Industrial Talk/BCC is talking to Rubin Domingo and Antonio Delgado, about "CISO Roundtable, Real Threats and Real Decisions impacting the market".
Overview
The roundtable examined practical cybersecurity risks and emphasized that security is a business responsibility, not solely an IT function.
Key Risks
Ruben identified concentration among major service providers and uneven cybersecurity maturity among smaller public bodies as significant threats.
Antonio highlighted ransomware, phishing, social engineering, and third-party risk as more immediate concerns than highly publicized AI attack scenarios.
Resilience Priorities
Organizations should prepare before an incident through containment plans, crisis communications, tested backups, alternate service instances, and provider redundancy.
Manufacturing environments need asset visibility, IT/OT network separation, and controls for legacy systems and connected devices.
Leadership should evaluate cyber risk alongside financial and legal risk; cyber insurance increasingly requires evidence of controls such as MFA, backups, incident response, training, EDR, and vulnerability management.
Open Questions
How can smaller organizations achieve adequate cybersecurity maturity with limited resources?
How should organizations adopt AI while protecting sensitive and critical data?
Action Items
Broadcast from the Barcelona Cybersecurity Congress in Barcelona on November 3–5, 2026. (@Scott Mackenzie)
Outline
Participants and Roles
Ruben: Technology and cybersecurity director for a public organization representing Catalan municipalities and the regional government; advisory board member of the Global CISO Council Spain chapter.
Antonio: CISO in an international education group serving schools across Europe, Latin America, and the United States.
Real Threats Versus Noise
Service-provider concentration can create broad systemic outages.
Smaller municipalities and organizations often lack dedicated cybersecurity resources.
Ransomware, phishing, social engineering, and third-party weaknesses remain operationally relevant.
Incident Preparedness
Contain affected systems first, coordinate communications, and restore services from prepared alternate environments.
Regulation and frameworks such as ISO 27001 and Spain’s National Security Scheme can drive preparedness.
Manufacturing and Education
Manufacturing requires IT/OT separation, visibility into connected assets, and legacy-system risk management.
Schools require layered identity controls, MFA, awareness training, phishing simulations, and protection of minors’ data.
AI, Leadership, and Insurance
AI should be adopted with policies, training, and controls against sensitive-data exposure.
CISOs should communicate business impact and risk to boards rather than focusing only on technical controls.
Cyber insurance validates organizational maturity and can support recovery after an attack.
If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation.
Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy!
RUBEN CORTES DOMINGO'S CONTACT INFORMATION:
Personal LinkedIn: https://www.linkedin.com/in/rubencortes/
Company LinkedIn: https://www.linkedin.com/company/consorci-aoc-2/home/
Company Website: https://www.aoc.cat/en/
ANTONIO DELGADO'S CONTACT INFORMATION:
Personal LinkedIn: https://www.linkedin.com/in/antoniodelgadociso/
Company LinkedIn: https://www.linkedin.com/company/affinitas-education/home/
Company Website: https://www.affinitasedu.com/
4