Episode 69 – David Bader from Eurotech and Travis Cox from Inductive Automation
Dan McCarthy: [00:00:06] Welcome everyone to the Manufacturing Matters podcast. We’re recording here live at Automate 2024. I’m here with my co-host Winn Hardin, whom you all know. And joining us today are Dave Bader of Eurotech, on my far left, Travis Cox of Inductive Automation. And we’re here to talk about cybersecurity today. I know that you two are working together on some project, but before we go there, I wanted to kind of introduce us to the audience a little bit with what each of you are doing individually. Dave, do you want to start?
David Bader: [00:00:35] Sure, absolutely. Thank you, dan. Again, my name is David Bader. I lead business development for Eurotech in North America. I’ve been in the industrial automation space for, I’d like to say 100 years because I don’t really like to mention that it’s been over 40. So I appreciate everyone listening. So Eurotech is a European-based company that builds devices and software to manage edge in the industrial space. Been around over 30 years and very excited to participate with this activity today.
Travis Cox: [00:01:10] Yeah. And I’m Travis Cox. I’m the chief technology evangelist for Inductive Automation, and Inductive Automation, we’re a software company. We provide Ignition, it’s our software platform. It’s a platform to develop any kind of industrial application from HMI/SCADA to MES and more. It’s really all about being able to empower people to turn great ideas into reality. And if they can dream up the application, hopefully they can build that with Ignition.
Winn Hardin: [00:01:34] Outstanding. So how did you guys come together and to what purpose?
Travis Cox: [00:01:38] Yeah. So we came together, Ignition as a software platform, it runs on Premise in the OT arena, and it runs at the edge or on a centralized server, but it has to run on a piece of equipment, right? And customers are always asking us: What computers can we run it on? What’s the best practices out there? And that’s how we got hooked up with Eurotech. In terms of being able to have, from a cybersecurity stance, all the way through from the hardware to the software.
David Bader: [00:02:06] Yeah, it’s pretty interesting, actually. You know, Travis and I met, and our first discussion was about cybersecurity. I mean, it was literally that was our first discussion. And it was about how Inductive Automation has kind of built their own infrastructure internally to meet industry standards for cybersecurity. But the OT space is really particular as far as the standards are concerned. So to get the highest level of cybersecurity, it includes hardware and software. So the ability for us to partner together, and we have many of our hardware products that we’ve already released into the market are built to that IEC 62443-4-2 standard, which combined with Inductive Automation’s 4-1 standard, gives our end user customers the opportunity to really elevate their cybersecurity posture in the field.
Travis Cox: [00:02:58] You know, we’re seeing, of course, with these Industry 4.0 digital transformation efforts where we’re blending the worlds of OT and IT, right? We’re having to move data from these HMI/SCADA systems now through the business up and even into the cloud. And when we’re doing that we have to be conscious about that data flow. We have to be conscious about these systems. right? These systems are still used to control equipment, machines. And we want to make sure we’re not opening ourselves up to any vulnerabilities. So in the old days, it might be okay to run on a specific OS that might be end of life. But these days it’s absolutely not, right? we have to really look at cybersecurity all the way through that entire stack now.
David Bader: [00:03:35] In fact, 20% of the cyberattacks right now are attributable to factory, OT kind of devices. So it’s really, it’s never been more important now than it is now for us to be able to be aware of this. So building that infrastructure from the beginning is super important.

Dan McCarthy: [00:03:55] Do most of the attacks kind of originate at the IT level, or is it . . .
David Bader: [00:03:58] Well, 20% right now, 20% of the attacks at the OT level are kind of really, really pretty significant. And there’s a number of reasons why, right? we’re connecting more things, as Travis said, right? We’re connecting from the whole IoT space all the way up to the IT level up to the cloud. So inherently we have legacy systems in the field, legacy operating systems, legacy PLCs, things that are really, that inherently have vulnerabilities.
Travis Cox: [00:04:30] Yeah. You know, with these systems on premise, I mean, a lot of the attack vectors aren’t necessarily bad actors coming from the outside world coming in. It’s people that work there that are going in and plugging in USB devices or accessing the systems with their laptops. And so with that world being so complicated, right? We really have to look at our architecture more closely.
