Blog

Notes on OT detection.

Signature-less detection, healthy OT networks, and the craft of catching what others miss.

19 Aug 2026

The Forgotten OT: Building Automation and the Attack Surface No One Owns

Two CISA advisories in the 13 August batch exposed building automation's quiet reality: BACnet controllers are OT, they sit at the corporate network's edge, and almost no security team is watching them. Here's the blind spot — and what passive detection changes.

NDRICS SecurityBACnetField-Level Attacks +4
Read →
14 Aug 2026

The OT Patch Gap: Why Vulnerabilities Linger Long After a Fix Ships

A single day's CISA advisory batch exposed why OT patching always lags the threat — including a hydropower control platform whose fix shipped 20 months before operators were told. Here's what detection adds inside that gap.

NDRICS SecurityOT Vulnerability ManagementICS Vulnerabilities +4
Read →
7 Aug 2026

When the PLC Configuration Is the Attack: What the Water Sector Campaign Reveals About OT Detection

The coordinated PLC attacks on US water utilities show that the most dangerous OT intrusions don't use malware — they use the device's own engineering interface. Here's what behavioral detection at Purdue Level 1 would see.

NDRICS SecurityField-Level AttacksBehavioral Detection +4
Read →
3 Aug 2026

Default Passwords Destroyed 30 Energy Sites in One Night: What the Poland Attack Teaches Us About OT Detection

The December 2025 attack on Poland's energy sector didn't use zero-days or exotic ICS malware. It used default credentials, shared VPN passwords, and missing MFA — and it bricked RTUs across 30 sites. Here's what that says about the limits of threat-based detection.

NDRICS SecuritySignature-less DetectionBehavioral Detection +4
Read →
30 Jul 2026

Between Detection and Action: Why Living-Off-The-Land Attacks Break the OT Response Playbook

OT security teams are detecting threats faster than ever — some reporting under 24 hours. But faster detection does not mean faster containment when the attack uses tools the operator trusts. Living-off-the-land attacks exploit the gap between 'we see it' and 'we can safely stop it,' and closing that gap requires a different kind of visibility.

NDRICS SecurityBehavioral DetectionSignature-less Detection +4
Read →
28 Jul 2026

When Your Vendor's Vendor Has the Keys: OT Supply Chain Risk and the Visibility Gap Nobody Talks About

Marathon Petroleum's CISO just told Help Net Security that supply chain risk in OT extends past third-party vendors to nth-party vendors — the ones you cannot see, cannot audit, and whose devices are already inside your network. Here is why passive behavioral monitoring is the only way to close that gap.

NDRICS SecurityOT SecurityNetwork Monitoring +5
Read →
27 Jul 2026

When the Project File You Opened This Morning Was the Attack

The CISA advisory for Rockwell Studio 5000 exposes three vulnerabilities in the engineering tool every automation professional uses daily. But the real story is not about the CVEs — it is about an attack surface that lives between IT and OT, where signatures cannot see and most monitoring tools do not look.

NDRICS SecuritySignature-less DetectionBehavioral Detection +4
Read →
21 Jul 2026

The Vendor VPN You Forgot About: Why Third-Party Access Is OT's Least-Governed Attack Surface

Every OT facility gives remote access to equipment vendors, system integrators, and support contractors. Most of those connections are persistent, unmonitored, and over-privileged — and authentication alone can't tell you whether the session is legitimate or the opening move of an attack.

NDRICS SecurityBehavioral DetectionNetwork Monitoring +4
Read →
20 Jul 2026

The IEC 62443 Compliance Trap: Why Checking Boxes Won't Catch the Attack Your Auditor Never Saw Coming

IEC 62443 is the most comprehensive OT security framework we have — but passing an audit and actually detecting attacks are two different things. Here's what the standard really demands.

NDRICS SecurityThreat DetectionBehavioral Detection +4
Read →
20 Jul 2026

The Enemy Inside the Fence: Why OT's Biggest Blind Spot Wears a Hard Hat

The Maroochy Shire incident wasn't malware — it was a disgruntled contractor with a radio. Two decades later, OT insider threats remain the detection challenge that credentials and signatures can't solve.

NDRICS SecurityThreat DetectionBehavioral Detection +4
Read →
14 Jul 2026

The Detection Gap Nobody Talks About: Why Purdue Level 1 Is Where Attacks Succeed

Most OT security tools live at Purdue Levels 2 and 3 — the HMI, the engineering workstation, the historian. But the actual process lives at Level 1, where controllers talk to field devices. And Level 1 is where signatures fail, baselines matter, and most organisations are flying blind.

NDRICS SecuritySignature-less DetectionBehavioral Detection +4
Read →
13 Jul 2026

The Software That Runs the Grid — and the Vulnerabilities No One Is Watching

Two Hitachi Energy advisories in a single CISA batch expose a structural blind spot: the energy management applications that bridge IT planning and OT operations are the least-defended attack surface in the modern grid.

NDRICS SecurityOT Vulnerability ManagementBehavioral Detection +4
Read →
10 Jul 2026

When Nation-States Don't Need Zero-Days: The New Shape of OT Targeting

Why nation-state OT attackers are shifting from expensive zero-days to abusing legitimate access, exposed protocols, and pre-compromised environments — and what that means for detection.

