Insights & Resources
Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.
312 articles
The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)
CISA's ICSA-26-225-01 flags a CVSS 7.1 deserialization-to-code-execution flaw in AVEVA Enterprise SCADA and its HMI. The attacker still needs to reach the service to send the payload. That reach is the part you control.
A CVSS 10 on the Box That Faces the Internet: Haiwell IoT Cloud HMI Gateway (ICSA-26-225-02)
CISA's ICSA-26-225-02 flags a CVSS 10 OS command injection in the Haiwell IoT Cloud HMI Gateway that runs commands as root. The gateway's whole job is to be reachable. That is exactly the problem, and the fix is to control the reach.
The Firewall in the OT Rack Is Also Just Software: Siemens RUGGEDCOM APE1808 (ICSA-26-225-06)
CISA's ICSA-26-225-06 carries FortiOS flaws onto the Siemens RUGGEDCOM APE1808, the ruggedized box that runs a firewall inside the plant. The security appliance has its own CVEs. That is the argument for defense in depth, not against firewalls.
The Access-Control System That Needs Access Control: Johnson Controls C-CURE 9000 (ICSA-26-204-01)
CISA's ICSA-26-204-01 flags a CVSS 9.6 remote-code-execution path in Johnson Controls C-CURE 9000 and victor, the servers that run building access control and video. An attacker with network access is the whole precondition. That is the part you control.
Lateral Movement in OT Networks: What It Is and How to Stop It
Lateral movement is how an attacker turns one foothold into control of the whole plant. Flat OT networks make it trivial. The durable fix is not more detection, it is removing the paths, per asset, so a compromise stays where it started.
Secure Remote Access for OT: Staff, Vendors, and the Flat-VPN Trap
OT secure remote access is not a VPN with a nicer login. It is identity for staff and third-party vendors, per-asset brokering, and a recorded session, kept on-premise. Here is how to do it without dropping anyone onto a flat network.
The Difference Between IT and OT Cybersecurity Explained
IT vs OT cybersecurity comes down to one inversion of priorities: IT protects data and prioritizes confidentiality, while OT protects a physical process and prioritizes safety and availability. Here is what that changes about how each is secured.
ABB Ability Zenon's Bundled MongoDB Flaws: What ICSA-26-218-01 Teaches OT Teams
CISA's ICSA-26-218-01 lists 13 MongoDB CVEs inside ABB Ability Zenon's IIoT services, several reachable without credentials. None of them are in the SCADA logic. They sit in a component you don't get to patch on your own schedule, which changes how you should respond.
US Water Utility Cyberattacks in 2026: What Happened and How to Secure OT
Hackers disrupted more than 30 Minnesota water systems in late July 2026 by reaching internet-exposed PLCs. Here is what happened, how the attacks worked, and the controls that stop them.
The Affirming Official's False Claims Act Risk in CMMC
Under CMMC, a senior company official must affirm the assessment. A false affirmation can expose that person and the company to False Claims Act liability. Here is what the affirming official is actually signing, and how to reduce the risk.
AWIA Risk and Resilience Certification: The Cybersecurity Part
AWIA requires community water systems serving more than 3,300 people to assess and certify their risk and resilience, and electronic control systems are explicitly in scope. Here is the cybersecurity part and how to satisfy it.
Cybersecurity in the EPA Sanitary Survey: What to Expect
The EPA's 2023 memo tying cybersecurity to sanitary surveys was withdrawn, but state primacy agencies and voluntary guidance are folding it in anyway. Here is what a survey now looks at, and how to prepare.
