Skip to content

Topic

OT

All articles on OT.

OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read
Comparison of OT monitoring platforms on an ICS network with evaluation criteria side by side

Cybersecurity

What Is the Best OT Cybersecurity Platform for ICS Networks? Selection Criteria

There is no single best OT cybersecurity platform — there is the right one for your ICS network, your protocols, and your maturity level. Concrete criteria for choosing without being guided by marketing.

4 min read
Industrial OT and IoT devices subject to the obligations of the Cyber Resilience Act

Regulations

Cyber Resilience Act: What Changes for OT and IoT Device Manufacturers

The Cyber Resilience Act introduces security obligations for manufacturers of products with digital elements. For OT and IoT device makers, the compliance scope is broad and the deadlines are approaching.

3 min read
Vulnerability management dashboard showing CVE and EPSS scores on an industrial OT system screen

Cybersecurity

CVE and EPSS in OT Environments: Which Vulnerabilities to Fix When You Can't Patch Everything

Patching everything in an OT environment is impossible. CVSS alone is not enough to set priorities. EPSS adds the missing dimension: the probability that a vulnerability is being actively exploited today.

6 min read
Cyber risk assessment for insurance policies in industrial OT environments

Risk Management

Cyber Insurance in Industry: Technical Requirements and How to Prepare for the Assessment

Insurers increasingly demand specific technical controls for OT environments. What they assess, how it affects the premium and how to prepare for the insurance assessment.

4 min read
Industrial HMI login screen with the password field highlighted, a manufacturing plant in the background

Cybersecurity

Default credentials in OT systems: a more widespread problem than you might think

Admin/admin, 1234, the vendor's factory credentials: how many OT installations still have access protected by default passwords? More than you would expect. How it happens, how attackers find it, and how to fix it without stopping production.

6 min read
Connected medical devices in a hospital environment monitored for security

Cybersecurity

OT Cybersecurity in Healthcare: Connected Medical Devices, Hospitals and NIS2

Hospitals are OT environments in their own right: thousands of connected medical devices, often unmanageable with traditional IT tools. How to secure the IoMT fleet under NIS2.

3 min read
Industrial protocols Modbus, DNP3, and OPC UA with vulnerability analysis

Cybersecurity

Vulnerabilities in Industrial Protocols: Modbus, DNP3, OPC UA, and the Hidden Risks

Modbus, DNP3, OPC UA, and PROFINET underpin industrial communications. Designed for reliability in closed networks, they carry intrinsic vulnerabilities that become critical in increasingly connected environments.

4 min read
Audit document with technical evidence and OT system logs on screen

Compliance

How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts

NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.

6 min read
Oil & gas facility with connected process control and safety systems

Cybersecurity

OT cybersecurity in oil & gas: refineries, pipelines and terminals under pressure

In oil & gas, cybersecurity is intertwined with process safety: a cyber incident can become a physical one. Risks, safety systems and strategies for refineries, pipelines and terminals.

3 min read
Industrial OT network assessment with passive traffic analysis and ICS device profiling

Cybersecurity

How an OT Assessment Is Conducted: Phases, Methods and What You Really Find

An OT network assessment is not a vulnerability scan run on corporate IT. Different methodology, different risks, and often surprising results: here is what to expect from a properly conducted industrial assessment.

6 min read
Restoring a PLC configuration from a golden image in an industrial plant

Business Continuity

Backup and Recovery in OT: PLC Golden Images and Industrial Disaster Recovery

When a controller fails or ransomware hits, only one question matters: how long until you restart? In OT, backup is not copying files, it is being able to rebuild a plant.

3 min read
Robotic automotive assembly line with KUKA arms in an industrial setting

Cybersecurity

OT Cybersecurity in Automotive Manufacturing: Robotic Lines and Supply Chains Under Attack

Automotive is among the sectors most exposed to OT attacks: robotic lines with proprietary protocols, MES/ERP integration and vendor remote access create a wide, hard-to-control attack surface.

