Vulnerability Assessments in Operational Technology: Scope, Limitations, and Practical Application
Vulnerability assessments are often treated as the most basic element of a cybersecurity program. In enterprise IT environments, they are typically automated, repeatable, and largely uncontroversial. In operational technology (OT) environments, however, vulnerability assessments are neither simple...
Threat and Vulnerability Assessments in Operational Technology: Clarifying Purpose, Scope, and Method
Operational Technology (OT) security has reached a point where high-level awareness is no longer the primary challenge. Many organizations operating industrial control systems (ICS) now know that there’s a problem with their environments being exposed, interconnected, and vulnerable to intentional...
Myth: “Insiders Are Not a Big Threat”
Introduction: Why This Myth Persists When people think of cybersecurity threats, they often imagine a hooded figure hunched over a keyboard in a dimly lit basement, launching sophisticated attacks from thousands of miles away. Headlines about ransomware gangs, nation-state hackers, and...
Implementing Network Segmentation in Brownfield Environments: Challenges and Strategies
As IT and OT systems continue to converge, industrial organizations are reaping operational efficiencies, but also facing a new wave of cybersecurity risks. For legacy operational technology (OT) and industrial control systems (ICS) already deployed in the field (often referred to as brownfield...
Network Segmentation: Strategy, Implementation, and Pitfalls
Cybersecurity teams and network engineers often talk about network segmentation as if it were just a simple firewall rule or VLAN setup. In reality, segmentation is a much larger concept. It’s a strategic and technical practice that divides a flat network into controlled, secure zones. The main...
Cyber and Operational Risk: Third Party/Supply Chain Compromise
Creating manufacturing facilities, power plants, processing plants, or other production facilities requires a substantial amount of manpower to bring them into operation. To accomplish this, third-party contractors are often utilized to handle various tasks and maintain specific portions of the...
Beyond Scores: Using KEV, CVSS, and EPSS to Strengthen OT Risk Management
In the world of Industrial Control Systems (ICS) and Operational Technology (OT), vulnerability management is fundamentally different from that in traditional IT environments. While IT teams can often patch quickly and absorb downtime, OT environments prioritize the SRP triad (Safety, Reliability,...
Myth: Security Incidents Only Affect Data, Not Operations
In many organizations, there’s a dangerous misconception that cybersecurity incidents are solely about data loss, data theft, or data privacy. It’s easy to fall into the trap of thinking that breaches only affect databases, spreadsheets, or email accounts. This mindset couldn’t be further from the...
Using Privileged Access Workstations in OT Environments: What the NCSC Got Right and How to Make it Work
In October 2025, the UK’s National Cyber Security Centre (NCSC) released new guidance on using Privileged Access Workstations (PAWs) in Operational Technology (OT) environments. This guidance builds directly on NCSC’s core Principles for Secure Privileged Access Workstations, published earlier in...
Cyber and Operational Risk: Disaster Recovery in Industrial Environments
Introduction In modern industrial environments, uptime is everything. From manufacturing plants and refineries to power generation facilities, operational technology (OT) systems are expected to operate continuously and without interruption. But cyberattacks, equipment failures, and natural...
Deciding When to Secure OT/ICS with a Single or Multi-Firewall Strategy
Safety, reliability, and control are paramount in all industries, not just on the plant floor or field but also on your digital infrastructure. As industrial operations become increasingly connected through Industrial Control Systems (ICS), SCADA networks, and remote access technologies,...
Myth: OT/ICS Systems Don’t Need Patching
Where the Myth Comes From Patching in the OT/ICS space has always been tricky. Many of the systems still in use today were designed 10, 20, even 30 years ago before cybersecurity was a consideration and before remote access became commonplace. Updates often meant downtime, requalification, and...
Get a clear picture of your OT cybersecurity risk
If you are frustrated at wasted time and resources spent on security projects with nothing to show for it, or need your security or operations team to do more with less, give us a call at (469) 574-4000 or send a message to info@enaxy.com. Let’s see how we can help ensure your assets are secure.