Winn Hardin: [00:04:54] And most of those are unintentional I’m assuming, most of them.
David Bader: [00:04:56] Well, I think for a while they were unintentional. But now there’s an incentive for people out there to create these problems, right? There’s businesses out there that are built around trying to, the bad actors, trying to build a business around . . .
Winn Hardin: [00:05:16] Intentionally, essentially.
David Bader: [00:05:18] Yeah, or charging money to get people back up and running.
Travis Cox: [00:05:21] A lot of it is not intentional. They don’t know that these things are happening, right? But they picked up this device or somebody said, “Hey, can you go look at this thing?” And they plug it in and all of a sudden we have ransomware issues that are happening out there.
David Bader: [00:05:34] Yeah. I mean, last year Brunswick Corporation, $1 billion company, right? Last year, I think June. So less than a year ago they had, they were down, their entire manufacturing operations were down for almost 10 days. Cost the company over $85 million. And that was through the OT space.
Winn Hardin: [00:05:57] So if someone wants to get started in this and start leveraging your capabilities, what are the first steps? How do they approach this challenge?
Travis Cox: [00:06:03] Yeah. You know I’ll start with this because we were just discussing that we can go and put Eurotech’s hardware in there. We can go put Ignition software on that. Get it installed and running. By default, those are not going to make you secure, right? All of the tools and the configuration is there to make it secure. But it really means that somebody has to apply that, right? And they have to understand how that works with the rest of their infrastructure.
Winn Hardin: [00:06:30] Was that a discipline of operations or is that a final integration step that is having to be done internally by the customer?
David Bader: [00:06:34] You know, I think it’s the first step, right? I think you need to understand where your vulnerabilities are. So bringing in a third party to understand what is the actual capability that you want to try to mitigate. And then from there you can start to build a solution. Now, as Travis said, we have a really prescribed solution that’s built to the highest standards together, right? And the 62443 standard is mandated in Europe and it is highly suggested everywhere else in the world for almost every vertical market. I know Inductive Automation spends a lot of time in manufacturing and other vertical markets as well, as do we. And these standards are being carried across all of these vertical markets. But the ultimate piece is, just because we put them in there doesn’t mean that you’ve inherently made it any more secure. So I think that’s a message that we really want to double stomp on here.
Travis Cox: [00:07:29] Yeah, absolutely. And from our standpoint, we have professionals on the OT side who absolutely have to keep the operations running, right? That is their job. That’s their domain. They know that domain. We can’t rely on them to understand the complexity of the world of cybersecurity. And of course IT, that is their main job. That’s one of their main jobs. And so really where the success comes is by companies building a culture where they’re bringing the two sides together and they’re building teams where they’re attacking this from both sides, where they’re understanding that you’ve got to put these tools in that are going to help operations but at the same time are using the same modern technologies and best practices that the IT is already applying, because then they can they can take all that, bring it in. The great example of where these things fall flat is like talk a lot about shadow IT, right? So if you look at the Oldsmar treatment plant in Florida. What had happened? They installed TeamViewer on a client workstation, HMI client workstation out there. And it wasn’t IT that did that. It was the operations team, right? So they can go access it remotely. That’s great.
Winn Hardin: [00:08:31] To be able to download technical support or maybe view their own systems remotely I’m assuming.
Dan McCarthy: [00:08:35] Absolutely. But it wasn’t applied necessarily with how we would do modern security practices where it’s two-factor authentication. It was just simple username and password. So somebody is a bad actor got in and was changing set points on the HMI that was already logged in to do so, right? So had the teams worked together and say, “Hey, look, we need to have remote access. What’s the best way that we can approach this?” You know, have the two professions come together. You know, then we’re going down the path together. You know, it’s all about risk mitigation. We can’t prevent everything. We’ve got to be able to apply what we can to make this work.
Winn Hardin: [00:09:08] So is there a third pillar here when we talk about software? We talk about hardware? Is there also a process cultural component?
