
Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
Episode: Regulation Is the Budget Unlock OT Has Been Waiting For: NIS2, the CRA, and Getting the Basics Right with Tobias Nitzsche
Pub date: 2026-09-21
Get Podcast Transcript →
powered by Listen411 - fast audio-to-text and summarization
Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep124/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
NIS2, the EU Cyber Resilience Act, and CIRCIA are converging between now and 2027, and for the first time the law is pushing cybersecurity requirements upstream into product design and supply chain. What does that actually change on the plant floor?
In this episode of Protect It All, host Aaron Crow talks with Tobias Nitzsche, Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, about the shift regulation is driving in OT: responsibility moving from the server rooms into the boardrooms, and from the operator to the manufacturer.
Tobias makes the case that what gets regulated are fundamentally the basics: risk assessment, asset inventory, cyber hygiene, and detection. The industry has preached these for a decade. Now the law demands them, which makes compliance the business case that finally unlocks long-overdue modernization budget. His advice: do not treat legislation as a paper exercise. Treat it as a utility.
The second half is about recovery, the foundation most plants skip. Aaron and Tobias dig into the vendor-install backup that has never been tested, recovery targets that ignore how long a plant really takes to come back, retain values operators tuned for years that live nowhere else, redundant controllers that are not cyber resilience, and vendor SLAs that send a system engineer when you needed a cyber expert. Tobias's practical pattern: keep a replica of your critical systems, restore into the bubble, and be as intrusive as you like there, scanners and all, without touching production.
Also in this one: NIS2 Article 20 and personal liability for executives, why a cyber incident does not need a nation state (bad firmware counts), where AI belongs in the Purdue model and where it does not, AI as the daily brief for the one-person water utility, Aaron's Exchange 5.5 story about the week the executives lost their email, borrowing the safety engineers' hazard studies as risk input, and why you should never fire up a wireless pineapple on an airplane.
In this episode, you'll learn:
- How NIS2, the Cyber Resilience Act, and CIRCIA move accountability to executives and manufacturers
- Why 24-hour incident reporting starts with detection, and why you can't wing it
- How to reframe your next modernization budget ask around compliance
- What a real recovery plan needs: tested backups, plant-realistic RPO and RTO, and captured retain values
- Why redundant controllers protect against failure, not compromise
- How to test restores and run scanners safely in a replica instead of production
- Where AI helps an understaffed operator and where it should never take control
Tune in to hear how the biggest regulatory wave in industrial cybersecurity history can become the budget unlock OT has been waiting for.
About the guest:
Tobias Nitzsche is Head of Legislation and Technology for Cybersecurity at ABB Energy Industries, where he translates the fast-moving regulatory landscape, including NIS2, the EU Cyber Resilience Act, and CIRCIA, into how products are designed and projects are delivered for critical infrastructure. Before this role he was ABB's Global Cyber Security Practice Lead, capping more than 20 years across IT and OT security. Having sat on both sides of the table, first delivering cybersecurity services to critical infrastructure operators and now shaping how legislation lands in engineering practice, he brings a combined view of policy, technology, and plant-floor reality that few in the industry carry. Tobias is based in Germany.
Important Links:
- LinkedIn of Tobias Nitzsche: https://www.linkedin.com/in/tobias-nitzsche-37339735/
- ABB Energy Industries: https://global.abb/group/en/organization/energy-industries
Learn more about PrOTect IT All:
Work with Aaron: https://protectitallpod.com/work/
The book: https://protectitallpod.com/book/
This episode: https://protectitallpod.com/ep124/
The OT Security Starter Kit: https://protectitallpod.com/starter-kit/
YouTube: https://www.youtube.com/@PrOTectITAll
Email: [email protected]
X: https://twitter.com/protectitall
Facebook: https://facebook.com/protectitallpodcast
To be a guest or suggest a guest or episode, email [email protected].
Please leave us a review on Apple or Spotify:
Apple: https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify: https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
The podcast and artwork embedded on this page are from Aaron Crow | Operational Technology & Cybersecurity Host, which is the property of its owner and not affiliated with or endorsed by Listen Notes, Inc.
Weitere Episoden von „@BEERISAC: OT/ICS Security Podcast Playlist“



Verpasse keine Episode von “@BEERISAC: OT/ICS Security Podcast Playlist” und abonniere ihn in der kostenlosen GetPodcast App.








