Insights & Resources
Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.
294 articles
A 9.9 in the Grid's Power-Flow Controllers: Hitachi Energy FACTS (ICSA-26-260-03)
CISA's ICSA-26-260-03 lists five CVEs in the GWS component of Hitachi Energy's FACTS Control Platform, the controllers behind STATCOMs, SVCs and series capacitors. Two score 9.9. The remediation is a list of mitigations. What that means for a transmission operator.
SCADA Security for Oil and Gas Pipelines: Distributed Sites, One Control per Site
Pipeline SCADA spans hundreds of miles. Wellheads, compressor stations, and refineries all connected, and all exposed. Here's how to secure them.
One FTP Packet Stops the PLC: Schneider Modicon M340 (ICSA-26-260-04)
CISA's ICSA-26-260-04 covers CVE-2025-6625 in the Modicon M340 controller and its Ethernet modules: a crafted FTP command causes a denial of service, no login needed. Two of the modules have no fix yet. What a water plant should do this week.
The Difference Between Secure Modbus and Modbus TCP
Plain Modbus/TCP has no authentication and no encryption. Secure Modbus, defined by the Modbus/TCP Security specification, adds TLS and X.509 role-based authorization. Here is the precise difference, where each fits, and how to migrate.
SCADA Security for Water Systems: What a Small Utility Can Do This Year
Water SCADA runs chemical dosing, pressure and flow, mostly on equipment nobody can patch, reached by on-call operators and integrators over a VPN. What a small utility can do this year, in the order that works, and what pays for it.
Why On-Premise OT Security Beats Cloud-Routed Solutions
Cloud-routed security adds latency, breaks air gaps, and surrenders data sovereignty. For OT, on-premise enforcement isn't just better, it's the only option that works.
Agent-Free Zero Trust: Why OT Environments Can't Use Endpoint Software
IT Zero Trust relies on endpoint agents. OT devices cannot run them. Here is why, and how network-layer enforcement provides equivalent protection without touching the device.
A Water Utility Caught CISA's Red Team in Two Minutes. The OT Jump Server Still Fell.
CISA's August 25, 2026 advisory AA26-237A describes two red team assessments run at the same time, one of them at a water and wastewater utility. That utility's SOC isolated three compromised workstations in 10, 2, and 20 minutes. The red team still got onto the jump server in the OT DMZ, using a password borrowed from the FTP service. The controls that worked were all detection. The ones that failed were all about access.
What the New CISA Zero Trust OT Guide Means for On-Premise Deployments
CISA, the Department of War, DOE, FBI, and Department of State published joint Zero Trust OT guidance on April 29, 2026. Three findings matter most for on-premise deployments: agentless network-layer enforcement is endorsed for legacy OT, microsegmentation must operate without redesign, and air-gap alone is called out as a false sense of security.
CMMC vs NIS2: One Compliance Architecture for Both Frameworks
Defense contractors operating in both the US and EU face CMMC and NIS2 simultaneously. The good news: a single on-premise architecture can satisfy both.
CUI Enclave Architecture: On-Premise Alternatives to GCC High
GCC High protects CUI while people collaborate on it. An on-premise enclave protects it once it reaches a printer, a CNC machine or a local file server. Most defense manufacturers need both.
Dragos 2026 Report: What the 3 New OT Threat Groups Mean for Your Factory
Dragos now tracks 26 OT threat groups. Three new ones emerged in 2025: SYLVANITE, PYROXENE, and AZURITE. Here's what manufacturers need to know.
›Browse all posts (294)
- A 9.9 in the Grid's Power-Flow Controllers: Hitachi Energy FACTS (ICSA-26-260-03)
- SCADA Security for Oil and Gas Pipelines: Distributed Sites, One Control per Site
- One FTP Packet Stops the PLC: Schneider Modicon M340 (ICSA-26-260-04)
- The Difference Between Secure Modbus and Modbus TCP
- SCADA Security for Water Systems: What a Small Utility Can Do This Year
- Why On-Premise OT Security Beats Cloud-Routed Solutions
- Agent-Free Zero Trust: Why OT Environments Can't Use Endpoint Software
- A Water Utility Caught CISA's Red Team in Two Minutes. The OT Jump Server Still Fell.
- What the New CISA Zero Trust OT Guide Means for On-Premise Deployments
- CMMC vs NIS2: One Compliance Architecture for Both Frameworks
- CUI Enclave Architecture: On-Premise Alternatives to GCC High
- Dragos 2026 Report: What the 3 New OT Threat Groups Mean for Your Factory
- How to Evaluate OT Security Vendors: A Buyer's Checklist for 2026
- How to Segment a Flat OT Network Without VLANs or Downtime
- MFA for Remote Access: VPNs, RDP, and Cloud Portals
- Multi-Site OT Security: How to Scale Zero Trust Across 50+ Locations
- Nozomi Networks vs Access Gate: When Visibility Alone Isn't Enough
- Overlay Networking vs VLANs: A Practical Comparison for OT Segmentation
- Power Grid Substation Security: Zero Trust for Distributed Energy OT
- Proxy-Based Security for OT: Why Proxies Succeed Where Agents Fail
- Ransomware Targeting Manufacturing in 2026: A 49% Increase and What to Do About It
- The True Cost of OT Security: TCO Comparison of Appliance vs Cloud Solutions
- Zero Trust for Legacy PLCs: The Lollipop Architecture Explained
- Zero Trust Readiness Checklist for Industrial Environments
- A Key You Cannot Rotate: AVEVA Pipeline Integrity Monitor (ICSA-26-253-01)
- The Last Hop: Carrying CUI From a Cloud Enclave to the Machine That Uses It
- CMMC 2.0: What Manufacturers Need to Know
- CMMC Readiness for Manufacturers After the Suspension
- Introducing Open-CMMC: An Open-Source CUI Enclave for CMMC Level 2
- Preparing for the CMMC 2.0 Compliance Deadline
- IXON VPN Client RCE: When the Remote Access Client Is the Attack Surface
- Choosing Between Star and Ring Topologies in ICS
- How to Use MITRE ATT&CK for ICS Threat Detection
- ICS vs SCADA Security What You Need to Know
- Industrial Network Topology Discovery and Mapping
- Using NetFlow and Logs for ICS Threat Hunting
- EPA Cybersecurity Requirements for Water and Wastewater Systems
- The ASE2000 Test Set: When IEC 60870-5-104 TLS Does Not Check the Certificate
- Serial-to-IP Device Servers: Four CISA Advisories in Three Days
- Real-Time PLC Data Streaming OPC-UA Modbus and Modern Integration Patterns
- How to Perform a Risk Assessment on Your OT Environment
- Patch Management in Operational Environments
- Understanding the Costs of MFA in OT and On-Premise Environments
- Credentials Sitting in Memory: Johnson Controls Simplex Incident Manager (ICSA-26-232-01)
- Secomea Alternatives: When Remote Access Is Not the Whole Problem
- Siemens SINEMA and Scalance: What Sits Between Remote Access and Segmentation
- Talk2M Alternatives: Industrial Remote Access Without a Vendor Cloud
- The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)
- A CVSS 10 on the Box That Faces the Internet: Haiwell IoT Cloud HMI Gateway (ICSA-26-225-02)
- The Firewall in the OT Rack Is Also Just Software: Siemens RUGGEDCOM APE1808 (ICSA-26-225-06)
- The Access-Control System That Needs Access Control: Johnson Controls C-CURE 9000 (ICSA-26-204-01)
- Lateral Movement in OT Networks: What It Is and How to Stop It
- The Difference Between IT and OT Cybersecurity Explained
- ABB Ability Zenon's Bundled MongoDB Flaws: What ICSA-26-218-01 Teaches OT Teams
- US Water Utility Cyberattacks in 2026: What Happened and How to Secure OT
- The Affirming Official's False Claims Act Risk in CMMC
- AWIA Risk and Resilience Certification: The Cybersecurity Part
- Cybersecurity in the EPA Sanitary Survey: What to Expect
- MFA for PLCs: Meeting CMMC 3.5.3 with a Compensating Control
- The NERC CIP Compliance Checklist for Power Utilities (2026)
- The C3PAO Bottleneck: How to Prepare When There Aren't Enough Assessors
- CMMC Phase II Suspended: What Actually Changes for Defense Manufacturers
- Deploying Firewalls Without Breaking ICS Traffic
- New York DOH Part 5: The Water Cybersecurity Requirements, Explained
- How to Spot Malicious Lateral Movement in OT Environments
- How to Detect Anomalies in Modbus and DNP3 Traffic
- What's New in Access Gate v26.6
- Flat Network vs Segmented Network in Industrial Environments
- NERC CIP Compliance: Network Security Monitoring Requirements
- Securing the IT/OT Boundary: Technical Architecture Patterns
- CMMC Level 2 for Manufacturers: Why VLANs Are Not Enough for Shop Floor OT
