Blog
Notes on OT detection.
Signature-less detection, healthy OT networks, and the craft of catching what others miss.
The Forgotten OT: Building Automation and the Attack Surface No One Owns
Two CISA advisories in the 13 August batch exposed building automation's quiet reality: BACnet controllers are OT, they sit at the corporate network's edge, and almost no security team is watching them. Here's the blind spot — and what passive detection changes.
Read → 14 Aug 2026The OT Patch Gap: Why Vulnerabilities Linger Long After a Fix Ships
A single day's CISA advisory batch exposed why OT patching always lags the threat — including a hydropower control platform whose fix shipped 20 months before operators were told. Here's what detection adds inside that gap.
Read → 7 Aug 2026When the PLC Configuration Is the Attack: What the Water Sector Campaign Reveals About OT Detection
The coordinated PLC attacks on US water utilities show that the most dangerous OT intrusions don't use malware — they use the device's own engineering interface. Here's what behavioral detection at Purdue Level 1 would see.
Read → 3 Aug 2026Default Passwords Destroyed 30 Energy Sites in One Night: What the Poland Attack Teaches Us About OT Detection
The December 2025 attack on Poland's energy sector didn't use zero-days or exotic ICS malware. It used default credentials, shared VPN passwords, and missing MFA — and it bricked RTUs across 30 sites. Here's what that says about the limits of threat-based detection.
Read → 30 Jul 2026Between Detection and Action: Why Living-Off-The-Land Attacks Break the OT Response Playbook
OT security teams are detecting threats faster than ever — some reporting under 24 hours. But faster detection does not mean faster containment when the attack uses tools the operator trusts. Living-off-the-land attacks exploit the gap between 'we see it' and 'we can safely stop it,' and closing that gap requires a different kind of visibility.
Read → 28 Jul 2026When Your Vendor's Vendor Has the Keys: OT Supply Chain Risk and the Visibility Gap Nobody Talks About
Marathon Petroleum's CISO just told Help Net Security that supply chain risk in OT extends past third-party vendors to nth-party vendors — the ones you cannot see, cannot audit, and whose devices are already inside your network. Here is why passive behavioral monitoring is the only way to close that gap.
Read → 27 Jul 2026When the Project File You Opened This Morning Was the Attack
The CISA advisory for Rockwell Studio 5000 exposes three vulnerabilities in the engineering tool every automation professional uses daily. But the real story is not about the CVEs — it is about an attack surface that lives between IT and OT, where signatures cannot see and most monitoring tools do not look.
Read → 21 Jul 2026The Vendor VPN You Forgot About: Why Third-Party Access Is OT's Least-Governed Attack Surface
Every OT facility gives remote access to equipment vendors, system integrators, and support contractors. Most of those connections are persistent, unmonitored, and over-privileged — and authentication alone can't tell you whether the session is legitimate or the opening move of an attack.
Read → 20 Jul 2026The IEC 62443 Compliance Trap: Why Checking Boxes Won't Catch the Attack Your Auditor Never Saw Coming
IEC 62443 is the most comprehensive OT security framework we have — but passing an audit and actually detecting attacks are two different things. Here's what the standard really demands.
Read → 20 Jul 2026The Enemy Inside the Fence: Why OT's Biggest Blind Spot Wears a Hard Hat
The Maroochy Shire incident wasn't malware — it was a disgruntled contractor with a radio. Two decades later, OT insider threats remain the detection challenge that credentials and signatures can't solve.
Read → 14 Jul 2026The Detection Gap Nobody Talks About: Why Purdue Level 1 Is Where Attacks Succeed
Most OT security tools live at Purdue Levels 2 and 3 — the HMI, the engineering workstation, the historian. But the actual process lives at Level 1, where controllers talk to field devices. And Level 1 is where signatures fail, baselines matter, and most organisations are flying blind.
Read → 13 Jul 2026The Software That Runs the Grid — and the Vulnerabilities No One Is Watching
Two Hitachi Energy advisories in a single CISA batch expose a structural blind spot: the energy management applications that bridge IT planning and OT operations are the least-defended attack surface in the modern grid.
