Governance & Risk Management
,
Operational Technology (OT)
,
Video
ManuSec Chicago Speaker Johnny Xmas on Value of Pentesting in OT Environments
In advance of QG Media’s 10th ManuSec Summit for cybersecurity in manufacturing, event speaker Johnny Xmas, global head of offensive security for a leading U.S. manufacturer, discusses pentesting in operational technology environments, overcoming the hurdles to offensive security programs and the evolving role of OT security.
See Also: From Data to Decisions: Maximizing Operational Efficiency Through IT-OT Integration
Offensive security faces unique challenges in OT environments, from inconsistent technology used across multiple manufacturing plants to shadow IT with hidden risks.
“You’ve got to take a big step back and go, ‘Let’s make sure what’s in those plants is supposed to be in those plants,'” Xmas said. “We’re talking about verification of asset inventory from an offensive attacker perspective.”
In this interview with Information Security Media Group, Xmas also discussed:
- How context matters more than exploits in OT environments;
- Two blind spots manufacturing organizations tend to face when they attempt offensive security for OT systems;
- Why security is becoming a core consideration for OT, and what the future holds.
Xmas is the global head of offensive security for a Fortune 200 food and beverage manufacturing company. He has been a dedicated and prominent figure in the information security community, sharing his extensive research and knowledge since 2002. Most notably recognized for his pivotal role in exposing the American TSA Master Key leaks in 2014 to 2018, uncovering Venmo stalking vulnerabilities in 2018, and being an overall nuisance.
ManuSec Summit in Chicago
Want to learn more? Register to join more than 150 IT and OT security leaders at the ManuSec Summit October 14-15 in Chicago. The content-rich ManuSec program emphasizes actionable insights and collaboration with senior leaders on the nation’s cyber resilience.

