TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

312 articles

OT SecurityICS Advisories

The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)

CISA's ICSA-26-225-01 flags a CVSS 7.1 deserialization-to-code-execution flaw in AVEVA Enterprise SCADA and its HMI. The attacker still needs to reach the service to send the payload. That reach is the part you control.

OT SecurityICS Advisories

A CVSS 10 on the Box That Faces the Internet: Haiwell IoT Cloud HMI Gateway (ICSA-26-225-02)

CISA's ICSA-26-225-02 flags a CVSS 10 OS command injection in the Haiwell IoT Cloud HMI Gateway that runs commands as root. The gateway's whole job is to be reachable. That is exactly the problem, and the fix is to control the reach.

OT SecurityICS Advisories

The Firewall in the OT Rack Is Also Just Software: Siemens RUGGEDCOM APE1808 (ICSA-26-225-06)

CISA's ICSA-26-225-06 carries FortiOS flaws onto the Siemens RUGGEDCOM APE1808, the ruggedized box that runs a firewall inside the plant. The security appliance has its own CVEs. That is the argument for defense in depth, not against firewalls.

OT SecurityICS Advisories

The Access-Control System That Needs Access Control: Johnson Controls C-CURE 9000 (ICSA-26-204-01)

CISA's ICSA-26-204-01 flags a CVSS 9.6 remote-code-execution path in Johnson Controls C-CURE 9000 and victor, the servers that run building access control and video. An attacker with network access is the whole precondition. That is the part you control.

OT SecuritySegmentation

Lateral Movement in OT Networks: What It Is and How to Stop It

Lateral movement is how an attacker turns one foothold into control of the whole plant. Flat OT networks make it trivial. The durable fix is not more detection, it is removing the paths, per asset, so a compromise stays where it started.

OT SecurityRemote Access

Secure Remote Access for OT: Staff, Vendors, and the Flat-VPN Trap

OT secure remote access is not a VPN with a nicer login. It is identity for staff and third-party vendors, per-asset brokering, and a recorded session, kept on-premise. Here is how to do it without dropping anyone onto a flat network.

OT Security

The Difference Between IT and OT Cybersecurity Explained

IT vs OT cybersecurity comes down to one inversion of priorities: IT protects data and prioritizes confidentiality, while OT protects a physical process and prioritizes safety and availability. Here is what that changes about how each is secured.

OT SecurityICS Advisories

ABB Ability Zenon's Bundled MongoDB Flaws: What ICSA-26-218-01 Teaches OT Teams

CISA's ICSA-26-218-01 lists 13 MongoDB CVEs inside ABB Ability Zenon's IIoT services, several reachable without credentials. None of them are in the SCADA logic. They sit in a component you don't get to patch on your own schedule, which changes how you should respond.

WaterOT Security

US Water Utility Cyberattacks in 2026: What Happened and How to Secure OT

Hackers disrupted more than 30 Minnesota water systems in late July 2026 by reaching internet-exposed PLCs. Here is what happened, how the attacks worked, and the controls that stop them.

CMMCCompliance

The Affirming Official's False Claims Act Risk in CMMC

Under CMMC, a senior company official must affirm the assessment. A false affirmation can expose that person and the company to False Claims Act liability. Here is what the affirming official is actually signing, and how to reduce the risk.

WaterCompliance

AWIA Risk and Resilience Certification: The Cybersecurity Part

AWIA requires community water systems serving more than 3,300 people to assess and certify their risk and resilience, and electronic control systems are explicitly in scope. Here is the cybersecurity part and how to satisfy it.

WaterCompliance

Cybersecurity in the EPA Sanitary Survey: What to Expect

The EPA's 2023 memo tying cybersecurity to sanitary surveys was withdrawn, but state primacy agencies and voluntary guidance are folding it in anyway. Here is what a survey now looks at, and how to prepare.

Browse all posts (312)