Episode 37 — Build OT Service Agreements: Procurement Requirements and What MSAs Must Cover:

This episode explains how service agreements shape OT security and resilience, because contracts determine what vendors can do, what they must do, and what evidence you can demand when something goes wrong. You’ll learn how procurement requirements should address OT realities, including site access rules, remote access methods, maintenance windows, incident notification obligations, and the need for security controls that do not compromise safety or deterministic performance. We cover what a Master Services Agreement should include at a practical level, such as responsibility boundaries, security expectations, data handling, logging and evidence retention, subcontractor controls, and the authority to audit or request proof of controls. The episode also highlights common contract gaps that become painful later, like vague language about “industry standard security,” undefined response timelines, and unclear ownership for patching and configuration drift. You’ll practice reading a scenario and selecting the contractual control that prevents repeat risk, such as requiring MFA for remote support, restricting tooling, mandating approved jump hosts, and establishing clear escalation paths that align with operations and safety leadership. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
Episode 37 — Build OT Service Agreements: Procurement Requirements and What MSAs Must Cover:
Broadcast by