David Bader: [00:09:14] 100% I think yeah. And that’s where I’m going with the understanding what problems are ahead of time, right? But it’s also education. And I think that’s where you were touching on with the people. I mean, I know walking into a factory and seeing an HMI or something like that with a Post-it note with the password and username on there, you know “admin, admin,” right? It’s just the way it was for a long time. So if we don’t educate the teams that are in the field, that are in the OT space, that this is not acceptable anymore, then it’s going to continue to happen. So yeah, I think that culture is big.
Dan McCarthy: [00:09:50] Are there particular verticals out there that are really sort of exhibiting, adopting this, embracing this?
Winn Hardin: [00:09:57] Particularly a specific threat?
David Bader: [00:10:01] Everybody’s in a different stage of their adoption. I don’t know that I can speak to any particular vertical. But if you look at like medical, right? I mean medical, it’s an amazing thing that they’ve gotten away with it as long as they have. But you can’t connect, in a medical device company, you can’t necessarily push data outside of a hospital or anything. It’s just not, it’s something that they tried to lock down for many years. That’s changing. So they have to really kind of catch up their standards. They have a technical directive called 60601 that is actually now adopting 62443. So each of the verticals have different perspectives. I think in my presentation that I did this week, I had a slide that had about 10 different verticals and the different relative standards that are related and how they all point back to 62443. You know, that’s kind of that overriding standard.
Dan McCarthy: [00:10:54] Now what about particular technologies? I know you were talking about edge AI. Is there particular technologies increasing the vulnerability to attack like this? You know, IoT is a big, big umbrella term, but.
David Bader: [00:11:08] I don’t know. It’s a great question that I haven’t really thought about it. I don’t think it’s a particular technology as much as it is the need for a particular technology to connect. And I think we talked about from edge to cloud or from . . . In fact, actually, what 62443 helps us to do in our solution is from the TPM area, right? From the chip design, we manage the certificates in a zero touch provisioned way, right? So from the chip all the way to the cloud, we can manage all of those certificates so that you don’t have to email a password or email somebody that certificate. And then when it needs to be updated because there’s additional bad actors that have been identified, you can update those certificates, right? So I think it’s the connectivity. I think there’s like a couple of things, right? It’s the legacy systems that we have in the OT space that are inherently vulnerable. I think the education of the people that we’re working with needs to be increased. And then I think that this zero touch, never trust, always verify approach, which is again going back to the IT side.
Travis Cox: [00:12:22] Nowadays, the more people are learning about zero trust and the models that are there, they start to understand why it’s so important, right? Because it’s like, first of all, you just have to trust nobody. When I put something in, I got to trust nobody.
Winn Hardin: [00:12:41] Welcome to modern times. It used to be just trust until they gave you a reason not to. But not anymore.
Travis Cox: [00:12:45] Yeah. And so, like I was saying before, I put Ignition in by default. It’s open, right? We have to go in there and we have to go and turn on SSL, make sure that the gateway is protected through certificate. And IT should manage that certificate. It should be something that they are handling, not some self-signed one, you know that you then still don’t get that trusted in your browser, right?
Dan McCarthy: [00:13:07] You have to keep that updated.
Travis Cox: [00:13:10] Exactly, and certificate management all the way through is really important. But you know, then being able to tie into their corporate identity systems. And IT has them, you know, it used to be Active Directory, and nowadays we’re talking about things like Okta and Duo and Microsoft ADFS and all these tools that provide secure authorization. And they provide multi-factor. That second form is incredibly important. And I know for a lot of OT people why they have Post-its on there is because they complain about how hard it is. I got to log in to get this system. Well, then they’re not understanding the landscape of cybersecurity. We’re not educating them properly to say, hey, the reason you’re doing this is because we need to have a better posture here, right? And with that second form can be something easy. It could be a badge. It could be acceptance on their phone. There’s all sorts of great technologies that are there. Biometrics, all of those.
David Bader: [00:14:02] And let’s face it, we’re all doing it on in our everyday daily life anyhow. There’s there’s no website or no modern technology that you’re accessing from your phone that doesn’t have a second form of authentication.
