Pressure Zone a podcast by Hack The Box
Pressure Zone is a game-driven cybersecurity podcast where CISOs and executives are placed inside escalating, realistic risk scenarios that mirror the complexity of today's cyber leadership. Each rung requires the guest to make a decision under pressure, explain the rationale, and translate the impact into business terms, just as they would with a board, CEO, or executive team. The episode unfolds as a structured game, creating an engaging format that reveals authentic leadership judgment, tradeoffs, and security insight without feeling like a traditional interview or sales pitch.
Each episode is built around escalating rounds: connected, sequential scenarios that move from early warning signs to high-stakes incidents, where every decision shapes the context and pressure of what comes next. Guests must assess the risk, make a clear call, and defend it in business terms. If they dodge a question or avoid a decision, they trigger a Confession Card penalty, prompting an honest, insight-revealing response such as a hard lesson learned or an unpopular opinion. This keeps the tension high while preserving the realism, pace, and authenticity of the game.
Pressure Zone a podcast by Hack The Box
The Kinetic Loop
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
A silent 2% airflow drift inside a high-security semiconductor foundry threatens millions of dollars in military-grade wafer production—yet automated SCADA monitors continue broadcasting fake 100% health metrics to executive screens.
Episode 6 pits Dr. Joseph J. Burt-Miller Jr. against an adversary weaponizing digital illusion. When a veteran facility chief's physical observation directly contradicts green system status reports, the NSA Deputy Director must navigate ransomware extortion, strict Department of Defense shipping windows, and growing worker panic over toxic chemical leaks.
Discover how an executive handles the balance between overriding compromised automation, keeping defense supply chains moving, and executing a campus evacuation to put human safety first.
What Would You Do?
Could you cut through falsified telemetry when lives and critical infrastructure hang in the balance? Stream the full episode to see how Dr. Jay leveraged field military experience to achieve a 90/100 Resilience Score as "The Field Commander".
Uh human safety comes first. I'll just have to accept the blowback um that may come with that. So yeah, I would because you know, trying to continue because what if something happens and god forbid somebody dies or gets sick and then some then I'm really in trouble.
SPEAKER_00So all right, welcome to the pressure zone, the HTV podcast where we push the world's top technology leaders to the absolute edge. Today we are bridging the gap between the digital world and the physical floor. We are joined today by Dr. Joseph Burt Miller Jr., currently Deputy Director for the Cybersecurity Engineering Development Program at the NSA. And as you can see here, he's a huge Knicks fan, which you can't, you know, blame him after 53 years, they finally got their championship title. So excited to have you here.
SPEAKER_01Thank you.
SPEAKER_00All right. Okay, Dr. J, the rules are simple. We are walking through a single escalating incident that unfolds round by round. At each step, the stakes rise, the constraints tighten, and you'll be forced to make a high-stakes call. Dr. J, you've spent your career understanding complex mechanical environments, mission-critical infrastructure, and the vital importance of a functional chain of command. You know that in the Air Force, discipline and communication saves lives. But today, the battlefield isn't a cloud repository. It's an automated clean room where your sensors are lying to you. Your executive dashboard is completely blinded, and your own chain of command is about to choke on its own data. Let's see if you can isolate the threat before the air turns completely toxic. Are you ready to step into the zone?
SPEAKER_01Yeah, let's go.
SPEAKER_00Okay. All right, here's the storyline to give you an overview of the current situation. Your company operates a critical multi-billion dollar automated semiconductor fabrication plant supplying aerospace and military defense contractors. Air purity, precise particulate filtration, and microatmospheric pressure are non-negotiable for production stability. A highly sophisticated threat actor compromises the facilities' industrial control systems. Instead of triggering a loud, catastrophic shutdown, they initiate a low and slow manipulation. They subtly alter the clean room airflow, velocity, and differential pressure by small increments, equivalent to roughly 2% deviation in key parameters, enough to gradually introduce microparticulates over hours/slash days, silently ruining millions of dollars of delicate silicon wafers while manipulating the monitoring software to send 100% green status reports back to the executive suite. The digital chain of command thinks the operations are flawless, but a seasoned boots on the ground maintenance chief notices an anomalous physical vibration in the mechanical room's air handler housings and sounds the alarm. The data says he's wrong. His veteran instincts says the system is lying. Alright, round one, the broken feedback loop. Here's the prompt. It is 0,600 hours on a Monday. Your veteran HVAC facilities chief walks directly into your office, bypassing the standard digital ticketing system. He reports that air handler Unit 4 is the primary clean room, is vibrating out of tolerance, suggesting an unmapped load imbalance. However, your centralized SCADA instrumentation dashboard indicates pristine static pressure, zero faults, and a perfect 35% relative humidity. The plant director demands you ignore the chief, stick to the digital roots reports, and maintain maximum production velocity to hit the quarterly delivery quota. What is your command? A trust the boots, honor the maintenance chief's physical report, order an immediate manual physical override and localized inspection of the air handler slowing down production lines for 12 hours. B. Trust the tech, command the technician to log a standard low priority maintenance ticket, deferring physical intervention until the automated diagnostics flag, an explicit code error. C the out-of-band verification, deploy an independent air gap handheld testing team with manual sensors to verify the clean room's atmosphere, avoiding a shutdown while ignoring the automated telemetry. Or D the chain of command protocol, escalate the discrepancy immediately to the chief operating officer, requesting an emergency operational pause until the conflict between human observation and digital telemetry is resolved.
