
Mythology and Metrics
OT Security needs metrics. I originally wrote more metrics, but we have almost no metrics. We includes asset owners, governments, vendors, industry groups, ... We shouldn't be funding anything that doesn't include a hypothesis and a metric that will provide data that...

Most People’s 1st Article On OT Security … OT Is Different Than IT
You just discovered OT. Maybe you're in IT and got a tour of your company's factory or mill. Maybe you went down a rabbit hole on some site or social media and learned about it. You want to share this world, and more often than not it leads to an article on how OT is...

Volt Typhoon Is A Fait Accompli In Cyber Persistence Theory
All Sides Accept Some Level Of Compromise Of Critical Infrastructure For Reconnaissance and Pre-Positioning If you want to understand US government cyber strategy, offense and defense, you need to master Cyber Persistence Theory. The US would argue they didn't invent...

Gresham’s Law – Part 2
Gresham's law is a monetary principle stating that "bad money drives out good". For example, if there are two forms of commodity money in circulation, which are accepted by law as having similar face value, the more valuable commodity will gradually disappear from...

Gresham’s Law – Part 1
Gresham's law is a monetary principle stating that "bad money drives out good". For example, if there are two forms of commodity money in circulation, which are accepted by law as having similar face value, the more valuable commodity will...

Does CambiOS Academy Shake Up The OT Security Training Market?
There were 12 organizations at the OT Security Training Roundup at S4x25. The entry bar was low. Buy a ticket and have an OT security training course to promote. The most noteworthy entrant was the launch of CambiOS Academy. The founders behind CambiOS Academy are a...

Gartner’s OT Visibility Magic Quadrant
Advisory services vendor Gartner put out their magic quadrant for "CPS Protection Platforms" on February 12th. (Right in the middle of S4x25, coincidence?) Having covered this market since 2016, I have a few things to say about their magic quadrant and report. Name:...

S4x25 Keynote: Your Value As An OT Security Professional
Here's the text version of my S4x25 keynote delivered on Feb 12th. Of course you don't get the seesaw that you have in the video. What are you worth? Not as a person. As an OT security professional. What’s your value? How much more is your value than a studious entry...

The Impact Of US Government OT Security Firings
Photo Source: https://www.flickr.com/photos/dbaron/3916976651/

Time For Action, We Have Plenty Of Advice
Seth Godin manages to put a lot of wisdom in his short daily blogs. This one hit me last week (key excerpt below). Generally, the advice isn’t really the hard part. There’s endless good advice just a click away. ... We might not need better advice. We might simply...
GET DALE'S ICS SECURITY NEWS & NOTES EMAIL EVERY FRIDAY
Article Archive By Year
Article Archive By Category
UPCOMING EVENTS
OTCEP ... 29 - 30 July 2025 in Singapore
One of the best OT Security events in Asia. Dale will be playing cowboy that week and will unfortunately miss it. Most of the rest of the OTCEP panel will be there on stage.
S4x26 ... 23 - 27 February 2026 in Miami South Beach
Save the date for S4x26. For the biggest and most future focused on ICS Security Event ... and likely our last time in Miami South Beach.