Insights & Resources
Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.
302 articles
A Key You Cannot Rotate: AVEVA Pipeline Integrity Monitor (ICSA-26-253-01)
CISA's ICSA-26-253-01 covers four flaws in AVEVA Pipeline Integrity Monitor, including a hard-coded cryptographic key. The two 8.4s are local-only, so the whole question is who can already reach the host.
The Last Hop: Carrying CUI From a Cloud Enclave to the Machine That Uses It
A cloud enclave holds CUI well and stops at the human. This is the architecture for the last hop: a FIPS 140-3 validated tunnel into a protocol-aware proxy sitting in front of the printer, the CNC or the bench instrument that cannot defend itself.
CMMC 2.0: What Manufacturers Need to Know
CMMC 2.0 consolidates the DoD's five maturity levels into three, changes assessment requirements, and reshapes how defense contractors must protect CUI. Here is what manufacturers need to know.
CMMC Readiness for Manufacturers After the Suspension
CMMC Phase II and its third-party audit deadline are suspended. Here is what still applies for defense manufacturers, and how to stay ready.
Introducing Open-CMMC: An Open-Source CUI Enclave for CMMC Level 2
We're releasing Open-CMMC, an Apache-2.0 hardened file browser for on-premise CUI storage that covers 72 of 110 NIST SP 800-171 Rev 2 controls directly in product code.
Preparing for the CMMC 2.0 Compliance Deadline
The CMMC 2.0 final rule is here. Learn what defense contractors need to do now to prepare for their assessment and avoid losing contract eligibility.
IXON VPN Client RCE: When the Remote Access Client Is the Attack Surface
On September 3, 2026, CISA published ten ICS advisories. One of them, ICSA-26-246-02, covers a CVSS 9.6 vulnerability in the IXON VPN Client that lets an attacker execute commands as root or SYSTEM on the engineer's own machine. IXON found it, fixed it, and blocked unpatched clients from its cloud. The architectural question it raises outlives the patch.
Choosing Between Star and Ring Topologies in ICS
Choosing the right network topology for your Industrial Control System (ICS) is a critical decision that impacts not only the performance and reliability of your industrial operations but also the sec...
CUI Enclave Architecture: On-Premise Alternatives to GCC High
GCC High protects CUI while people collaborate on it. An on-premise enclave protects it once it reaches a printer, a CNC machine or a local file server. Most defense manufacturers need both.
How to Use MITRE ATT&CK for ICS Threat Detection
Securing Industrial Control Systems (ICS) is critical. MITRE ATT&CK is a comprehensive framework designed to document and share knowledge about a...
ICS vs SCADA Security What You Need to Know
ICS and SCADA system security remains a critical concern. As the backbone of industrial oper...
Industrial Network Topology Discovery and Mapping
You cannot secure a network you have not mapped, and in OT the mapping itself can break production. Here is how to discover assets and build a real topology using passive capture, switch configuration ingest, and protocol-native queries, what each method can and cannot see, and how to turn the result into a segmentation design.
›Browse all posts (302)
- A Key You Cannot Rotate: AVEVA Pipeline Integrity Monitor (ICSA-26-253-01)
- The Last Hop: Carrying CUI From a Cloud Enclave to the Machine That Uses It
- CMMC 2.0: What Manufacturers Need to Know
- CMMC Readiness for Manufacturers After the Suspension
- Introducing Open-CMMC: An Open-Source CUI Enclave for CMMC Level 2
- Preparing for the CMMC 2.0 Compliance Deadline
- IXON VPN Client RCE: When the Remote Access Client Is the Attack Surface
- Choosing Between Star and Ring Topologies in ICS
- CUI Enclave Architecture: On-Premise Alternatives to GCC High
- How to Use MITRE ATT&CK for ICS Threat Detection
- ICS vs SCADA Security What You Need to Know
- Industrial Network Topology Discovery and Mapping
- Using NetFlow and Logs for ICS Threat Hunting
- EPA Cybersecurity Requirements for Water and Wastewater Systems
- The ASE2000 Test Set: When IEC 60870-5-104 TLS Does Not Check the Certificate
- A Water Utility Caught CISA's Red Team in Two Minutes. The OT Jump Server Still Fell.
