Johnny Xmas, the global head of offensive security for a major U.S. manufacturer, emphasized the growing importance of offensive security practices within operational technology (OT) environments in the manufacturing sector. In a detailed interview ahead of the 10th ManuSec Summit, he highlighted the unique challenges that manufacturing organizations face when implementing red teaming and penetration testing in OT settings. One of the primary hurdles is the inconsistent technology landscape across multiple manufacturing plants, which complicates the standardization of security assessments. Shadow IT, or unauthorized technology deployments, introduces hidden risks that can undermine even well-designed security programs. Xmas stressed the necessity of thorough asset inventory verification from an attacker's perspective, ensuring that all devices and systems present in manufacturing plants are accounted for and authorized. He pointed out that in OT environments, understanding the context of systems and processes is often more critical than focusing solely on technical exploits. Manufacturing organizations frequently encounter two major blind spots: incomplete visibility into their OT assets and a lack of understanding of how those assets interact within the broader operational context. These gaps can leave critical systems exposed to sophisticated attacks. Xmas also discussed the evolving role of security in OT, noting that it is increasingly becoming a core consideration for manufacturing leadership, rather than an afterthought. He advocated for a holistic approach to offensive security, integrating both IT and OT perspectives to maximize operational resilience. The interview underscored the need for specialized skills and methodologies tailored to the unique requirements of OT environments, as traditional IT security approaches may not be directly applicable. Xmas's insights reflect a broader industry trend toward proactive security measures, such as red teaming, to identify and remediate vulnerabilities before they can be exploited by adversaries. He also touched on the future of OT security, predicting that as manufacturing systems become more interconnected, the demand for advanced offensive security capabilities will continue to grow. The discussion provided actionable guidance for manufacturing CISOs, including the importance of cross-functional collaboration and continuous improvement in security practices. By prioritizing offensive security, manufacturers can better defend against emerging threats and ensure the integrity and availability of their critical operations. The interview serves as a call to action for manufacturing organizations to invest in robust red teaming and pentesting programs tailored to the complexities of OT environments. Ultimately, the integration of offensive security into manufacturing operations is positioned as a strategic imperative for safeguarding industrial assets and maintaining competitive advantage in an increasingly digital landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.