backup Recovery 08.06.2026

What happens when a production line grinds to a halt, not because of a technical failure, but because trust in the engineering environment has been lost? In this episode we break down the real cost of an OT cyber incident, and explore the complexities of recovery in operational technology environments. We walk through a real case where the question is no longer just about restoring systems, but ab...

Cyber Gaps in Automotive Supply 05.06.2026

What happens when a vulnerability is discovered in a car's system after production has started, and nobody knows who's responsible for fixing it? In this episode we break down the messy world of automotive cybersecurity, where gaps in responsibility between companies can put entire systems at risk. We walk through real-world scenarios where the lack of clear agreements and ownership can le...

When Patches Stop Production 03.06.2026

What happens when a security patch intended to protect your system ends up being the cause of a catastrophic operational incident? In this episode we break down the nuances of patch management in industrial environments, where the stakes are high and the consequences of a mistake can be devastating. We walk through real-world scenarios where a simple patch can bring down an entire production line,...

Ransomware Beyond Encryption 01.06.2026

What if a single login credential was all a hacker needed to bring your entire production line to a grinding halt, without even touching your industrial control systems? In this episode we break down the grey zone where ransomware attacks on operational technology can have devastating consequences, and explore the often-overlooked vulnerabilities that can allow attackers to move undetected between...

Beyond Asset Coverage 29.05.2026

Can a single overlooked device really bring down your entire network, and are you unwittingly leaving the door open to cyberattacks by focusing on the wrong security strategy? In this episode we break down the flaws in traditional network visibility programs and explore how microsegmentation can limit the damage of unseen assets. We walk through real-world examples of how IT dependencies and vendo...

When Containment Fails Recovery 28.05.2026

What if your team contained a cyber incident, but the real damage was only just beginning? In this episode we break down the disconnect between IT and engineering timelines, and explore how the NIS2 directive is raising the bar for incident recovery and accountability. We walk through the implications of Articles 20, 21, and 34, and what they mean for management bodies and cybersecurity teams. We...

Exposed Paths in OT Networks 25.05.2026

What if the biggest security risk to your industrial control systems isn't a malicious hacker, but rather a simple disconnect between when a work order closes and when network access is actually shut off? In this episode we break down the hidden dangers of insecure remote access conditions and explore why PAM is not failing in OT, but rather being asked to enforce a physical work state it cannot s...

Shipping the Code That Security Rejected 21.05.2026

Your vehicle's biggest security threat might be arriving with a perfectly valid digital signature and your company's own stamp of approval. In this episode, we break down why the shift to software-defined vehicles is currently failing at the release gate. We walk through the uncomfortable reality of SOP pressure and argue that current security assessments are often treated as advisory rather than...

When a Patch Reopens the Safety Case 20.05.2026

A simple security patch can fix a vulnerability and still become a total operational nightmare that brings an entire railway network to a standstill. In this episode, we break down the high-stakes collision between the new Cyber Resilience Act and the rigid, uncompromising world of railway safety certification. We walk through why architectural perfection is a myth for brownfield systems and how t...

The Trap of the Trusted Engineering Session 19.05.2026

Your VPN is lying to you about how safe your plant actually is. In this episode, we break down why relying on MFA and session monitoring is just giving you a front-row seat to your own incident. We walk through the reality of session hijacking in brownfield OT and argue why the network should never be the one deciding who gets to touch the control layer. This is about the high-stakes shift from le...

When VEX Becomes a Bureaucratic Shield 15.05.2026

Your SBOM is probably useless, and it is time we talked about why. In this episode, we look past the hype of vulnerability scanning to the uncomfortable reality of the software-defined vehicle. We walk through how suppliers are using VEX as a bureaucratic shield to dodge patches and why your security program is likely just a mountain of expensive noise. We argue that if you are not prepared to cha...

Listen to the Cybersecurity Under Pressure. Real Attacks, Real Lessons podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.