›Browse all posts (312)
- The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)
- A CVSS 10 on the Box That Faces the Internet: Haiwell IoT Cloud HMI Gateway (ICSA-26-225-02)
- The Firewall in the OT Rack Is Also Just Software: Siemens RUGGEDCOM APE1808 (ICSA-26-225-06)
- The Access-Control System That Needs Access Control: Johnson Controls C-CURE 9000 (ICSA-26-204-01)
- Lateral Movement in OT Networks: What It Is and How to Stop It
- Secure Remote Access for OT: Staff, Vendors, and the Flat-VPN Trap
- The Difference Between IT and OT Cybersecurity Explained
- ABB Ability Zenon's Bundled MongoDB Flaws: What ICSA-26-218-01 Teaches OT Teams
- US Water Utility Cyberattacks in 2026: What Happened and How to Secure OT
- The Affirming Official's False Claims Act Risk in CMMC
- AWIA Risk and Resilience Certification: The Cybersecurity Part
- Cybersecurity in the EPA Sanitary Survey: What to Expect
- MFA for PLCs: Meeting CMMC 3.5.3 with a Compensating Control
- SCADA Remote Access for Small Water Utilities
- The NERC CIP Compliance Checklist for Power Utilities (2026)
- Real-Time PLC Data Streaming OPC-UA Modbus and Modern Integration Patterns
- The C3PAO Bottleneck: How to Prepare When There Aren't Enough Assessors
- CMMC Readiness for Manufacturers After the Suspension
- CMMC Phase II Suspended: What Actually Changes for Defense Manufacturers
- Deploying Firewalls Without Breaking ICS Traffic
- EPA Cybersecurity Requirements for Water and Wastewater Systems
- New York DOH Part 5: The Water Cybersecurity Requirements, Explained
- How to Spot Malicious Lateral Movement in OT Environments
- Water Utility Cybersecurity: Securing SCADA from Treatment Plant to Tap
- OPC UA Security: What Every OT Engineer Should Know
- How to Detect Anomalies in Modbus and DNP3 Traffic
- MFA for Remote Access: VPNs, RDP, and Cloud Portals
- OPC-UA Authentication in Air-Gapped Environments
- The Difference Between Secure Modbus and Modbus TCP
- The Role of TLS in Securing OPC UA
- What's New in Access Gate v26.6
- Flat Network vs Segmented Network in Industrial Environments
- NERC CIP Compliance: Network Security Monitoring Requirements
- Oil & Gas Pipeline Security: Protecting Distributed SCADA Across Vast Geographies
- Power Grid Substation Security: Zero Trust for Distributed Energy OT
- Purdue Model Limitations and Alternatives for Modern OT
- Securing the IT/OT Boundary: Technical Architecture Patterns
- Understanding the Costs of MFA in OT and On-Premise Environments
- How to Use MITRE ATT&CK for ICS Threat Detection
- Best Practices for Designing a Secure ICS Network
- CMMC Level 2 for Manufacturers: Why VLANs Are Not Enough for Shop Floor OT
- CMMC vs NIS2: One Compliance Architecture for Both Frameworks
- How CMMC Handles Exceptions and Compensating Controls
- How to Write an SSP Section for a Network with Legacy PLCs
- Secure Remote Access for Legacy Systems
- What the CMMC Enduring Exception Actually Requires You to Document
- Why Your OT Network Has No Identity Layer (And What Happens When an Attacker Notices)
- Zero Trust for Legacy PLCs: The Lollipop Architecture Explained
- Agent-Free Zero Trust: Why OT Environments Can't Use Endpoint Software
- What the New CISA Zero Trust OT Guide Means for On-Premise Deployments
- How to Segment a Flat OT Network Without VLANs or Downtime
- What a C3PAO Looks for in an OT Environment
- Zero Trust for Air-Gapped OT Networks: What Works and What Doesn't
- Cybersecurity for Police Evidence Systems: Sovereign, Auditable, On-Premise
- From Unboxing to Zero Trust in 4 Hours: What Deployment Actually Looks Like
- How Ski Resorts and Distributed Infrastructure Operators Deploy Zero Trust
- How to Evaluate OT Security Vendors: A Buyer's Checklist for 2026
- Multi-Site OT Security: How to Scale Zero Trust Across 50+ Locations
- Port & Maritime OT Security: Protecting Crane Control and Terminal Systems
- Proxy-Based Security for OT: Why Proxies Succeed Where Agents Fail
- Rail Signaling Cybersecurity: Protecting Safety-Certified Infrastructure
- Session Recording for OT Compliance: Meeting CMMC and NIS2 Audit Requirements
- The True Cost of OT Security: TCO Comparison of Appliance vs Cloud Solutions
- Securing Airport Baggage Handling Systems Without Requalification
- AI-Powered Attacks on Industrial Networks: What OT Teams Should Prepare For
- How to Configure YubiKey with Trout Access Gate
- Supply Chain Attacks on OT: The PYROXENE Campaign and Lessons for Operators
