Insights & Lessons from Our Podcast Miniseries on Incident Response with Simon Rommer

In our Energy Talks miniseries “Why Should You Talk About Incident Response?”, OMICRON cybersecurity expert Simmon Rommer speaks with OMICRON and guest experts from the power and cybersecurity industries to explore the essential steps of incident response for critical infrastructure. Across five episodes, the series highlights the unique challenges of IT and OT collaboration, the importance of preparation and identification, and the practical approaches to containment, eradication, and recovery. With real-world insights, case studies, and expert perspectives, the discussions highlight why proactive planning, cross-team cooperation, and continuous improvement are vital to strengthening resilience in the energy sector.

Past & Future OT Cyber Incident Response and Disaster Recovery

In the first episode, our cybersecurity experts Simon Rommer and Andreas Klien explore the critical roles of IT and OT in cyber incident response and disaster recovery alongside other experts from the power industry. They discuss disaster recovery from an OT perspective, using a recent CrowdStrike incident as a case study. Simon also highlights key considerations for utilities when developing OT incident response and recovery processes and offers practical tips for those without established plans.

Listen to Episode 1

Podcast Episode, Simon Rommer, Andreas Klien

Cybersecurity Preparedness Protecting Against Threat Scenarios

In the second episode, Simon Rommer speaks with Tibor Külkey from ALSEC Cybersecurity Consulting, a leading OT security consultancy in Switzerland. Simon and Tibor discuss the critical importance of preparation, which is the first step in the incident response process according to the SANS Institute, an organization that specializes in cybersecurity training, certifications, and research. This conversation between OT security experts highlights the need for a proactive approach to cybersecurity in the energy sector, the distinction between general and specific threat scenarios, and the regulatory frameworks in Switzerland compared to the European Union

Listen to Episode 2

Tibor Kuelkey, ALSEC

The Importance of Identification in Cybersecurity Incident Response

In the third episode, Simon Rommer speaks with Johann Stockinger who is Head of Digital Forensics and Incident Response at the Deutsche Telekom Security Operations Center. Simon and Johann talk about the importance of identification, which is the second step in the incident response process. Johann highlights the complexities of cybersecurity, particularly in the context of data overload, the importance of historical data analysis, and pro-active threat hunting. He emphasizes the role of SIEM in security operations, the necessity of specialized tools in operational technology (OT) security, and the convergence of IT and OT security monitoring.

Listen to Episode 3

Incident Response, Podcast, Simon Rommer

Learn About Containment, Eradication and Recovery in Cybersecurity Incident Response

In the fourth episode, Simon Rommer speaks with Stephan Mikiss, who is Head of Managed Security Services at SEC Consult and a SANS-certified forensics analyst based in Vienna, Austria. Simon and Stephan discuss the steps of containment, eradication and recovery in the incident response process and highlight the need for collaboration between IT and OT teams to effectively manage cybersecurity incidents. Simon and Stephan also explore the iterative nature of incident response, the unique challenges posed by OT environments, and the necessity of understanding both the business model and the attacker's motives to make informed decisions during a crisis.

Listen to Episode 4

Stephan Mikiss, SEC Consult

Learn About Recovery and Decision-Making in Cybersecurity Incident Response

In the fifth and final episode, Simon Rommer discusses the critical cybersecurity incident response steps of recovery and decision-making, as well as lessons learned, with his guest Dr. Marie Moe, who is a Principal Security Consultant based in the United Kingdom at Mandiant Consulting, which is part of Google Cloud. Simon and Marie emphasize the importance of thorough incident investigation, the role of business decisions in recovery, and the need for continuous improvement in incident response processes. They also discuss the necessity of collaboration between IT and OT teams, the significance of post-incident reviews, and the proactive measures organizations should take to prepare for future incidents.

Listen to Episode 5

Dr Marie Moe, Mandiant Consulting

Ready to 
Protect Your 
OT Network?

Your power grid deserves the same level of cybersecurity and expertise as your IT. 

Let us help protect your critical operations with solutions tailored for OT environments.

Get in Touch Today

Resources