5 min read
OT cybersecurity business case with ROI and investment roadmap

Risk Management

The OT Cybersecurity Budget: How to Build the Business Case and Measure ROI

The OT cybersecurity budget is often an afterthought next to IT, even when operational risk is far higher. How to build a convincing business case and measure the ROI of industrial security investments.

4 min read
Petrochemical plant with industrial piping and control valves

Cybersecurity

OT Cybersecurity in the Chemical Industry: Where Cyber Security and Physical Safety Meet

In the chemical industry a cyber incident can cause the release of hazardous substances, explosions and harm to people. Safety/security convergence is no abstraction: the Triton attack on Safety Instrumented Systems proved the last physical line of defense can be compromised.

5 min read
Automated food & beverage production line with conveyor belts and control systems

Cybersecurity

OT cybersecurity in food & beverage: traceability, digital HACCP and production lines under attack

Italian food & beverage has a wide, poorly protected OT attack surface: dosing lines, digital HACCP systems, connected cold rooms for traceability. An OT attack here can compromise food safety and brand reputation.

5 min read
Automated warehouse with AS/RS systems, vertical racking and AGVs on the floor

Cybersecurity

OT cybersecurity in logistics and automated warehouses: heterogeneous systems and high turnover

Modern automated warehouses run complex OT networks: a WMS wired to the automation, heterogeneous PLCs from many vendors, AGVs and mixed protocols. High turnover and frequent vendor work break segmentation, and downtime hits the supply chain instantly.

6 min read
Legacy industrial control panel with dated HMI and PLC in an Italian manufacturing plant

Cybersecurity

OT Systems That Cannot Be Updated: Compensating Controls and Risk Reduction

PLCs with 2008 firmware, HMIs running embedded Windows XP, systems that cannot be touched by contract: the reality of Italian plants. How to manage risk when patching is not an option.

5 min read
SOC with OT network monitoring sensors and industrial analysis dashboard

Cybersecurity

Building a SOC for OT Environments: Requirements, Tools, and Operational Metrics

An IT SOC cannot see OT environments. Building monitoring capabilities for industrial networks requires different sensors, different skills, and playbooks specific to OT protocols and threats.

4 min read
Vulnerability management dashboard for OT systems with contextualized scoring

Cybersecurity

Vulnerability Management in OT: Why Traditional Patching Does Not Work

In OT environments, traditional patch management is often impossible. Legacy systems, certifications to maintain, very rare maintenance windows: how to build a VM program that actually works.

4 min read
Pharmaceutical production line with OT control systems and GMP validation

Compliance

Cybersecurity in Pharmaceutical Manufacturing: OT, GMP and Converging FDA Regulations

Pharma faces strict quality regulations that now overlap with OT cybersecurity needs. How to integrate GMP, FDA 21 CFR Part 11 and IEC 62443 into one coherent program.

3 min read
Railway network architecture with SCADA and signalling systems

Cybersecurity

Railway Cybersecurity: Specific Challenges and a Regulatory Approach

Railway networks are becoming more connected and more exposed. An analysis of systems at risk, the regulatory framework and defence strategies for an often overlooked critical infrastructure.

3 min read
Secure remote access in OT environments: attack vectors and defensive controls

Cybersecurity

Secure remote access in OT environments: the most underestimated attack vector

Remote access to OT environments exploded after the pandemic, but security practices never caught up. Here is why it became the attackers' favorite entry vector.

4 min read
Industrial OT network with unauthorized devices connected to switches and PLCs in a manufacturing plant

Cybersecurity

Shadow Devices in OT Networks: The Assets Nobody Knows They Have

Maintenance laptops left connected, 4G modems installed by vendors, uncatalogued switches: shadow devices in OT networks are more common than you think and represent concrete blind spots for security.

5 min read
Industrial data center with racks, BMS, and cooling systems

Cybersecurity

OT Security in Industrial Data Centers: BMS, DCIM, and Operational Continuity

Data centers are cyber-physical environments with OT systems often ignored by IT security programs. BMS, PDUs, cooling systems, and UPS units are critical assets with real vulnerabilities.

