
Critical Assets Podcast
by Patrick Miller
Is this your podcast?Insights from recent episode analysis
Audience Interest
Podcast Focus
Publishing Consistency
Platform Reach
Insights are generated by CastFox AI using publicly available data, episode content, and proprietary models.
Most discussed topics
Brands & references
Est. Listeners
Insufficient chart data. Estimates will improve as the show charts.
- Per-Episode Audience
Est. listeners per new episode within ~30 days
N/A🎙 Weekly cadence·11 episodes·Last published 2w ago - Monthly Reach
Unique listeners across all episodes (30 days)
N/A - Active Followers
Loyal subscribers who consistently listen
N/A
Market Insights
Platform Distribution
Reach across major podcast platforms, updated hourly
Total Followers
—
Total Plays
—
Total Reviews
—
* Data sourced directly from platform APIs and aggregated hourly across all major podcast directories.
On the show
From 11 epsHosts
Recent guests
Recent episodes
Turning Cyber Risk Into a Decision You Can Defend
Aug 15, 2026
49m 07s
The Attack Surface You Eat: Cyber Risk in Food and Agriculture
Jul 8, 2026
1h 10m 21s
Policy Pulse: Regulatory Roundtable - Cyber Strategy, Large Loads, AI & CISA in Flux
May 11, 2026
1h 00m 18s
Policy Pulse: Regulatory Roundtable - NERC CIP, Cybersecurity Strategy, AI & Electric Sector
Feb 1, 2026
1h 02m 05s
Vulnerability Overload: Making Prioritization Work in the Real World
Jul 20, 2025
35m 36s
Social Links & Contact
Official channels & resources
Official Website
Login
RSS Feed
Login
| Date | Episode | Topics | Guests | Brands | Places | Keywords | Sponsor | Length | |
|---|---|---|---|---|---|---|---|---|---|
| 8/15/26 | Turning Cyber Risk Into a Decision You Can Defend | Patrick Miller sits down with Scott Kannry, co-founder and CEO of Axio, to work through cyber risk quantification as a security decision tool for OT and critical infrastructure. Scott came up in the insurance industry at Aon in the early days of cyber coverage. He founded Axio with Dave White to close the gap between a technical security program and a number a CFO and a board can act on.The conversation stays practical. Why you start on the impact side instead of arguing about probability. How NERC CIP already thinks in consequence. Why the events that matter most are rare, huge, and short on data. How to compare controls, insurance, and compliance spend on the same dollar scale. What AI and quantum do to the "it will never happen" excuse. And a new D&O option for CISOs built on top of consistent quantification.Full show notes, links, and the episode transcript are on the Ampyx Cyber episode page at ampyxcyber.com/podcast.Topics covered:The founding of Axio and the insurance-meets-frameworks originA short history of cyber insurance, from data breach to business interruption to cyber-physicalThe four loss categories Axio uses, first and third party, financial and tangibleCoverage gaps for industrial facilities and the danger of assumed coverageImpact-first quantification versus probability-first modelingNERC CIP and consequence-only risk ratingFiduciary duty, duty of care, and defensible decisionsSecurity decision support versus vanity security metricsThe art and science of pricing control ROIAI and quantum, and why low-probability high-impact events deserve attention nowA D&O insurance option for CISOs tied to consistent quantification | 49m 07s | ||||||
| 7/8/26 | cybersecurityfood security+5 | Kristin King | AnzenSageAnzenOT+2 | — | cyber riskfood cybersecurity+5 | — | 1h 10m 21s | ||
| 5/11/26 | cybersecuritycritical infrastructure policy+5 | Joy DittoEarl Shockley | MythosGlasswing+5 | China | cyber strategylarge loads+6 | — | 1h 00m 18s | ||
| 2/1/26 | regulatory developmentscybersecurity+4 | — | Ampyx CyberInpowerd+4 | — | NERC CIPcybersecurity strategy+5 | — | 1h 02m 05s | ||
| 7/20/25 | vulnerability managementpatching challenges+5 | Kylie McClanahan | CVSSCSAF+4 | — | vulnerability managementpatching+7 | — | 35m 36s | ||
| 4/13/25 | cybersecurityleadership+4 | Darren Highfill | Norfolk SouthernNIST+1 | — | CISOcybersecurity program+5 | — | 44m 04s | ||
| 1/4/25 | incident responseforensics+5 | Lesley Carhart | OT/ICScybersecurity+1 | — | incident responseforensics+5 | — | 44m 32s | ||
| 3/3/24 | cybersecurityworkforce development+5 | Cynthia HsuErin Owens | DOE CESEREventleaf+1 | — | cybersecurity careersOT security+5 | — | 1h 08m 23s | ||
| 11/9/23 | CybersecurityEngineering+3 | Ginger Wright | Idaho National LaboratoryCyber Informed Engineering | — | Cyber Informed Engineeringcybersecurity+4 | — | 53m 39s | ||
| 9/5/23 | cybersecurity regulationthreat hunting+4 | Danielle Jablanski | Ampere Industrial SecurityNozomi Networks+2 | — | cybersecurityregulation+5 | — | 59m 18s | ||
Want analysis for the episodes below?Free for Pro Submit a request, we'll have your selected episodes analyzed within an hour. Free, at no cost to you, for Pro users. | |||||||||
