Eric Sorensen
Security Breach
A weekly discussion of new developments and the latest cybersecurity threats, including ransomware, malware, phishing schemes, DDoS attacks and more, facing the U.S. industrial sector.
Author
Eric Sorensen
Category
Podcast website
Latest episode
Jun 24, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Avoiding 'Shiny New Objects' 30.08.2023 34:41
Send us Fan Mail Assessing the priorities, assets and technology strategies that make cybersecurity a journey, not a destination. A recent report from OT cybersecurity solutions provider Cyolo discussed several factors related to secure remote access in the industrial sector. Specifically, it identified a lack of visibility, insufficient user education and training, and weak access control as the...
Knowing 'What is Good' 23.08.2023 38:15
Send us Fan Mail Using data to break down silos, reverse engineer outcomes, and identify emerging threats like WormGPT. According to recent report from Trellix, 31 percent of CISOs identified a lack of buy-in and use of cyber tools as one of their leading challenges. Additionally, of those who have experienced a large security incident, significant stress to the SecOps team and major attrition fro...
Security Breach: 'The Edge Always Goes to the Attacker' 18.08.2023 49:35
Send us Fan Mail Embracing the 'not if, but when' mindset. Cybersecurity solutions provider Trellix recently unveiled their 2023 Voice of the CISO report. Among other topics, it explored the top 5 challenges cited by Chief Information Security Officers who responded to the Trellix survey. In order, they included: Too many different sources of information. A growing attack surface created...
Phishing Lessons and 'Shifting the Target' 10.08.2023 53:14
Send us Fan Mail How a global manufacturer learned from past attacks, and the most critical benefit of security tools. IBM research shows a 33 percent increase in cyberattacks against manufacturing companies between 2021-2022. Of those, according to IBM, 44 percent occurred because industrial companies failed to apply the appropriate software patches. With this in mind, it’s not a surprise that ad...
The Growing Problem of 'Insecure by Design' 04.08.2023 41:30
Send us Fan Mail "It just boggles the mind that things that are so important to how our world works are so shockingly unprotected." According to ABI Research, less than five percent of critical industrial infrastructure is monitored for threats. The company also reports that by 2030 industrial environments will house more than 1.2 billion connection points for machines and production sys...
Cloud Apps are Elevating Malware Threats 25.07.2023 35:19
Send us Fan Mail Netskope Threat Labs , a leading provider of threat analysis and cyber defense strategies for cloud-based vulnerabilities, recently published their most recent Threat Labs Report. Findings specific to manufacturing include: Cloud-delivered malware increased from 32 percent to 66 percent in the past twelve months, led by downloads from popular apps like Microsoft OneDrive, Google D...
AI - Use It or Lose! 13.07.2023 19:10
Send us Fan Mail The latest tools and technology needed to create and defend your data fortress. A couple of recent ransomware attacks offer perspective on evolving cybersecurity concerns within the industrial sector Gentex is a Michigan-based manufacturer of electronic safety systems for the automotive sector. They were attacked by a ransomware gang called Dunghill, which is believed to be a rebr...
The Best Way to Identify, Defeat Hackers 29.06.2023 42:34
Send us Fan Mail Vital defensive tactics that go beyond the attacker. The sensor and communication technology associated with remote monitoring has proven to be both a time-saving and productivity enhancing tool, as well as a potentially debilitating cyber defense vulnerability for the industrial sector. The issues stem from a combination of internal failures and the evolution of highly innovative...
The Impressive and Terrifying Evolution of Ransomware Gangs 21.06.2023 34:39
Send us Fan Mail How hackers are targeting ERP systems and automating more attacks. Adding to the data supporting a surge in cyber-criminal activity is the FBI Crime Compliant Center’s most recent Internet Crime Report. The IC3 data shows that while the number of reported complaints actually dipped by about five percent last year, the financial losses directly attributed with Ransomware, Phishing...
Humans, 'Promiscuous Devices' Creating More Threats 13.06.2023 26:47
Send us Fan Mail How increasingly complex attacks might demand taking humans out of the cybersecurity loop. First published in 2014, the National Institute of Standards and Technology (NIST) recently announced updates to its Cybersecurity Framework (CSF). The goal of version 2.0 of the CSF is to better integrate areas like supply chain risk management and governance. All of these measures would ap...
Enemies at the Gate 07.06.2023 39:24
Send us Fan Mail Credential harvesting, backdoor attacks and staying on top of who or what is logging into your networks. While more connection points can create more security soft spots for industrial enterprises, it’s no surprise that hackers would generally prefer to log in, as opposed to break in. It’s rumored that credential theft via phishing schemes is how attackers were able to infiltrate...
The Bad Guys Are Salivating Over Manufacturing 01.06.2023 43:18
Send us Fan Mail Inside the resurgence of ransomware attacks and the rise of billion-dollar "unicorn" hacker gangs. Believe it or not, there was a time in recent history when we actually experienced a reprieve in ransomware attacks. According to a report from Black Kite, a leading provider of third-party risk management and cyber intelligence, a number of factors contributed to a flatten...