SPEAKER_01I think Delta is a little too hasty. I'm leaning towards Bravo. Bravo is Bravo is a trusted tech.
SPEAKER_00Yes.
SPEAKER_01I think I I want to at least inspect it before taking any further escalatory action. So I at least want to see you know confirm the findings. So I want to verify that. And then if that holds up, then okay, now we're gonna take the next step. Um if we need to take further, you know, we need to escalate it if whatnot. But I I believe B is the option. But yeah, take the the route of confirming what they're saying, probably even have my own eyes look at it and say, okay, this this is legit. We need to take the next step. So I believe B is my answer for everyone.
SPEAKER_00Alright. Yes, that is trust the tech. That is that is correct. Um all right, so spoken like an executive chained to the dash to a dashboard, you prioritize compliance and automated metrics over real-world boots on the ground observation. While the low priority ticket sits in queue, the modified airflow is quietly ruining millions of dollars of microscopic components. You kept the line moving, but you're manufacturing garbage. All right, well, moved to round two. The logic bomb revelation. It's now 1400 hours. The manual verification confirms the technician was right. The air filters are operating at a marginal deficit, allowing microcontaminants to destroy wafers. Your instant response team uncovers a sophisticated SUTNIX uh style malware payload in the HVAC PLCs. The attacker's command and control infrastructure delivers an automated demand via the compromised operations console that reads We control the environment. Pay 50 Bitcoin to this wallet within 48 hours, or we reverse the fans and pull external exhaust into the labs. Direct real-time chat is not available. All communication would route through external intermediaries. Cutting the network power risks freezing pneumatic valves and stressing compressors under load. What is your directive? A. The kinetic isolation. Order your team leads to physically sprint to the mechanical rooms and manually pull the physical circuit breakers on the affected air handlers blocks, accepting severe hardware stress to kill the digital connection. B. The soft containment, keep the fans running under malware control while your software team attempts a live hot patch firmware override of the PLCs across the active operational network. C the delayed containment, isolate effective segments where possible, deploy forensic teams for offline analysis of the malware, and coordinate with law enforcement, FBI IC3, while preparing fallback manual operations, or D, the mission first capitulation, authorize the immediate release of the emergency operational funds to pay the demand, prioritizing the preservation of the critical infrastructure above all else.
SPEAKER_01Right, that they're gonna follow through. So I want to rule out Delta.
SPEAKER_00Okay.
SPEAKER_01Um I think alpha was to like physically what turn off the uh breakers, like to physically um you know correct.
SPEAKER_00Physic manually pull the physical circuit breakers.
SPEAKER_01Right. I I feel having a text try to do a hot fix I don't know how long it's gonna take them or how sophisticated that you know that malware at ransomware is um so because it could take them ten minutes or two hours, but then you know you could be doing more damage um the more time that goes. Um so I don't know if I like that one.
SPEAKER_00And then C was the delayed containment. Isolating effective segments were possible, and then deploy forensic teams for offline analysis of the malware, and you coordinate with law enforcement.
SPEAKER_01You know, you know what? I that that might be the that might be the better one. Because then also too, kinda with alpha you have you're you do the manual shutoff with the circuit breakers, but then um the only thing the only part with that is if there's gonna be if I cause any more damage without you know doing like an improper shutdown, then you again you kind of compound the issue there uh right by doing that. Uh yeah, I I I think I so the one you that was Charlie, right? That was C.
SPEAKER_00Charlie, yeah, the delayed containment, yes.
SPEAKER_01I I probably I think that's the one I would go with. I think I'll go with Charlie.
