Evidence-led analysisPodcast + written referenceOT · Automotive · Rail · Product · AIMon · Wed · Fri
Industrial · Product · Cyber-physical security

When the incident is real, the decision matters more than the headline.

Cybersecurity Under Pressure examines real attacks, technical failure paths and the evidence needed to make defensible decisions across OT, automotive, railway, product and AI security.

Antonio González in the Cybersecurity Under Pressure studio
Founder & Editor · Cybersecurity Under Pressure
By the numbers

A growing technical reference, not another alert stream.

Community reach and publishing depth, kept deliberately simple and transparent.

1200+ LinkedIn newsletter subscribers Editorial snapshot · 13 Sep 2026
43+ In-depth analyses Evidence-led written reference
90+ Podcast episodes Real attacks · real lessons
6 Security domains OT · Automotive · Rail · Product · AI · Supply Chain
Featured analysisOT & ICS · PLC Security · Vulnerability Lifecycle · 6 min · 3 sources

SIMATIC S7-1500 MFP Shows Why an Embedded Linux Subsystem Needs Its Own Assurance Case

Siemens SSA-019113 tracks inherited Linux vulnerabilities in the GNU/Linux subsystem of the SIMATIC S7-1500 MFP. The assurance challenge is managing a second software lifecycle inside the same controller boundary.

The decision

Manage the additional GNU/Linux subsystem as an explicit software component inside the PLC assurance case. Track its version and inherited vulnerabilities separately, then reconnect that evidence to the controller's actual network reachability and process authority.

Read analysis →
Latest analysis

Signals worth keeping.

All analysis →
OT & ICS · PLC Security · Vulnerability Lifecycle

SIMATIC S7-1500 MFP Shows Why an Embedded Linux Subsystem Needs Its Own Assurance Case

Siemens SSA-019113 tracks inherited Linux vulnerabilities in the GNU/Linux subsystem of the SIMATIC S7-1500 MFP. The assurance challenge is managing a second software lifecycle inside the same controller boundary.

Read analysis →
Hardware Security · Verification · Release Assurance

Chip Security Sign-Off Needs Evidence, Not Another Checkbox

Semiconductor security is moving toward formal sign-off. The useful gate is not another certification label, but traceable evidence that security requirements, verification coverage and residual risk survive the hardware, firmware and system boundary.

Read analysis →
Product Security · Cryptography · Lifecycle

Airwall Shows Why a Hardcoded Key Becomes a Lifecycle Problem

CVE-2026-64887 in Johnson Controls Airwall is a local hardcoded-key vulnerability. The broader engineering lesson is that embedded cryptographic secrets become lifecycle dependencies once products are deployed at scale.

Read analysis →
Hardware Security · ASIC · Supply Chain Assurance

NSA ASIC Guidance Shows Why Hardware Assurance Starts Before the Chip Exists

NSA's 2026 ASIC threat catalog and LoA1 guidance show why hardware assurance has to cover design requirements, EDA environments, third-party IP and manufacturing evidence before silicon reaches the product.

Read analysis →
Automotive · Aftermarket · Trust Boundaries

KARR/SWDS Shows Why Aftermarket Vehicle Authority Must Be Constrained

Shared Bluetooth authentication in dealer-installed anti-theft systems exposes a broader automotive lesson: aftermarket components should receive only the vehicle authority their function requires.

Read analysis →
OT & ICS · Industrial Networking · Remote Access

Weidmüller Shows Why a Security Router Is a Privileged OT Asset

An unauthenticated command-injection flaw can execute shell commands as root on affected Weidmüller industrial security routers. The deeper lesson is that a boundary device inherits exceptional authority over every conduit it protects.

Read analysis →
Explore by decision

Find the problem you need to decide.

Sectors tell you where the system operates. Decision lenses help you find the recurring assurance problem across sectors.

More analysis

Ideas worth carrying beyond the feed.

Some questions deserve a durable, sourced answer even when there is no companion episode. These analyses keep the engineering argument easy to find and revisit.

The podcast

One case.
More room
to reason.

Read the evidence and technical implications, or take the same case into the podcast for a deeper discussion of trade-offs and decisions.

Browse episodes
Explore by domain

Cyber risk changes with the system.

Operational context determines consequence, evidence needs and which mitigations are actually viable.

The Weekly Brief

Three real incidents. The engineering consequence. The decision that matters.

About five minutes, once a week. For OT, product security, automotive, railway and critical-infrastructure professionals who need evidence and decisions, not another alert stream.

About the publication

Not another cybersecurity news feed.

Use the format that fits the moment: read the sourced analysis, listen to a deeper discussion, or join the debate with practitioners on LinkedIn.

About Cybersecurity Under Pressure →
Guided discovery

Follow a decision, not a feed.

Reading Paths connect incidents, engineering constraints and the next decision across the existing library.

Browse all Reading Paths →