Read → 10 Jul 2026When Nation-States Don't Need Zero-Days: The New Shape of OT Targeting
Why nation-state OT attackers are shifting from expensive zero-days to abusing legitimate access, exposed protocols, and pre-compromised environments — and what that means for detection.
Read → 7 Jul 2026Why Your IT Threat Intel Feed Won't Save Your OT Network
IP hashes, domain IOCs, and malware signatures dominate IT threat intelligence — but OT attacks don't use malware, don't phone home to known C2 servers, and often don't touch the internet at all. Here's what operators should be looking for instead.
Read → 6 Jul 2026The Most Dangerous Device on Your OT Network Isn't Vulnerable — It's Invisible
Why the forgotten engineering workstation, the orphaned HMI, and the vendor laptop left plugged in after commissioning represent OT's hardest asset management problem — and how behavioral detection catches what no inventory audit can.
Read → 2 Jul 2026The Most Dangerous OT Attacks Don't Break In — They Log In
Why the hardest ICS attacks to detect use legitimate credentials, not malware — and what real-world incidents from Maroochy to Oldsmar teach us about closing the blind spot.
Read → 30 Jun 2026When Authentication Exists But Nobody Uses It — The DNP3 Security Paradox
DNP3 has had Secure Authentication since 2007. But utilities routinely disable it — the polling overhead is real, and legacy RTUs predate the standard. That gap between what the protocol can do and what the network actually does is where detection lives.
Read → 29 Jun 2026The Modbus blind spot: when a valid command is the attack
Modbus was built in 1979 for uptime, not authentication. Understanding why millions of OT commands carry no identity is the first step to detecting the ones that shouldn't be there.
Read → 26 Jun 2026One Day, Seven Advisories: What CISA's Latest ICS Batch Reveals About OT Detection
When a single day's CISA advisories span DCS servers, PLC programming tools, power monitors, and EV charging infrastructure, the real story isn't any one vulnerability — it's what the diversity of the attack surface demands from detection.
Read → 25 Jun 2026What a $4.1 Billion OT Security Deal Says About the Market — and What It Doesn't Say
When a single acquisition reshapes the OT security landscape overnight, it validates the category. But the consolidation wave also raises a question nobody's asking: who holds the keys to your control network data?
Read → 25 Jun 2026When the Tool That Guards the Network Is What an Attacker Exploits
The Siemens SINEC INS advisory exposes a discomforting pattern — OT network management tools that are meant to give operators visibility are themselves becoming the attack surface. What happens when the monitor is the entry point?
Read → 23 Jun 2026The SANS OT Skills Crisis — and the Detection Strategy That Closes the Gap
The SANS 2026 report confirms what every OT security manager already feels: there aren't enough skilled people. But the data also reveals that the right detection approach cuts containment time by nearly an order of magnitude.
Read → 22 Jun 2026Beyond Access: Why Adversaries Mapping Your Control Loops Changes Everything About OT Defense
The Dragos 2026 Year in Review confirms that industrial threat actors have moved beyond network access to process-level understanding — control loop mapping represents the most dangerous escalation in OT threat sophistication since Stuxnet.
Read → 22 Jun 2026ICS Vulnerabilities Just Hit a Record. Here's What the Numbers Don't Tell You.
A record spike in ICS vulnerabilities is making headlines, but the attacks that evade detection don't need CVEs — they use legitimate access and leave no signature footprint.
Read → 21 Jun 2026When the Vulnerability Scanner Can't Save You
ICS vulnerabilities hit record highs in 2026 and attacks are shifting to field-level devices. Here's why the old playbook fails in OT — and what actually works.
Read → 20 Jun 2026What a healthy OT network looks like
OT networks have a heartbeat — deterministic, periodic, predictable. Knowing what 'healthy' looks like is half of good detection.
Read → 18 Jun 2026Why OT attacks don't (usually) have signatures
Signatures catch what's been seen before. In OT, the attacks that do real damage usually haven't been — here's why, and what to do about it.
Read →