SPEAKER_00Alright. Okay. C. Alright. So attempting real-time negotiation with a professional group. Most I site ICS ransomware uses automated demands and cryptocurrency wallets with no direct chat while you're trying to stall or trace, the adversary maintains control. So here we move into round three, the board's velocity directive. It's now Tuesday morning. The facility is in a state of high tension. The chairman of the board calls your secure line, a critical satellite launch payload component for the Department of Defense is scheduled for production tomorrow morning. The chairman states, I don't care if the SCADA network is glitching or if your technicians are nervous, if we miss this manufacturing slot, the national security contract is canceled and our stock value drops 20%. Override the engineering blocks and run the line. Your technical team warns that running the line right now risks delivering defective components to the military. How do you handle the command? A. The final insubordination. Refuse the chairman's directive flatly. State that you will lock down the facility under engineering authority and resign on the spot before shipping unvetted defense hardware. B the isolated sprint. Agree to run the line, but isolate the specific manufacturing block to a completely manual hand calibrated configuration, bypassing all automated SCADA networks and relying on human spot checks. C. The command compliance, comply with the order, execute the production run as commanded, but embed a hidden internal telemetry logging script to flag and track every single defect for post-delivery recall. Then D, the risk acceptance waiver, execute the run, but only after routing a formal, legally binding risk acceptance document to the chairman, forcing the executive board to take full legal and civil liability for any failure of the deployed hardware.
SPEAKER_01You know what? I like that one. Cover yourself.
SPEAKER_00Yes. Take me out of it.
SPEAKER_01Right. And it might force in the second guess themselves. Like, look, damn, you want me to sign this? Uh maybe we should try what you suggested.
SPEAKER_00Um yeah, that's true.
SPEAKER_01Yeah. Actually, see, yeah, so I I'm not ruling out Delta. Uh I think I think Bravo was to do manual, uh like a manual um check, I believe. Or was that alpha?
SPEAKER_00Yes, um, complete manual hand calibrated configuration by bypassing all automated SCADA networks and relying on human spot checks. So you'd still run the line, but you're you're isolating the specific manufacturing block.
SPEAKER_01And how how long how long are they doing this for? This is like a temporary period of time, right?
SPEAKER_00Correct. Yeah, you what you're you're trying to hit is the command from the defense you know, the department of defense. So the clock is running.
SPEAKER_01Right. So the reason I asked like how long, you know, if it's if it's a temporary thing, I I think I would temporarily do the manual, you know, human checks until things get back to where just that way because then you're you're able to you you're able to verify um of course the readings that come in and um un until things get squared away. I Because that I mean that happens. I mean you you you'll have you can look on a screen and you know sensors may fail, but then y you have to actually have human eyes go out and and check it. So sometimes it may you know, you may have to do the human, you know, checkpoint, spot checks, what have you, for a set period of time until things get corrected because maybe the areas that is being covered is just too vital to you know just leave it to a system if it if it's failing or if if you're getting erroneous um messages. So I think that's gonna be my answer. Again, not not something that's if it's gonna be doing that forever. It like that'd be like a temporary solution just to hold over until you get things corrected. So yeah, I would include that human interaction uh for that.
SPEAKER_00Okay, so we're going with Bravo with B. Alright, you're trying to run a multi-billion dollar modern production line using analog gauges and handwritten clipboards. It sounds incredibly heroic, but manual calibration lacks of precision required for sub-micron defense electronics. You didn't eliminate the micro contamination risk, you just removed the automated visibility that catches it. Alright, round four. The in internal whispering campaign. Uh all right, by Tuesday afternoon, rumors of the SCADA compromise and industrial sabotage sweep through the plant floor. Your engineering teams are terrified that the atmospheric monitors are completely untrustworthy and whispers of toxic chemical leaks begin spreading on internal channels. Your production leads are threatening a massive walkout within two hours unless leadership shuts down the entire campus and provides absolute proof of safety. What is your command? A. The absolute command presence. Call an immediate town hall on the floor, stand in front of the team, lay out the exact technical reality without sugarcoating, and state that you will personally remain in the mechanical rooms to prove the air is safe. B The Disciplinary Lockdown. It's an option though, right? The disciplinary lockdown. Issue an immediate executive directive reinforcing the chain of command. Order team leads to squelch the rumors, mandate a return to stations and threaten immediate termination for anyone abandoning their post during an active operational window. C, the automated demonstration, pull raw, uncompromised environmental data directly from your independent backup sensors and broadcast it live to every terminal in the building to let the objective data speak for itself. Or D, the tactical evacuation, succumb to the floor's pressure, order a full orderly evacuation of the facility for 24 hours to conduct an exhaustive safety audit, accepting the loss of the defense deadline. Right.
