Ctrl+Alt+Mfg Ep. 18: Audacious Goals for Infrastructure Security, with Danielle Jablanski of STV

Speakers: Danielle Jablanski of STV

Danielle Jablanski of STV on the gap between IT and OT, effect-based cybersecurity and why securing the built environment requires a shift from awareness to capability.

Operational technology (OT) cybersecurity has become a boardroom issue, but too many conversations still focus on awareness instead of action. While ransomware and data breaches dominate headlines, the greater risk for industrial organizations lies in the systems that control critical infrastructure — power grids, water treatment plants, manufacturing facilities, transportation networks and other cyber-physical environments where a cyberattack can have real-world consequences.

Danielle “DJ” Jablanski joined the Ctrl+Alt+Mfg podcast to discuss the evolving OT cybersecurity landscape. Jablanski leads STV’s operational technology cybersecurity consulting program and previously served as a subject matter expert in the Office of the Technical Director at the Cybersecurity and Infrastructure Security Agency (CISA). Her experience spans government, consulting and industry, giving her a unique perspective on both policy and practice.

Throughout the conversation, Jablanski argued that organizations need to shift their thinking from simply recognizing cyber risks to developing the capabilities needed to manage them.

OT security is about protecting the physical world

Jablanski’s path into OT cybersecurity began in an unexpected place: nuclear weapons policy.

“I was actually working in nuclear weapons when I started looking at cybersecurity,” she said. “The more we got away from the physical world in that policy work, the more I wanted to go back to things that exploded.”

That search led her into industrial control systems (ICS) and critical infrastructure security, where she found a field that directly connects cybersecurity with physical operations. Unlike traditional information technology (IT) environments, OT systems control equipment and processes that cannot simply be taken offline for routine maintenance. Industrial environments often rely on decades-old control systems, specialized equipment and continuous operations that create very different security challenges.

Jablanski believes many professionals underestimate how approachable the field actually is.

“A lot of people tend to argue that you need an engineering background to focus in OT, and I think that that’s just belligerently wrong,” she said.

Instead, she encourages security professionals to start by understanding how everyday systems work.

“You use products, services and resources every single day,” she said. “If you want to work to secure a product, a resource or any other type of critical infrastructure, then you can learn about it.”

Awareness isn’t the problem anymore

One of Jablanski’s strongest observations is that the OT security industry has moved beyond the awareness stage. During her time at CISA, she frequently heard calls for more education about OT cybersecurity. She believes that conversation now needs to evolve.

“I was over awareness,” she said. “I hated the word awareness.”

She explained that convincing people OT security matters is no longer the biggest obstacle.

“It takes me about 20 minutes to convince somebody why OT is important,” Jablanski said. “Tops, 20 minutes. They get it.”

Instead, organizations struggle because they lack the tools, processes and expertise needed to build mature security programs.

“The problem is the gap in capabilities and capacity and competence between IT and OT,” Jablanski said. “It really isn’t even competence anymore. It is capabilities.”

While enterprise IT security has matured rapidly over the past decade — with sophisticated security platforms, automation and AI-assisted defenses — OT security remains years behind.

“If you compare the markets, the tools, the approaches, the security controls, the technical veracity, the introduction of AI, OT is so far behind,” she said.

That gap, however, also represents an enormous opportunity.

“We’ve got 10-plus years of growth that’s going to be happening in this market.”

Network segmentation is never finished

Few topics receive more attention in industrial cybersecurity than network segmentation. Jablanski agrees it remains foundational but cautions against treating it as a one-time project. Many organizations assume installing firewalls or creating network zones completes the work. In reality, segmentation encompasses architecture, asset management, access control, vulnerability management and continuous monitoring.

“It’s not one and done,” she said. “It’s not a set it and forget it. It’s not a perfect tool.”

Effective segmentation begins with understanding how industrial processes actually function. Organizations must identify critical assets, understand dependencies, evaluate worst-case scenarios and determine which systems are truly essential to maintaining safe operations. Only after that groundwork is complete can technologies like firewalls, software-defined networking, data diodes and monitoring platforms be deployed strategically.

