CISA’s Secure by Design pledges are reshaping what manufacturers can ask of OT vendors, but most purchase orders still don’t say any of it. Here’s how to write contract language that actually holds up.
Read MoreCategory: IT & CYBER SECURITY
The Attestation Isn’t the Answer: A Scoring Rubric for Secure-by-Design Claims in Your Next PLC RFP
CISA’s secure-by-design pledge has turned into vendor attestation paperwork showing up in 2026 procurement cycles. Here’s a practical rubric for telling substantive commitments apart from marketing copy — and RFP language that forces vendors to be specific.
Read MoreYour Zone-and-Conduit Diagram Isn’t Evidence Anymore
OEMs are starting to demand proof of IEC 62443 segmentation and access control, not just a network diagram — here’s what evidence actually holds up and how to start building it now.
Read MoreYour PLC Just Got IEC 62443 Certified. Here’s What That Actually Covers.
IEC 62443-4-1/4-2 certification is showing up in mainstream PLC and HMI product lines, but it certifies a development process and a component, not your plant. Here’s how to interrogate the badge during procurement instead of trusting it.
Read MoreWhen a CISA Advisory Hits a PLC You Didn’t Know You Had
CISA’s accelerated ICS advisory cadence is exposing a structural gap: most plants can’t tell if an advisory applies to their line without calling the OEM. Here’s how to close that gap with zone/conduit mapping and better vendor SLAs.
Read MoreKEV Deadlines Meet the Maintenance Window: A Practical OT Patch Cadence for CISA’s New Pace
CISA’s Known Exploited Vulnerabilities catalog is moving faster and reaching deeper into ICS/OT, but plants still can’t reboot a PLC mid-shift. Here’s how to triage advisories, build a defensible patch cadence, and document it so it holds up in an audit.
Read MoreDrawing Zones and Conduits That Survive Contact With a Real Plant Floor
Segmentation-first OT guidance is turning up in insurance renewals and customer questionnaires, but the standard’s zone-and-conduit model breaks down fast when applied by device type. Here’s how to draw it by consequence instead, and defend it to an auditor without a full re-architecture.
Read MoreYour OT Asset Inventory Will Be Audited Someday. Here’s How to Make It Survive.
CISA’s push on OT asset visibility and looming CIRCIA reporting rules are turning asset inventory into a compliance requirement, not a someday project — and passive discovery tools alone won’t get you there.
Read MoreThe SBOM Is Coming to Your Next PLC Purchase — Here’s How to Actually Use It
CISA’s SBOM push is starting to show up in PLC, HMI, and MES RFPs — but a software bill of materials only matters if someone on your team knows what to do with it. Here’s a workflow, and contract language, that actually gets used.
Read MoreSecure by Demand Is Showing Up in Your RFPs. Here’s How to Actually Score It.
CISA’s Secure by Demand framework is migrating from whitepaper to RFP boilerplate at utilities and large manufacturers. Here’s how to use it as a real scoring rubric instead of a compliance checkbox.
Read More