Ctrl+Alt+Mfg Ep. 9: When cyberattacks go physical, with Ian Bramson of Black & Veatch

Speakers: Ian Bramson, Black & Veatch

Why clean builds, supply-chain visibility, AI-driven defense and a back-to-basics approach are becoming essential for securing industrial operations.

Cybersecurity threats are no longer confined to stolen data or locked laptops. Increasingly, they are crossing the digital divide into the physical world, shutting down pipelines, disrupting factories and putting human safety at risk. For manufacturers and operators of critical infrastructure, the message is clear: Cybersecurity is now an operational imperative.

That was the central theme of a recent episode of the Ctrl+Alt+Mfg podcast, where hosts Gary Cohen and Stephanie Neil were joined by Ian Bramson, vice president of global industrial cybersecurity at Black & Veatch. Bramson, a longtime leader in operational technology (OT) security, laid out why traditional approaches to cybersecurity are no longer enough and what industrial organizations must do to keep pace.

When cyber risk becomes physical risk

High-profile incidents such as the Colonial Pipeline ransomware attack served as a wake-up call for many outside the cybersecurity community. The attack, which caused fuel shortages and panic buying across the U.S. East Coast, illustrated how a digital intrusion could ripple quickly into real-world consequences.

Manufacturing, Bramson said, sits squarely in the crosshairs.

“Cybersecurity is constantly evolving, but it’s going at the speed of business,” Bramson said. “Business itself is getting way more digital, way more dependent on connectivity. When everything that makes operations go gets more connected, that’s where the risk really starts to grow.”

Unlike traditional information technology (IT) systems, OT environments control physical processes, such as valves, motors, pumps and production lines. A successful attack can impact safety, uptime, environmental compliance and supply chains all at once.

“If somebody really wants to have an impact, that’s the spot,” Bramson said. “When you can open a valve at the wrong time, you instantly have site security, public safety, the economy and supply chains all in play.”

The expanding attack surface

One reason industrial cybersecurity has become so challenging is the sheer growth of the attack surface. Remote access, cloud connectivity, industrial Internet of Things (IIoT) devices and third-party software have all multiplied the number of potential entry points.

“Every supplier, every vendor, every piece of software that’s connected to your system is a potential doorway for attackers,” Bramson said. “One weak link can ripple through a supply chain and compromise a lot of things downstream.”

Compounding the problem is the age of many industrial systems. Legacy equipment and protocols were never designed with cybersecurity in mind, yet they are now being connected to global networks.

“Many organizations don’t even know what they have in their operating environment,” Bramson said. “If you don’t know what you need to protect, it’s very hard to understand where your vulnerabilities are.”

Back to cyber basics: visibility and resilience

With threats evolving so quickly — from ransomware to cloud misconfigurations to AI-driven attacks — it can be tempting to chase the latest headline risk. Bramson cautioned against that approach.

“Ransomware is important. You absolutely have to pay attention to it,” he said. “But if you only look at the last thing that happened, you’re going to get hit by the next thing.”

Instead, Bramson advocates a return to fundamentals. He urges industrial leaders to ask a few core questions: Do you know what assets you need to protect? Do you know where your vulnerabilities are? Can you detect when someone is in your system and can you get them out?

“As things get more complex, I often say, ‘Let’s just get simpler,’” Bramson said. “You have to build a very strong foundation. That’s what makes you resilient.”

That foundation includes people as well as technology. Bramson jokingly refers to humans as “meatware,” but the point is serious.

“We’re often the weakest link,” he said. “How prepared are your people? How do you manage change when vendors come onsite and plug into your systems?”

Why clean build matters in manufacturing

One of the most actionable concepts discussed on the podcast was the idea of a clean build. Traditionally, cybersecurity has been bolted onto industrial systems after they are already up and running, which can be a costly and disruptive process.

“Operations don’t stop,” Bramson said. “Trying to add cybersecurity after the fact is like adding seatbelts to a car while you’re driving it.”