NDRICS SecurityNation-State ThreatsBehavioral Detection +4
Read →
7 Jul 2026

Why Your IT Threat Intel Feed Won't Save Your OT Network

IP hashes, domain IOCs, and malware signatures dominate IT threat intelligence — but OT attacks don't use malware, don't phone home to known C2 servers, and often don't touch the internet at all. Here's what operators should be looking for instead.

NDRICS SecurityThreat IntelligenceBehavioral Detection +4
Read →
6 Jul 2026

The Most Dangerous Device on Your OT Network Isn't Vulnerable — It's Invisible

Why the forgotten engineering workstation, the orphaned HMI, and the vendor laptop left plugged in after commissioning represent OT's hardest asset management problem — and how behavioral detection catches what no inventory audit can.

NDRICS SecurityAsset ManagementShadow OT +3
Read →
2 Jul 2026

The Most Dangerous OT Attacks Don't Break In — They Log In

Why the hardest ICS attacks to detect use legitimate credentials, not malware — and what real-world incidents from Maroochy to Oldsmar teach us about closing the blind spot.

NDRICS SecurityInsider ThreatsBehavioral Detection +3
Read →
30 Jun 2026

When Authentication Exists But Nobody Uses It — The DNP3 Security Paradox

DNP3 has had Secure Authentication since 2007. But utilities routinely disable it — the polling overhead is real, and legacy RTUs predate the standard. That gap between what the protocol can do and what the network actually does is where detection lives.

NDRICS SecurityDNP3Signature-less Detection +4
Read →
29 Jun 2026

The Modbus blind spot: when a valid command is the attack

Modbus was built in 1979 for uptime, not authentication. Understanding why millions of OT commands carry no identity is the first step to detecting the ones that shouldn't be there.

NDRICS SecurityModbusSignature-less Detection +4
Read →
26 Jun 2026

One Day, Seven Advisories: What CISA's Latest ICS Batch Reveals About OT Detection

When a single day's CISA advisories span DCS servers, PLC programming tools, power monitors, and EV charging infrastructure, the real story isn't any one vulnerability — it's what the diversity of the attack surface demands from detection.

NDRICS SecuritySignature-less DetectionOT Vulnerability Management +4
Read →
25 Jun 2026

What a $4.1 Billion OT Security Deal Says About the Market — and What It Doesn't Say

When a single acquisition reshapes the OT security landscape overnight, it validates the category. But the consolidation wave also raises a question nobody's asking: who holds the keys to your control network data?

Industry ConsolidationCybersecurity M&AOT Security MarketData Sovereignty +4
Read →
25 Jun 2026

When the Tool That Guards the Network Is What an Attacker Exploits

The Siemens SINEC INS advisory exposes a discomforting pattern — OT network management tools that are meant to give operators visibility are themselves becoming the attack surface. What happens when the monitor is the entry point?

Siemens SINEC INSOT Vulnerability ManagementNetwork Management SecurityAttack Surface +3
Read →
23 Jun 2026

The SANS OT Skills Crisis — and the Detection Strategy That Closes the Gap

The SANS 2026 report confirms what every OT security manager already feels: there aren't enough skilled people. But the data also reveals that the right detection approach cuts containment time by nearly an order of magnitude.

SANSOT Skills GapCybersecurity WorkforceDetection Strategy +3
Read →
22 Jun 2026

Beyond Access: Why Adversaries Mapping Your Control Loops Changes Everything About OT Defense

The Dragos 2026 Year in Review confirms that industrial threat actors have moved beyond network access to process-level understanding — control loop mapping represents the most dangerous escalation in OT threat sophistication since Stuxnet.

Control Loop MappingOT Threat IntelligenceIndustrial Threat ActorsICS Security +2
Read →
22 Jun 2026

ICS Vulnerabilities Just Hit a Record. Here's What the Numbers Don't Tell You.

A record spike in ICS vulnerabilities is making headlines, but the attacks that evade detection don't need CVEs — they use legitimate access and leave no signature footprint.

ICS VulnerabilitiesCVESignature-less DetectionOT Security +3
Read →
21 Jun 2026

When the Vulnerability Scanner Can't Save You

ICS vulnerabilities hit record highs in 2026 and attacks are shifting to field-level devices. Here's why the old playbook fails in OT — and what actually works.

ICS VulnerabilitiesOT Vulnerability ManagementField-Level AttacksCVE +3
Read →
20 Jun 2026

What a healthy OT network looks like

OT networks have a heartbeat — deterministic, periodic, predictable. Knowing what 'healthy' looks like is half of good detection.

OT Network BaselineAnomaly DetectionNetwork MonitoringICS Security +3
Read →
18 Jun 2026

Why OT attacks don't (usually) have signatures

Signatures catch what's been seen before. In OT, the attacks that do real damage usually haven't been — here's why, and what to do about it.

Signature-less DetectionBehavioral DetectionAnomaly DetectionOT Attacks +3
Read →