TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

195 articles

CMMCAsset Management

CMMC Requirements for OT and IoT Specialized Assets

CMMC treats OT and IoT as specialized assets. At Level 2 you list them in the asset inventory, the SSP and the network diagram, and show they are managed under your risk-based policies. At Level 3 they are assessed, and an intermediary device can supply the controls they lack.

UtilitiesWater

EPA Cybersecurity Requirements for Water and Wastewater Systems

There is no standalone federal cybersecurity rule for water utilities, but there is an enforceable federal requirement. It lives in the Safe Drinking Water Act, and EPA is enforcing it. Here is exactly what the law asks for and what it does not.

UtilitiesWater

New York DOH Part 5: The Water Cybersecurity Requirements, Explained

New York added cybersecurity requirements to 10 NYCRR Part 5, its drinking water regulation. If your system serves more than 3,300 people, Appendix 5-E applies, and the main operational technology requirements take effect January 1, 2027.

NIS2Compliance

NIS2 Directive Explained: Requirements, Scope, and Who Must Comply in 2026

NIS2 is the EU's cybersecurity law for essential and important entities in 18 sectors. Who must comply, the ten Article 21 security measures, the 24-hour reporting rule, and what it all means for industrial and OT networks.

CMMC

OT vs IT CMMC Controls: Where the 110 Controls Diverge

CMMC applies the same NIST 800-171 controls to IT and OT, but the way you meet them differs. IT enforces controls on the endpoint; OT usually enforces them on the network around the machine.

ICS AdvisoriesOT Security

Protect a SCADAPack x70 RTU With No Patch (ICSA-26-258-04)

CISA's ICSA-26-258-04 covers CVE-2026-81861 in Schneider Electric SCADAPack x70 RTUs: the legacy Secure Lock feature protects passwords with keys built into every device, so anyone who captures an unlock or password change can recover the password. All versions are affected and there is no firmware fix. The fix is configuration, and here is the order to do it in.

ICS AdvisoriesPower Grid

Siemens Reyrolle 7SR5 Relays: What to Do Before You Patch

CISA's ICSA-26-258-05 covers 14 CVEs in Siemens Reyrolle 7SR5 protection relays before V2.70. The most severe, CVSS 9.8, lets an attacker calculate web session IDs and skip the login. Relay firmware takes time to test and roll out, so the first job is to control who can reach the relay's web interface.

Zero TrustCISA

What the New CISA Zero Trust OT Guide Means for On-Premise Deployments

CISA, the Department of War, DOE, FBI, and Department of State published joint Zero Trust OT guidance on April 29, 2026. Three findings matter most for on-premise deployments: agentless network-layer enforcement is endorsed for legacy OT, microsegmentation must operate without redesign, and air-gap alone is called out as a false sense of security.

OT SecurityBuyer's Guide

How to Evaluate OT Security Vendors: A Buyer's Checklist for 2026

Not all OT security products are the same. Some monitor. Some enforce. Some require cloud. Here's a structured framework for evaluating vendors.

Zero TrustNetwork Segmentation

How to Segment a Flat OT Network Without VLANs or Downtime

Your OT network is flat. Everything can reach everything. VLANs require switch reconfiguration, recabling, and downtime. Overlay networking segments the network in software without touching the physical layer.

Network DesignSegmentation

Overlay Networking vs VLANs: A Practical Comparison for OT Segmentation

VLANs require switch reconfiguration, re-cabling, and downtime. Overlay networks deploy on top of your existing infrastructure in a day. Same segmentation result, different effort.

Zero TrustOT Security

Zero Trust for Legacy PLCs: The Lollipop Architecture Explained

Legacy PLCs cannot authenticate users, log sessions, or encrypt traffic. The lollipop architecture puts a proxy in front of each asset, enforcing Zero Trust at the network layer without modifying the device.

›Browse all posts (195)