- Overlay Networking vs VLANs: A Practical Comparison for OT Segmentation
- Why On-Premise OT Security Beats Cloud-Routed Solutions
- Nozomi Networks vs Access Gate: When Visibility Alone Isn't Enough
- Top OT Cyber Threats in 2026: What to Watch
- What Is MFA and Why Every Organization Needs It in 2026
- Introducing Open-CMMC: An Open-Source CUI Enclave for CMMC Level 2
- Claroty vs Access Gate: Monitoring vs Enforcement for OT Networks
- Control Loop Mapping: How Attackers Are Learning to Manipulate Physical Processes
- CUI Enclave Architecture: On-Premise Alternatives to GCC High
- Dragos 2026 Report: What the 3 New OT Threat Groups Mean for Your Factory
- NIS2 Management Liability: Why Executives Are Personally on the Hook
- Ransomware Targeting Manufacturing in 2026: A 49% Increase and What to Do About It
- NIS2 Enforcement Is Live: What Changed and What to Do First
- Centralized Audit Logging for Multi-Site Operations
- CMMC Compliance for Defense Suppliers: Practical Guide
- Compliance Audit Readiness for Critical Infrastructure
- Cybersecurity for Naval Shipboard Systems
- Defense Contractor Facility Security: Beyond the Perimeter
- Detecting Anomalies in Industrial Protocols
- IEC 62443 Zones and Conduits Explained
- Network Visibility: You Can't Protect What You Can't See
- NIS2 Operational Technology: What Manufacturers Need to Know
- OT Patch Management Challenges and Strategies
- Ransomware in Manufacturing: Lessons from Recent Attacks
- Remote Access: Biggest Attack Vector in OT
- Securing UAV Ground Stations: MAVLink Vulnerabilities
- Supply Chain Attacks Targeting Industrial Control Systems
- Bringing Two-Factor Authentication to the Factory Floor: Constraints and Practical Methods
- From Control Room to Field Device: Adapting Two-Factor Authentication to Industrial Reality
- OT and Legacy Systems impact on NIS2
- Air-Gapped But Not Safe: Misconceptions in Legacy Security
- Air-Gapped vs Layered Security Architectures
- Aligning Factory Networks with DoD Requirements
- Automating Compliance Monitoring in ICS
- Badge vs Password Why Physical Identity Matters for OT Cybersecurity
- Balancing Security and Uptime in Manufacturing
- Best Tools for Monitoring Industrial Protocol Security
- Beyond the Acronym How PLCs Became the Backbone of Modern Industrial Automation
- Breaking Down Data Silos How to Extract Maximum Value from Your PLC Networks
- Bridging IT and OT: A Step-by-Step Integration Guide
- Bridging Legacy Protocols and Cloud Architectures
- Building a SOC for OT: Tools and Tips
- Building Fault-Tolerant Network Paths in OT
- Building for Scalability in Industrial Networks
- Change Management for Industrial Network Security
- Change Management in ICS Environments
- Choosing Between Star and Ring Topologies in ICS
- CMMC 2.0: What Manufacturers Need to Know
- CMMC Level 2 Requirements for OT Specialized Assets
- CMMC Secure Specialized Assets
- Common Attack Vectors in Legacy ICS
- Common Language: How IT and OT Teams Can Align
- Common MFA Mistakes and How to Avoid Them
- Common Pitfalls in Achieving ISO 27001 for Industrial Networks
- Common Root Causes of OT Downtime
- Compliant Remote Access Solutions for Manufacturers
- Continuous Verification in 24/7 Manufacturing Operations
- Creating Standard Operating Procedures for OT Security
- Daily Maintenance Tasks for OT Cybersecurity
- Data Diodes vs Firewalls for IT/OT Separation
- Dealing with Firmware Limitations in Legacy Equipment
- Deep Packet Inspection vs Flow-Based Monitoring What's Best for OT
- Design Patterns for Converged IT/OT Monitoring
- Designing for Predictable Network Behavior in OT
- Designing Redundant Communication Paths in OT
- Detecting and Responding to ICS Attacks in Real Time
- Device Authentication for Legacy Industrial Equipment
- Device Identity in Zero Trust Industrial Networks
- DNP3 Security Implementation in SCADA Systems
- Documenting Security Controls for Industrial Assessments
- Endpoint Visibility in IT/OT Convergence
- EtherNet/IP Vulnerability Assessment and Mitigation
- Failover Strategies for Mission-Critical OT Networks
- Failure Modes in SCADA Networks
- FIDO2 and Passkeys The Future of MFA for Critical Infrastructure
- Firewall Placement Strategies for Industrial Networks
- From Door to Data How Badge Access Enhances Cybersecurity in Industrial Environments
- From Factory Floor to Cloud Building Robust Data Pipelines from PLC Systems
- From SaaS Security to Factory Floor Security The Two Faces of Zero Trust
- GDPR and OT: What Data Privacy Means for Industrial Control Systems
