TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

302 articles

OT SecurityICS Advisories

A Key You Cannot Rotate: AVEVA Pipeline Integrity Monitor (ICSA-26-253-01)

CISA's ICSA-26-253-01 covers four flaws in AVEVA Pipeline Integrity Monitor, including a hard-coded cryptographic key. The two 8.4s are local-only, so the whole question is who can already reach the host.

CMMCArchitecture

The Last Hop: Carrying CUI From a Cloud Enclave to the Machine That Uses It

A cloud enclave holds CUI well and stops at the human. This is the architecture for the last hop: a FIPS 140-3 validated tunnel into a protocol-aware proxy sitting in front of the printer, the CNC or the bench instrument that cannot defend itself.

CMMC 2.0Manufacturers

CMMC 2.0: What Manufacturers Need to Know

CMMC 2.0 consolidates the DoD's five maturity levels into three, changes assessment requirements, and reshapes how defense contractors must protect CUI. Here is what manufacturers need to know.

CMMCCompliance

CMMC Readiness for Manufacturers After the Suspension

CMMC Phase II and its third-party audit deadline are suspended. Here is what still applies for defense manufacturers, and how to stay ready.

CMMCOpen Source

Introducing Open-CMMC: An Open-Source CUI Enclave for CMMC Level 2

We're releasing Open-CMMC, an Apache-2.0 hardened file browser for on-premise CUI storage that covers 72 of 110 NIST SP 800-171 Rev 2 controls directly in product code.

CMMCCompliance

Preparing for the CMMC 2.0 Compliance Deadline

The CMMC 2.0 final rule is here. Learn what defense contractors need to do now to prepare for their assessment and avoid losing contract eligibility.

ICS AdvisoriesOT Remote Access

IXON VPN Client RCE: When the Remote Access Client Is the Attack Surface

On September 3, 2026, CISA published ten ICS advisories. One of them, ICSA-26-246-02, covers a CVSS 9.6 vulnerability in the IXON VPN Client that lets an attacker execute commands as root or SYSTEM on the engineer's own machine. IXON found it, fixed it, and blocked unpatched clients from its cloud. The architectural question it raises outlives the patch.

Star topologyRing topology

Choosing Between Star and Ring Topologies in ICS

Choosing the right network topology for your Industrial Control System (ICS) is a critical decision that impacts not only the performance and reliability of your industrial operations but also the sec...

CMMCArchitecture

CUI Enclave Architecture: On-Premise Alternatives to GCC High

GCC High protects CUI while people collaborate on it. An on-premise enclave protects it once it reaches a printer, a CNC machine or a local file server. Most defense manufacturers need both.

MITRE ATT&CKICS threat detection

How to Use MITRE ATT&CK for ICS Threat Detection

Securing Industrial Control Systems (ICS) is critical. MITRE ATT&CK is a comprehensive framework designed to document and share knowledge about a...

SCADA

ICS vs SCADA Security What You Need to Know

ICS and SCADA system security remains a critical concern. As the backbone of industrial oper...

Network topologyAsset discovery

Industrial Network Topology Discovery and Mapping

You cannot secure a network you have not mapped, and in OT the mapping itself can break production. Here is how to discover assets and build a real topology using passive capture, switch configuration ingest, and protocol-native queries, what each method can and cannot see, and how to turn the result into a segmentation design.

Browse all posts (302)