- Serial-to-IP Device Servers: Four CISA Advisories in Three Days
- Real-Time PLC Data Streaming OPC-UA Modbus and Modern Integration Patterns
- How to Perform a Risk Assessment on Your OT Environment
- Patch Management in Operational Environments
- Understanding the Costs of MFA in OT and On-Premise Environments
- Credentials Sitting in Memory: Johnson Controls Simplex Incident Manager (ICSA-26-232-01)
- Zero Trust Readiness Checklist for Industrial Environments
- Secomea Alternatives: When Remote Access Is Not the Whole Problem
- Siemens SINEMA and Scalance: What Sits Between Remote Access and Segmentation
- Talk2M Alternatives: Industrial Remote Access Without a Vendor Cloud
- The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)
- A CVSS 10 on the Box That Faces the Internet: Haiwell IoT Cloud HMI Gateway (ICSA-26-225-02)
- The Firewall in the OT Rack Is Also Just Software: Siemens RUGGEDCOM APE1808 (ICSA-26-225-06)
- The Access-Control System That Needs Access Control: Johnson Controls C-CURE 9000 (ICSA-26-204-01)
- Lateral Movement in OT Networks: What It Is and How to Stop It
- Secure Remote Access for OT: Staff, Vendors, and the Flat-VPN Trap
- The Difference Between IT and OT Cybersecurity Explained
- ABB Ability Zenon's Bundled MongoDB Flaws: What ICSA-26-218-01 Teaches OT Teams
- US Water Utility Cyberattacks in 2026: What Happened and How to Secure OT
- The Affirming Official's False Claims Act Risk in CMMC
- AWIA Risk and Resilience Certification: The Cybersecurity Part
- Cybersecurity in the EPA Sanitary Survey: What to Expect
- MFA for PLCs: Meeting CMMC 3.5.3 with a Compensating Control
- SCADA Remote Access for Small Water Utilities
- The NERC CIP Compliance Checklist for Power Utilities (2026)
- The C3PAO Bottleneck: How to Prepare When There Aren't Enough Assessors
- CMMC Phase II Suspended: What Actually Changes for Defense Manufacturers
- Deploying Firewalls Without Breaking ICS Traffic
- New York DOH Part 5: The Water Cybersecurity Requirements, Explained
- How to Spot Malicious Lateral Movement in OT Environments
- Water Utility Cybersecurity: Securing SCADA from Treatment Plant to Tap
- How to Detect Anomalies in Modbus and DNP3 Traffic
- MFA for Remote Access: VPNs, RDP, and Cloud Portals
- The Difference Between Secure Modbus and Modbus TCP
- What's New in Access Gate v26.6
- Flat Network vs Segmented Network in Industrial Environments
- NERC CIP Compliance: Network Security Monitoring Requirements
- Oil & Gas Pipeline Security: Protecting Distributed SCADA Across Vast Geographies
- Power Grid Substation Security: Zero Trust for Distributed Energy OT
- Securing the IT/OT Boundary: Technical Architecture Patterns
- CMMC Level 2 for Manufacturers: Why VLANs Are Not Enough for Shop Floor OT
- CMMC vs NIS2: One Compliance Architecture for Both Frameworks
- How to Write an SSP Section for a Network with Legacy PLCs
- Secure Remote Access for Legacy Systems
- What the CMMC Enduring Exception Actually Requires You to Document
- Why Your OT Network Has No Identity Layer (And What Happens When an Attacker Notices)
- Zero Trust for Legacy PLCs: The Lollipop Architecture Explained
- Agent-Free Zero Trust: Why OT Environments Can't Use Endpoint Software
- What the New CISA Zero Trust OT Guide Means for On-Premise Deployments
- How to Segment a Flat OT Network Without VLANs or Downtime
- What a C3PAO Looks for in an OT Environment
- Zero Trust for Air-Gapped OT Networks: What Works and What Doesn't
- Cybersecurity for Police Evidence Systems: Sovereign, Auditable, On-Premise
- From Unboxing to Zero Trust in 4 Hours: What Deployment Actually Looks Like
- How Ski Resorts and Distributed Infrastructure Operators Deploy Zero Trust
- How to Evaluate OT Security Vendors: A Buyer's Checklist for 2026
- Multi-Site OT Security: How to Scale Zero Trust Across 50+ Locations
- Port & Maritime OT Security: Protecting Crane Control and Terminal Systems
- Proxy-Based Security for OT: Why Proxies Succeed Where Agents Fail
- Rail Signaling Cybersecurity: Protecting Safety-Certified Infrastructure
- Session Recording for OT Compliance: Meeting CMMC and NIS2 Audit Requirements
