Skip to content

Topic

cybersecurity

All articles on cybersecurity.

OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read
Industrial OT and IoT devices subject to the obligations of the Cyber Resilience Act

Regulations

Cyber Resilience Act: What Changes for OT and IoT Device Manufacturers

The Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. For OT and IoT device makers, the compliance scope is broad and the deadlines are approaching.

3 min read
Vulnerability management dashboard showing CVE and EPSS scores on an industrial OT system screen

Cybersecurity

CVE and EPSS in OT Environments: Which Vulnerabilities to Fix When You Can't Patch Everything

Patching everything in an OT environment is impossible. CVSS alone is not enough to set priorities. EPSS adds the missing dimension: the probability that a vulnerability is being actively exploited today.

6 min read
Industrial HMI login screen with the password field highlighted, a manufacturing plant in the background

Cybersecurity

Default credentials in OT systems: a more widespread problem than you might think

Admin/admin, 1234, the vendor's factory credentials: how many OT installations still have access protected by default passwords? More than you would expect. How it happens, how attackers find it, and how to fix it without stopping production.

6 min read
Audit document with technical evidence and OT system logs on screen

Compliance

How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts

NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.

6 min read
Industrial OT network assessment with passive traffic analysis and ICS device profiling

Cybersecurity

How an OT Assessment Is Conducted: Phases, Methods and What You Really Find

An OT network assessment is not a vulnerability scan run on corporate IT. Different methodology, different risks, and often surprising results: here is what to expect from a properly conducted industrial assessment.

6 min read
Robotic automotive assembly line with KUKA arms in an industrial setting

Cybersecurity

OT Cybersecurity in Automotive Manufacturing: Robotic Lines and Supply Chains Under Attack

Automotive is among the sectors most exposed to OT attacks: robotic lines with proprietary protocols, MES/ERP integration and vendor remote access create a wide, hard-to-control attack surface.

5 min read
OT cybersecurity business case with ROI and investment roadmap

Risk Management

The OT Cybersecurity Budget: How to Build the Business Case and Measure ROI

The OT cybersecurity budget is often an afterthought next to IT, even when operational risk is far higher. How to build a convincing business case and measure the ROI of industrial security investments.

4 min read
Petrochemical plant with industrial piping and control valves

Cybersecurity

OT Cybersecurity in the Chemical Industry: Where Cyber Security and Physical Safety Meet

In the chemical industry a cyber incident can cause the release of hazardous substances, explosions and harm to people. Safety/security convergence is no abstraction: the Triton attack on Safety Instrumented Systems proved the last physical line of defense can be compromised.

5 min read
Automated food & beverage production line with conveyor belts and control systems

Cybersecurity

OT cybersecurity in food & beverage: traceability, digital HACCP and production lines under attack

Italian food & beverage has a wide, poorly protected OT attack surface: dosing lines, digital HACCP systems, connected cold rooms for traceability. An OT attack here can compromise food safety and brand reputation.

5 min read
Automated warehouse with AS/RS systems, vertical racking and AGVs on the floor

Cybersecurity

OT cybersecurity in logistics and automated warehouses: heterogeneous systems and high turnover

Modern automated warehouses run complex OT networks: a WMS wired to the automation, heterogeneous PLCs from many vendors, AGVs and mixed protocols. High turnover and frequent vendor work break segmentation, and downtime hits the supply chain instantly.

6 min read
Legacy industrial control panel with dated HMI and PLC in an Italian manufacturing plant

Cybersecurity

OT Systems That Cannot Be Updated: Compensating Controls and Risk Reduction

PLCs with 2008 firmware, HMIs running embedded Windows XP, systems that cannot be touched by contract: the reality of Italian plants. How to manage risk when patching is not an option.

5 min read
SOC with OT network monitoring sensors and industrial analysis dashboard

Cybersecurity

Building a SOC for OT Environments: Requirements, Tools, and Operational Metrics

An IT SOC cannot see OT environments. Building monitoring capabilities for industrial networks requires different sensors, different skills, and playbooks specific to OT protocols and threats.

4 min read
Vulnerability management dashboard for OT systems with contextualized scoring

Cybersecurity

Vulnerability Management in OT: Why Traditional Patching Does Not Work

In OT environments, traditional patch management is often impossible. Legacy systems, certifications to maintain, very rare maintenance windows: how to build a VM program that actually works.

4 min read
Industrial OT network with unauthorized devices connected to switches and PLCs in a manufacturing plant

Cybersecurity

Shadow Devices in OT Networks: The Assets Nobody Knows They Have

Maintenance laptops left connected, 4G modems installed by vendors, uncatalogued switches: shadow devices in OT networks are more common than you think and represent concrete blind spots for security.

5 min read
Supply chain attack diagram against industrial OT environments

Cybersecurity

Supply Chain Attacks in OT: The Vector That Bypasses the Physical Perimeter

Supply chain attacks are among the hardest to detect and prevent. In industrial OT, the supplier chain is often long, poorly monitored, and holds privileged access to control systems.

3 min read
Technical diagram of hardware TAP and SPAN port on an industrial switch in an OT Purdue network

Cybersecurity

TAP vs SPAN Port in OT Environments: How to Choose Where to Place Sensors

Passive OT traffic monitoring depends on where and how traffic is captured. Hardware TAPs and SPAN ports have very different characteristics in industrial environments: a wrong choice means incomplete data or operational risks.

6 min read
Industrial plant control room with safety systems highlighted and anomaly indicators on Safety Instrumented Systems

Cybersecurity

Triton/TRISIS: When Attackers Target Industrial Safety Systems

Triton/TRISIS is the first documented malware designed to disable Safety Instrumented Systems — the systems that prevent physical industrial accidents. Its impact goes beyond the targeted plant: it changes the perimeter of what must be monitored.

5 min read
MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna