
Episode #15
Billion Dollar Pilots and Boil Water Notices: Securing OT Environments
βThe only thing that isn't digital in the Department of War is the bayonet.β That line from DoW CISO Aaron Bishop set the tone for a standing-room panel Brian moderated in Washington, DC, with partners at Armis. In Episode 15 of The GIST of Govt IT, Brian and Sean bring listeners the lessons learned from that breakfast briefing on securing the converged IT, IoT, and OT enterprise β featuring Bishop, Department of Transportation CISO Dr. Justin Ubert, and Armisβ Director of Civilian Strategy Matthew Shelbetter. The conversation digs into the central insight all three panelists shared: the hardest part of convergence isn't the technology, it's the culture. IT security teams and OT operators speak different languages, hold different priorities (availability and safety first), and have to learn to meet in the middle β often starting with nothing more sophisticated than a room, a tabletop exercise, and a lot of pizza and Mountain Dew. Brian and Sean also unpack Bishop's concept of mission-relevant terrain for cybersecurity, why attack path mapping and asset discovery are the foundation, how to pay for OT security when the funding is scattered (identity-for-agents riding on AI budgets, consensus-building at HHS, and Bishop's $1B OT security pilot anchored to a zero trust framework), and why the community β local utilities, mayors, volunteer responders, partners like Dominion Energy β has to be in the room before the house is on fire. Plus, three Monday-morning takeaways straight from the panelists. The Panel & Blog β’ When the Perimeter Disappears Breakfast Briefing Recap Blog β’ Aaron Bishop, CISO, Department of War β’ Dr. Justin Ubert, CISO, Department of Transportation β’ Matthew Shelbetter, Director of Civilian Strategy, Armis β’ Armis Federal Policy & Frameworks Referenced β’ OMB M-26-14 and the CISA Logging Reference Architecture : https://www.whitehouse.gov/omb/memoranda/ β’ DoD OT Zero Trust Reference Architecture β’ CISA Zero Trust Maturity Model β’ GSA βEliminate, Automate, and Optimizeβ playbook for AI/agents β’ NIST SP 800-82 β Guide to Operational Technology Security The Threat Backdrop β’ CISA advisory on Iranian-affiliated actors targeting water and critical infrastructure β’ CISA Industrial Control Systems resources β’ EPA Water and Wastewater cybersecurity resources The Three Monday-Morning Takeaways β’ Dr. Justin Ubert: Get the disparate teams β red, blue, OT, leadership β in the same room β’ Matthew Shelbetter: Talk to the operators; educate leadership and frontline managers, then get the right platforms and partners β’ Aaron Bishop: Start with asset discovery β know what you have, where it is, and who owns it Related Episodes β’ Episode 14: A Pause, Not a Pass on CMMC β’ Episode 13: Fed Christmas in July? The OMB M-26-14 Holiday Rush Begins! β’ Episode 7: Iran Came for the Dams and We Got Lucky: Frontline Insights into the OT Fight Upcoming Events β’ Upcoming GIST 360 webinars and fall breakfast briefings The Hosts & Show β’ Swish β’ GIST 360 CONNECT WITH US Got an idea for a future episode? Want to be a guest? Let us know. Brian Lake - blake@swishdata.com Sean Applegate - sapplegate@swishdata.com Subscribe wherever you get your podcasts: Apple Podcasts, Spotify, or gist360.com.






