On the morning of Monday, July 27, the operating controls at the well and water treatment plant in Braham, Minnesota, went dark. Braham is a city of about 1,700 people. Public works crews had the plant running again in roughly two hours on manual operation. Braham was one of more than 30 community water systems [ ] The post OT Manual Operations Plan: What Manual Operation Buys You appeared first…
A security assessment fills a report with findings the way a Pokedex fills with entries. Neither one wins a fight. Here’s why so many OT programs stall the day after the assessment, and how to build one that actually sticks. Anyone who played Pokemon knows the trap, even if they never called it that. Catching [ ] The post The Security Assessment Was the Easy Part (Like Catching a Magikarp)…
A CVSS score can tell you how severe a vulnerability looks on paper. It cannot tell you whether that vulnerability is reachable in your environment, whether the asset can be patched, or whether the affected system touches a process that matters. An AI tool can surface more findings. It cannot decide which ones your team [ ] The post Context is the Missing Layer in OT Security appeared first on…
The dangerous intruder in OT today isn’t bombing the wall. They walked through the front door with a key that shouldn’t be in their hand. OT credential abuse happens when an attacker uses a legitimate account, vendor connection, remote-access pathway, or service credential to enter an industrial environment without exploiting a software vulnerability. The login [ ] The post OT Credential Abuse:…
The term Artificial Intelligence (AI) often covers everything from a mathematical decision tree written in 2011 to a large language model deployed last quarter. Discussions about AI in OT cybersecurity rarely distinguish between the two, because it forces a harder conversation that gets into the nuts and bolts of the solutions. But that harder conversation [ ] The post The Transparency Curve:…
Agentic AI in OT is moving into operational workflows faster than anyone is governing it. Every helpful one is a credential you didn’t badge and an actor you likely aren’t watching. Here’s how to keep your own robots from becoming someone else s. The premise of the original Mega Man is quietly brilliant. Dr. Light built [ ] The post Agentic AI in OT: An Army of Helpers You Never Hired appeared…
If you have sat in a vendor briefing in the last eighteen months, you have heard the pitch: AI-powered threat detection. AI-driven SOC. AI for OT security. This implies that artificial intelligence is an entirely new asset that can be added to the defender s toolkit. It isn t. Machine learning has been quietly doing the heavy [ ] The post LLMs in OT Security: Translation Layer, Not Detection Layer…
Let’s talk about mapping INSM to what you can actually see across NERC, FERC, NIST, and NIS2. Mapping INSM means documenting where you have visibility, where you do not, and how your monitoring aligns to trust zones, east-west flows, and regulatory expectations. If you run an OT security program in 2026, you have four regulators [ ] The post Lighting the Map: Mapping INSM in OT appeared first on…
Part 2 of 2: Why the quality of your OT segmentation in real industrial environments matters more than the label on the framework you used to get there. In Part 1, we walked through the Purdue Model and IEC 62443 as two frameworks that do different jobs. Purdue is the architectural reference. IEC 62443 is [ ] The post OT Segmentation: Why the Framework Matters Less Than the Discipline appeared…
Part 1 of a 2-part series detailing what IEC 62443 and the Purdue Model actually do, and why conflating them may cost you clarity. In OT security, two frameworks come up in almost every serious conversation about network segmentation: the Purdue Model and IEC 62443. They get compared. They get conflated. They get pitched as [ ] The post The Purdue Model and IEC 62443: Two Frameworks, Different…