TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

329 articles

NERC CIPPower utilities

Checklist for NERC CIP Compliance in Power Utilities

Safeguarding critical infrastructure in power utilities is essential. The North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) stan...

Flat networksSegmented networks

Flat Network vs Segmented Network in Industrial Environments

Flat network vs segmented network in OT: lateral-movement risk, compliance under CMMC, NIS2, and IEC 62443, and a migration path without production downtime.

NERC CIPCompliance

NERC CIP Compliance: Network Security Monitoring Requirements

Adherence to regulatory standards like NERC CIP is crucial for critical infrastructure security. For IT security professionals, compliance officers, and defense contractors, understanding the nuances...

UtilitiesOil and Gas

Oil & Gas Pipeline Security: Protecting Distributed SCADA Across Vast Geographies

Pipeline SCADA spans hundreds of miles. Wellheads, compressor stations, and refineries all connected — and all exposed. Here's how to secure them.

UtilitiesPower Grid

Power Grid Substation Security: Zero Trust for Distributed Energy OT

RTUs, relays, and SCADA across hundreds of substations. Most are unmanned, many are decades old. Here's how to deploy zero-trust security across distributed grid infrastructure.

UtilitiesWater

Water Utility Cybersecurity: Securing SCADA from Treatment Plant to Tap

Water treatment plants run SCADA systems that control chemical dosing, pressure, and flow. A compromise doesn't just cost money — it's a public health risk.

Segmentation

Purdue Model Limitations and Alternatives for Modern OT

The Purdue Model defined OT segmentation for decades. But remote access, IIoT, and cloud analytics have eroded every layer. Here is what breaks, why, and what to use instead.

IT/OT convergenceBoundary security

Securing the IT/OT Boundary: Technical Architecture Patterns

Three architecture patterns for securing the IT/OT boundary: industrial DMZ, zero trust segmentation, and secure remote access. Each solves a different part of the problem.

AuthenticationOT Security

Understanding the Costs of MFA in OT and On-Premise Environments

Multi-factor authentication for OT and on-premise systems costs more than the cloud pricing page suggests. This post breaks down the hardware, licensing, and operational figures so you can budget accurately for a plant-floor rollout.

MITRE ATT&CKICS threat detection

How to Use MITRE ATT&CK for ICS Threat Detection

Securing Industrial Control Systems (ICS) is critical. MITRE ATT&CK is a comprehensive framework designed to document and share knowledge about a...

ICS network designBest practices

Best Practices for Designing a Secure ICS Network

ICS network security is critical. As the backbone of critical infrastructure, ICS networks demand robust security measures to protec...

SegmentationNetwork Design

Breaking Down Broadcast Storms How Layer 3 Segmentation Saves Your Network

Broadcast storms are the silent saboteurs of network performance, wreaking havoc by flooding your system with an overwhelming amount of traffic. These storms can lead to significant downtime, producti...

Browse all posts (329)