Eric Sorensen
Security Breach
A weekly discussion of new developments and the latest cybersecurity threats, including ransomware, malware, phishing schemes, DDoS attacks and more, facing the U.S. industrial sector.
Author
Eric Sorensen
Category
Podcast website
Latest episode
Jun 24, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Time to 'Rip off the Band-Aid' to Ensure Security 05.09.2024 39:13
Send us Fan Mail A smarter, well-funded hacker community means embracing basic, yet daunting cyber challenges. In manufacturing, regardless of your role, avoiding downtime is an obvious priority, and one of the motivating factors driving investments in cybersecurity. In working to mitigate potential DDoS attacks or malware drops, manufacturers are tapping into more resources in heightening their a...
Combating the 20th Century Mafia with a Stronger Human Firewall 28.08.2024 46:07
Send us Fan Mail Sophos recently reported that 65 percent of manufacturing and production organizations were hit by ransomware last year, which, unlike other sectors, is an increase. Overall, these attacks have increased by 41 percent for manufacturing since 2020. Additionally, the cybersecurity firm found that 44 percent of computers used in manufacturing have been impacted by a ransomware attack...
Tearing Down the 'Set It and Forget It' Mindset 22.08.2024 41:54
Send us Fan Mail I recently watched an interesting documentary called Turning Point: The Bomb and the Cold War on Netflix. Great watch – I’d highly recommend it. Essentially it positioned nearly every prominent geo-political event since World War II as fallout from the U.S. dropping the nuclear bomb on Japan to end World War II. Similarly, we can look at a number of recent, major cybersecurity eve...
Bridging the IT-OT Divide 15.08.2024 20:30
Send us Fan Mail When I was a kid, we always looked forward to my dad’s work picnic. He was a tool and dye maker for a leading caster manufacturer that would rent out a local park, make a ton of food and put on various games and activities for the families. One of the highlights of this day was a softball game pitting the office versus the shop. The good-natured shots that were fired across the du...
'There's No Bulletproof Vest' in Cybersecurity 08.08.2024 51:29
Send us Fan Mail An ethical cyber researcher breaks down the 'tsunami of exposed data' he continues to uncover. When it comes to solving industrial cybersecurity's biggest challenges, I think we have to continue to ask questions that simultaneously tackle basic blocking and tackling concerns, as well as those that lead to bad news. Both prevent us from putting our heads in the sand...
Are We Over-Connected? 02.08.2024 19:51
Send us Fan Mail The landscape of industrial cybersecurity continues to change and evolve, and demands a vigilant monitoring of the next threat, vulnerability or potential soft spot in our defenses. That’s why we continue to produce Security Breach , and, by the way, continue to be so appreciative of the growth and support we’ve received from each of you. That said, once in a while it’s good to ta...
The $25M 'Wake-Up Call' Supply Chain Hack 24.07.2024 30:42
Send us Fan Mail According to IBM’s Cost of a Data Breach Report , nearly 20 percent of the organizations surveyed stated that they have experienced a breach stemming from a compromise in their supply chain, or a vulnerability related to it. The average cost of these breaches was estimated at just under $4.5 million. Their data also found that attacks emanating from the supply chain had a longer l...
The Dollars and Sense of Cybersecurity 19.07.2024 40:27
Send us Fan Mail Due to the rise in attacks on manufacturing and critical infrastructure, and the devasting impacts these attacks have on daily lives around the world, the World Economic Form recently unveiled a report entitled Building a Culture of Cyber Resilience in Manufacturing . This initiative not only identified the sector’s primary challenges for developing a culture of cyber resilience,...
There's No 'Plant the Flag' Moment in Cybersecurity 11.07.2024 33:08
Send us Fan Mail When looking at industrial cybersecurity, more attention is being paid to how workers are logging in to access critical machinery, software or data. And according to Trustwave Threat Intelligence’s recent Manufacturing Threat Landscape report, 45 percent of attacks experienced by manufacturers stemmed from the bad guys accessing credentials. Whether by utilizing brute-force tactic...
'Nobody Should Get Ransomwared' 27.06.2024 38:05
Send us Fan Mail As we’ve discussed numerous times on Security Breach , terms like change, evolution and constant are more than just buzz terms – they’re a simple reality of working in the industrial OT space. Whether we’re discussing threat actors from Stuxnet to Lockbit, tactics from social engineering to double-extortion ransomware, or vulnerability sources ranging from weak passwords to embedd...
The Protection and Productivity of Zero Trust 20.06.2024 43:09
Send us Fan Mail Over the last nearly 100 episodes of Security Breach we’ve discussed a wide range of strategies for protecting the manufacturing enterprise. But perhaps the most polarizing of these has been Zero Trust. While some unwaveringly champion the cause of this approach, others question the ways in which it is typically deployed. Perhaps this dichotomy is best represented in Palo Alto and...
OT's Legacy Tech Challenges 12.06.2024 28:14
Send us Fan Mail One of the more common obstacles that we discuss here on Security Breach is how increased connectivity has combined with new Industry 4.0 technologies to constantly expand the OT attack surface. In the midst of all this expansion, it’s easy to either overlook cybersecurity concerns, or put too much trust in the embedded security features of the new assets. So, while this usually...
