Security's Real Breaking Point Isn't the Firewall
Critical Software's Pedro Cordeiro joins RunSafe Security and Schneider Electric to unpack where industrial cybersecurity really breaks down.

In this Automation World webinar, Nikola Dalcekovic and Andrew Kling of Schneider Electric join Joe Saunders of RunSafe Security and Pedro Cordeiro of Critical Software to discuss what it takes to turn security into a genuine business enabler — drawing on their combined experience in cloud security, distributed systems, and large-scale industrial cybersecurity. Together, they explore how security can support business priorities instead of slowing them down.
Ask most organizations where their security breaks down, and they'll point to a missing patch or a misconfigured firewall. Ask Pedro Cordeiro, Principal Engineer for Energy at Critical Software, and he'll point somewhere less obvious: the seams.
Speaking alongside other professionals, Pedro laid out a picture of industrial cybersecurity that has less to do with any single vulnerability and more to do with what happens between the pieces of a system.
Where It Breaks
"It would break down mostly at the integration boundary," Pedro said. Systems today are assembled from components built by different vendors, each optimized in isolation — but nobody owns the connection between them. Add implicit trust between internal components, third-party libraries, and security requirements that arrive too late in the process, and you have fragility baked in before the system ever ships.
And it doesn't stop at design. "Even well-designed systems degrade over time," he noted. Configuration drift during deployment means security breaks down not just on the drawing board, but in operation — quietly, over years.
The Risk Nobody Can See
Not everything Pedro sees is a warning sign. One pattern, in particular, tells him a security culture is maturing: engineers catching vulnerabilities in the pipeline, not in production — raising security questions before anyone asks them to. It's a small, easy-to-miss behavior. But when he sees it, he takes it as a genuine signal that things are heading in the right direction.
Pressed on where security gaps most often creep into organizations today, Pedro pointed to open-source components: no SBOMs, no vulnerability tracking, no update path. Bootloaders and board support packages inherited from vendors go unreviewed for years. The risk isn't dramatic — it's silent, because most organizations simply don't know it's there.
The uncomfortable detail: these vulnerabilities rarely come from direct dependencies. They come from transitive dependencies — dependencies of dependencies, layers deep. And then there's the slower-burning problem of end-of-life components: software development kits and tools that vendors quietly abandon while the product built on them stays in the field for ten or twenty more years. That's a long window of unpatched, unmonitored exposure, with no remediation path even for a team that wants one.
Treating Resilience as Architecture, Not a Feature
Pedro was direct about one common mistake: assuming a vulnerability's severity score tells you how urgent it is. A 9 isn't automatically more urgent to fix than an 8 or a 7 — context decides that, not the number.
What he sees organizations doing well is treating resilience as an architectural property rather than a bolt-on feature: threat modeling at design time, compartmentalized trust zones, fail-safe mechanisms, and continuous runtime monitoring for hardware integrity and network anomalies. Many are anchoring this work to external frameworks like IEC 62443 for energy and industrial automation — using it to structure risk assessments, security design, and the definition of security zones. Crucially, the organizations doing this well don't treat it as a one-time exercise. SBOMs, risk assessments, zone definitions — all of it needs to be maintained continuously, not generated once and forgotten.
What AI Won't Fix
Asked about AI's role in the security landscape, Pedro didn't overclaim. AI, he agreed, will speed up the security landscape across the board. But one practical step remains largely unaddressed regardless of how capable the tooling gets: the SBOM. Without it, there's no real vulnerability management, no meaningful incident response, and — under current and incoming regulation — no path to compliance.
It's a theme that runs through all of Pedro's answers: resilience isn't a single control you add, and it isn't a score you chase. It's what's left standing at the seams, in the dependencies you didn't write, and in the decisions made early enough that you never had to choose between safety and security in the first place.
Watch the full webinar, "From Friction to Force Multiplier: Making Security a True Business Enabler," for the complete conversation with Run Safe Security, Schneider Electric, and Critical Software.