- How to Write an SSP Section for a Network with Legacy PLCs
- What the CMMC Enduring Exception Actually Requires You to Document
- Why Your OT Network Has No Identity Layer (And What Happens When an Attacker Notices)
- What a C3PAO Looks for in an OT Environment
- Zero Trust for Air-Gapped OT Networks: What Works and What Doesn't
- Cybersecurity for Police Evidence Systems: Sovereign, Auditable, On-Premise
- From Unboxing to Zero Trust in 4 Hours: What Deployment Actually Looks Like
- How Ski Resorts and Distributed Infrastructure Operators Deploy Zero Trust
- Port & Maritime OT Security: Protecting Crane Control and Terminal Systems
- Rail Signaling Cybersecurity: Protecting Safety-Certified Infrastructure
- Session Recording for OT Compliance: Meeting CMMC and NIS2 Audit Requirements
- Securing Airport Baggage Handling Systems Without Requalification
- AI-Powered Attacks on Industrial Networks: What OT Teams Should Prepare For
- How to Configure YubiKey with Trout Access Gate
- Supply Chain Attacks on OT: The PYROXENE Campaign and Lessons for Operators
- Top OT Cyber Threats in 2026: What to Watch
- What Is MFA and Why Every Organization Needs It in 2026
- Control Loop Mapping: How Attackers Are Learning to Manipulate Physical Processes
- NIS2 Management Liability: Why Executives Are Personally on the Hook
- NIS2 Enforcement Is Live: What Changed and What to Do First
- Centralized Audit Logging for Multi-Site Operations
- Compliance Audit Readiness for Critical Infrastructure
- Cybersecurity for Naval Shipboard Systems
- Defense Contractor Facility Security: Beyond the Perimeter
- Detecting Anomalies in Industrial Protocols
- Network Visibility: You Can't Protect What You Can't See
- NIS2 Operational Technology: What Manufacturers Need to Know
- OT Patch Management Challenges and Strategies
- Ransomware in Manufacturing: Lessons from Recent Attacks
- Securing UAV Ground Stations: MAVLink Vulnerabilities
- Supply Chain Attacks Targeting Industrial Control Systems
- Bringing Two-Factor Authentication to the Factory Floor: Constraints and Practical Methods
- From Control Room to Field Device: Adapting Two-Factor Authentication to Industrial Reality
- OT and Legacy Systems impact on NIS2
- Air-Gapped But Not Safe: Misconceptions in Legacy Security
- Air-Gapped vs Layered Security Architectures
- Aligning Factory Networks with DoD Requirements
- Automating Compliance Monitoring in ICS
- Badge vs Password Why Physical Identity Matters for OT Cybersecurity
- Balancing Security and Uptime in Manufacturing
- Best Tools for Monitoring Industrial Protocol Security
- Beyond the Acronym How PLCs Became the Backbone of Modern Industrial Automation
- Breaking Down Data Silos How to Extract Maximum Value from Your PLC Networks
- Bridging IT and OT: A Step-by-Step Integration Guide
- Bridging Legacy Protocols and Cloud Architectures
- Building a SOC for OT: Tools and Tips
- Building Fault-Tolerant Network Paths in OT
- Building for Scalability in Industrial Networks
- Change Management for Industrial Network Security
- Change Management in ICS Environments
- CMMC Level 2 Requirements for OT Specialized Assets
- CMMC Secure Specialized Assets
- Common Attack Vectors in Legacy ICS
- Common Language: How IT and OT Teams Can Align
- Common MFA Mistakes and How to Avoid Them
- Common Pitfalls in Achieving ISO 27001 for Industrial Networks
- Common Root Causes of OT Downtime
- Continuous Verification in 24/7 Manufacturing Operations
- Creating Standard Operating Procedures for OT Security
- Daily Maintenance Tasks for OT Cybersecurity
- Data Diodes vs Firewalls for IT/OT Separation
- Dealing with Firmware Limitations in Legacy Equipment
- Deep Packet Inspection vs Flow-Based Monitoring What's Best for OT
- Design Patterns for Converged IT/OT Monitoring
- Designing for Predictable Network Behavior in OT
- Designing Redundant Communication Paths in OT
- Detecting and Responding to ICS Attacks in Real Time
- Device Authentication for Legacy Industrial Equipment
- Device Identity in Zero Trust Industrial Networks
- Documenting Security Controls for Industrial Assessments
- Endpoint Visibility in IT/OT Convergence
- EtherNet/IP Vulnerability Assessment and Mitigation