Shutting Down 'Spy Board' Threats 05.06.2024 34:21
Send us Fan Mail Those of you with a military or law enforcement connection are probably, and unfortunately, familiar with the term collateral damage. While this phrase has a legacy in these environments, it’s also become an unwelcome addition to the realm of cybersecurity. Examples of this dynamic can be found in a number of hacktivist attacks that targeted infrastructure in a certain region, but...
The OT Threat Landscape's Infectious Nature 30.05.2024 43:35
Send us Fan Mail Viewing hacks as diseases to address evolving threats, vulnerabilities and tools like AI. Like many of you, I recently dove into Verizon’s 2024 Data Breach Investigations Report (DBIR ) . And while there’s a plethora of data housed in the report that could fuel conversations on a multitude of topics, I chose the following two pieces of information: While credential harvesting and...
Knowing How to Arm Yourself for Battle 20.05.2024 36:41
Send us Fan Mail It starts with a dedication to enhanced visibility. One of the big conversations regarding OT security revolves around the use of tools. Some have too many, others not enough and everyone is searching for the funds to mange and obtain the right ones for a constantly evolving threat landscape. The key to understanding which tools are right for you and your organization not only dem...
Supply Chains Are a Hacker's Gateway 16.05.2024 33:17
Send us Fan Mail Many attacks on manufacturers are just the first step in going after even bigger targets. One of the inescapable truths about the industrial sector is that it is usually the ultimate proving ground for product performance. When we look at some of the technologies that have created seismic social shifts, tools like operational software, wireless connectivity and numerous monitoring...
The Hacks! 08.05.2024 16:04
Send us Fan Mail In this episode, we dive into some of the most notorious attacks to hit manufacturing over the last six months. In addition to speaking with cybersecurity experts from around the world for this podcast, I’ve also been able to do a fair amount of reporting on our websites regarding several high-profile industrial attacks. So, I felt like it could be interesting to present some of t...
Security Breach: Predictions That Landed 01.05.2024 31:28
Send us Fan Mail A look back at Security Breach guest's most accurate and timely industrial cybersecurity predictions. As we near our 100th episode of Security Beach , I thought it would be a good time to take a look back at some of our guest’s predictions from the previous 12 months. If you want to check out the full episodes from any of these previous guests, you can find them in the show...
DMZs, Alarm Floods and Prepping for 'What If?' 24.04.2024 47:50
Send us Fan Mail The new factors impacting a growing attack surface, and how to evolve your cyber risk strategies. The origins of what we talk about here on Security Breach can go back to any number of transformational events, but the reality is that all of them contributed an individual component to the unique mosaic that is the legacy of industrial cybersecurity. What is most interesting is that...
Weaponizing Secure-By-Design 17.04.2024 42:25
Send us Fan Mail How a greater focus on new and legacy OT connections could alter the cybersecurity battlefield. Everything old … is new again. While that might seem like a natural lead-in for discussing hacker tactics, that same mantra rings true when discussing OT technology. Mordor Intelligence recently reported that U.S. manufacturing spent over $307 billion on digital transformation technolog...
The Impacts of Over-Connectivity and Mobile Defeatism 10.04.2024 48:44
Send us Fan Mail The good, the bad and the ugly of mobile device security in the expanding OT attack landscape. Included in the challenges associated with securing an ever-expanding OT attack surface is the role played by the increasing use of mobile devices – at both the enterprise and individual level. In fact, according to a recent report from Imprivata , only 46 percent of manufacturing organi...
Hackers Learn How to Attack You, From You 03.04.2024 34:36
Send us Fan Mail It's not always about the ransom, data theft or denial of service. Many cheered with the recent crackdowns on groups like LockBit, and rightfully so. However, the harsh reality is that most of these victories are short-lived. For example, after law enforcement seized control of multiple LockBit websites and stolen data, the group was back to running extortion campaigns withi...
The Largest Attack Surface - People 28.03.2024 44:25
Send us Fan Mail How we're failing to properly support and train our most important cybersecurity asset. According to Nozomi Networks February 2024 OT-IoT Security Report , manufacturing was exposed to more common vulnerabilities and exposures, or CVEs, than any other sector - realizing a 230 percent year-over-year increase in this area. Addressing even a fraction of these CVEs would be daunt...
Avoiding a 'Chicken Little' Cybersecurity Strategy 21.03.2024 39:24
Send us Fan Mail Threat intelligence is important, but why manufacturers should focus on risk factors first. When it comes to the industrial sector’s ongoing cybersecurity challenges, we all know that there's more to defend, but what is most concerning is that we’re not responding quickly enough to the expanding threat landscape. In case you needed proof, here are some of the recent stats fro...
Cybersecurity's Greatest Weapon - Awareness 13.03.2024 36:56
Send us Fan Mail The sector's (forced) cyber awakening needs to focus on making it harder to be a hacker. Regardless of how complex the attack, how organized the hacker, or how advanced the tools and tactics, security solutions usually lie in very fundamental practices. So, while you might think you already know enough about segmentation strategies, framework development, asset visibility or...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.