There is no universal OT security playbook

One misconception Jablanski frequently encounters is the belief that organizations simply need to adopt an existing framework to become secure. Her experience tells a different story. During a nationwide listening tour while at CISA, she met with nearly 30 organizations representing every U.S. critical infrastructure sector using industrial control systems.

“None of them said that they actually used an adopted 62443,” she said.

Instead of searching for a perfect framework, she recommends organizations develop security programs tailored to their own operational realities.

“I’ve told people to beg, borrow and steal from frameworks and build your own baselines because you’re never going to get anywhere without starting today,” she said.

The goal is not compliance for its own sake but building a practical roadmap that reflects each organization’s assets, risks and operational priorities.

Looking beyond individual assets

One of the more nuanced discussions during the podcast centered on cyber-physical risk assessment. Security teams often focus either on protecting individual devices or defending critical business functions. Jablanski argues neither approach is sufficient by itself.

“If you’re spending all of your focus on TTPs from a threat actor, you might not actually even be understanding your core interdependencies and your worst-case scenarios,” she explained.

Likewise, organizations that focus exclusively on patching vulnerabilities may overlook broader operational risks. Understanding how systems interact, and what happens when those interactions fail, is becoming increasingly important as industrial operations become more interconnected.

The built environment creates new challenges

Today, Jablanski spends much of her time thinking about the built environment. That includes not only traditional industrial facilities but transportation systems, commercial buildings, water infrastructure, smart facilities and other connected systems.

As digital technologies become embedded throughout infrastructure, organizations face new strategic decisions around vendor selection, interoperability and supply chain risk.

One concern she highlighted is balancing vendor consolidation with resilience. Organizations often reduce the number of suppliers to simplify operations and reduce third-party risk. However, that strategy can introduce new vulnerabilities.

“What does an OT SolarWinds type event look like if we have that vendor consolidation?” she asked.

Conversely, relying on numerous specialized vendors can create fragmented security architectures that become difficult to manage. These decisions increasingly require balancing operational efficiency, cybersecurity and long-term resilience.

Engineering firms have a security opportunity

Jablanski believes engineering, procurement and construction (EPC) firms and system integrators can play a much larger role in improving cybersecurity outcomes. Too often, cybersecurity enters projects only after systems have been designed and installed. She would like to see cybersecurity become part of project planning from the very beginning.

“I would love to see this sub-sector … form a common language, a framework or a maturity model that they can consult at the beginning of an RFP process or proposal or bidding,” she said.

Rather than creating another lengthy checklist of security controls, she advocates asking a handful of fundamental questions during every project. Those conversations can help identify cybersecurity expectations early, reducing costly retrofits later.

OT security efforts should start today

For organizations overwhelmed by the complexity of OT cybersecurity, Jablanski offered surprisingly simple advice. She recommends setting ambitious long-term objectives while making steady progress with available resources.

“I spent the whole podcast saying, ‘You need to be holistic. You need to be strategic. You’ve got to take all these inputs and define your outputs correctly,’” she said. “But I also think you have to start today with what you have and keep an audacious goal in mind.”

When it comes to OT security, simply deploying another technical tool or checking a compliance box won’t get the job done. It requires understanding industrial processes, managing cyber-physical risk, designing secure systems from the outset and continuously improving capabilities over time.

As Jablanski warned, organizations that wait for the perfect framework or complete certainty risk standing still while threats continue to evolve.

“You run the risk of six years from now being at the same place you are today if you don’t get started,” Jablanski said. “Pick an audacious goal and start today.”

The Ctrl+Alt+Mfg Podcast

Make sure to check out other episodes of the Ctrl+Alt+Mfg Podcast, where hosts Gary Cohen and Stephanie Neil discuss a range of digital transformation insights. The last five episodes are listed below:

Ep. 13: Bad data, broken maintenance, with Paul Ross of Limble and Ross Fergerson of RBC Bearings

Ep. 14: From data silos to smart factories, with John Dyck of CESMII and John Harrington of HighByte

Ep. 15: Industrial AI’s reality check, with Josh Peeno of JPeeno Innovation Group

Ep. 16: The system integrator playbook, with Daniel Gomez of Omnicon

Ep. 17: Rethinking Industrial Data, with Gary Tillery of Skkynet