# The Hidden Risk of Your Infrastructure Page: https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/the-hidden-risk-of-your-infrastructure Text version: https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/the-hidden-risk-of-your-infrastructure.md Podcast: [Threat Talks - Your Gateway to Cybersecurity Insights](https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159) Published: 2026-04-28T08:00:00+00:00 Episode link: https://threat-talks.com/the-hidden-risk-of-your-infrastructure/ Audio file: https://2.gum.fm/op3.dev/e/pdcn.co/e/pscrb.fm/rss/p/pdst.fm/e/dts.podtrac.com/redirect.mp3/media.transistor.fm/9ee24374/9701ce7c.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/the-hidden-risk-of-your-infrastructure Duration seconds: 1602 ## Resource Volt Typhoon spent years pre-positioning inside US critical infrastructure. Salt Typhoon pulled off one of the largest espionage campaigns in history. They didn't break in. They were already there. So what do you actually do about it? Caitlin Clarke , Senior Director of Cybersecurity Services at Venable and former Special Assistant to the President for Cybersecurity and Emerging Technology, joins Lieuwe Jan Koning, Co-founder and CTO at ON2IT Cybersecurity, to work through the practical steps security leaders should be taking right now, before the regulatory guidance catches up with the threat. What's in this episode for you: A clearer view of what's actually in your stack. Hardware is the easy part. Software updates, open source libraries, AI-generated code, outsourced R&D — any of it could be adversarial, and most teams have never asked. A practical way to map your supply chain before you have to. Fourth party. Nth party. Vendor exit strategies baked into business continuity. Procurement and security in the same room before the purchase, not after the incident. A framing that goes beyond the technical. Insider risk. IP theft. Economic espionage. Nation state actors target people and research, not just networks — and that's the gap most organizations leave wide open. Timestamps 00:00 – Introduction: Critical Infrastructure and the Nation State Threat 01:45 – Volt Typhoon, Salt Typhoon and Why CISOs Need to Think Differently 03:21 – What Is Actually in Your Stack: Critical Infrastructure Cybersecurity Beyond Hardware 09:32 – Mapping Your Supply Chain Including Your Supplier's Suppliers 16:34 – Software, Open Source and AI: The Layers of Risk Most Organizations Have Not Mapped 21:59 – Insider Risk, IP Theft and Economic Security + Wrap Up Key Topics Covered Why cost… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/threat-talks-your-gateway-to-cybersecurity-insights-6755159/episodes/the-hidden-risk-of-your-infrastructure/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/threat-talks-your-gateway-to-cybersecurity-insights-6755159/the-hidden-risk-of-your-infrastructure.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.