TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

294 articles

OT SecurityICS Advisories

A 9.9 in the Grid's Power-Flow Controllers: Hitachi Energy FACTS (ICSA-26-260-03)

CISA's ICSA-26-260-03 lists five CVEs in the GWS component of Hitachi Energy's FACTS Control Platform, the controllers behind STATCOMs, SVCs and series capacitors. Two score 9.9. The remediation is a list of mitigations. What that means for a transmission operator.

UtilitiesOil and Gas

SCADA Security for Oil and Gas Pipelines: Distributed Sites, One Control per Site

Pipeline SCADA spans hundreds of miles. Wellheads, compressor stations, and refineries all connected, and all exposed. Here's how to secure them.

OT SecurityICS Advisories

One FTP Packet Stops the PLC: Schneider Modicon M340 (ICSA-26-260-04)

CISA's ICSA-26-260-04 covers CVE-2025-6625 in the Modicon M340 controller and its Ethernet modules: a crafted FTP command causes a denial of service, no login needed. Two of the modules have no fix yet. What a water plant should do this week.

Secure ModbusModbus TCP

The Difference Between Secure Modbus and Modbus TCP

Plain Modbus/TCP has no authentication and no encryption. Secure Modbus, defined by the Modbus/TCP Security specification, adds TLS and X.509 role-based authorization. Here is the precise difference, where each fits, and how to migrate.

UtilitiesWater

SCADA Security for Water Systems: What a Small Utility Can Do This Year

Water SCADA runs chemical dosing, pressure and flow, mostly on equipment nobody can patch, reached by on-call operators and integrators over a VPN. What a small utility can do this year, in the order that works, and what pays for it.

OT SecurityArchitecture

Why On-Premise OT Security Beats Cloud-Routed Solutions

Cloud-routed security adds latency, breaks air gaps, and surrenders data sovereignty. For OT, on-premise enforcement isn't just better, it's the only option that works.

Zero TrustOT Security

Agent-Free Zero Trust: Why OT Environments Can't Use Endpoint Software

IT Zero Trust relies on endpoint agents. OT devices cannot run them. Here is why, and how network-layer enforcement provides equivalent protection without touching the device.

Water and WastewaterOT Security

A Water Utility Caught CISA's Red Team in Two Minutes. The OT Jump Server Still Fell.

CISA's August 25, 2026 advisory AA26-237A describes two red team assessments run at the same time, one of them at a water and wastewater utility. That utility's SOC isolated three compromised workstations in 10, 2, and 20 minutes. The red team still got onto the jump server in the OT DMZ, using a password borrowed from the FTP service. The controls that worked were all detection. The ones that failed were all about access.

Zero TrustCISA

What the New CISA Zero Trust OT Guide Means for On-Premise Deployments

CISA, the Department of War, DOE, FBI, and Department of State published joint Zero Trust OT guidance on April 29, 2026. Three findings matter most for on-premise deployments: agentless network-layer enforcement is endorsed for legacy OT, microsegmentation must operate without redesign, and air-gap alone is called out as a false sense of security.

CMMCNIS2

CMMC vs NIS2: One Compliance Architecture for Both Frameworks

Defense contractors operating in both the US and EU face CMMC and NIS2 simultaneously. The good news: a single on-premise architecture can satisfy both.

CMMCArchitecture

CUI Enclave Architecture: On-Premise Alternatives to GCC High

GCC High protects CUI while people collaborate on it. An on-premise enclave protects it once it reaches a printer, a CNC machine or a local file server. Most defense manufacturers need both.

Threat IntelligenceOT Security

Dragos 2026 Report: What the 3 New OT Threat Groups Mean for Your Factory

Dragos now tracks 26 OT threat groups. Three new ones emerged in 2025: SYLVANITE, PYROXENE, and AZURITE. Here's what manufacturers need to know.

Browse all posts (294)