IEC 62443-4-2 certification badges are now common on PLC, HMI, and remote-access datasheets, but the certificate describes what a component can do, not what your plant actually has. Here’s how to read the claim correctly and turn it into a real zone/conduit design.
Read MoreCategory: IT & CYBER SECURITY
When the KEV Catalog Says “Patch Now” and Your PLC Can’t Come Down Until the Fall Outage
When a CISA KEV-listed vulnerability shows up in a PLC that can’t be patched until the next scheduled outage, the answer isn’t to ignore the SLA — it’s to build a compensating-control case that holds up when an insurer or OEM auditor asks for proof.
Read MoreCISA Wants Machine-Readable OT Inventories. Your Spreadsheet Won’t Cut It
CISA and sector regulators are asking for component-level software visibility into ICS environments, but most plants can’t produce an SBOM for a PLC on demand. Here’s a maturity model for getting there.
Read MoreNaming IEC 62443 in Your RFP Isn’t a Security Requirement — It’s a Trap
Citing IEC 62443 in a purchase order without target security levels and evidence requirements is a paper shield — here’s how to write SL-T clauses that let you actually reject a bad bid.
Read MoreYour Segmentation Diagram Is Lying to You, and CISA’s Attestation Push Is About to Prove It
CISA’s secure-by-design attestation framework and cyber insurers are both starting to ask for proof of OT segmentation, not just a diagram of it. Most plants will fail that test — here’s how to close the gap using tools you already own.
Read MoreYour OT Recovery Plan Has an RTO Number Nobody Has Ever Tested
Manufacturers are writing OT recovery time objectives into insurance forms and security questionnaires without ever timing a real MES-to-PLC restore. Here’s what a tested plan actually requires.
Read MoreZero Trust Meets Zone and Conduit: A Practitioner’s Guide to Reconciling Two Segmentation Models
IT wants zero trust plant-wide; OT already has zone and conduit segmentation under IEC 62443. Here’s where those two models actually agree, where they collide, and how to write a joint policy that survives both audits.
Read MoreCISA Advisories Aren’t Suggestions Anymore — Your Patch Triage Shouldn’t Be Either
CISA’s ICS advisories keep getting more frequent and more specific, but most plants still respond to all of them the same way — slowly. Here’s a practical framework for triaging by Purdue level, exploitability, and asset reality within 72 hours.
Read MoreCISA Wants SBOMs From Your PLC Vendor. Here’s What to Actually Do With One.
CISA’s tightening cadence on ICS advisories and SBOM/VEX expectations creates real work for plant teams, not just vendors — here’s a practical triage workflow for the Monday-morning “what do we do with this” problem.
Read MoreYour PLC Has 40 Open-Source Components Inside It and You Have No Idea What They Are
CISA’s secure-by-design push and NIST CSF 2.0 are pointing toward mandatory SBOM ingestion for OT asset owners, but most plants still can’t consume a machine-readable SBOM even when the vendor hands them one. Here’s how to actually build that workflow.
Read More