- High Availability NAC Deployment for Continuous Operations
- HMI Network Isolation Strategies
- How Compliance Can Drive Better OT Security
- How Network Changes Affect PLC Performance
- How Network Traffic Logs Help You Comply with CMMC and IEC 62443
- How to Add Visibility to Dark OT Networks
- How to Audit Industrial Protocol Traffic Effectively
- How to Benchmark ICS Network Performance
- How to Build a Resilient OT Backbone
- How to Build a Zero Trust Architecture for Manufacturing
- How to Build an Incident Response Plan for ICS
- How to Build an OT Cybersecurity Roadmap for Your Factory
- How to Comply with IEC 62443 in Practice
- How to Conduct a Post-Incident Analysis in OT
- How to Connect Sites Without Increasing Risk
- How to Correlate Network Traffic and Device Behavior in OT
- How to Create Secure Zones in SCADA Networks
- How to Design an ICS Network for High Availability
- How to Enforce East-West Traffic Isolation in OT
- How to Implement Least Privilege Access in Industrial Networks
- How to Implement MFA in Legacy OT Environments Without Breaking Operations
- How to Integrate Zero Trust with Existing ICS Infrastructure
- How to Leverage IT Tooling in OT Networks
- How to Manage Passwords on Hundreds of ICS Devices
- How to Monitor Latency in ICS Networks
- How to Monitor SCADA Network Traffic Without Disrupting Operations
- How to Perform a Risk Assessment on Your OT Environment
- How to Roll Out MFA Without Frustrating Your Team
- How to Roll Out New OT Security Tech with Minimal Downtime
- How to Safely Route Business Data from ICS Systems
- How to Secure 20-Year-Old PLCs in Modern Networks
- How to Secure Legacy OT Systems Without Breaking Them
- How to Secure Shared Infrastructure Between IT and OT
- How to Train Operators on OT Security Best Practices
- How to Use NetFlow for Industrial Network Visibility
- ICS Honeypots: Revealing Real-World Attacks on Industrial Protocols
- ICS Network Design: Mistakes to Avoid
- ICS Protocol Deep Packet Inspection: Tools and Techniques
- ICS vs SCADA Security What You Need to Know
- IEC 62443 Zone Implementation with Network Access Control
- Implementing Network Traffic Analysis Without Slowing Down Production
- Implementing Zero Trust in Air-Gapped OT Networks
- Indicators of Compromise in SCADA Environments
- Industrial Malware: Network-Based Detection Strategies
- Industrial Network Topology Discovery and Mapping
- Industry 4.0 Data Architecture Why Your PLC Strategy Determines Digital Transformation Success
- Insider Threat Detection in Manufacturing Environments
- Integrating Badge Access with Windows Login and Remote Sessions
- Integrating Serial Devices into IP Networks Securely
- Integrating Sysmon and OT Logging: A Unified View
- Inventory and Asset Management in ICS Operations
- ISA/IEC 62443 Asset Identification and Documentation
- Key Metrics to Track Zero Trust Adoption in OT
- Latency Requirements in Industrial Control Systems
- Lateral Movement Detection in Industrial Networks
- Layer 2 vs Layer 3 Why Your Network's Broadcast Domains Are Killing Performance
- Legacy Device Inventory: Where to Start
- Legacy OT Systems: Risks and Modern Mitigations
- Lessons Learned from the TRITON Malware Attack
- Maintenance Window Planning for Security Updates
- Managing Mixed IT/OT Device Inventories
- Mapping OT Controls to NIST SP 800-53
- MFA for Service Accounts and Industrial Devices Is It Possible
- Network Access Control (NAC) for SCADA and ICS
- Network Security Impact on Real-Time Control Loops
- Network Traffic Baselines Why They're Critical in Industrial Security
- NIS2 Asset Inventory Requirements What You Need to Track and How to Do IT on Premise
- NIS2 Compliance a Practical Guide to Meeting Article 21 Security Obligations
- NIS2 Compliance for Manufacturing Securing OT Legacy Machines and on Premise Systems
- NIS2 Directive Explained: Requirements, Scope, and Who Must Comply in 2026
- NIST Cybersecurity Framework for Manufacturing Systems
- OT-Specific IDS: What to Look For
- OT vs IT CMMC Controls
- Passive vs Active Traffic Monitoring in ICS Networks
- Patch Management in Operational Environments
- Phased NAC Deployment in Live Manufacturing Environments
- PLC Explained What Every Manufacturing Professional Should Know About Programmable Logic Controllers
- PLC vs SCADA vs DCS Understanding Industrial Control System Hierarchies
- Plug and Play NIS2 Compliance Achieving Coverage Without Agents or Cloud Dependency
