
134: Engineers Belong at the Table: Cyber-Informed Engineering and the End of the OT/IT Boundary
Three veterans of critical infrastructure security trace how the field went from arguing that infrastructure was even a target to treating digital risk as an engineering hazard. Ginger Wright, Sarah Freeman, and Marc Sachs define cyber-informed engineering in plain terms, share real examples of consequences engineered out of a system, explain why adversaries already read your engineering documentation, and make the case that engineers don't need to become hackers to belong in this conversation. They close with why engineers should come to Level Zero. Guests: Sarah Freeman (MITRE); Marc Sachs (Center for Internet Security) Host / moderator: Ginger Wright (Idaho National Laboratory) Chapters: 00:00 Welcome and panel introductions 02:52 Why engineering is up first at Level Zero 04:24 From 'not a target' to target du jour 08:03 Y2K to WannaCry: when the OT/IT boundary became fiction 12:28 Engineering out the consequence (NIST 800-82 Rev. 3) 14:31 Why engineers belong at the table 19:01 Digital risk and defining CIE / CCE 22:13 Real examples of designed-out consequences 28:34 Where CIE runs into regulation 32:40 Engineer pushback and 'fighting the scenario' 37:01 Digital risk is just another hazard 40:01 The five whys, and why come to Level Zero Recorded at the CS²AI Online Symposium, "Level Zero: Visions & Reflections." Join us at Level Zero 2027, April 23–30 at Georgia Tech in Atlanta: pre-conference training, the Conflag Zero™ tabletop exercise, and three days of practitioner-led sessions built so you can put what you learn to work the Monday you get back. Questions: info@levelzeroconference.com · Sponsorship: sponsor@levelzeroconference.com Produced by CS²AI (Control System Cyber Security Association International).













