TroutTrout
Blog

Insights & Resources

Guidance on CMMC compliance, industrial cybersecurity, and OT network protection.

203 articles

Zero TrustOT Security

Agent-Free Zero Trust: Why OT Environments Can't Use Endpoint Software

IT Zero Trust relies on endpoint agents. OT devices cannot run them. Here is why, and how network-layer enforcement provides equivalent protection without touching the device.

Air-gapped securityMisconceptions

Air-Gapped But Not Safe: Misconceptions in Legacy Security

Air-gapped systems have long been perceived as the ultimate safeguard against cyber threats in industrial and OT security. The concept is simple: isolate critica...

Air-gappedLayered security

Air-Gapped vs Layered Security Architectures

In today’s rapidly evolving cybersecurity landscape, organizations face the challenging task of safeguarding both operational technology (OT) and information technology (IT) environments. For IT secur...

Compliance automationICS monitoring

Automating Compliance Monitoring in ICS

Maintaining compliance with regulatory standards in industrial control systems (ICS) is a daunting task for many organizations. As these systems become more intercon...

OT SecurityICS Advisories

The SCADA You Cannot Patch on Tuesday: AVEVA Enterprise SCADA (ICSA-26-225-01)

CISA's ICSA-26-225-01 flags a CVSS 7.1 deserialization-to-code-execution flaw in AVEVA Enterprise SCADA and its HMI. The attacker still needs to reach the service to send the payload. That reach is the part you control.

OT SecurityICS Advisories

A Key You Cannot Rotate: AVEVA Pipeline Integrity Monitor (ICSA-26-253-01)

CISA's ICSA-26-253-01 covers four flaws in AVEVA Pipeline Integrity Monitor, including a hard-coded cryptographic key. The two 8.4s are local-only, so the whole question is who can already reach the host.

Identity

Badge vs Password Why Physical Identity Matters for OT Cybersecurity

OT cybersecurity conversations often center around digital credentials and network protocols. However, the physical aspects of cybersecurity, specificall...

Monitoring toolsIndustrial protocol

Best Tools for Monitoring Industrial Protocol Security

Ensuring robust security for industrial protocols in OT is non-negotiable. With cyber threats becoming increasingly sophisticated, organizations must prioritize...

PLC

Beyond the Acronym How PLCs Became the Backbone of Modern Industrial Automation

The term "PLC" has become synonymous with efficiency, precision, and reliability in industrial automation. Programmable Logic Controllers (PLCs) are not just the sil...

SOCOT security operations

Building a SOC for OT: Tools and Tips

A Security Operations Center (SOC) specifically tailored for operational technology (OT) environments is becoming increasingly crucial. Unlike t...

OT Security

Building Fault-Tolerant Network Paths in OT

Building fault-tolerant network paths is a critical component of OT security, ensuring continuous operation and maintaining robust defenses against cyber threa...

ScalabilityIndustrial networks

Building for Scalability in Industrial Networks

Today's industrial networks are experiencing unprecedented growth due to the rapid adoption of automation, IoT devices, and digital transformation initiatives. Ensuring these networks can scale effect...

›Browse all posts (203)