- Protocol-Aware Firewalls for Industrial Control Systems
- Protocol Gateways: The Good, the Bad, and the Ugly
- Protocol Whitelisting: How to Reduce Attack Surface in OT
- Real-World ICS Breaches and What We Can Learn
- Red Team vs Blue Team Exercises for Industrial Networks
- Redundant Link Design for OT Systems
- Redundant Network Design with Integrated Security Controls
- Reference Architectures for ICS Network Security
- Remote Access Security for Industrial Maintenance
- Remote Site Deployment Best Practices
- Retrofitting Security Controls in Brownfield Installations
- Role of QoS in ICS Communications
- Routed vs Switched Networks
- Scheduling Maintenance Windows in 24/7 Plants
- Secure Commissioning of New ICS Equipment
- Secure Workarounds for Unsupported Protocols
- Securing 20-Year-Old PLCs: Non-Intrusive Approaches
- Securing Industrial Ethernet/IP: A Practical Guide
- Security Implications of Using PROFINET in Manufacturing
- Security Policies That Work Across IT and OT
- Security Risks of Uncontrolled IT/OT Interfaces
- Serial-to-Ethernet Gateway Security Considerations
- Simulating Cyberattacks on PLCs: Safe Testing Techniques
- Software-Defined Perimeter in Manufacturing
- Strategies for Enabling Logging in Old ICS Devices
- The Case for Out-of-Band Management in OT
- The Difference Between Technical and Administrative Controls in OT
- The Future of Hybrid IT/OT Teams
- The Reliability Impact of Cybersecurity Controls
- The Role of Emulators in ICS Legacy Integration
- The Role of MFA in CMMC NIS2 and IEC 62443 Compliance
- The Role of Multi-Factor Authentication in OT
- The Role of SIEMs in OT/IT Environments
- The Role of Syslog in Meeting CMMC Logging Requirements
- Tips for Upgrading Factory Network Infrastructure
- Top 10 Audit-Ready Controls for OT Networks
- Top 10 OT Cybersecurity Threats Facing Manufacturers in 2025
- Top 5 Benefits of Using Badge Access for ICS and SCADA Terminals
- Top 5 Metrics to Monitor in Industrial Network Traffic
- Top 5 MFA Methods Compared: SMS, TOTP, Biometrics, Hardware Keys & Push Notifications
- Top Frameworks for OT Cybersecurity IEC 62443 NIST and More
- Top Mistakes During IT/OT Network Mergers
- Top Vulnerabilities in DNP3 and How to Mitigate Them
- Training Operations Staff on Network Security Tools
- Training OT Operators on Network Hygiene
- Troubleshooting ICS Performance With Netflow
- Understanding NIS2 Requirements for ICS Networks
- Understanding SCADA Protocol Behavior for Better Defenses
- User Identity and Access in Air-Gapped Environments
- Using Demilitarized LANs to Isolate OT Assets
- Using NetFlow and Logs for ICS Threat Hunting
- Using SNMP Effectively in OT Environments
- Using Software-Defined Networking (SDN) in OT
- Using Traffic Analysis for Incident Response in ICS
- Vendor Access Controls During Field Maintenance
- Vendor Access Risks in OT and How to Control Them
- What Is Badge Access for Digital Systems A Beginner's Guide for IT and OT Teams
- What Is Network Traffic Analysis A Guide for OT Engineers
- What Is OT Cybersecurity A Beginner's Guide for Industrial Teams
- What OT Security Teams Can Learn from IT Breach Reports
- When Never Trust Always Verify Meets Legacy PLCs
- Where the Packets Roam
- Why Air Gaps Are No Longer Enough in OT Security
- Why Early Detection is Key in OT Security
- Why IT/OT Convergence Fails Without Governance
- Why Jitter Matters in Real Time OT Traffic
- Why Legacy Protocols Pose a Risk in Modern OT Networks
- Why Patching Isn't Always an Option in OT
- Why ZTNA in OT Isn't the Same as in IT
- Windows XP in Industrial Networks: Containment Strategies
- Wireless Design Considerations for Industrial Zones
- YubiKeys in Manufacturing Hands-On MFA for Shared Workstations
- Zero Downtime Deployment Techniques for Industrial Networks
- Zero Trust in OT How to Get Started
- Zero Trust in OT: Why the Perimeter is Dead
- Zero Trust OT Gateways: What They Are and How They Work
- Zero Trust Policy Framework for Critical Infrastructure
- Zero Trust Principles Applied to PLC Communications
- Zero Trust Readiness Checklist for Industrial Environments
- Zero Trust vs Traditional Firewalling: What's More Effective in OT?
- Zone and Conduit Architecture with Modern NAC Solutions
- Zone-Based Firewalling for ICS: Best Practices
- Why Zero Trust Matters for Manufacturing
- Preparing for the CMMC 2.0 Compliance Deadline
- Securing Legacy Manufacturing Equipment for CMMC
- On-Premise vs Cloud Enclave for CUI Protection