Travis Cox: [00:14:13] But what we’re really trying to do here is say that, look, 62443, and that standard has the best practices, right? These are standards bodies that come together and say, look, we must have these things, and that will evolve. It will change. There will be additions to them as we go forward, but as long as vendors are aligning to that and the company is educated on what to do and they have their teams working together, ultimately then they’re going to apply all those best practices. They’re going to learn about those best practices, and they have products that they know will have things in them that they need. And that’s really what is so exciting I think about the collaboration we have is that together we can market as: You have the tool set you need both from a hardware and a software standpoint to to do your due diligence, right? And we’re also going to provide to you best practices. They have great documentation around this. We’ve got a security hardening guide that talks about how to do that. We have our security trust portal where they can go in and see any CVEs or vulnerabilities or just what’s out there, what’s going on so that they are armed with the best information possible, right, to take action.
Winn Hardin: [00:15:24] So now your solutions usually deployed at the gateway, every open portal basically? Or is this something that each control system, each machine?
Travis Cox: [00:15:32] Yeah. So I’ll take that one because it differs for different verticals, different companies, how they want to approach it. But if you look at traditional HMI systems, they’re at the edge. They’re critical assets, critical machines, they’re right next to those PLCs. Well, those PLCs, as as you mentioned earlier, they’re not secure.
Winn Hardin: [00:15:56] I mean, it’s the current trend, right? So every one of them has got a doorway right outside. Unless somehow you’re directing all that traffic through a central portal or gateway.
Travis Cox: [00:16:05] And we can have a layer 3 switch where we do VLANs and all that. But I think even a better posture is to have an edge device that goes out there with segregated Ethernet ports, right? Where they can’t cross over. You talk to the control system locally, and you have the edge software that provides the HMI and provides the way to get data to a higher-level system. So you get the best of both worlds.
David Bader: [00:16:24] Sorry to interrupt, and it provides the way to be able to provide remote device connectivity as well in a secure way rather than just opening up a VPN, right? So everybody now just says, hey, yeah, I have a VPN. Let’s open it up. You know the standards now, you kind of prescribe an outgoing VPN that doesn’t allow incoming data. So connecting to the cloud, being able to provide patches and things like that remotely. That’s another feature that is very important in this whole infrastructure.
Travis Cox: [00:16:54] And like I said, whether you’re at the edge or whether you have one centralized server, the same principles apply. You have the PLC network be separate, connect to that over its own network, and then have the application sit there that has all the best practices applied. So there’s different arenas, but the principles are the same.
Winn Hardin: [00:17:11] The plant network is probably, the existing plant network in that facility is probably driving that, where you’re going to make recommendations.
David Bader: [00:17:18] Yeah. Yes and no. I mean I think for us it’s portable, right? So we can put gateways with this capability with 64. But we can also put edge servers, and we can do anything in between, right? We can do edge AI servers that also have the security built in that are doing very high-level inference at the edge, you know, and all of those can be equipped with that kind of capability.
Travis Cox: [00:17:40] Yeah. With that being said, the connectivity, though, is one of the big drivers, for putting the edge out there. So we talked for a long time about hub and spoke architectures, right? Because those at the spokes, at the edge. You know if you ever lost communication at a remote site, let’s say a critical asset, maybe it’s in a building where a forklift could cut the fiber to that building. You need to have that functionality locally. You cannot have that blind, right? And so edge has actually been around for a while from that standpoint. That’s what HMI is really all about, right? We’re just talking about connecting the edge now to a high-level system at the end of the day. And so it becomes really important, like architecture, connectivity, and how they want to do this. But now we’re in this weird state of digital transformation. We’re talking about a lot more data. Now we’re unleashing the 90% of data with strata data. We want to get it out. We’re also doing it from a scalability standpoint. Distributing these systems.
Dan McCarthy: [00:18:36] And how do you do those patches? How do you maintain that system across that whole enterprise or that whole multiple enterprise kind of operation?
Travis Cox: [00:18:44] Before you might have had one gateway. Not so bad to keep that patch. But now if you have 100 edge gateways out there, you’ve got to think about it a little more. And you should be applying technology that’s going to help you do that, right? Progress forward in a much faster way.
Dan McCarthy: [00:18:57] Is the charge for this in the enterprise, is it IT pretty much or does OT buy in or does OT drive this?
