The list of similarities between typical IT networks and OT networks is pretty short. They both comprise computers that process and store data. And that’s about it. OT environments often include machines that have been in place for decades and haven’t been updated or maybe even touched in years, by design. Taking a critical computer in a hospital, manufacturing facility, or power plant offline or even updating its OS can lead to very real, very painful consequences. Lesley Carhart has been cleaning up malware, intrusions, ransomware, and other messes in OT networks for the better part of two decades and recently joined Dennis Fisher on the Decipher podcast to talk about the special challenges OT networks present and why old malware still thrives in these environments. This is an edited and condensed portion of that conversation.

Dennis Fisher: For those who aren’t familiar with your work, could you give us a quick description of your role and a bit of your background?

Lesley Carhart: I’m Lesley, and I usually start by saying I’m a cybersecurity janitor. I’ve been working in incident response for almost 20 years, focusing on some very old and very weird computers. My day job is with Dragos, where I do industrial cybersecurity, incident response, and forensic investigations. When a power plant or transportation system gets hacked, and those low-level systems like PLCs are impacted, I’m one of the few people in the world who goes in to investigate. I also do a lot of community teaching and mentoring.

Dennis Fisher: I saw you posting about Conficker recently. That’s a ghost from the past for those of us who have been in this industry for a long time. It was a seminal event back in 2008, and I hadn’t really thought about it in 15 years. Why is Conficker relevant again in 2026?

Lesley Carhart: We only talk about AI these days, so I figured we could talk about Conficker for a minute. But honestly, it is relevant. Industrial computer networks stay in place for a long time and do very important things. When I deal with Conficker infections in bulk today, people ask, "Why didn’t they patch their computers?" They assume it’s laziness, but dealing with OT (Operational Technology) is incredibly challenging. These are computers that keep people alive; they have to stay in place for 20, 30, or 40 years.

Maturity in industrial cybersecurity is increasing, and teams are finally performing threat hunting and architecture assessments. They’re finding that these networks are riddled with these old worms—Conficker, Wannacry, Mariposa—that we thought were relics. Conficker is just the perfect example because it’s brilliant and spreads so fast. If it gets into an unpatched system running Windows XP, it spreads to everything.

Dennis Fisher: It’s a literal health and safety issue. From the outside, observers might think, "Why don’t you just update the software in your factory or hospital?" But you can’t, because people could die. When you and your team go into these networks and see malware from 2009 crawling around, how do you begin to address that when the systems can’t be easily patched or upgraded?

Lesley Carhart: It’s really challenging. We’re actually releasing a white paper on this because there are three main approaches. First, you can barrel in and try to clean everything at once. That’s hugely expensive and impactful—you risk breaking things in catastrophic ways, sometimes worse than the infection itself.

Second, you projectize it. You create a long-term plan to know exactly where the infection is, and how to isolate and quarantine sections of the process network without killing anyone or stopping production.

Third, and this is the one that’s hard for enterprise security people to accept, you leave it alone. You do a risk assessment, confirm the systems are robust enough to withstand the infection, and decide it’s safer to leave it than to risk the stability of the plant by cleaning it.

Dennis Fisher: Is there a tipping point where you eventually have to force an upgrade? How does that work in highly regulated industries like utilities or medical?

Lesley Carhart: It varies by the company's margins and the regulations they face. Manufacturing has thin margins, so they operate on a "break-fix" basis—they run until it literally can't run anymore. In some places, like Australia, there’s a real culture of fixing things by hand—soldering parts or buying bits on eBay to keep 30-year-old equipment alive. It’s amazing, actually.

In regulated sectors, even the most mature organizations I see, with incredible defensive teams, still have the really old stuff. They build architectural bastions around it—defensive layers, monitoring, isolation, and things like data diodes to ensure traffic only flows in one direction. But they still have those old systems. It’s very hard to fully modernize.

Dennis Fisher: You mentioned the talent shortage in OT. It sounds like you’re trying to build a community from the ground up because it’s not really taught in universities.

Lesley Carhart: Exactly. It’s hard to hire for OT because most people want to work on AI or cloud security—they don't want to work on computers from the nineties. And it’s not a major curriculum in most international schools. We need cybersecurity people who have experience with life-safety applications. I’m constantly telling students: if you can't find a job, go spend time in a factory or agriculture, learn how an industrial process works, and then merge that with cybersecurity. We need those people really badly.

Dennis Fisher: For someone trying to get into this field, how do they get that practical experience without buying a PLC off eBay and breaking things?

Lesley Carhart: Usually, it’s having a prior life in one of those industries—maybe your family business or a job you had in university. You don't need to learn every industrial process, just learn one. Learn how the puzzle pieces fit together. That will help you understand what actually matters in industrial cybersecurity.