More Open Source Security episodes

Securing critical infrastructure with Josh Corman thumbnail

Securing critical infrastructure with Josh Corman

Published 27 Jul 2026

Duration: 35:38

"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."

Episode Description

Open Source Security welcomes Josh Corman to talk about the challenges around securing our critical infrastructure. Specifically the discussion center...

Overview

The podcast discusses key challenges and evolving dynamics in cybersecurity, particularly as they relate to critical infrastructure and public safety. A central theme is the motivation behind hackers, explained through the "Five P's" framework - Protector, Puzzler, Prestige, Profit, and Protest/Patriotism - which helps clarify intentions and improve communication between hackers and regulated sectors like healthcare and transportation. The discussion emphasizes the high-stakes nature of cyber-physical systems, where failures in operational technology (OT) can lead to real-world harm, such as disruptions to water, power, hospitals, and transportation. Unlike traditional IT, OT vulnerabilities can result in physical damage even without malicious intent, underscoring the need for better risk assessment, engineering resilience, and proactive defense strategies.

The conversation also highlights systemic weaknesses in securing critical infrastructure, including delayed patching, supply chain risks, and under-resourced security teams. Simulations and crisis drills are proposed as essential tools for preparedness, similar to medical emergency training. The podcast critiques the cybersecurity industry's overreliance on technological fixes and lack of transparency, calling for physical engineering solutions - such as water hammer mitigation - to prevent catastrophic failures. Initiatives aimed at strengthening infrastructure resilience, particularly for water systems and hospitals, are discussed, along with the importance of public awareness, community engagement, and policy reform. The need for honest risk communication, international norms, and a shift from fear-based narratives to actionable preparedness is emphasized throughout.

What If

  • What if you built a micro-SaaS that helps small water utilities manage cyber-physical resilience using publicly available engineering controls?
    • Move: Research and compile the U27.org blueprints and engineering solutions (e.g., water hammer mitigation, manual override setups) into a simple no-code tool that guides small utility operators through implementation steps, checklists, and cost estimates.
    • Why Now?: 151,000 U.S. water facilities - only 420 in ISAC - with increasing attention on pre-positioned threats like Volt Typhoon; regulators and funders (e.g., Craig Newmark) are seeking scalable, low-cost interventions now.
    • Expected Upside: Establish first-mover credibility in critical infrastructure resilience SaaS, generate revenue via municipal subscriptions (<$500/yr), and unlock grants or partnerships with nonprofits focused on public safety.
  • What if you launched a vulnerability disclosure platform tailored for OT/industrial systems, using the Five P's to align hacker intent with operator trust?
    • Move: Build a lightweight, open-source disclosure portal where researchers can submit OT vulnerabilities and self-identify their motivation (Protector, Puzzler, etc.), with guided templates that translate technical findings into operational risk summaries for non-technical teams.
    • Why Now?: OT systems are dangerously underrepresented in current disclosure ecosystems (e.g., Glasswing); rising incidents like hospital HVAC failures show urgent need for trusted channels between hackers and infrastructure defenders.
    • Expected Upside: Become a trusted intermediary for high-impact OT disclosures, attract funding from public-interest tech orgs, and differentiate through behavioral design (motivation tagging) that reduces fear and improves patching rates.
  • What if you created a simulation toolkit for solo developers to stress-test their own apps against real-world cyber-physical failure scenarios?
    • Move: Develop a downloadable CLI tool that simulates outage cascades (e.g., "HVAC fails in 117F heat," "internet patch fails during hospital surge") and evaluates app resilience based on response time, failover design, and manual override support.
    • Why Now?: CrowdStrike-style accidents prove that even non-malicious failures can collapse critical systems - developers need practical tools now to design for failure before regulators mandate it.
    • Expected Upside: Capture early adopters in healthcare IT, smart building tech, and municipal software spaces; monetize via pro features or integrations, while positioning as essential prep for future cybersecurity audit standards.

Takeaway

  • Apply the "Five P's" framework to clarify your own motivations and communication when disclosing vulnerabilities, ensuring your intent (e.g., "Protector" or "Puzzler") is explicitly stated to reduce misinterpretation by organizations.
  • Prioritize securing or designing fallbacks for high-consequence systems in your software projects - especially those impacting health, safety, or critical infrastructure - by integrating simple engineering controls (e.g., physical fail-safes) even in digital products.
  • Focus vulnerability disclosure efforts on systems tied to essential services (like water or hospitals), and align with initiatives like U27.org to contribute scalable, low-cost solutions rather than only pursuing high-profile IT targets.
  • Conduct simple simulation exercises for worst-case scenarios (e.g., ransomware on a medical device or HVAC control system) to test response plans and identify single points of failure in your software's operational environment.
  • Advocate for and adopt SBOM++ practices in your development workflow to increase software transparency, and push back against "snake oil" security claims by emphasizing verifiable, incremental improvements over hype-driven fixes.

Recent Episodes of Open Source Security

31 Aug 2026 Sovereign Tech Agency with Erik Moller

"Explores the Sovereign Tech Agency's efforts to sustain open-source software as critical infrastructure, emphasizing public investment, digital sovereignty, and strategic funding for projects like *curl* and AI security."

17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

More Open Source Security episodes