Talking OT Cyber Risk on Technical Safety Perspective

When Safety Meets Cyber Security: Managing Risk

Armexa CSO John Cusimano was recently featured in the Technical Safety Perspective webinar series. This is a great watch for anyone new to OT cybersecurity.

 

For decades, process safety and cybersecurity evolved as distinct functions with their own standards, terminology, and reporting lines. Safety instrumented systems (SIS) were designed and validated to protect against equipment failure and human error, largely isolated from the corporate network. As industrial facilities have connected control systems, safety systems, and business networks to enable remote monitoring, predictive maintenance, and operational efficiency, that isolation has eroded. A cyberattack today can trigger the same consequences engineers have spent decades designing safety systems to prevent — equipment damage, environmental releases, and threats to personnel. Frameworks like IEC 61511 for functional safety and ISA/IEC 62443 for industrial cybersecurity increasingly need to be applied together rather than in isolation, and organizations that treat them as separate problems are left with blind spots neither discipline was designed to catch on its own.

Cusimano is well positioned to speak to that convergence. He brings more than 30 years of experience across process control, functional safety, and industrial cybersecurity, including time as a Managing Director at a Big 4 consulting firm leading its Cyber OT and IoT practice, and founding two ICS/OT cybersecurity consulting practices before joining Armexa. He is a voting member of the ISA99 cybersecurity standards committee and chaired the subcommittee that authored ISA/IEC 62443-3-2:2020, the standard governing IACS security risk assessment and design — the same standard that underpins how organizations scope and prioritize cybersecurity investment across safety-critical systems.

That combination of safety and cybersecurity depth is central to how Armexa approaches OT cyber risk: starting from the consequences a facility is already managing through its process safety program, then evaluating how a cyber event could produce those same consequences. It’s a practical, asset-owner perspective built from firsthand experience inside critical operations, not a generic IT security lens applied to the plant floor.

For plant managers, safety engineers, and OT security practitioners looking to understand where these disciplines intersect, the full conversation is available through the embedded webinar above. Reach out to Armexa to talk through how a combined safety-and-cybersecurity risk view could apply to your own facility.

 

Facebook
X
LinkedIn

Latest Posts

Skip to content