- The True Cost of OT Security: TCO Comparison of Appliance vs Cloud Solutions
- Securing Airport Baggage Handling Systems Without Requalification
- AI-Powered Attacks on Industrial Networks: What OT Teams Should Prepare For
- How to Configure YubiKey with Trout Access Gate
- Supply Chain Attacks on OT: The PYROXENE Campaign and Lessons for Operators
- Overlay Networking vs VLANs: A Practical Comparison for OT Segmentation
- Why On-Premise OT Security Beats Cloud-Routed Solutions
- Nozomi Networks vs Access Gate: When Visibility Alone Isn't Enough
- Top OT Cyber Threats in 2026: What to Watch
- What Is MFA and Why Every Organization Needs It in 2026
- Claroty vs Access Gate: Monitoring vs Enforcement for OT Networks
- Control Loop Mapping: How Attackers Are Learning to Manipulate Physical Processes
- Dragos 2026 Report: What the 3 New OT Threat Groups Mean for Your Factory
- NIS2 Management Liability: Why Executives Are Personally on the Hook
- Ransomware Targeting Manufacturing in 2026: A 49% Increase and What to Do About It
- NIS2 Enforcement Is Live: What Changed and What to Do First
- Centralized Audit Logging for Multi-Site Operations
- Compliance Audit Readiness for Critical Infrastructure
- Cybersecurity for Naval Shipboard Systems
- Defense Contractor Facility Security: Beyond the Perimeter
- Detecting Anomalies in Industrial Protocols
- Network Visibility: You Can't Protect What You Can't See
- NIS2 Operational Technology: What Manufacturers Need to Know
- OT Patch Management Challenges and Strategies
- Ransomware in Manufacturing: Lessons from Recent Attacks
- Remote Access: Biggest Attack Vector in OT
- Securing UAV Ground Stations: MAVLink Vulnerabilities
- Supply Chain Attacks Targeting Industrial Control Systems
- Bringing Two-Factor Authentication to the Factory Floor: Constraints and Practical Methods
- From Control Room to Field Device: Adapting Two-Factor Authentication to Industrial Reality
- OT and Legacy Systems impact on NIS2
- Air-Gapped But Not Safe: Misconceptions in Legacy Security
- Air-Gapped vs Layered Security Architectures
- Aligning Factory Networks with DoD Requirements
- Automating Compliance Monitoring in ICS
- Badge vs Password Why Physical Identity Matters for OT Cybersecurity
- Balancing Security and Uptime in Manufacturing
- Best Tools for Monitoring Industrial Protocol Security
- Beyond the Acronym How PLCs Became the Backbone of Modern Industrial Automation
- Breaking Down Data Silos How to Extract Maximum Value from Your PLC Networks
- Bridging IT and OT: A Step-by-Step Integration Guide
- Bridging Legacy Protocols and Cloud Architectures
- Building a SOC for OT: Tools and Tips
- Building Fault-Tolerant Network Paths in OT
- Building for Scalability in Industrial Networks
- Change Management for Industrial Network Security
- Change Management in ICS Environments
- CMMC Level 2 Requirements for OT Specialized Assets
- CMMC Secure Specialized Assets
- Common Attack Vectors in Legacy ICS
- Common Language: How IT and OT Teams Can Align
- Common MFA Mistakes and How to Avoid Them
- Common Pitfalls in Achieving ISO 27001 for Industrial Networks
- Common Root Causes of OT Downtime
- Compliant Remote Access Solutions for Manufacturers
- Continuous Verification in 24/7 Manufacturing Operations
- Creating Standard Operating Procedures for OT Security
- Daily Maintenance Tasks for OT Cybersecurity
- Data Diodes vs Firewalls for IT/OT Separation
- Dealing with Firmware Limitations in Legacy Equipment
- Deep Packet Inspection vs Flow-Based Monitoring What's Best for OT
- Design Patterns for Converged IT/OT Monitoring
- Designing for Predictable Network Behavior in OT
- Designing Redundant Communication Paths in OT
- Detecting and Responding to ICS Attacks in Real Time
- Device Authentication for Legacy Industrial Equipment
- Device Identity in Zero Trust Industrial Networks
- Documenting Security Controls for Industrial Assessments
- Endpoint Visibility in IT/OT Convergence
- EtherNet/IP Vulnerability Assessment and Mitigation
- Failover Strategies for Mission-Critical OT Networks
- Failure Modes in SCADA Networks
- FIDO2 and Passkeys The Future of MFA for Critical Infrastructure
- Firewall Placement Strategies for Industrial Networks
