Blog
Seventeen draft standards now show what a CRA claim will consist of. The manufacturer declares its own scope, some requirements are handed to your environment, and for operational technology no standard exists yet.
Blog
Business continuity plans and disaster recovery plans are not the same thing, and the interdependencies between business, IT and OT decide whether you pay for resilience up front or during the incident.
Blog
Faster patching is the wrong investment for most legacy OT, because the supplier controls the calendar and the plant operator controls the change window. The money goes into compensating controls and into procurement.
Blog
The system owner carries the security risk for the OT estate and mostly doesn't govern like it. The access restrictions were inherited from a build project where cybersecurity wasn't on the requirements list, and the aftermarket business model is what keeps them in place.
Blog
Two OpenAI models escaped a sandboxed evaluation and hacked Hugging Face to steal the answer key for their own test. The AI is the headline, but the failure is older: a boundary that was assumed to hold, rather than proven to hold, did not hold. What that means for anyone signing agents into production.
Blog
A certificate signals that you follow a recognised process. It won't tell you your risk context, or what your security programme should cover and what it shouldn't. That decision is yours, and it is the part that actually reduces risk.
Blog
Chinna Botla's piece on integrating OT telemetry into enterprise SOCs gets the direction right. The harder part it understates is organisational. The automation teams own the assets, and detection only becomes response when the integration reaches the people who can act.
Blog
The value of AI and its risk are the same feature: it acts without you scripting every step. You cannot control that decision yet, only what AI is allowed to do, and the controls that would change that are still a promise. So the question is not whether to deploy AI, but where you can afford the trade.
Blog
A cyber programme for a newly standalone business should be dimensioned from its market position, management's actual intentions, and the mandatory floor. Not scaled down from the parent's programme. Here is the planning discipline that gets it right at the start.
Blog
Most organisations confuse risk appetite with risk tolerance. Between the two sits governance, and almost nobody manages that gap. Here is why it stays open.
Blog
Most projects treat security as a late-stage constraint. The system security concept, aligned to buy-build-run phases, makes it a business input from the start.
Blog
Dale Peterson's OTI Impact Score addresses the industry signal problem. The partner it needs is organisational resilience, the ability to coordinate internally before communicating externally.
Blog
Every organisation has an ISMS. Most of them don't have a management system. Here's the difference, and why it matters under NIS2.
Blog
Dale Peterson asks where the evidence is that OT asset inventory reduces incidents. From building a global OT security programme across 40+ manufacturing sites, here are the answers.
Blog
Recovery targets derived from a solid BIA are the right foundation. But five realities sit outside that formal scope, and they're where plans actually break down in practice.
Blog
AI-driven vulnerability discovery is outpacing OT remediation cycles. What manufacturing security teams need to know about software composition visibility, response planning, and the growing gap between known and fixed.
Blog
Without understanding the full system context, risk assessments default to compliance control catalogue validation. Security concepts, widely used in military classified systems, offer a better path.
Blog
How new EU regulations reshape supplier relationships and procurement strategy, even if you don't manufacture digital products
Blog
Most organisations start with standardised control catalogues and work backwards to justify coverage. Few start with business context, threat landscape, and actual vulnerabilities to determine which controls reduce risk and which waste resources.
Blog
A Norwegian court case delivers a €5.6 million lesson on business continuity, supplier management, and why manufacturing executives can't outsource operational accountability
Blog
Most security governance is theatre. Committees that rubber-stamp, decisions that decide nothing, metrics that measure activity not outcomes. Here's how to build governance that actually works.
Blog
Most cybersecurity incidents trace back to implicit risk acceptances hidden in everyday business choices. The hardest root causes to analyse are those buried in decisions we never understood we were making.
Blog
Threshold-based IR coverage, pre-approved suppliers, and using preventative services strategically