- Failover Strategies for Mission-Critical OT Networks
- Failure Modes in SCADA Networks
- FIDO2 and Passkeys The Future of MFA for Critical Infrastructure
- Firewall Placement Strategies for Industrial Networks
- From Door to Data How Badge Access Enhances Cybersecurity in Industrial Environments
- From Factory Floor to Cloud Building Robust Data Pipelines from PLC Systems
- From SaaS Security to Factory Floor Security The Two Faces of Zero Trust
- GDPR and OT: What Data Privacy Means for Industrial Control Systems
- High Availability NAC Deployment for Continuous Operations
- HMI Network Isolation Strategies
- How Compliance Can Drive Better OT Security
- How Network Changes Affect PLC Performance
- How Network Traffic Logs Help You Comply with CMMC and IEC 62443
- How to Add Visibility to Dark OT Networks
- How to Audit Industrial Protocol Traffic Effectively
- How to Benchmark ICS Network Performance
- How to Build a Resilient OT Backbone
- How to Build a Zero Trust Architecture for Manufacturing
- How to Build an Incident Response Plan for ICS
- How to Build an OT Cybersecurity Roadmap for Your Factory
- How to Conduct a Post-Incident Analysis in OT
- How to Connect Sites Without Increasing Risk
- How to Correlate Network Traffic and Device Behavior in OT
- How to Enforce East-West Traffic Isolation in OT
- How to Implement Least Privilege Access in Industrial Networks
- How to Implement MFA in Legacy OT Environments Without Breaking Operations
- How to Integrate Zero Trust with Existing ICS Infrastructure
- How to Leverage IT Tooling in OT Networks
- How to Manage Passwords on Hundreds of ICS Devices
- How to Monitor SCADA Network Traffic Without Disrupting Operations
- How to Roll Out MFA Without Frustrating Your Team
- How to Roll Out New OT Security Tech with Minimal Downtime
- How to Safely Route Business Data from ICS Systems
- How to Secure 20-Year-Old PLCs in Modern Networks
- How to Secure Legacy OT Systems Without Breaking Them
- How to Secure Shared Infrastructure Between IT and OT
- How to Train Operators on OT Security Best Practices
- How to Use NetFlow for Industrial Network Visibility
- ICS Honeypots: Revealing Real-World Attacks on Industrial Protocols
- ICS Protocol Deep Packet Inspection: Tools and Techniques
- Implementing Network Traffic Analysis Without Slowing Down Production
- Implementing Zero Trust in Air-Gapped OT Networks
- Industrial Malware: Network-Based Detection Strategies
- Industry 4.0 Data Architecture Why Your PLC Strategy Determines Digital Transformation Success
- Insider Threat Detection in Manufacturing Environments
- Integrating Badge Access with Windows Login and Remote Sessions
- Integrating Serial Devices into IP Networks Securely
- Integrating Sysmon and OT Logging: A Unified View
- Inventory and Asset Management in ICS Operations
- Key Metrics to Track Zero Trust Adoption in OT
- Latency Requirements in Industrial Control Systems
- Lateral Movement Detection in Industrial Networks
- Layer 2 vs Layer 3 Why Your Network's Broadcast Domains Are Killing Performance
- Legacy Device Inventory: Where to Start
- Legacy OT Systems: Risks and Modern Mitigations
- Lessons Learned from the TRITON Malware Attack
- Maintenance Window Planning for Security Updates
- Managing Mixed IT/OT Device Inventories
- Mapping OT Controls to NIST SP 800-53
- MFA for Service Accounts and Industrial Devices Is It Possible
- Network Security Impact on Real-Time Control Loops
- Network Traffic Baselines Why They're Critical in Industrial Security
- NIS2 Asset Inventory Requirements What You Need to Track and How to Do IT on Premise
- NIS2 Compliance a Practical Guide to Meeting Article 21 Security Obligations
- NIS2 Compliance for Manufacturing Securing OT Legacy Machines and on Premise Systems
- NIS2 Directive Explained: Requirements, Scope, and Who Must Comply in 2026
- NIST Cybersecurity Framework for Manufacturing Systems
- OT-Specific IDS: What to Look For
- OT vs IT CMMC Controls
- Phased NAC Deployment in Live Manufacturing Environments
- PLC Explained What Every Manufacturing Professional Should Know About Programmable Logic Controllers
- PLC vs SCADA vs DCS Understanding Industrial Control System Hierarchies