| 6/26/23 | AIOT+5 | Amanda Freick | Ampere Industrial SecurityAltruistic+1 | — | AImachine learning+6 | — | 43m 54s | ||
| 5/11/23 | OT CybersecurityICS Security+4 | Gabe Agboruche | SANS ICSCompTIA+5 | — | OT CybersecurityICS Security+6 | — | 42m 26s | ||
| 3/9/23 | Simplifying ICS Security Metrics | Getting started with ICS and OT security metrics can be hard. What do you measure? How do you represent it? Do you even have the data? In this podcast, we talk with Erin Torruella to share her experience from building and managing metrics for multiple different sectors. She provides great advice on where to start and how to get the effort going in the right direction.ChatGPT response was…Operational Technology (OT) and Industrial Control Systems (ICS) are crucial components of critical infrastructure, and their security is essential for ensuring the safety, reliability, and availability of essential services. To measure the success or failure of an OT/ICS security program, several metrics can be considered, such as:1. Vulnerability Management Metrics: This metric measures the number of vulnerabilities identified, the number of vulnerabilities remediated, and the time it takes to remediate the vulnerabilities.2. Incident Response Metrics: This metric measures the effectiveness of the incident response process. It includes the time it takes to detect, contain, and resolve an incident, as well as the number and severity of incidents.3. Compliance Metrics: This metric measures compliance with relevant security standards, regulations, and policies. It includes the number of audits conducted, the number of non-compliances identified, and the time it takes to remediate non-compliances.4. Risk Management Metrics: This metric measures the effectiveness of the risk management program. It includes the number and severity of risks identified, the number of risks mitigated, and the time it takes to mitigate the risks.5. Awareness Metrics: This metric measures the effectiveness of the security awareness program. It includes the number of training sessions conducted, the number of employees trained, and the level of understanding demonstrated by employees.6. Asset Management Metrics: This metric measures the effectiveness of the asset management program. It includes the number and types of assets identified, the level of asset classification, and the accuracy of the asset inventory.7. Performance Metrics: This metric measures the performance of the OT/ICS infrastructure. It includes uptime, availability, and response time.Thanks for listening!Show links:Erin Torruella...LinkedIn - https://www.linkedin.com/in/erin-torruella/Twitter - https://twitter.com/LadySqrrlMastodon - https://infosec.exchange/@ladysqrrlJD Christopher SANS talk on ICS Security Metrics - https://www.youtube.com/watch?v=gIsLP_Dtv7MJD Christopher SANS blog post on ICS Security Metrics -https://www.sans.org/blog/mature-ics-security-with-metrics/S.M.A.R.T. Methodology - https://en.wikipedia.org/wiki/SMART_criteriaDHS CISA Cross-Sector Cyber Performance Goals - https://www.cisa.gov/cross-sector-cybersecurity-performance-goals | 43m 39s | ||||||
| 2/8/23 | What to do about FERC's new INSM Order 887 | FERC has issued Order 887, directing NERC to create new Critical Infrastructure Protection (CIP) cybersecurity standards for Internal Network Monitoring Systems (INSM). In this episode, Patrick Miller, CEO of Ampere Industrial Security talks with Carter Manucy, IT/OT Cybersecurity Director for Florida Municipal Power Authority (FMPA). Hear from a real electric utility asset owner, on what this Order means for the industry and what you should do next.Show links:Carter Manucy LinkedIn Profile - https://www.linkedin.com/in/cmanucy/FERC Order 887 - https://www.ferc.gov/media/e-1-rm22-3-000FERC INSM NOPR - https://www.federalregister.gov/documents/2022/01/27/2022-01537/internal-network-security-monitoring-for-high-and-medium-impact-bulk-electric-system-cyber-systemsNational Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems - https://www.amperesec.com/blog/industry-brief-national-security-memorandum-on-improving-cybersecurity-for-critical-infrastructure-control-systemsNERC INSM Practice Guide - https://www.nerc.com/pa/comp/guidance/CMEPPracticeGuidesDL/CMEP%20Practice%20Guide%20-%20Network%20Monitoring%20Sensors.pdfCorresponding Ampere Blog post - https://www.amperesec.com/blog/what-to-do-about-fercs-new-insm-order-887 | 32m 32s | ||||||
Showing 14 of 14
Pitch Fit is a Pro feature
See how bookable this show is for guests, which brands already advertise, the per-episode ad value, and the best-fit guest and sponsor profile. The numbers are blurred on the free plan.
How readily this show books outside guests like you.
How proven this show is for host-read sponsorships.
For Guests
ProFor Advertisers
ProUpgrade to Pro to unlock guest cadence, sponsor categories, fit scores, and per-episode ad value for this show.