This podcast breaks down real cybersecurity incidents to understand what actually went wrong, not in theory, but in practice. Each episode analyzes a recent attack, explains the technical mechanics in clear language, and translates them into concrete lessons for security, engineering, and business teams. Topics covered: OT security, ICS cybersecurity, industrial control systems, critical infrastructure protection, NIS2 compliance, Zero Trust architecture, operational technology resilience, railway cybersecurity, automotive security, and cyber-physical systems.
Pitch Analysis
Required Pod Score for this show. PitchCentric checks your profile against host openness, topical fit, and audience signals before you generate a pitch.
Contact path
Verified email
Booking probability
34%
Guest openness
Selective
Verified email on file
80/100
Required Score
Sign up to generate a grounded pitch for Cybersecurity Under Pressure. Real Attacks, Real Lessons.
What is Cybersecurity Under Pressure. Real Attacks, Real Lessons?
Cybersecurity Under Pressure. Real Attacks, Real Lessons is a technology podcast hosted by Antonio González, with 82 episodes on record and a Required Pod Score of 80. PitchCentric scores this show on Booking Probability, Listen Score, and live audience signals refreshed every 24 hours.
About the host
Antonio González hosts Cybersecurity Under Pressure. Real Attacks, Real Lessons, a technology show with 82 episodes published.
Our AI reads these to draft pitches. Use them as grounding for a pitch that cites a real guest and a specific topic.
Cybersecurity Under Pressure. Real Attacks, Real Lessons
Trusted Software, Wrong Weld: Why OT Integrity Is Not Process Integrity
Aug 19, 202638 min
A welding robot can execute trusted software, accept authorized commands and still produce the wrong physical result. That distinction sits at the heart of this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons. We examine a fundamental problem in industrial cybersecurity: the difference between proving that software and commands are legitimate and proving that the physical process is still doing what engineering intended. The Technical Breakdown separates logical intent from authorized operation. A valid command can be authenticated. Software can remain trusted. Access controls can work as designed. And yet the resulting action can still be wrong for the process. That changes the security question. Instead of asking only, “Was this command authorized?”, industrial defenders also need to ask whether the resulting physical behaviour remains within the expected engineering envelope. The challenge becomes even harder in brownfield environments, where legacy controllers, operational constraints and existing industrial architectures limit how easily new security controls can be introduced. In The Pressure Test, you take the role of engineering and security leadership at a Tier-1 automotive supplier producing structural chassis components. The problem is no longer theoretical: you have to decide how much assurance is enough when production, legacy technology and the physical consequences of a wrong decision all matter. The episode concludes with a practical principle: selective assurance. Not every signal requires the same level of validation, but the parameters and actions capable of changing the physical process deserve stronger scrutiny than simple software trust can provide. Because in OT, trusted software does not automatically mean a trusted outcome. Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and practical lessons for cybersecurity leaders. Explore all episodes and resources: https://cybersecurityunderpressure.com/episodes
Cybersecurity Under Pressure. Real Attacks, Real Lessons
Bendix EC80 Brake Recall: When Safety Urgency Meets Cybersecurity Controls
Aug 17, 202641 min
A brake recall is first and foremost a physical safety issue. But what happens when the pressure to act quickly collides with the security controls protecting a critical vehicle system? In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we use the Bendix EC80 brake recall to examine a difficult product cybersecurity problem: how to preserve cyber resilience when safety-critical engineering decisions have to move fast. The Technical Breakdown starts with the asset itself, examining the hardware and the trust boundary around a critical braking system. From there, the discussion moves beyond architecture and into the environments where remediation actually has to work. The factory floor. The service bay. The engineering sprint cycle. These are the places where cybersecurity requirements meet operational reality, and where a control that looks straightforward on paper can become much harder to enforce under safety, production and time pressure. In The Pressure Test, the evidence is incomplete but the clock is already running. Production schedules, physical highway safety, product availability and regulatory obligations all compete for attention. The challenge is not simply deciding whether security or safety comes first, but determining how to protect both when delaying action also carries risk. The key lesson is that safety and cybersecurity cannot be engineered as separate lifecycle problems. Safety-critical remediation needs security mechanisms and operational processes designed to remain effective even when the organisation is under pressure to act quickly. Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and practical lessons for cybersecurity leaders. Explore all episodes and resources: https://cybersecurityunderpressure.com/episodes
Cybersecurity Under Pressure. Real Attacks, Real Lessons
Railway AI at Risk: When Subcontractor Leaks Break the Trust Chain
Aug 14, 202637 min