Travis Cox: [00:19:04] It’s a really, really good question because traditionally from a SCADA perspective, OT drives that, right? And they’re responsible for that. However, all these digital transformation initiatives are not driven by OT. They’re all IT based. They’re the ones that have the budgets. They have the data scientists that are trying to turn data into insight. And what we’re doing is saying, look, we’ll connect down. We’ll get that information to a system that’s fundamentally insecure. Well, we should build a better foundation. We should have a SCADA system and/or HMIs that are in their own right secure and modern but have the ability to speak IT languages so that we can get that data up. And now it’s a matter of collaboration between the teams rather than, it’s like, “You’re going to connect down to me and get my data.” No, we’re going to provide it to you, so that you can do those initiatives.
David Bader: [00:19:56] But I think it’s part of this evangelism that we’re doing, right, is this partnership and everything, is to make it easier for these two teams to talk together because inherently they have always butted heads, right? I mean, the IT guys and the OT guys, “You’re stepping on my feet,” right. And I think, to your point about providing IT-kind-of capabilities at the OT level makes it easier for the IT guys to come down, and it helps the OT guys understand exactly why the IT guys make the decisions that they do.
Dan McCarthy: [00:20:26] Common dashboard for both that they’re able to access? Or what is the interface for the OT guys versus the IT guys? The IT guys have to see the whole enterprise whereas the OT guys have to see their plant, their operation.
Travis Cox: [00:20:38] Yeah, IT’s more focused on the health of the systems and what the network looks like and connectivity and uptime of servers.
Winn Hardin: [00:20:45] And in terms of dashboards, they’re going to be accessing your software, UI, UX, in terms of running on your hardware systems, right? So in terms of engagement with the security system, it’s going to be at Induction Automation.
Travis Cox: [00:20:58] Yeah. Yeah. And you want that to fit into how all the other applications that they’re doing, how they all work at the same time.
Winn Hardin: [00:21:05] So what are the biggest challenges you guys see right now? I mean, I can envision where adding a software module to an existing HMI PLC, people might be willing to do that. They can see the additional cost, but you really can’t have the security without the hardware platform.
David Bader: [00:21:22] Yeah, I mean, well, let’s just say this, you can’t easily create an overall secure solution quickly without having built from the ground up to the standards, right? Again, we’re going to reemphasize the fact that inherently, we’re not secure, right? When we work with with Inductive Automation, that system isn’t secure. But we’re giving you the tools that are able to make the entire system secure much quicker than you would otherwise, and we’re building that to the industry, in many cases, mandated requirements. So I mentioned briefly that in Europe, this is a mandate, right? This is a fineable offense if you don’t build to these standards, right? And what we’re doing in the U.S., is we’re saying, okay, we’ve made recommendations. But I look at almost everything as an ROI or a total cost of ownership, right? So when you think about the Brunswick case that I just mentioned or the Applied Materials case that happened also last year that cost them $250 million and 10 days of lost productivity. They reported in their quarterly report that it affected their overall business. So if you start looking at it as a total cost of ownership, you don’t need a law to tell you that this is important.
Winn Hardin: [00:22:42] $250 million is one thing. A 5% drop in your stock price could be a whole different animal.
David Bader: [00:22:47] That’s a good point.
Travis Cox: [00:22:48] Absolutely. Yeah. I mean the big challenge is of course education, right? And mandates help because it helps gear people to: What do I need to know and be able to achieve that. And the other thing that’s a challenge besides education is just the fact that a lot of systems here are older. And they’re getting to end of life of these systems. They’re running on antiquated OSs or hardware. And you know, they’ve got to do something. They can’t let that be. Also, there’s probably not even a product off the shelf that they can find if it goes down, right? They’re going to have to learn something new. So what we hope, of course, is that when they’re looking at something new that we take a more modern mindset and think about cybersecurity along with, of course, just the operations things that are needed, right? But put it all together.
Dan McCarthy: [00:23:38] Yeah I agree. I agree. I think that’s really important.
Winn Hardin: [00:23:42] Yeah. Well you know, we talk about education being such a key component. We’re probably, what are we about 10 years into this discussion? You know where we started to see OT threats early on, the famous ones and overseas and everything. You have government actors, doing these things. I think that’s about how long the conversation has been going on, right?
