Blog
Blog
Analyses and background articles on OT threats, IEC 62443 and vulnerability management, written by the IACS Radar team.
What the growth in KEV entries means for the energy sector
The CISA KEV catalogue has been growing steadily for several years. What does that mean for prioritisation within OT environments in the energy sector?
IEC 62443 certification: hype or necessity for grid operators?
More and more tenders list IEC 62443 certification as a requirement. What does that mean in practice, and when does it make sense?
Why substations are a growing target
Substations combine physical criticality with increasing digital connections. What makes them attractive to attackers, and what can grid operators do about it?
Three lessons from a year of following ICS advisories
What a year of systematically following ICS advisories yields in practical insights for vulnerability management in OT.
Secure by design starts with the procurement conditions
Security requirements that are only tested at delivery come too late. Why procurement conditions are the best point of leverage.
Practising incident response in an OT environment: where to start
Applying an IT incident response plan one-to-one to OT does not work. Practical points to get started.
Stay up to date
Newsletter sign-up will follow in a later version of this platform.