Using MITRE DeTT&CT Framework to Enhance OT/ICS Cybersecurity

Cybersecurity for Industrial Control Systems (ICS) and Operational Technology (OT) environments requires specialized strategies due to their distinct operational characteristics and stringent safety requirements. The MITRE DeTT&CT framework provides a tool and methodology designed to score and...

Cyber and Operational Risk: AI Tools in the Enterprise

In modern environments, cybersecurity and operations are no longer separate concerns. The same actions that keep systems running can also introduce risk. This series explores how those risks intersect in real-world environments and how to manage them together. In this post, we will look at AI...

Intro to the Cyber and Operational Risk Convergence Series

Introduction Industrial environments are no longer secure behind the “air gap.” As IT and OT systems continue to converge, their risks are also becoming more interconnected. What once were two separate domains, IT security and OT operations, are now interdependent in ways that create new...

Iranian Cyber Actors Are Targeting U.S. PLCs

Introduction In April 2026, CISA released a cybersecurity advisory warning that Iranian-affiliated APT actors are exploiting internet-facing operational technology devices, including Rockwell Automation/Allen-Bradley PLCs, across U.S. critical infrastructure. At first glance, it may look like a...

Myth: OT Cybersecurity is IT’s Job

Introduction As cyber threats evolve in complexity and frequency, the distinction between IT (Information Technology) and OT (Operational Technology) environments has never been more critical or more misunderstood. One of the most dangerous myths in industrial cybersecurity is that protecting OT...

DoD Guidance on implementing Zero-Trust

Introduction The Department of Defense (DoD) released guidance designed to “coordinate, synchronize, and accelerate adoption” of the implementation of zero trust within Operational Technology (OT) cybersecurity frameworks. They emphasize the need for OT-specific guidance due to the unique...

What Does an OT SOC Analyst Look Like?

As cyber threats continue to evolve, Operational Technology (OT) environments have become a growing target for both cybercriminals and nation-state actors. Critical infrastructure sectors, including energy, manufacturing, water treatment, and transportation, are becoming increasingly reliant on...

Myth: “Compliance Equals Security”

Introduction: Why This Myth Persists In boardrooms and audit reports, compliance frameworks often serve as the standard for cybersecurity maturity. If an organization can demonstrate to auditors that it aligns with ISO 27001, NERC CIP, or IEC 62443, executives may assume the systems are secure,...

Telnet in OT: The Risk Everyone Knows and Still Can’t Remove

The recent disclosure of CVE-2026-32746 once again brought Telnet into focus. Telnet is a legacy remote-access protocol that lets users connect to and manage systems over a network via a command-line interface. Unlike modern alternatives, it transmits data in plaintext and was designed for trusted...

Get a clear picture of your OT cybersecurity risk

If you are frustrated at wasted time and resources spent on security projects with nothing to show for it, or need your security or operations team to do more with less, give us a call at (469) 574-4000 or send a message to info@enaxy.com. Let’s see how we can help ensure your assets are secure.