David Bader: [00:24:00] I think publicly that’s probably as long as it’s been going on. But, again, it goes back to that additional vulnerability because of now things becoming more and more connected, right? So we can look at best practices in the past where, yeah, we’re not going to connect to anything, right? Our plan is going to be completely an island. That’s not feasible. You can’t manage any operation that way today. So yeah, I think 10 years makes sense. But I think it’s accelerating.
Travis Cox: [00:24:27] There’s a drumbeat. I mean, every week you’re hearing about ransomware, malware attacks at the industrial level as opposed to . . .
David Bader: [00:24:37] Literally today, in our booth here at the show, a company came in and we were having a general discussion, and I started talking about cybersecurity. And I said, hey you’re a small company, you got to be aware. And he said, “Yeah, we got hacked this week.” This week.
Dan McCarthy: [00:24:52] At the OT level?
David Bader: [00:24:54] At the OT level.
Winn Hardin: [00:24:54] How big was that company roughly?
David Bader: [00:24:56] I have no idea. You know, it was the first time I met them and they were scared.
Winn Hardin: [00:25:00] But the point is, you don’t have to be a $100 million company.
David Bader: [00:25:03] That’s right. Absolutely. That’s right.
Winn Hardin: [00:25:05] You’re relatively small, typically $5–$20 million. It probably has a lot to do with who you’re doing business with in terms of your visibility. You know, whether you’re becoming a target for bad actors.
David Bader: [00:25:17] We talked a little bit about, there’s inadvertent attacks too, right? There’s things that just happen. So in 62443, there’s multiple layers, right. So service layer 1 is designed to prevent those inadvertent attacks and also kind of tamper evident at the field, right? So again if a guy turned a screwdriver or whatever, you get a bit, you’re able to at least enunciate that there’s a problem and you can decide what you want to do with the system there. But SL2 is designed very specifically around targeted attacks, known targeted attacks. Now there’s 3 and 4 as well, but there’s nobody at the OT level that are 3 and 4. Eurotech is actually taking a stance where we’re at this point, several of our products are SL2, kind of designed to SL2 standards, which again, is a way to maintain the known-attack kind of vector that people are starting to see. But you know, we’re certified to that standard. You can build to a standard, but there’s also the added and extra requirements to get certified to that standard by a third party. You know, independent certification.

Dan McCarthy: [00:26:27] The mandate in Europe, is there a timeline on that? It’s not just greenfield. It’s there’s no grandfather.
David Bader: [00:26:31] No, no it’s underway now. And by 2027, I think it’s going to encompass everything. So off the top of my head I don’t remember, but I do have some references to talk about it. But it’s in play right now.
Winn Hardin: [00:26:46] So I’m going to guess you guys have some European offices.
David Bader: [00:26:48] We do. We’re a European company.
Winn Hardin: [00:26:50] That’s right. Yeah, yeah.
Travis Cox: [00:26:53] Yeah. We have several European distributors.
David Bader: [00:26:55] We work together in Europe quite a bit.
Winn Hardin: [00:26:57] Yeah. Outstanding.
Travis Cox: [00:26:58] You know, one thing I want to say is that, like, it’s easy to turn a blind eye to this stuff.
Winn Hardin: [00:27:03] Plus it’s an area that these folks just don’t understand. They don’t get that.
Travis Cox: [00:27:07] Right. “It hasn’t happened to me. It’s not going to be a concern of mine.” But see, that’s the fundamental problem, right? Is that the DNA and the culture of these companies have to change. And saying, look, cybersecurity is something we have to take seriously all the way across the board. Now, of course, IT’s doing that right. You’re talking about the technical details of these things are important for them to monitor, right? But it’s not just those. It’s everybody that’s got to be a part. Leaders have to basically set a standard that, look, we’re all going to follow. We’re going to be trained, and we’re going to follow these techniques. And this is also just people, I mean our company we do, we have every employee go through a series, a training series of videos. It’s actually quite, quite fun to watch these videos, but it’s really good acting and stuff. But it is to kind of talk about these ransomwares and these attacks and the social engineering that’s out there and all these things that are happening, right? So that we can be better prepared, so that we maybe we look at the email a second, two times, right? Rather than just clicking on something. They were thinking about, oh, I should, what is this coming from? And if everybody in the organization is doing that, then not only do you have the right protections in place with your systems, but you also have people that are thinking about it. And that combination is really important.
