Find partners
You Gotta Hack That

You Gotta Hack That

Hosted by You Gotta Hack That

Episodes

31

Latest episode

Feb 2026

Language

EN

About the show

Felix explores Internet of Things (IoT) and Operational Technology cyber security. Perfect for project managers, developers, and those learning about penetration testing in this niche area. Email Felix using helpme@yg.ht Get more information at the website: yougottahackthat.com Find You Gotta Hack That on LinkedIn and X @gotta_hack

Listen to episodes

31 recent
February 25, 2026Episode 3021 min

Nerds vs suits

In this episode of You Gotta Hack That, Felix sits down with Alex Ward to unpack the real gap in OT security, nerds versus suits. They dig into why “good enough” thinking persists, how risk gets lost in translation between engineers and the board, and why signing off risk can focus minds fast. They also get into the uncomfortable bits, safety, insider threats, and why recovery and business continuity often matter as much as prevention in industrial environments. Expect blunt talk, practical framing, and a few war stories from the OT frontline.

February 18, 2026Episode 2927 min

Mag stripes died... Is contactless dangerous again?

From carbon-copy receipts and zip-zap machines to mag stripes, chip and PIN, contactless and mobile wallets, payment tech keeps evolving, and attackers evolve right alongside it. Felix sits down with Gareth, a payments industry veteran of 30 years, to unpack the real hardware attack surface: skimmers in stripe readers, ATM overlays, contactless relay tricks, and why static QR codes are basically begging to be abused. They also dig into why raising contactless limits changes theft economics, how phone theft turns into credential theft, and why the EU Cyber Resilience Act means you need to think about hardware security now.

February 9, 2026Episode 2825 min

Getting a career in OT...

In this episode, Felix is joined by Anjan, a cybersecurity engineer working at the sharp end of OT product security and compliance in UK manufacturing. They dig into what it really looks like to build security into connected industrial kit, especially with major regulation deadlines looming. Anjan shares a practical path into the industry, starting with bug bounty and vulnerability disclosure, then moving into IoT and OT during his Masters, including work on an autonomous vehicle project. Expect honest talk on “audit equals secure” myths, risk-based security, and how to start building an OT security career.

February 5, 2026Episode 2717 min

And the winner is .... 'lowest compliance effort'

In this episode, Felix continues his conversation with David Rogers (Copper Horse) about the latest State of Vulnerability Disclosure report and why “what counts as IoT” is messy. They explore how consumer devices end up everywhere (including factories), how category labels can become compliance loopholes, and why good vulnerability disclosure needs more than a generic support page. David also shares concerns about the EU Cyber Resilience Act drifting toward tick-box compliance, and what that could mean for product security teams and, ultimately, all of us. Plus: the report’s dataset is open for anyone to check.

January 26, 2026Episode 2621 min

Ever heard of an insecurity canary?

In the first of this two-part episode, Felix is joined by David Rogers (Copper Horse) to unpack a surprisingly powerful way to measure IoT security: vulnerability disclosure policies. David shares what eight years of research reveals about how easy (or impossible) it can be for security researchers to report flaws. We discuss why the lack of a clear route to report vulnerabilities to a vendor is an “insecurity canary” and how security researchers and businesses struggle to get along without enabling easy communications on these topics. We dig into the results from the Copper Horse annual report, the impact of new regulation, and why retailers might be the hidden force improving the market. Plus: the long tail of ultra-cheap devices, and why security shouldn’t be a luxury.

January 21, 2026Episode 2524 min

OT Threats, Penetration Testing, and Resilience

In this episode of the You Gotta Hack That podcast, the conversation continues with Emily, a principal industrial cyber security consultant, as they delve into the real-world threats facing operational technology (OT) environments. The discussion highlights the inadequacies of traditional IT penetration testing when applied to OT networks, emphasizing the need for tailored approaches that consider the unique vulnerabilities and operational realities of these systems. Emily and Felix explore the concept of dwell time, illustrating how sophisticated attackers can remain undetected within networks for extended periods, gathering intelligence before launching attacks. They stress the importance of understanding actual risks and the necessity of continuous monitoring and testing to ensure robust cyber security measures are in place.

January 12, 2026Episode 2424 min

Demystifying ISA 62443

In this episode of You Gotta Hack That, Felix sits down with Emily, a principal industrial cyber security consultant and former national utility cyber lead, to demystify ISA/IEC 62443. Why do so many teams treat it like a silver bullet and why does that backfire fast? Emily breaks down what 62443 actually is (spoiler: it’s a family of standards), why “be compliant” isn’t a requirement, and why maintenance matters as much as deployment. If you’re trying to secure OT environments, this one will help you focus on what to do first.And don't forget to check out our training courses to get hands-on and nerdy.

May 8, 2025Episode 2318 min

The implications of phone theft

In this episode, Felix and Alex discuss the alarming rise of phone thefts in London, sharing personal anecdotes and insights into the implications of losing a device. They explore security measures, user behaviors, and the broader impact of identity theft in today's digital age. The conversation emphasizes the importance of enhancing phone security and being proactive in protecting personal information.

April 17, 2025Episode 2219 min

Autonomous ships, cyber security and the workboat code

In this conversation, Felix and Oli discuss the development of a hydrogen-powered uncrewed surface vessel (USV) and the associated cybersecurity challenges. They explore the importance of integrating cybersecurity measures from the outset, navigating regulatory frameworks like Workboat Code 3, and the ongoing challenges of ensuring compliance and safety in a rapidly evolving technological landscape. The discussion highlights the need for thorough documentation, the role of regulations in shaping industry practices, and the future of cybersecurity in maritime technology.

December 18, 2024Episode 2119 min

Attacking Santa's Christmas deliveries

Felix and Alex discuss the attack surface and disruption opportunities for a Cyber attack against Santa's Christmas delivery schedule.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts