PodcastOT & ICS · Supply Chain

The 6-Step Supply Chain Bleed: When Your Safety Blueprints Leak and the Lifeboats Catch Fire

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we follow the evidence into one of the most consequential architectural debates in industrial cybersecurity today: Should Safety Instrumented Systems (SIS) be strictly segregated from Basic Process Control Systems (BPCS)?

Cybersecurity Under Pressure podcast artworkPodcast episode
Episode brief
Listen here

Listen to the full episode.

What this episode examines

In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we follow the evidence into one of the most consequential architectural debates in industrial cybersecurity today: Should Safety Instrumented Systems (SIS) be strictly segregated from Basic Process Control Systems (BPCS)?

The conversation is no longer theoretical. CISA Advisory AA-2026-2697 details Iranian-linked actors actively targeting internet-exposed PLCs, and the threat landscape has shifted from opportunistic ransomware to deliberate, physics-aware attacks. Adversaries are no longer just locking screens—they are hunting for PLC project files, logic diagrams, and network maps to understand your process before they break it.

We map the six-stage Supply Chain Bleed in forensic detail:

Classification – sensitive engineering assets locked in a fortified central repository.

Distribution – access granted to a vetted prime contractor.

Delegation – specialized tasks farmed out to tier-3 and tier-4 subcontractors.

Read the technical analysis

The companion Analysis develops the sourced technical argument, trust boundary and operational decision in a durable written reference.

Related analysisSafety Independence Must Survive a Cyber CompromiseRead analysis →