More Open Source Security episodes

Securing critical infrastructure with Josh Corman thumbnail

Securing critical infrastructure with Josh Corman

Published 27 Jul 2026

Duration: 35:38

"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."

Episode Description

Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion center...

Overview

The podcast discusses key challenges and evolving dynamics in cybersecurity, particularly as they relate to critical infrastructure and public safety. A central theme is the motivation behind hackers, explained through the "Five P's" framework - Protector, Puzzler, Prestige, Profit, and Protest/Patriotism - which helps clarify intentions and improve communication between hackers and regulated sectors like healthcare and transportation. The discussion emphasizes the high-stakes nature of cyber-physical systems, where failures in operational technology (OT) can lead to real-world harm, such as disruptions to water, power, hospitals, and transportation. Unlike traditional IT, OT vulnerabilities can result in physical damage even without malicious intent, underscoring the need for better risk assessment, engineering resilience, and proactive defense strategies.

The conversation also highlights systemic weaknesses in securing critical infrastructure, including delayed patching, supply chain risks, and under-resourced security teams. Simulations and crisis drills are proposed as essential tools for preparedness, similar to medical emergency training. The podcast critiques the cybersecurity industry's overreliance on technological fixes and lack of transparency, calling for physical engineering solutions - such as water hammer mitigation - to prevent catastrophic failures. Initiatives aimed at strengthening infrastructure resilience, particularly for water systems and hospitals, are discussed, along with the importance of public awareness, community engagement, and policy reform. The need for honest risk communication, international norms, and a shift from fear-based narratives to actionable preparedness is emphasized throughout.

What If

  • What if you built a micro-SaaS that helps small water utilities manage cyber-physical resilience using publicly available engineering controls?
    • Move: Research and compile the U27.org blueprints and engineering solutions (e.g., water hammer mitigation, manual override setups) into a simple no-code tool that guides small utility operators through implementation steps, checklists, and cost estimates.
    • Why Now?: 151,000 U.S. water facilities - only 420 in ISAC - with increasing attention on pre-positioned threats like Volt Typhoon; regulators and funders (e.g., Craig Newmark) are seeking scalable, low-cost interventions now.
    • Expected Upside: Establish first-mover credibility in critical infrastructure resilience SaaS, generate revenue via municipal subscriptions (<$500/yr), and unlock grants or partnerships with nonprofits focused on public safety.
  • What if you launched a vulnerability disclosure platform tailored for OT/industrial systems, using the Five P's to align hacker intent with operator trust?
    • Move: Build a lightweight, open-source disclosure portal where researchers can submit OT vulnerabilities and self-identify their motivation (Protector, Puzzler, etc.), with guided templates that translate technical findings into operational risk summaries for non-technical teams.
    • Why Now?: OT systems are dangerously underrepresented in current disclosure ecosystems (e.g., Glasswing); rising incidents like hospital HVAC failures show urgent need for trusted channels between hackers and infrastructure defenders.
    • Expected Upside: Become a trusted intermediary for high-impact OT disclosures, attract funding from public-interest tech orgs, and differentiate through behavioral design (motivation tagging) that reduces fear and improves patching rates.
  • What if you created a simulation toolkit for solo developers to stress-test their own apps against real-world cyber-physical failure scenarios?
    • Move: Develop a downloadable CLI tool that simulates outage cascades (e.g., "HVAC fails in 117F heat," "internet patch fails during hospital surge") and evaluates app resilience based on response time, failover design, and manual override support.
    • Why Now?: CrowdStrike-style accidents prove that even non-malicious failures can collapse critical systems - developers need practical tools now to design for failure before regulators mandate it.
    • Expected Upside: Capture early adopters in healthcare IT, smart building tech, and municipal software spaces; monetize via pro features or integrations, while positioning as essential prep for future cybersecurity audit standards.

Takeaway

  • Apply the "Five P's" framework to clarify your own motivations and communication when disclosing vulnerabilities, ensuring your intent (e.g., "Protector" or "Puzzler") is explicitly stated to reduce misinterpretation by organizations.
  • Prioritize securing or designing fallbacks for high-consequence systems in your software projects - especially those impacting health, safety, or critical infrastructure - by integrating simple engineering controls (e.g., physical fail-safes) even in digital products.
  • Focus vulnerability disclosure efforts on systems tied to essential services (like water or hospitals), and align with initiatives like U27.org to contribute scalable, low-cost solutions rather than only pursuing high-profile IT targets.
  • Conduct simple simulation exercises for worst-case scenarios (e.g., ransomware on a medical device or HVAC control system) to test response plans and identify single points of failure in your software's operational environment.
  • Advocate for and adopt SBOM++ practices in your development workflow to increase software transparency, and push back against "snake oil" security claims by emphasizing verifiable, incremental improvements over hype-driven fixes.

Recent Episodes of Open Source Security

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

13 Jul 2026 Red Hat's Project Lightwell with Mo Duffy

"Project Lightwell uses AI and open-source collaboration to detect and fix vulnerabilities missed by traditional tools, emphasizing upstream transparency, AI's role in security, and Red Hat's efforts to sustain long-term open-source security through collaboration and patch adoption."

29 Jun 2026 AIBOM, CBOM, and HBOM with Allan Friedman

The evolution of Software Bill of Materials (SBOM) beyond manufacturing into cryptographic, hardware, and AI domains faces challenges in unified integration, compliance, tooling, and dependency tracking, requiring open-source collaboration, standardized frameworks, and adaptive policies to meet industry demands in procurement and risk management.

22 Jun 2026 Packagist and Composer security with Jordi Boggiano

Strategies for securing open-source ecosystems include malware detection via third-party feeds, transparency logs, rapid incident response, blocking malicious downloads, private registry controls, immutable package releases, standardized workflows, MFA enforcement, and technical proposals like artifact validation and build attestation, while addressing challenges like maintainer hacking, AI risks, usability trade-offs, and the need for ecosystem-wide alignment and human verification.

More Open Source Security episodes