- From Door to Data How Badge Access Enhances Cybersecurity in Industrial Environments
- From Factory Floor to Cloud Building Robust Data Pipelines from PLC Systems
- From SaaS Security to Factory Floor Security The Two Faces of Zero Trust
- GDPR and OT: What Data Privacy Means for Industrial Control Systems
- High Availability NAC Deployment for Continuous Operations
- HMI Network Isolation Strategies
- How Compliance Can Drive Better OT Security
- How Network Changes Affect PLC Performance
- How Network Traffic Logs Help You Comply with CMMC and IEC 62443
- How to Add Visibility to Dark OT Networks
- How to Audit Industrial Protocol Traffic Effectively
- How to Benchmark ICS Network Performance
- How to Build a Resilient OT Backbone
- How to Build a Zero Trust Architecture for Manufacturing
- How to Build an Incident Response Plan for ICS
- How to Build an OT Cybersecurity Roadmap for Your Factory
- How to Conduct a Post-Incident Analysis in OT
- How to Connect Sites Without Increasing Risk
- How to Correlate Network Traffic and Device Behavior in OT
- How to Create Secure Zones in SCADA Networks
- How to Enforce East-West Traffic Isolation in OT
- How to Implement Least Privilege Access in Industrial Networks
- How to Implement MFA in Legacy OT Environments Without Breaking Operations
- How to Integrate Zero Trust with Existing ICS Infrastructure
- How to Leverage IT Tooling in OT Networks
- How to Manage Passwords on Hundreds of ICS Devices
- How to Monitor SCADA Network Traffic Without Disrupting Operations
- How to Roll Out MFA Without Frustrating Your Team
- How to Roll Out New OT Security Tech with Minimal Downtime
- How to Safely Route Business Data from ICS Systems
- How to Secure 20-Year-Old PLCs in Modern Networks
- How to Secure Legacy OT Systems Without Breaking Them
- How to Secure Shared Infrastructure Between IT and OT
- How to Train Operators on OT Security Best Practices
- How to Use NetFlow for Industrial Network Visibility
- ICS Honeypots: Revealing Real-World Attacks on Industrial Protocols
- ICS Protocol Deep Packet Inspection: Tools and Techniques
- Implementing Network Traffic Analysis Without Slowing Down Production
- Implementing Zero Trust in Air-Gapped OT Networks
- Indicators of Compromise in SCADA Environments
- Industrial Malware: Network-Based Detection Strategies
- Industry 4.0 Data Architecture Why Your PLC Strategy Determines Digital Transformation Success
- Insider Threat Detection in Manufacturing Environments
- Integrating Badge Access with Windows Login and Remote Sessions
- Integrating Serial Devices into IP Networks Securely
- Integrating Sysmon and OT Logging: A Unified View
- Inventory and Asset Management in ICS Operations
- Key Metrics to Track Zero Trust Adoption in OT
- Latency Requirements in Industrial Control Systems
- Lateral Movement Detection in Industrial Networks
- Layer 2 vs Layer 3 Why Your Network's Broadcast Domains Are Killing Performance
- Legacy Device Inventory: Where to Start
- Legacy OT Systems: Risks and Modern Mitigations
- Lessons Learned from the TRITON Malware Attack
- Maintenance Window Planning for Security Updates
- Managing Mixed IT/OT Device Inventories
- Mapping OT Controls to NIST SP 800-53
- MFA for Service Accounts and Industrial Devices Is It Possible
- Network Access Control (NAC) for SCADA and ICS
- Network Security Impact on Real-Time Control Loops
- Network Traffic Baselines Why They're Critical in Industrial Security
- NIS2 Asset Inventory Requirements What You Need to Track and How to Do IT on Premise
- NIS2 Compliance a Practical Guide to Meeting Article 21 Security Obligations
- NIS2 Compliance for Manufacturing Securing OT Legacy Machines and on Premise Systems
- NIS2 Directive Explained: Requirements, Scope, and Who Must Comply in 2026
- NIST Cybersecurity Framework for Manufacturing Systems
- OT-Specific IDS: What to Look For
- OT vs IT CMMC Controls
- Phased NAC Deployment in Live Manufacturing Environments
- PLC Explained What Every Manufacturing Professional Should Know About Programmable Logic Controllers
- PLC vs SCADA vs DCS Understanding Industrial Control System Hierarchies