- Plug and Play NIS2 Compliance Achieving Coverage Without Agents or Cloud Dependency
- Protocol-Aware Firewalls for Industrial Control Systems
- Protocol Gateways: The Good, the Bad, and the Ugly
- Protocol Whitelisting: How to Reduce Attack Surface in OT
- Real-World ICS Breaches and What We Can Learn
- Red Team vs Blue Team Exercises for Industrial Networks
- Redundant Link Design for OT Systems
- Redundant Network Design with Integrated Security Controls
- Remote Site Deployment Best Practices
- Retrofitting Security Controls in Brownfield Installations
- Role of QoS in ICS Communications
- Routed vs Switched Networks
- Scheduling Maintenance Windows in 24/7 Plants
- Secure Commissioning of New ICS Equipment
- Secure Workarounds for Unsupported Protocols
- Securing 20-Year-Old PLCs: Non-Intrusive Approaches
- Securing Industrial Ethernet/IP: A Practical Guide
- Security Implications of Using PROFINET in Manufacturing
- Security Policies That Work Across IT and OT
- Security Risks of Uncontrolled IT/OT Interfaces
- Serial-to-Ethernet Gateway Security Considerations
- Simulating Cyberattacks on PLCs: Safe Testing Techniques
- Software-Defined Perimeter in Manufacturing
- Strategies for Enabling Logging in Old ICS Devices
- The Case for Out-of-Band Management in OT
- The Difference Between Technical and Administrative Controls in OT
- The Future of Hybrid IT/OT Teams
- The Reliability Impact of Cybersecurity Controls
- The Role of Emulators in ICS Legacy Integration
- The Role of MFA in CMMC NIS2 and IEC 62443 Compliance
- The Role of Multi-Factor Authentication in OT
- The Role of SIEMs in OT/IT Environments
- The Role of Syslog in Meeting CMMC Logging Requirements
- Tips for Upgrading Factory Network Infrastructure
- Top 10 Audit-Ready Controls for OT Networks
- Top 10 OT Cybersecurity Threats Facing Manufacturers in 2025
- Top 5 Benefits of Using Badge Access for ICS and SCADA Terminals
- Top 5 Metrics to Monitor in Industrial Network Traffic
- Top 5 MFA Methods Compared: SMS, TOTP, Biometrics, Hardware Keys & Push Notifications
- Top Frameworks for OT Cybersecurity IEC 62443 NIST and More
- Top Mistakes During IT/OT Network Mergers
- Training Operations Staff on Network Security Tools
- Training OT Operators on Network Hygiene
- Understanding NIS2 Requirements for ICS Networks
- Understanding SCADA Protocol Behavior for Better Defenses
- User Identity and Access in Air-Gapped Environments
- Using Demilitarized LANs to Isolate OT Assets
- Using SNMP Effectively in OT Environments
- Using Software-Defined Networking (SDN) in OT
- Vendor Access Controls During Field Maintenance
- Vendor Access Risks in OT and How to Control Them
- What Is Badge Access for Digital Systems A Beginner's Guide for IT and OT Teams
- What Is Network Traffic Analysis A Guide for OT Engineers
- What Is OT Cybersecurity A Beginner's Guide for Industrial Teams
- What OT Security Teams Can Learn from IT Breach Reports
- When Never Trust Always Verify Meets Legacy PLCs
- Where the Packets Roam
- Why Air Gaps Are No Longer Enough in OT Security
- Why Early Detection is Key in OT Security
- Why IT/OT Convergence Fails Without Governance
- Why Jitter Matters in Real Time OT Traffic
- Why Legacy Protocols Pose a Risk in Modern OT Networks
- Why Patching Isn't Always an Option in OT
- Why ZTNA in OT Isn't the Same as in IT
- Windows XP in Industrial Networks: Containment Strategies
- Wireless Design Considerations for Industrial Zones
- YubiKeys in Manufacturing Hands-On MFA for Shared Workstations
- Zero Downtime Deployment Techniques for Industrial Networks
- Zero Trust in OT How to Get Started
- Zero Trust in OT: Why the Perimeter is Dead
- Zero Trust OT Gateways: What They Are and How They Work
- Zero Trust Policy Framework for Critical Infrastructure
- Zero Trust Principles Applied to PLC Communications
- Zero Trust vs Traditional Firewalling: What's More Effective in OT?
- Zone and Conduit Architecture with Modern NAC Solutions
- Zone-Based Firewalling for ICS: Best Practices
- Why Zero Trust Matters for Manufacturing
- Securing Legacy Manufacturing Equipment for CMMC
- On-Premise vs Cloud Enclave for CUI Protection