TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

316 articles

Network topologyAsset discovery

Industrial Network Topology Discovery and Mapping

You cannot secure a network you have not mapped, and in OT the mapping itself can break production. Here is how to discover assets and build a real topology using passive capture, switch configuration ingest, and protocol-native queries, what each method can and cannot see, and how to turn the result into a segmentation design.

OT SecurityICS Advisories

Credentials Sitting in Memory: Johnson Controls Simplex Incident Manager (ICSA-26-232-01)

CISA published ICSA-26-232-01 on August 20, 2026: Johnson Controls Simplex Incident Manager keeps passwords and authentication tokens in cleartext in system memory. It scores 5.8 and is not remotely exploitable, which is exactly why it is worth reading carefully. Credential harvesting is never step one of an intrusion, it is step two.

Zero TrustOT Security

Zero Trust Readiness Checklist for Industrial Environments

A 12-domain, evidence-based readiness checklist for Zero Trust in OT and ICS: network access control, authentication and access management, device and data protection, and the deployment phases that get you from assessment to full rollout without stopping production.

OT SecurityRemote Access

Secomea Alternatives: When Remote Access Is Not the Whole Problem

Secomea does industrial remote access well, and its self-hosted GateManager holds up on sovereignty. The gap is everything a plant needs that a remote-access product is not built to do.

OT SecurityRemote Access

Siemens SINEMA and Scalance: What Sits Between Remote Access and Segmentation

SINEMA Remote Connect is self-hosted, which answers the sovereignty question most of this category fails. Segmentation is a separate purchase in Scalance hardware, and that is where the cost and the cabling arrive.

OT SecurityRemote Access

Talk2M Alternatives: Industrial Remote Access Without a Vendor Cloud

Ewon Cosy plus Talk2M is the default for machine builders, and deservedly so. Here is what changes when the plant is yours, and what NIS2 supply-chain review asks about a vendor-operated rendezvous.

OT SecurityICS Advisories

The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)

CISA's ICSA-26-225-01 flags a CVSS 7.1 deserialization-to-code-execution flaw in AVEVA Enterprise SCADA and its HMI. The attacker still needs to reach the service to send the payload. That reach is the part you control.

OT SecurityICS Advisories

A CVSS 10 on the Box That Faces the Internet: Haiwell IoT Cloud HMI Gateway (ICSA-26-225-02)

CISA's ICSA-26-225-02 flags a CVSS 10 OS command injection in the Haiwell IoT Cloud HMI Gateway that runs commands as root. The gateway's whole job is to be reachable. That is exactly the problem, and the fix is to control the reach.

OT SecurityICS Advisories

The Firewall in the OT Rack Is Also Just Software: Siemens RUGGEDCOM APE1808 (ICSA-26-225-06)

CISA's ICSA-26-225-06 carries FortiOS flaws onto the Siemens RUGGEDCOM APE1808, the ruggedized box that runs a firewall inside the plant. The security appliance has its own CVEs. That is the argument for defense in depth, not against firewalls.

OT SecurityICS Advisories

The Access-Control System That Needs Access Control: Johnson Controls C-CURE 9000 (ICSA-26-204-01)

CISA's ICSA-26-204-01 flags a CVSS 9.6 remote-code-execution path in Johnson Controls C-CURE 9000 and victor, the servers that run building access control and video. An attacker with network access is the whole precondition. That is the part you control.

OT SecuritySegmentation

Lateral Movement in OT Networks: What It Is and How to Stop It

Lateral movement is how an attacker turns one foothold into control of the whole plant. Flat OT networks make it trivial. The durable fix is not more detection, it is removing the paths, per asset, so a compromise stays where it started.

OT SecurityRemote Access

Secure Remote Access for OT: Staff, Vendors, and the Flat-VPN Trap

OT secure remote access is not a VPN with a nicer login. It is identity for staff and third-party vendors, per-asset brokering, and a recorded session, kept on-premise. Here is how to do it without dropping anyone onto a flat network.

Browse all posts (316)