3 min read
Supply chain attack diagram against industrial OT environments

Cybersecurity

Supply Chain Attacks in OT: The Vector That Bypasses the Physical Perimeter

Supply chain attacks are among the hardest to detect and prevent. In industrial OT, the supplier chain is often long, poorly monitored, and holds privileged access to control systems.

3 min read
Technical diagram of hardware TAP and SPAN port on an industrial switch in an OT Purdue network

Cybersecurity

TAP vs SPAN Port in OT Environments: How to Choose Where to Place Sensors

Passive OT traffic monitoring depends on where and how traffic is captured. Hardware TAPs and SPAN ports have very different characteristics in industrial environments: a wrong choice means incomplete data or operational risks.

6 min read
Industrial plant control room with safety systems highlighted and anomaly indicators on Safety Instrumented Systems

Cybersecurity

Triton/TRISIS: When Attackers Target Industrial Safety Systems

Triton/TRISIS is the first documented malware designed to disable Safety Instrumented Systems — the systems that prevent physical industrial accidents. Its impact goes beyond the targeted plant: it changes the perimeter of what must be monitored.

5 min read
Water treatment plant with SCADA systems and field IoT sensors

Cybersecurity

Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure

Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.

3 min read
Zero Trust architectural diagram applied to an industrial OT network

Cybersecurity

Zero Trust in OT: Applicable Principles and Real Limits in Industrial Environments

Zero Trust is the security framework of the moment, but applying it to OT environments requires pragmatism: here is what actually works and where the model shows its limits.

4 min read
Abstract illustration: artificial intelligence and vulnerability discovery in OT systems

Cybersecurity

AI changed vulnerability discovery: but there is an OT gap you cannot ignore

New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

2 min read
Monitoring platform screen mapping OT and IoT assets in an industrial plant

Cybersecurity

OT/IoT Asset Visibility: Why It Is the First Pillar of Security

You cannot protect what you cannot see: complete OT/IoT asset visibility is the foundation of every industrial cybersecurity strategy.

2 min read
Screen showing malware code and AI symbols highlighting automated payload generation

Cybersecurity

AI in offensive cybersecurity: from payloads to APT operations

Artificial intelligence does not create autonomous threats, but it makes attacks faster and more variable. What changes for those defending OT environments.

2 min read
Representation of a compromised industrial PLC affected by a chain of CODESYS vulnerabilities

Cybersecurity

CODESYS Under Attack: Three Chained Flaws to Plant a Backdoor in a PLC

Three chained CVEs in the CODESYS Control runtime let a Service user replace the PLC application with a backdoored version and run code as root.

3 min read
Power grid control panel in the dark during a blackout

Cybersecurity

The Iberian Blackout: Lessons for Critical Energy Infrastructure

The blackout that brought Spain and Portugal to a standstill shows how fragile energy grids are and why visibility into OT assets is decisive.

2 min read
Industrial network diagram with sensors mapping PLCs, HMIs and OT devices across the levels of the Purdue model

Cybersecurity

How to Achieve Complete OT/ICS Asset Visibility

A hands-on guide to building a complete OT/ICS asset inventory: sensors, passive and active discovery, DPI and behavioral baselines without stopping production.

2 min read
WAGO industrial PLC controller with status indicators and field cables connected in an electrical panel

Cybersecurity

WAGO PLC Vulnerabilities: The Chain That Leads to Full Control

Eight vulnerabilities in the WAGO 750-8216 PLC can be chained to obtain root privileges on the device. Technical analysis and plant impact.

2 min read
Industrial SOC analyst working alongside an AI assistant that filters alerts and anomalies on OT systems

Cybersecurity

Skills Gap in OT Cybersecurity: Leaving to AI What It Does Best

Flat budgets and too few, half-expert analysts: how artificial intelligence can close the skills gap in OT security without replacing people.

2 min read
MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna