Skip to content

Topic

cybersecurity

All articles on cybersecurity.

OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read
Industrial OT and IoT devices subject to the obligations of the Cyber Resilience Act

Regulations

Cyber Resilience Act: What Changes for OT and IoT Device Manufacturers

The Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. For OT and IoT device makers, the compliance scope is broad and the deadlines are approaching.

3 min read
Vulnerability management dashboard showing CVE and EPSS scores on an industrial OT system screen

Cybersecurity

CVE and EPSS in OT Environments: Which Vulnerabilities to Fix When You Can't Patch Everything

Patching everything in an OT environment is impossible. CVSS alone is not enough to set priorities. EPSS adds the missing dimension: the probability that a vulnerability is being actively exploited today.

6 min read
Industrial HMI login screen with the password field highlighted, a manufacturing plant in the background

Cybersecurity

Default credentials in OT systems: a more widespread problem than you might think

Admin/admin, 1234, the vendor's factory credentials: how many OT installations still have access protected by default passwords? More than you would expect. How it happens, how attackers find it, and how to fix it without stopping production.

6 min read
Flat industrial OT network without segmentation, with heterogeneous devices and undocumented connections

Cybersecurity

Flat OT Networks: Why Most Factories Don't Know What's on Their Network

In Italian manufacturing SMEs the OT network is often a flat network with no up-to-date inventory. Unknown devices, undocumented expansions, knowledge held only in the technician's head: any industrial security project starts with understanding what's on the network.

6 min read
Architectural diagram of an Industrial DMZ with a dual-homed firewall, historian replica and jump server between the IT network and the OT network

Cybersecurity

Industrial DMZ: How to Design the Boundary Zone Between IT and OT Networks

The industrial DMZ is the architectural layer that separates IT and OT and manages data flows between the two worlds. Designing it well is the difference between a secure connection and a direct path to the heart of the production network.

5 min read
Industrial network diagram with colored security zones and conduits between them

Compliance

IEC 62443 zones and conduits: how to apply it to a real plant without a year of consulting

IEC 62443 is often seen as out of reach for SMEs. Yet zones and conduits are practical tools you can apply to real plants, starting from visibility and reaching formal segmentation step by step.

5 min read
Network diagram showing an attacker's path from the IT segment to the OT segment through jump servers and industrial networks

Cybersecurity

How Attackers Cross the IT-OT Boundary: Techniques and Detection Signals

The pivot from IT into the OT network is the critical phase of nearly every documented industrial attack. Understanding the techniques used to cross this boundary is the first step to detecting it early.

6 min read
Matrix diagram of the MITRE ATT&CK for ICS framework with techniques highlighted over an industrial SCADA background

Cybersecurity

MITRE ATT&CK for ICS: How to Use It to Build Concrete Detection Rules

MITRE ATT&CK for ICS is not a document to skim once and file away. Turning its techniques into concrete detection rules means knowing what you can really see on your network and what stays out of reach without endpoint visibility.

5 min read
OT network diagram with a passive sensor on a TAP and an out-of-band monitoring architecture

Cybersecurity OT

NDR for OT Environments: Why Passive Monitoring Is the Only Safe Architecture

Placing an inline monitoring system between SCADA and PLC introduces latency that industrial systems cannot tolerate. The right answer is passive out-of-band monitoring, with isolation and network changes as the response tool.

5 min read
Audit document with technical evidence and OT system logs on screen

Compliance

How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts

NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.

6 min read
NIS2 notification timeline diagram showing the 24-hour and 72-hour windows, evidence documents and CSIRT-IT contacts

Cybersecurity

OT incident notification under NIS2: obligations, timelines and what to have ready before it happens

NIS2 sets tight deadlines for notifying significant incidents: 24 hours for the early warning, 72 hours for the detailed notification. In OT, being ready to meet them takes preparation that starts long before the incident.

6 min read
NIS2 compliance checklist against an industrial backdrop with control equipment

Compliance

NIS2 for a Manufacturing SME: a Practical Checklist Without Getting Lost in Bureaucracy

NIS2 is not just for large companies. Manufacturing SMEs within scope have concrete obligations: OT asset inventory, vulnerability management, detection, incident notification. A practical checklist.

5 min read
Diagram of the six NIST CSF 2.0 functions mapped onto an industrial plant

Compliance

NIST CSF 2.0 Applied to OT: Using It as a Roadmap for Manufacturing SMEs

NIST CSF 2.0 adds the Govern function to the original five. How to map OT capabilities onto the framework's six functions and use it as a self-assessment tool and roadmap to prioritize industrial security investments.

7 min read
Architectural diagram of OPC-UA servers with indicators of misconfigured security settings, certificates and anonymous sessions highlighted

Cybersecurity

OPC-UA: The Most Widely Used OT Protocol and Its Most Common Security Problems

OPC-UA is the de facto standard for communication in modern SCADA systems, but it is often deployed with degraded security settings for legacy client compatibility. Here is what shows up in the traffic and what an attacker can exploit.

6 min read
Operational resilience diagram with the prevention-detection-response-recovery cycle

Business Continuity

Operational Resilience and Cybersecurity: Two Sides of the Same Coin in Critical Infrastructure

Operational resilience and cybersecurity are not separate programs: one without the other is incomplete. How to integrate ISO 22301 and IEC 62443 into a coherent approach for critical infrastructure.

4 min read
OSINT search on Shodan for exposed industrial OT systems with Modbus protocols and HMI interfaces

Cybersecurity

OSINT on Industrial Plants: What Attackers Find Before You Do

Before launching an attack, threat actors look for publicly available information about their targets. Shodan, Censys and other OSINT tools can find OT systems exposed on the internet in seconds. Understanding what they see is the first step to reducing your own exposure.

6 min read
Industrial OT network assessment with passive traffic analysis and ICS device profiling

Cybersecurity

How an OT Assessment Is Conducted: Phases, Methods and What You Really Find

An OT network assessment is not a vulnerability scan run on corporate IT. Different methodology, different risks, and often surprising results: here is what to expect from a properly conducted industrial assessment.

6 min read
Dashboard with OT security KPIs and KRIs for a board presentation, trend charts and industrial risk traffic lights

Cybersecurity

OT Metrics for the Board: Turning Industrial Security into Decision-Ready Numbers

Management wants numbers. But which OT metrics communicate real risk instead of mere compliance? How to build a dashboard of KPIs and KRIs that speaks of potential downtime, not checklists.

6 min read
Robotic automotive assembly line with KUKA arms in an industrial setting

Cybersecurity

OT Cybersecurity in Automotive Manufacturing: Robotic Lines and Supply Chains Under Attack

Automotive is among the sectors most exposed to OT attacks: robotic lines with proprietary protocols, MES/ERP integration and vendor remote access create a wide, hard-to-control attack surface.

5 min read
OT cybersecurity business case with ROI and investment roadmap

Risk Management

The OT Cybersecurity Budget: How to Build the Business Case and Measure ROI

The OT cybersecurity budget is often an afterthought next to IT, even when operational risk is far higher. How to build a convincing business case and measure the ROI of industrial security investments.

4 min read
Petrochemical plant with industrial piping and control valves

Cybersecurity

OT Cybersecurity in the Chemical Industry: Where Cyber Security and Physical Safety Meet

In the chemical industry a cyber incident can cause the release of hazardous substances, explosions and harm to people. Safety/security convergence is no abstraction: the Triton attack on Safety Instrumented Systems proved the last physical line of defense can be compromised.

5 min read
Automated food & beverage production line with conveyor belts and control systems

Cybersecurity

OT cybersecurity in food & beverage: traceability, digital HACCP and production lines under attack

Italian food & beverage has a wide, poorly protected OT attack surface: dosing lines, digital HACCP systems, connected cold rooms for traceability. An OT attack here can compromise food safety and brand reputation.

5 min read
Waterworks SCADA control room with monitoring screens and geographic maps

Cybersecurity

OT Cybersecurity for Local Utilities: Waterworks, Power Grids and Waste Plants with Zero Internal Resources

Local utilities (water operators, power distributors, waste treatment plants) are NIS2-regulated entities with security resources close to zero. SCADA systems 15 to 20 years old connected to the internet, run by a single technician: how to set up OT security from this starting point.

6 min read
Incident response team handling an incident in an industrial OT environment

Cybersecurity

Incident response in OT environments: the critical differences from IT

IT incident response playbooks do not work in OT. Isolating a compromised system can halt production; powering off a device can cause physical damage. How to build OT IR that actually works.

4 min read
Legacy industrial control panel with dated HMI and PLC in an Italian manufacturing plant

Cybersecurity

OT Systems That Cannot Be Updated: Compensating Controls and Risk Reduction

PLCs with 2008 firmware, HMIs running embedded Windows XP, systems that cannot be touched by contract: the reality of Italian plants. How to manage risk when patching is not an option.

5 min read
Reconstructing an industrial OT network topology from passive traffic monitoring with a PLC SCADA HMI dependency map

Cybersecurity

OT Network Topology: How to Reconstruct It When No Documentation Exists

OT network topology often lives only in a technician's head, or in a 2014 diagram that was never updated. Rebuilding it from scratch with passive traffic monitoring: why it is necessary and how it is done in practice.

6 min read
Four-level chart representing OT security maturity, from blind to operational, with icons for assets, vulnerabilities and detection

Cybersecurity

OT Security Maturity Model: From Zero Visibility to Advanced Detection

A practical four-level framework to assess OT security maturity and build a concrete roadmap. Each level has clear prerequisites, measurable goals and a defined next step.

6 min read
Integration diagram between OT monitoring sensors and a SIEM platform with a SOC, showing normalized data flows and correlation of IT and OT events

Cybersecurity

Integrating OT Monitoring with Existing SIEM and SOC: Data, Formats and Added Value

Many companies already run a SIEM or a managed SOC, but these systems are blind to OT. How to feed OT monitoring events into the SOC, which formats to use and which alerts to escalate.

6 min read
SOC with OT network monitoring sensors and industrial analysis dashboard

Cybersecurity

Building a SOC for OT Environments: Requirements, Tools, and Operational Metrics

An IT SOC cannot see OT environments. Building monitoring capabilities for industrial networks requires different sensors, different skills, and playbooks specific to OT protocols and threats.

4 min read
Automated warehouse with AS/RS systems, vertical racking and AGVs on the floor

Cybersecurity

OT cybersecurity in logistics and automated warehouses: heterogeneous systems and high turnover

Modern automated warehouses run complex OT networks: a WMS wired to the automation, heterogeneous PLCs from many vendors, AGVs and mixed protocols. High turnover and frequent vendor work break segmentation, and downtime hits the supply chain instantly.

6 min read
Vulnerability management dashboard for OT systems with contextualized scoring

Cybersecurity

Vulnerability Management in OT: Why Traditional Patching Does Not Work

In OT environments, traditional patch management is often impossible. Legacy systems, certifications to maintain, very rare maintenance windows: how to build a VM program that actually works.

4 min read
Industrial network map with indicators of compromise and lateral movement from IT to OT

Cybersecurity

Sandworm and Manufacturing: State APTs Do Not Target Only Large Infrastructure

Sandworm is known for shutting off the lights in Ukraine and launching NotPetya. But its techniques are being replicated against European manufacturing, often as collateral damage. How an APT attack on an industrial OT network works and why SMEs are within range too.

5 min read
SCADA historian server in an industrial server room with connections between the corporate IT network and the OT process network

Cybersecurity

The SCADA Historian as a Lateral Attack Vector from IT to OT

Industrial process historians collect data from PLCs and expose it to business systems. This makes them a natural bridge between IT and OT, and a prime vector for lateral movement.

6 min read
Industrial OT network with unauthorized devices connected to switches and PLCs in a manufacturing plant

Cybersecurity

Shadow Devices in OT Networks: The Assets Nobody Knows They Have

Maintenance laptops left connected, 4G modems installed by vendors, uncatalogued switches: shadow devices in OT networks are more common than you think and represent concrete blind spots for security.

5 min read
Supply chain attack diagram against industrial OT environments

Cybersecurity

Supply Chain Attacks in OT: The Vector That Bypasses the Physical Perimeter

Supply chain attacks are among the hardest to detect and prevent. In industrial OT, the supplier chain is often long, poorly monitored, and holds privileged access to control systems.

3 min read
Technical diagram of hardware TAP and SPAN port on an industrial switch in an OT Purdue network

Cybersecurity

TAP vs SPAN Port in OT Environments: How to Choose Where to Place Sensors

Passive OT traffic monitoring depends on where and how traffic is captured. Hardware TAPs and SPAN ports have very different characteristics in industrial environments: a wrong choice means incomplete data or operational risks.

6 min read
Industrial plant control room with safety systems highlighted and anomaly indicators on Safety Instrumented Systems

Cybersecurity

Triton/TRISIS: When Attackers Target Industrial Safety Systems

Triton/TRISIS is the first documented malware designed to disable Safety Instrumented Systems — the systems that prevent physical industrial accidents. Its impact goes beyond the targeted plant: it changes the perimeter of what must be monitored.

5 min read
Control panel of an industrial plant showing NIS2 compliance indicators and an OT asset map

Regulations

NIS2 Is Here: Now What? An Operational Guide to Your Next Steps

The NIS2 directive has been transposed: what matters now is what to do in practice. From entity classification to OT asset visibility, an operational checklist.

2 min read
A board of directors meeting discussing an operational and cyber risk chart

Risk Management

Talking About Operational Cyber Risk With the Board

How to translate cyber risk on industrial systems into business language and bring it to the boardroom table.

3 min read
MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna
© 2026 MON5 · All rights reserved