TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

307 articles

OT SecurityICS Advisories

ABB Ability Zenon's Bundled MongoDB Flaws: What ICSA-26-218-01 Teaches OT Teams

CISA's ICSA-26-218-01 lists 13 MongoDB CVEs inside ABB Ability Zenon's IIoT services, several reachable without credentials. None of them are in the SCADA logic. They sit in a component you don't get to patch on your own schedule, which changes how you should respond.

WaterOT Security

US Water Utility Cyberattacks in 2026: What Happened and How to Secure OT

Hackers disrupted more than 30 Minnesota water systems in late July 2026 by reaching internet-exposed PLCs. Here is what happened, how the attacks worked, and the controls that stop them.

CMMCCompliance

The Affirming Official's False Claims Act Risk in CMMC

Under CMMC, a senior company official must affirm the assessment. A false affirmation can expose that person and the company to False Claims Act liability. Here is what the affirming official is actually signing, and how to reduce the risk.

WaterCompliance

AWIA Risk and Resilience Certification: The Cybersecurity Part

AWIA requires community water systems serving more than 3,300 people to assess and certify their risk and resilience, and electronic control systems are explicitly in scope. Here is the cybersecurity part and how to satisfy it.

WaterCompliance

Cybersecurity in the EPA Sanitary Survey: What to Expect

The EPA's 2023 memo tying cybersecurity to sanitary surveys was withdrawn, but state primacy agencies and voluntary guidance are folding it in anyway. Here is what a survey now looks at, and how to prepare.

CMMCAuthentication

MFA for PLCs: Meeting CMMC 3.5.3 with a Compensating Control

CMMC control 3.5.3 requires MFA, but a legacy PLC cannot run it. The compliant path is a compensating control enforced at the network, documented as an enduring exception. Here is the defensible way to document it, subject to your assessor's determination.

WaterRemote Access

SCADA Remote Access for Small Water Utilities

Small water systems need remote access to SCADA for on-call operators and integrators, but a flat VPN is exactly what regulators and attackers exploit. Here is the affordable, defensible pattern.

NERC CIPPower utilities

The NERC CIP Compliance Checklist for Power Utilities (2026)

A practical, standard-by-standard NERC CIP checklist for power utilities, updated for CIP-003-9 vendor remote access (live April 2026) and CIP-015 internal network security monitoring. What each control asks for, and how to produce the evidence.

ModbusOPC-UA

Real-Time PLC Data Streaming OPC-UA Modbus and Modern Integration Patterns

Getting live data off a PLC sounds simple until you have to do it without slowing the controller or opening a hole in the network. How OPC-UA and Modbus compare for real-time streaming.

CMMCCompliance

The C3PAO Bottleneck: How to Prepare When There Aren't Enough Assessors

The C3PAO shortage was so severe the DoW suspended CMMC Phase II citing this exact math. Here is how to use the pause to get CMMC-ready.

CMMCCompliance

CMMC Readiness for Manufacturers After the Suspension

CMMC Phase II and its third-party audit deadline are suspended. Here is what still applies for defense manufacturers, and how to stay ready.

CMMCCompliance

CMMC Phase II Suspended: What Actually Changes for Defense Manufacturers

The Department of War suspended CMMC Phase II and its mandatory third-party audit. Here is what changed, what did not, and what defense manufacturers should do now.

Browse all posts (307)