When Level 4 Can Reach Level 1, the Diagram Is No Longer the Architecture
Why IIoT, cloud connectivity, remote access, and AI require OT leaders to govern authority paths, not only network levels. The Purdue diagram on the wall may…
Thirty Water Systems, Seven States, One Warning
Why OT cybersecurity assessments must examine operational exposure, lifecycle risk, engineering authority, and recovery capability.
Two Years On: What My 2024 OT Predictions Got Right, Got Wrong, and Missed Entirely
Most prediction lists in this industry are written to be forgotten. The ones worth writing are the ones you have to live with.
When Pride Turns Into Exposure: How Social Media Posts Put ICS Environments at Risk
Across industrial environments, one recurring pattern is that the people most committed to their work can unintentionally expose operational details online.
Lessons from the Field: When Pride Turns Into Exposure: How Social Media Posts Risk ICS Environments
Public disclosures about industrial work create risk because attackers can combine small details into an actionable view of an environment.
Beyond the Hype: AI, Autonomy, and the Architecture of Reality in OT
The Question That Started It A question I was asked recently: “What’s the future of OT?” My answer was clear—AI. Not the hype-cycle AI that fills conference…
Defense in Depth in OT: The Architecture of Resilience
From Shadows to Structure In the previous edition, “Shadows in the Machine,” we explored how unseen actions within trusted networks can cripple entire plants.
Shadows in the Machine: When Cyber Shadows Eclipse the Industrial Dawn
A fictionalized scenario inspired by real OT cybersecurity incidents 🕒 Rotterdam, 2:17 AM — October 2025 The night shift in a sprawling chemical plant moved…
My Top 10 OT Cybersecurity Predictions for 2025: A Technical Assessment and Strategic Outlook
As we reach the midpoint of 2025, it's the right moment to revisit the OT cybersecurity predictions I shared in April 2024. Over the past year.
Implementing Defense in Depth for Critical Infrastructure Protection: Begin with an assessment. Avoid being misled by silver bullets.
As cyber threats continue to change and grow, organizations are always moving to protect their digital and operational treasures.