David Bader: [00:28:21] It’s pretty interesting too, you know, you when you visit a customer or you visit a show like this and you see people working on their laptops maybe at lunch or something, and then they walk away from their open laptop. It’s the culture, that simple culture of, hey, you can’t leave your laptop open anymore because that is a path of vulnerability. And people just have to be educated.
Winn Hardin: [00:28:47] Yeah.
Travis Cox: [00:28:48] Yeah. But I mean, in lack of that too, if companies are moving towards, that’s great. But at least there’s assurance that with what we’re marketing and kind of putting out there, there’s assurance that, hey, we do have products that will allow us to get there. And we can have a pretty good, a much better secure system than we’ve had before.
Winn Hardin: [00:29:06] 100%. We’re probably hearing the tiniest fraction of a percent in terms of the attacks that are actually happening, because people are not wanting to, I mean, they’re not promoting this. No one’s talking about the fact they get hacked.
Travis Cox: [00:29:18] And let’s face it, critical infrastructure, government, military, nuclear, all the power plants, all these things are obviously big attack vectors. And what’s cool now is government’s actually putting funding for these organizations to enhance their cybersecurity stance. They just don’t know that it’s there. You know they do that, and they can get access to these kind of products, then things can change.
Winn Hardin: [00:29:41] But it’s got to be at the end, right?
Travis Cox: [00:29:42] It’s got to be at end to end. Yeah. For sure. You can’t just put a product in and think it’s going to solve a problem, unfortunately.
David Bader: [00:29:50] We’re just trying to allow it to be an easier lift to build that posture.
Dan McCarthy: [00:29:57] Dave, Travis, is there any other key value props, points that we haven’t covered? Something that you want to, last thought you want to leave the audience with?
Travis Cox: [00:30:04] Well, like I said, I think it’s important to really, it’s time to enhance our cybersecurity posture, right? To really be educated about these. We do a lot, at least our company will do a session with companies to kind of talk about it. “What do you have? What are you worried about?” These kind of things. And we can offer any guidance and help there. We’re there to educate, right? At the end of the day, we have products we want to sell, but we’re also there to educate.
Winn Hardin: [00:30:33] Where should people go to when they want to learn more?
David Bader: [00:30:35] Eurotech.com.
Travis Cox: [00:30:36] Inductiveautomation.com.
David Bader: [00:30:38] One thing I’ll say is that this partnership is opening up the discussion a little bit more as well, right? So having the ability to talk to customers about these kinds of applications and these things. I mean, Eurotech’s been been doing this for quite some time now. We’re the first from a hardware perspective to be certified at this level.
Winn Hardin: [00:30:58] Zero touch.
David Bader: [00:30:59] Yeah. And having this partnership with Inductive Automation is something that is really opening up the discussion. So I’m super excited.
Travis Cox: [00:31:07] We’ve seen it here, right? Automate. We’ve had customers come because they heard about that and they want to know more. And that’s a great thing to see.
Winn Hardin: [00:31:14] This is more of a fact check all the way across the board. I hope you guys are taking the message out there. There’s an awful lot of industries that are gobbling up automation technology. Every one of them is vulnerable.
Travis Cox: [00:31:29] Absolutely.
David Bader: [00:31:30] Yep. Thanks for having us.
Winn Hardin: [00:31:31] Travis, we can’t thank you enough for giving us some time today. This is a critical topic. I’m glad that we’re having a deep, deep dive on this. This will not be the last time that Manufacturing Matters will look at this topic. So if you’ve got any questions for Dave or Travis, please shoot them over to us. You can click below. Like the episode we have right now. If you want to see any past episodes, go to manufacturing-matters.com. If you’d like to be on the show, reach out to us, ping us. And again, if you’ve got any questions, be sure to go by these gentlemen’s websites. Find out. I’m sure they’ve got a whole lot of educational material on their websites that will help you understand the threat and how hardware and software are working together to make the world a safer place. So until our next episode, thank you so much for Manufacturing Matters and we’ll see you soon.