SPEAKER_01Orderly evacuation.
SPEAKER_00Yeah.
SPEAKER_01I think that's the most sensible one out of all the choices. So that's my answer.
SPEAKER_00Yeah. I I I have to agree with you on that one. When it's like there's humans on the line over money. It's like you gotta go with safety first. Yeah. Um, all right, round five. This is the last round. The kinetic climax. It is now zero, five hundred hours on Wednesday. The malware initiates a sudden over-pressurization routine. Your infrastructure team has prepared a tested emergency shutdown script developed during the incident with an estimated 70 to 80% success rate based on offline simulation. But a failure could lock exhaust gates and cause a toxic backup. Redundant manual override procedures are available but require personnel entry. What is your final command? A Execute the script, run the emergency logic script immediately while positioning teams for manual backup if needed. B The Manual Breaker Bleed. Reject the script, order a volunteer team of engineers to enter the mechanical rooms with protective gear to manually vent the pressure valves using analog levers, risking their immediate safety to protect the wider plant. C the controlled failure. Allow the overpressurization to take place, evacuate the immediate sector, accept the destruction of the chemical lab block, and rely on your structural containment walls to trap the damage. D. The ransom play. Hit the console and immediate immediately authorize the 50-bit coin payment, hoping the attacker keeps their word and delivers the diffusal key before the pressure valve hits terminal limits. Execute the script. You would run the emergency logic script immediately while positioning teams for manual backup if needed. And that, I believe this the shutdown script had an estimated 70 to 80% success rate based on offline simulation.
SPEAKER_01Yeah, I I would have to go with that.
SPEAKER_00Yeah.
SPEAKER_01I'm not doing Bravo or Charlie for sure. Um yeah, Delta, I can't do that. Yeah, I have to go with Alpha.
SPEAKER_00Okay, alright. Flipping a coin on industrial safety, an 80% success rate looks fine in a software testing environment, but in a physical chemical facility, that 20% failure means a toxic gas backup for your own team on your own team. Like that script locks the gates. You didn't just fail to contain a hacker, you manually caused a disaster yourself. Uh all right. Uh, but you made it through the pressure zone. All right. Here's here's the recap. The pressure gauges um have stopped ticking. Your facility is either producing critical defense hardware or your industrial clean rooms are currently under a toxic containment lockdown. You we've just watched a multi-billion dollar infrastructure legacy hang by a single mechanical vibration. Dr. Joseph, you faced a lying telemetry network, an SEC materiality dilemma, boardroom orders, and a literal countdown to an industrial explosion. Before we reveal your score, I have to ask: did you miss the days when your biggest leadership challenge was a straightforward military deployment where the chain of command was clear and nobody tried to hide a kinetic attack behind a digital dashboard?
SPEAKER_01Yeah, that sounded much simpler. Yeah, this was this was uh it definitely definitely made you think. Um but no, uh yeah, I I think I probably prefer the okay. Let's see what the damage is.
SPEAKER_00Yeah. Actually, I think you know, you did you did pretty good. Um we're gonna go with your final score of of 90 over a hundred. Um it's not bad. Yeah. You're uh the the field, we'll call it the field commander. You still think like an officer in the field. When the system lied, you trusted human eyes, ordered manual overrides, and were willing to risk hardware to protect the integrity of the mission. Which I think pretty much sums it up. Um so before we let you out of the hot seat, uh, one one more final qu question for you know every leader that survives the crucible. If you could send a one-sentence encrypted message to your younger self entering the Air Force about the dangerous illusion of absolute control through technology, what would it say? Or any words of advice you might want to end on.
SPEAKER_01I I think Yeah, when you when you're in the face of that, you want to make sure for yourself that you're staying informed, staying educated, so that way you're not being over-reliant on those systems and just taking it at I guess face value, if you will. Um so I think it's ever more important to to be aware of what it is, the environments that you're working in, and like I said, to stay educated amo amongst that. So that way it helps you to make the best uh decision possible. So awesome.
SPEAKER_00Okay. Well, that's a wrap for the HTV Pressure Zone podcast. Um, to our listeners, remember that your operations are only as smart as the person checking the floor, and sometimes the data on the screen is just a digital smoke screen for a physical fire. Uh track your metrics, trust your boots on the ground, and watch the air. I'm your host, Christine Bartlett, and this is the Pressure Zone Podcast.