A clean build approach shifts cybersecurity earlier, into the design and construction phases of new facilities, major upgrades or expansions. That includes not only building in security capabilities, such as network segmentation and monitoring, but also ensuring vulnerabilities aren’t introduced during construction.

“Clean build means you’re not introducing exploits while you’re building,” Bramson said. “Companies do acceptance testing all the time to see if equipment works. They rarely test for the cyber aspect. So they’re accepting the cyber risk of the entire supply chain without really checking.”

By incorporating cyber acceptance testing and supply chain risk management from the start, organizations can significantly reduce long-term risk and cost.

Supply chains as attack vectors

Supply chain vulnerabilities remain one of the most difficult challenges in industrial cybersecurity. Even when a facility relies on trusted automation vendors, the provenance of components and software deeper in the chain can be unclear.

“I might know where this motherboard came from,” Bramson said. “But do I know where the components on that motherboard came from?”

Attackers, he added, are adept at exploiting these blind spots, sometimes using smaller suppliers as stepping stones to larger targets. Addressing the risk requires pushing cybersecurity requirements upstream.

“Cyber has to be part of who you select,” Bramson said. “If you can’t show that you have clean security, you might lose that bid. When it affects the top line, that’s when people really start to move.”

Standards such as IEC 62443 can help translate cybersecurity expectations into concrete procurement and design requirements, rather than vague assurances.

AI vs. AI in cybersecurity

Artificial intelligence is accelerating both sides of the cybersecurity equation. Attackers are using AI to scan networks, craft more convincing phishing and deepfake attacks and generate novel exploits. Defenders, Bramson said, must respond in kind.

“If you’re not using AI and they are, you’re going to get dusted,” he said.

At the same time, many manufacturers are already deploying AI in operations without fully understanding the security implications.

“Your company is already using AI,” Bramson said. “Who do you think is going to protect that? It’s going to be the cyber group.”

Visibility is critical, especially when AI is embedded in supplier systems.

“Cyber comes down to visibility and control,” he said. “Can you see what’s happening, and can you do something about it?”

Why the cloud is a force of nature

Cloud adoption presents similar tradeoffs. While the business case is often compelling, OT environments are tightly coupled to physical assets that cannot simply be “lifted and shifted.”

“Cloud is a force of nature,” Bramson said. “You can’t hide from it. But how you do it, that’s a different game.”

Organizations must understand their legacy systems, contractual constraints and fallback options if cloud connectivity is disrupted. Safety and uptime, Bramson emphasized, remain paramount.

Keep cybersecurity simple and start early

Asked for one takeaway for industrial leaders, Bramson returned to his core message.

“Stick to the basics. Keep it simple. Start early,” he said. “Build that strong foundation, and you’ll be much better prepared to deal with all the ambiguity and risk that’s coming.”

For manufacturers navigating an increasingly complex cyber-physical world, that advice may be the most practical defense of all.

The Ctrl+Alt+Mfg Podcast

Make sure to check out other episodes of the Ctrl+Alt+Mfg podcast, where hosts Gary Cohen and Stephanie Neil discuss a range of digital transformation insights:

Ep. 1: Resetting and Rethinking Manufacturing

Ep. 2: Uniting Disparate Data With John Lee, Matrix Technologies

Ep. 3: Rethinking OT Security With Leah and Jeremy Dodson, Piqued Solutions

Ep. 4: Making Digital Transformation Real With Alicia Lomas, Lomas Manufacturing

Ep. 5: Reducing MES Project Risk With Ryan Crownover, Vertech

Ep. 6: Digital Transformation – Hype, Reality & What’s Next With Mike Ouellette, Engineering.com

Ep. 7: Digital twins explained — how virtual plants are transforming manufacturing, with Matt Wise and Cole Switzer, E Tech Group

Ep. 8: Inside the 2026 State of Automation Report, with Mark Hoske, Control Engineering