Your railway systems may be secure. Your AI environment may be protected. But what happens when sensitive information escapes through a subcontractor? In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine a growing challenge for railway cybersecurity: protecting sensitive AI and engineering assets across a supply chain that extends far beyond the organisation itself. We trace how information can move through subcontractors and suppliers, how seemingly isolated leaks can expose a much wider technical and operational picture, and why securing the primary organisation is no longer enough when critical knowledge is distributed across the engineering ecosystem. The discussion then moves from technical exposure to the harder questions. What are the business and regulatory consequences when sensitive railway information crosses the expected trust boundary? How should organisations manage subcontractors that are essential to engineering and innovation while also expanding the attack and exposure surface? In The Pressure Test, you step into the role of the CISO or incident commander and face the decisions that follow a serious third-party exposure: contain the incident, determine what has actually been compromised, preserve operations and decide what can still be trusted. The key lesson is clear: AI security cannot stop at your organisational boundary. In complex railway ecosystems, trust has to be engineered, governed and continuously verified across the entire supply chain. Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and practical lessons for cybersecurity leaders. Explore all episodes and resources: https://cybersecurityunderpressure.com/episodes
Cybersecurity Under Pressure. Real Attacks, Real Lessons
Why Signed Firmware Is Still Vulnerable: The Trust Chain Behind the Signature
Aug 12, 202644 min
A valid digital signature tells you that firmware was signed by a trusted key. It does not necessarily tell you that everything behind that signature can still be trusted. In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine one of the most dangerous assumptions in product cybersecurity: that signed firmware automatically means secure firmware. We trace the problem back through the engineering and software supply chain, exploring how a securely designed product can still inherit compromise from the systems, processes and trust relationships used to build and release its software. The discussion then moves from architecture to operational reality. What happens when strong security controls collide with availability, lifecycle constraints and incident response? How should organisations decide whether firmware can still be trusted when the cryptography works but the surrounding chain of trust is in question? The Pressure Test puts those decisions into a realistic incident scenario, where technical certainty is limited and the consequences of the wrong call are significant. The key lesson is simple: code signing is an essential control, but it is not the end of firmware security. Trust has to extend across the entire lifecycle behind the signature. Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and practical lessons for cybersecurity leaders.
Cybersecurity Under Pressure. Real Attacks, Real Lessons
Minnesota Water Cyberattacks: When OT Security Meets Physical Risk
Aug 10, 202639 min
What happens when a cyberattack moves beyond IT systems and begins to threaten the physical processes communities depend on? In this episode of Cybersecurity Under Pressure: Real Attacks, Real Lessons, we examine the cyberattacks targeting water systems in Minnesota and the deeper OT security lessons behind them. We break down how attackers can exploit weaknesses around industrial environments, use detailed engineering knowledge against defenders, and turn access to PLCs and operational systems into a potential physical consequence. But the technical compromise is only part of the problem. The harder question is what operators do next. How do you contain an incident without disrupting essential services? When does isolation create more operational risk than it removes? And how should an incident commander respond when the evidence is incomplete but the consequences of waiting could be significant? The episode closes with a practical lesson for security, risk and business leaders: protecting critical infrastructure requires more than defending the network perimeter. It requires understanding the physical process, the engineering ecosystem and the decisions that must still work when the organisation is under pressure. Thanks for listening to Cybersecurity Under Pressure. Follow the show for more real attacks, technical breakdowns and lessons for cybersecurity leaders.
Every question we get asked before someone starts their trial.
If you have a concern about deliverability, AI quality, data privacy, or whether this will actually work for your specific situation, it's probably answered below.
What is the difference between Founder Solo and Founder Pro?
Founder Solo gives you 50 AI pitches per month using the credit model (Standard pitches cost 1 credit, Enriched pitches cost 2). Founder Pro raises that to 200 credits per month and adds full Booking Probability access, unlimited Magic Match, Apollo enrichment credits, and data export capabilities. Both plans use the same credit system, so you can stretch your monthly budget further by using Standard-mode drafting.
How do agency tiers work?
Agency tiers have no base fee. You pay per managed client and per talent profile. Agency Standard is $199 per client per month; Agency Pro is $399 per client per month. Both add $39 per talent profile per month. Your own team's user seats are always free.
What is a talent profile?
A talent profile represents one person (founder, executive, or spokesperson) you are booking onto podcasts. It includes their bio, topics, headshots, and outreach history. Team plans include 5 profiles; agency plans are pay-as-you-go.
Can I switch plans later?
Yes, at any time. Upgrades take effect immediately; downgrades apply at the end of the current billing period. Contact support if you need help migrating between plan families.
Do you offer a free trial?
Every paid plan includes a 15-day free trial. Your card is saved at signup but you will not be charged until day 16. Cancel any time from your dashboard.
What happens if I cancel?
You keep access until the end of your current billing period. No charges after that. Your data is retained for 30 days in case you reactivate.
Is the 20% annual discount automatic?
Yes. Select Annual on the pricing toggle and the discounted price is applied automatically at checkout. The annual price shown is the full year cost.
What if I have more than 50 profiles or 20 clients?
That is our Enterprise tier. Contact our sales team and we will build a custom plan with volume pricing, a dedicated account manager, and SLA guarantees.