More than Security, Cyber Defense Is 'Life Safety' 25.05.2023 35:18
Send us Fan Mail Strategies for breaking down IT silos in learning how people, devices and networks can be attacked. Providing a significant assist to transparency efforts in cybersecurity is the Strengthening American Cybersecurity Act, which was signed into law in March 2022. Unlike other regulatory efforts focused on updating network security, or mandating agencies like CISA (Cybersecurity and...
Making Hackers Pay (Literally) 18.05.2023 49:18
Send us Fan Mail Why cybersecurity is all about ROI, and other "unsexy" stuff on which to build your defenses. In previous episodes of Security Breach , we’ve discussed penetration testing, ethical hackers, cataloging connection points, and getting a handle on all those API connections. These strategies are centered on developing defenses that reduce your attack surface, make attackers e...
Hackers Want to Steal, Extort Competitive Advantages 10.05.2023 35:27
Send us Fan Mail Supply chain management has always been a priority for the industrial sector, but over the last three-plus years, its importance has been elevated for numerous reasons. The problem, from a cybersecurity perspective, is that as soon as an operational area starts to garner more attention, it also becomes a hotter target for hackers. Elise Manna-Browne, director of advisory services...
An Unlikely Assist from Ransomware and the Looming Threats of AI 03.05.2023 36:26
Send us Fan Mail One of the biggest challenges surrounding industrial cybersecurity is the size of the attack surface that must be monitored, assessed, and constantly updated in order to evolve with the rising number of complex threat actors. Throw in a growing number of connection points, APIs and new and legacy network component combinations, and the complexity only grows. This makes improving v...
Trusting the Creative Hacker 24.04.2023 41:31
Send us Fan Mail The industrial sector continues to be a hot target for hackers. Ransomware, malware and phishing attacks all continue to escalate in both frequency and potency. The on-going mixture of new technologies with legacy systems invites attention, and the reality is that it continues to pay dividends for hackers and ransomware groups. However, there are solutions. One of which is to work...
The Cybercriminal's Favorite Pastime 07.04.2023 34:53
Send us Fan Mail Perhaps the only topic that solicits a uniform response is when my guests are asked about the most important part of a cybersecurity plan. The common mantra is that there has to be buy-in throughout the organization for any plan to be successful, and it starts at the top. Obtaining C-level support is obviously vital when it comes to loosening the corporate purse strings for softwa...
Balancing The Light and Dark Forces of Technology 30.03.2023 36:00
Send us Fan Mail As we continue to see an increase in attacks targeting the ICS, it’s about more than just the industrial sector creating cyber defense plans, cataloging connection points and shoring up vulnerabilities. The reality is that it’s going to take a communal effort to keep manufacturing – the largest single contributor to our country’s GDP – safe and secure. As we’ve learned from a lega...
Thinking Like the Bad Guy 23.03.2023 26:28
Send us Fan Mail The latest high-profile hack of Dole Foods reinforces the need to upgrade operational technology security, and not just for the manufacturer. The distributors, logistics providers, retailers and end-users that rely so heavily on the role manufacturing plays are beginning to understand how critical and far-reaching the effects of a production-ceasing hack can be. And so do the bad...
Breaking Down the Dole Foods Ransomware Attack 16.03.2023 28:33
Send us Fan Mail Joining the ranks of high-profile ransomware attacks at Nissan, Colonial Pipeline, JBS Foods, Schneider Electric and even Foxconn, is Dole Foods. The global food processor was the victim of a ransomware attack in early February that led to shutting down production systems throughout North America, and halted shipments to numerous retailers and distributors. As if this wasn’t enoug...
The Air Gap Lie and The Spectrum of Extortion 08.03.2023 39:37
Send us Fan Mail While the growth of ransomware, phishing schemes and other nefarious cyber activities are obviously not positive developments for the industrial sector, the resulting exposure and fallout from high profile events like Colonial Pipeline, JBS and, most recently, Dole Foods, have mandated a need for more data on attack surfaces, hacker tactics and the bad actors themselves. In this e...
Latest Ransomware Attacks Educate, then Humiliate 27.02.2023 27:03
Send us Fan Mail One of the on-going topics that we cover here on Security Breach is ransomware attacks. The risk of continually discussing a topic is that it can become like white noise – always present, but in the background and potentially easier to dismiss. Well, if that’s the case, recent findings from Dragos 2022 Cybersecurity Year in Review report should help to re-orient your perspective....
Hiding, Not Running from Hackers 20.02.2023 29:21
Send us Fan Mail When it comes to securing the industrial enterprise, a great deal of focus is being paid to what might seem like the little things – such as passwords, logins or credentials that are used to limit access to networks or data platforms. The problem has been the continued use of weak, easy to remember passwords and login workarounds that have created vulnerabilities, and contributed...
Hacker's Insight: 'How Can I Make Stuff Worse' 13.02.2023 26:46
Send us Fan Mail The potential of smarter factories driven by advanced technologies and greater connectivity is exciting … but equally daunting. That’s because in our enthusiasm to embrace all the time and cost savings associated with the machines, automation and data associated with these advancements, the industrial sector often pushes one of the most important aspects of all this connectivity i...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.