ICS vulnerability insights, advisory analysis, and practical OT security guidance.
An advisory says "affected versions below V7.2" — but do you actually know which of your 200 PLCs are running V7.2? ICS firmware version tracking is the unsolved gap between receiving an advisory and knowing whether you're exposed.
39 ICS security advisories published this week (7 critical, 5 high severity, 1 actively exploited). Here are the ones that matter.
OT asset inventories are almost always outdated — not because people are lazy, but because OT environments evolve in ways that resist conventional asset tracking. Here's why, and what a realistic starting point looks like.
44 ICS security advisories published this week (7 critical, 6 high severity, 1 actively exploited). Here are the ones that matter.
ABB's cybersecurity advisory portal covers AC500 PLCs and Symphony Plus DCS, but the disclosure picture is more opaque than most vendors. Here's how to monitor ABB ICS vulnerabilities effectively.
34 ICS security advisories published this week (3 critical, 14 high severity, 1 actively exploited). Here are the ones that matter.
Schneider Electric Modicon M340, Quantum, and M580 have a serious vulnerability history — including the fallout from ModiPwn research on the UMAS protocol. Here's what to watch and how to monitor it.
133 ICS security advisories published this week (2 critical, 10 high severity, 3 actively exploited). Here are the ones that matter.
Rockwell Automation's vulnerability disclosure is fragmented across multiple channels — here's how to actually track ControlLogix, Logix Designer, and FactoryTalk advisories before they bite you.
25 ICS security advisories published this week (3 critical, 5 high severity). Here are the ones that matter.
Network-based OT monitoring tools like Dragos and Claroty are powerful but require deploying sensors on live plant — intelligence-based monitoring is a different category that needs no network access at all.
16 ICS security advisories published this week (0 critical, 7 high severity). Here are the ones that matter.
CISA's Known Exploited Vulnerabilities catalogue flags CVEs with confirmed active exploitation — here's what that means for ICS operators and why KEV entries deserve different treatment from standard advisories.
32 ICS security advisories published this week (6 critical, 7 high severity). Here are the ones that matter.
What Article 21 of the NIS2 Directive actually requires from essential entities on vulnerability handling, and what that looks like in practice for OT/ICS operators.
21 ICS security advisories published this week (4 critical, 4 high severity, 1 actively exploited). Here are the ones that matter.
Power management systems are among the most security-relevant OT systems on a vessel, yet they're often overlooked in cybersecurity assessments. Here's what maritime engineers need to know about PMS vulnerabilities and maritime PLC security.
86 ICS security advisories published this week (16 critical, 15 high severity, 3 actively exploited). Here are the ones that matter.
38 ICS security advisories published this week (1 critical, 7 high severity). Here are the ones that matter.
IACS Unified Requirements E26 and E27 apply to newbuild ships contracted on or after 1 July 2024. Here's what they require from shipyards, equipment suppliers, and ship owners — and what vulnerability monitoring has to do with it.
42 ICS security advisories published this week (3 critical, 16 high severity). Here are the ones that matter.
30 ICS security advisories published this week (6 critical, 3 high severity). Here are the ones that matter.
IMO Resolution MSC-FAL.1/Circ.3 required cyber risk management in SMS systems from January 2021. Five years on, most operators still treat it as a checkbox. Here's what it actually means for managing ICS vulnerabilities on your vessels.
33 ICS security advisories published this week (3 critical, 1 high severity). Here are the ones that matter.
Siemens publishes its own security advisories through ProductCERT before CISA republishes them. If you run Siemens equipment, here's what the difference means for your alert timing.
IT patch Tuesday doesn't work in OT. Here's why ICS patch management is different, what a realistic process looks like, and how to track it without adding headcount.
CIP-007 and CIP-010 require documented vulnerability management processes. Here's what auditors look for and how to build an audit trail without adding headcount.
CISA publishes hundreds of ICS advisories per year. Most teams either ignore them or drown in them. There's a better way.