What Is The True Level Of OT Cyber Incidents?

What Is The True Level Of OT Cyber Incidents?

This article attempts to frame the question after my back and forth with Robert M. Lee last Friday. Question: How many cyber attacks are resulting in non-trivial consequence events in OT / Operations? Stipulation 1: Ransomware and other causes of outages on IT cyber...

read more
Disconnected: Manufacturing and OT Security

Disconnected: Manufacturing and OT Security

Last week I attended Inductive Automation's Ignition Community Conference (ICC). Primarily to get smarter on what's going on in bleeding edge manufacturing, but also to verify and understand why there is a disconnection between manufacturing automation / data...

read more
My OT Security Vendor Was Aquired … What Should I Do?

My OT Security Vendor Was Aquired … What Should I Do?

Here is an anonymized question I received after the Mitsubishi Electronics acquisition of Nozomi Networks. I have a project ongoing right now to select an asset inventory/detection product. This news hit right before our proof of concept phase, and obviously I...

read more
We Won, We Lost (Part 2)

We Won, We Lost (Part 2)

Check out Part 1 here. We Won: An OT Security Community There is a thriving OT security community in 2025. This is a huge win. We started S4 in 2007 because there was no place where one of our researchers could present the first publicly disclosed OT vulnerabilities...

read more
We Won, We Lost (Part 1)

We Won, We Lost (Part 1)

It's been 24 years since the 9/11 attacks, and the beginning of serious OT security concerns. It's been 15 years since Stuxnet was discovered. The results are an odd dichotomy. We Won - The Impact Of OT Cyber Incidents Has Been Minimal Experts have predicting disaster...

read more
USG Reset … What About Private Industry?

USG Reset … What About Private Industry?

I had a number of public comments and private "yes, and" conversations after last week's US Government (USG) Reset article similar to: just as government needs to show results, so does industry. Outside of entrenched, IT specific security providers, the public record...

read more
US Government Reset On OT Security Is An Opportunity

US Government Reset On OT Security Is An Opportunity

CISA and other US government departments have accomplished little in OT cyber security and risk management over the past two decades. There has been an increase in funding and activity, not results. While the loss of talent and capability this year in the USG is...

read more
It Won’t Work In OT

It Won’t Work In OT

What Will Fall Next? A common refrain for any new proposed technology: It Won’t Work In OT. A short and incomplete list or examples: 90’s: Windows and Ethernet (yes, there was a battle with many experts insisting Windows workstations and servers connected by Ethernet...

read more
Quantum Cryptography In OT?

Quantum Cryptography In OT?

We've received a few proposed sessions on quantum cryptography in OT in our S4x26 Call For Presentations. This isn't new. We've received these every year this decade. They don't get selected. Why? S4's motto is Create The Future. While timelines vary, there is a...

read more
What We Know – Stuxnet 15 Years Later

What We Know – Stuxnet 15 Years Later

The US House Homeland Security Committee's subcommittee on Cybersecurity and Infrastructure Protection is holding a hearing today entitled Fully Operational: Stuxnet 15 Years Later and the Evolution of Cyber Threats To Critical Infrastructure. Two of the four...

read more

GET DALE'S ICS SECURITY NEWS & NOTES EMAIL EVERY FRIDAY

UPCOMING EVENTS

OTCEP ... 29 - 30 July 2025 in Singapore

One of the best OT Security events in Asia. Dale will be playing cowboy that week and will unfortunately miss it. Most of the rest of the OTCEP panel will be there on stage.

S4x26 ... 23 - 27 February 2026 in Miami South Beach

Save the date for S4x26. For the biggest and most future focused on ICS Security Event ... and likely our last time in Miami South Beach.