OT & ICS
Security decisions where cyber controls can affect process availability, engineering access and physical recovery.
What changes in OT & ICS
Production recovery needs a defensible evidence chain, not only restored systems.
Read →AnalysisSafety Independence Must Survive a Cyber CompromiseIf control and safety share the same identities, engineering paths or infrastructure, a cyber incident can turn nominal independence into common-mode failure.
Read →AnalysisThe Remote Access Path Nobody Questions AnymoreLegacy VPN trust can quietly bypass the plant segmentation model.
Read →AnalysisWhen Legitimate Engineering Workflows Can Carry Malicious Control LogicIndustrial logic can be malicious even when it was compiled and deployed by the organisation’s own trusted engineering process.
Read →AnalysisIndustrial 5G Makes Radio Availability Part of the Safety and Production ModelPrivate 5G can provide strong identity and segmentation while still remaining physically vulnerable to selective interference.
Read →AnalysisEV Charging Security Is Becoming Grid ResilienceThe risk is not one compromised charger. It is coordinated control across an ecosystem that can aggregate into material grid behaviour.
Read →New evidence and decisions
Siemens SSA-019113 tracks inherited Linux vulnerabilities in the GNU/Linux subsystem of the SIMATIC S7-1500 MFP. The assurance challenge is managing a second software lifecycle inside the same controller boundary.
Read →Latest analysis · 9 Sep 2026Weidmüller Shows Why a Security Router Is a Privileged OT AssetAn unauthenticated command-injection flaw can execute shell commands as root on affected Weidmüller industrial security routers. The deeper lesson is that a boundary device inherits exceptional authority over every conduit it protects.
Read →Latest analysis · 2 Sep 2026PLCnext Shows Why Critical CVEs Need Reachability EvidenceCVE-2025-41769 can expose PLCnext controllers to unauthenticated PROFINET buffer-overflow attacks. Remediation is primary, but brownfield risk decisions also need evidence of who can actually reach the vulnerable service.
Read →