- Plug and Play NIS2 Compliance Achieving Coverage Without Agents or Cloud Dependency
- Protocol-Aware Firewalls for Industrial Control Systems
- Protocol Gateways: The Good, the Bad, and the Ugly
- Protocol Whitelisting: How to Reduce Attack Surface in OT
- Real-World ICS Breaches and What We Can Learn
- Red Team vs Blue Team Exercises for Industrial Networks
- Redundant Link Design for OT Systems
- Redundant Network Design with Integrated Security Controls
- Remote Access Security for Industrial Maintenance
- Remote Site Deployment Best Practices
- Retrofitting Security Controls in Brownfield Installations
- Role of QoS in ICS Communications
- Routed vs Switched Networks
- Scheduling Maintenance Windows in 24/7 Plants
- Secure Commissioning of New ICS Equipment
- Secure Workarounds for Unsupported Protocols
- Securing 20-Year-Old PLCs: Non-Intrusive Approaches
- Securing Industrial Ethernet/IP: A Practical Guide
- Security Implications of Using PROFINET in Manufacturing
- Security Policies That Work Across IT and OT
- Security Risks of Uncontrolled IT/OT Interfaces
- Serial-to-Ethernet Gateway Security Considerations
- Simulating Cyberattacks on PLCs: Safe Testing Techniques
- Software-Defined Perimeter in Manufacturing
- Strategies for Enabling Logging in Old ICS Devices
- The Case for Out-of-Band Management in OT
- The Difference Between Technical and Administrative Controls in OT
- The Future of Hybrid IT/OT Teams
- The Reliability Impact of Cybersecurity Controls
- The Role of Emulators in ICS Legacy Integration
- The Role of MFA in CMMC NIS2 and IEC 62443 Compliance
- The Role of Multi-Factor Authentication in OT
- The Role of SIEMs in OT/IT Environments
- The Role of Syslog in Meeting CMMC Logging Requirements
- Tips for Upgrading Factory Network Infrastructure
- Top 10 Audit-Ready Controls for OT Networks
- Top 10 OT Cybersecurity Threats Facing Manufacturers in 2025
- Top 5 Benefits of Using Badge Access for ICS and SCADA Terminals
- Top 5 Metrics to Monitor in Industrial Network Traffic
- Top 5 MFA Methods Compared: SMS, TOTP, Biometrics, Hardware Keys & Push Notifications
- Top Frameworks for OT Cybersecurity IEC 62443 NIST and More
- Top Mistakes During IT/OT Network Mergers
- Training Operations Staff on Network Security Tools
- Training OT Operators on Network Hygiene
- Understanding NIS2 Requirements for ICS Networks
- Understanding SCADA Protocol Behavior for Better Defenses
- User Identity and Access in Air-Gapped Environments
- Using Demilitarized LANs to Isolate OT Assets
- Using SNMP Effectively in OT Environments
- Using Software-Defined Networking (SDN) in OT
- Vendor Access Controls During Field Maintenance
- Vendor Access Risks in OT and How to Control Them
- What Is Badge Access for Digital Systems A Beginner's Guide for IT and OT Teams
- What Is Network Traffic Analysis A Guide for OT Engineers
- What Is OT Cybersecurity A Beginner's Guide for Industrial Teams
- What OT Security Teams Can Learn from IT Breach Reports
- When Never Trust Always Verify Meets Legacy PLCs
- Where the Packets Roam
- Why Air Gaps Are No Longer Enough in OT Security
- Why Early Detection is Key in OT Security
- Why IT/OT Convergence Fails Without Governance
- Why Jitter Matters in Real Time OT Traffic
- Why Legacy Protocols Pose a Risk in Modern OT Networks
- Why Patching Isn't Always an Option in OT
- Why ZTNA in OT Isn't the Same as in IT
- Windows XP in Industrial Networks: Containment Strategies
- Wireless Design Considerations for Industrial Zones
- YubiKeys in Manufacturing Hands-On MFA for Shared Workstations
- Zero Downtime Deployment Techniques for Industrial Networks
- Zero Trust in OT How to Get Started
- Zero Trust in OT: Why the Perimeter is Dead
- Zero Trust OT Gateways: What They Are and How They Work
- Zero Trust Policy Framework for Critical Infrastructure
- Zero Trust Principles Applied to PLC Communications
- Zero Trust vs Traditional Firewalling: What's More Effective in OT?
- Zone and Conduit Architecture with Modern NAC Solutions
- Zone-Based Firewalling for ICS: Best Practices
- Why Zero Trust Matters for Manufacturing
- Securing Legacy Manufacturing Equipment for CMMC
- On-Premise vs Cloud Enclave for CUI Protection