Listen

Description

Podcast Synopsis: Critical Infrastructure and Operational Technology Cybersecurity

This episode features Sam McKenzie and Karl Dawson, two seasoned professionals in cybersecurity and operational technology (OT), discussing the convergence of IT and OT in critical infrastructure, and the growing complexity facing asset operators.

Sam McKenzie, head of technology operations at the City of Stonnington, shares his early experiences growing up off-grid, which fostered a lifelong interest in protecting essential services. With a 25-year career across telecommunications, energy, and healthcare, Sam emphasises the vulnerability of modern society's reliance on critical infrastructure. His perspective blends physical asset protection and cybersecurity, drawing parallels between safeguarding farm resources and national infrastructure.

Karl Dawson, a consultant at Cordant with a background in electronics and networking, outlines his journey from technician to cybersecurity professional. With experience in water utilities, energy, and government sectors, he has moved through helpdesk, project management, and penetration testing roles—especially in smart metering systems. Karl highlights the blurred boundary between IT and OT and notes the administrative, rather than purely technical, distinction that often separates the two.

The discussion explores:

Sam shares insights from his white paper on cyber-physical safety in Australia's critical infrastructure, based on interviews with over 50 industry leaders. He finds a persistent leadership gap in understanding and managing OT risks. This disconnect, he suggests, stems from legacy engineering assumptions being upended by the increasing interconnectivity of formerly isolated systems, often now exposed to insecure networks for operational efficiency.

Karl expands on this with practical considerations:

The conversation underscores a central tension: the imperative to modernise OT systems versus the practical and financial limitations that inhibit progress. It concludes with reflections on how leadership must evolve its view—shifting from purely technical risk management to safety-focused governance that recognises the physical consequences of cyber events.

This episode delivers a clear warning: many critical systems continue to operate on fragile, outdated infrastructure while the attack surface expands. The burden of modernisation falls not just on engineers but also on executives and regulators to align operational, financial, and safety objectives.