In this episode of Podomation, the official podcast of the International Society of Automation (ISA), the conversation moves to day two of the ISA OT Cybersecurity Summit, held in June 2026 in Prague. The focus centers on what Europe's evolving cybersecurity regulations mean in practice and how to translate them into meaningful cyber resilience.
Podomation Episode 011: OT Cybersecurity Summit Day Two opens with a forum on the NIS2 Directive and the Cyber Resilience Act (CRA), bringing together perspectives from multiple asset-intensive industries. The panel's central message is clear: regulations can have a significant impact on how organizations understand, manage and secure their operational technology (OT) environments. The episode also includes excerpts from a keynote presented by Mark Harbord, chief information security officer for the UK Parliament, who explores how shifting cyber threats in Europe are driving new legislation.
What is Podomation?
Podomation is ISA's podcast showcasing top subject-matter experts in the industrial automation community. Its guests speak on a broad range of topics that matter to automation professionals, including industry 4.0, digital transformation, manufacturing and machine control, instrumentation, connectivity, OT cybersecurity and continuous and batch processing.
Some episodes (including this one) are recorded live during ISA events, and others are recorded in studio. Each podcast conversation highlights the role of automation in making the world a better place — and the impact our community has across industries.
Podomation Episode 011: OT Cybersecurity Summit Day Two
The “From Compliance to Execution: Navigating NIS2 & the Cyber Resilience Act in Asset-Intensive Industries” forum, in addition to welcoming Steve Mustard of au2mation as moderator, featured Ilja David of Iron OT, Gustav Martin Bartel of Robert Bosch GmbH, Dr. Lukasz Kister of Honeywell and Petr Kopřiva of BDO Consulting s.r.o.
One point of clarification in the forum discussion was to distinguish NIS2 from the CRA. NIS2 primarily applies to operators of essential and important services, requiring them to protect systems and manage cyber risk in day-to-day operations. The CRA, on the other hand, is directed at manufacturers of digital products, requiring security to be embedded across the full product lifecycle — from planning and design through release, vulnerability management, patching, security support and end of life. That lifecycle emphasis represents a major shift. Manufacturers can no longer rely on a "release and forget" approach. Under the CRA, products must be delivered securely by default, and manufacturers must continue addressing vulnerabilities throughout the product's supported life. Still, secure-by-default products can create challenges for operators with legacy systems, who must understand and accept the risk of altering default configurations.
For critical infrastructure organizations, obstacles are often more human and organizational than technical. Resistance to change, limited regulatory understanding and weak asset visibility can all become issues. The panel also challenged the idea that compliance is a checklist: NIS2 and the CRA are both rooted in risk-based thinking and start with risk assessment.
The panelists emphasized that secure-by-default does not mean removing legacy or insecure protocols outright. Interoperability is itself a CRA requirement. Manufacturers must understand the full "product security context," including how and where a product will be deployed, then clearly communicate residual risks to end users who deviate from security guidance. The CRA and NIS2 together create a "bridge" requiring manufacturers and asset owners to collaborate closely and share risk information since the real-world impact of a vulnerability depends heavily on the context around deployment.
Common implementation gaps include a shortage of cybersecurity expertise, confusion over which vendor products to purchase and organizations underestimating the true long-term commitment of cybersecurity. The panelists stressed that procurement and supply-chain relationships are becoming central to cybersecurity, with security clauses and SLAs that must be negotiated at the contract stage and understood by operational staff, not just legal teams.
Looking ahead to the CRA's 2027 deadline for the full application of essential cybersecurity requirements, panelists cautioned that harmonized standards (including a European version of ISA/IEC 62443-4-1 and 4-2) are still being finalized, but organizations already using ISA/IEC 62443 are well-positioned. Unless a product is distinguished as “important” or “critical,” CRA compliance takes a risk-based, self-determined approach.
Obligations for reporting vulnerabilities and incidents are set to begin 11 September 2026. Regulators are expected to focus early enforcement on ensuring organizations are on the right track rather than immediately penalizing gaps.
Keynote: A geopolitical view of cyber resilience
The episode closes with highlights from UK Parliament CISO Mark Harbord's keynote, which framed cybersecurity as a matter of national security. Harbord described a shift from technical security and compliance checklists toward operational resilience, mandatory governance and supply-chain assurance — since "we're all each other's supply chain." He outlined major threats including state-sponsored operations, ransomware-as-a-service, hybrid warfare, AI-enabled attacks and OT-specific risks in energy, water, healthcare and transport.
Harbord also detailed the UK's forthcoming Cyber Security and Resilience Bill. He described it as an update and expansion of the UK's post-Brexit NIS framework, aligning it more closely with EU regulations like NIS2, the Digital Operational Resilience Act (DORA) and the CRA. His closing message echoed the panel's: Europe now treats cybersecurity as a strategic resilience issue tied to sovereignty and democratic stability — far from just a technical problem to delegate and forget.
Listen to the full conversation
The OT Cybersecurity Summit is a must-attend event that shows just how and why cybersecurity is so foundational to safe and reliable industrial operations. Mark your calendars for next year’s summit, scheduled for 16-17 June 2027 in Athens, Greece.
To hear more of the speakers’ thoughts from this year in Prague, please visit Podomation or search for “Podomation” wherever you listen to podcasts.
Ready for the next episode of Podomation?
Make sure to subscribe on your podcast platform of choice to get access to new episodes as soon as they’re ready. Podomation is available on Spotify, Apple Podcasts and many more. If you enjoy these discussions, please leave us a review on any of these platforms. You can also play back episodes here any time.
