TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

330 articles

OPC UAOT security

OPC UA Security: What Every OT Engineer Should Know

OPC UA ships with a layered security model that most deployments leave half-configured. This primer walks through the SecureChannel, message security modes, security policies, and the difference between application and user authentication, so you can tell a hardened endpoint from an open door.

ModbusDNP3

How to Detect Anomalies in Modbus and DNP3 Traffic

A practical guide to detecting anomalies in Modbus and DNP3 traffic: baselining normal behavior, spotting function-code and object anomalies, catching unauthorized writes, and monitoring passively.

Modbus TCPICS security

How to Secure Modbus TCP: Best Practices for Modern ICS Networks

Modbus TCP has no built-in authentication or encryption. Here's how to lock it down without breaking your process.

AuthenticationRemote Access

MFA for Remote Access: VPNs, RDP, and Cloud Portals

With remote access central to modern business operations, securing this access is critical. Whether navigating the complexities of VPNs, Remote Desktop Protocol (RDP), or cloud portals, MFA closes the most common entry points for breaches.

OPC-UAAir-gapped networks

OPC-UA Authentication in Air-Gapped Environments

An air-gapped OPC-UA deployment cannot reach an external CA or pull a CRL from the internet. Here is how to run application certificates, trust lists, and user authentication entirely offline.

ModbusOPC-UA

Real-Time PLC Data Streaming OPC-UA Modbus and Modern Integration Patterns

Getting live data off a PLC sounds simple until you have to do it without slowing the controller or opening a hole in the network. How OPC-UA and Modbus compare for real-time streaming.

ModbusEncryption tunnels

Securing Modbus TCP Networks: Beyond Basic Firewall Rules

Modbus TCP, an industrial protocol used extensively in Operational Technology (OT) environments, is foundational to industrial communication. However, its lack of built-in security features presents u...

Secure ModbusModbus TCP

The Difference Between Secure Modbus and Modbus TCP

Plain Modbus/TCP has no authentication and no encryption. Secure Modbus, defined by the Modbus/TCP Security specification, adds TLS and X.509 role-based authorization. Here is the precise difference, where each fits, and how to migrate.

TLSOPC UA

The Role of TLS in Securing OPC UA

TLS is often described as the way to secure OPC UA, but the protocol most industrial deployments use, opc.tcp, never touches TLS. Here is how OPC UA actually encrypts traffic, the role TLS does play, and where it tends to break in the field.

Access GateRelease

What's New in Access Gate v26.6

Access Gate v26.6 focuses on running Zero Trust at scale: network-based fleet upgrades, privileged remote access for OT, protocol-aware access rules, a reworked Tailscale integration, and new built-in threat detections.

NERC CIPPower utilities

Checklist for NERC CIP Compliance in Power Utilities

Safeguarding critical infrastructure in power utilities is essential. The North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) stan...

Flat networksSegmented networks

Flat Network vs Segmented Network in Industrial Environments

Flat network vs segmented network in OT: lateral-movement risk, compliance under CMMC, NIS2, and IEC 62443, and a migration path without production downtime.

Browse all posts (330)