Skip to content

Topic

SCADA

All articles on SCADA.

Comparison of OT monitoring platforms on an ICS network with evaluation criteria side by side

Cybersecurity

What Is the Best OT Cybersecurity Platform for ICS Networks? Selection Criteria

There is no single best OT cybersecurity platform — there is the right one for your ICS network, your protocols, and your maturity level. Concrete criteria for choosing without being guided by marketing.

4 min read
Industrial HMI login screen with the password field highlighted, a manufacturing plant in the background

Cybersecurity

Default credentials in OT systems: a more widespread problem than you might think

Admin/admin, 1234, the vendor's factory credentials: how many OT installations still have access protected by default passwords? More than you would expect. How it happens, how attackers find it, and how to fix it without stopping production.

6 min read
Architectural diagram of an Industrial DMZ with a dual-homed firewall, historian replica and jump server between the IT network and the OT network

Cybersecurity

Industrial DMZ: How to Design the Boundary Zone Between IT and OT Networks

The industrial DMZ is the architectural layer that separates IT and OT and manages data flows between the two worlds. Designing it well is the difference between a secure connection and a direct path to the heart of the production network.

5 min read
Network diagram showing an attacker's path from the IT segment to the OT segment through jump servers and industrial networks

Cybersecurity

How Attackers Cross the IT-OT Boundary: Techniques and Detection Signals

The pivot from IT into the OT network is the critical phase of nearly every documented industrial attack. Understanding the techniques used to cross this boundary is the first step to detecting it early.

6 min read
Matrix diagram of the MITRE ATT&CK for ICS framework with techniques highlighted over an industrial SCADA background

Cybersecurity

MITRE ATT&CK for ICS: How to Use It to Build Concrete Detection Rules

MITRE ATT&CK for ICS is not a document to skim once and file away. Turning its techniques into concrete detection rules means knowing what you can really see on your network and what stays out of reach without endpoint visibility.

5 min read
OT network diagram with a passive sensor on a TAP and an out-of-band monitoring architecture

Cybersecurity OT

NDR for OT Environments: Why Passive Monitoring Is the Only Safe Architecture

Placing an inline monitoring system between SCADA and PLC introduces latency that industrial systems cannot tolerate. The right answer is passive out-of-band monitoring, with isolation and network changes as the response tool.

5 min read
Oil & gas facility with connected process control and safety systems

Cybersecurity

OT cybersecurity in oil & gas: refineries, pipelines and terminals under pressure

In oil & gas, cybersecurity is intertwined with process safety: a cyber incident can become a physical one. Risks, safety systems and strategies for refineries, pipelines and terminals.

3 min read
Architectural diagram of OPC-UA servers with indicators of misconfigured security settings, certificates and anonymous sessions highlighted

Cybersecurity

OPC-UA: The Most Widely Used OT Protocol and Its Most Common Security Problems

OPC-UA is the de facto standard for communication in modern SCADA systems, but it is often deployed with degraded security settings for legacy client compatibility. Here is what shows up in the traffic and what an attacker can exploit.

6 min read
Waterworks SCADA control room with monitoring screens and geographic maps

Cybersecurity

OT Cybersecurity for Local Utilities: Waterworks, Power Grids and Waste Plants with Zero Internal Resources

Local utilities (water operators, power distributors, waste treatment plants) are NIS2-regulated entities with security resources close to zero. SCADA systems 15 to 20 years old connected to the internet, run by a single technician: how to set up OT security from this starting point.

6 min read
Legacy industrial control panel with dated HMI and PLC in an Italian manufacturing plant

Cybersecurity

OT Systems That Cannot Be Updated: Compensating Controls and Risk Reduction

PLCs with 2008 firmware, HMIs running embedded Windows XP, systems that cannot be touched by contract: the reality of Italian plants. How to manage risk when patching is not an option.

5 min read
Reconstructing an industrial OT network topology from passive traffic monitoring with a PLC SCADA HMI dependency map

Cybersecurity

OT Network Topology: How to Reconstruct It When No Documentation Exists

OT network topology often lives only in a technician's head, or in a 2014 diagram that was never updated. Rebuilding it from scratch with passive traffic monitoring: why it is necessary and how it is done in practice.

6 min read
SCADA historian server in an industrial server room with connections between the corporate IT network and the OT process network

Cybersecurity

The SCADA Historian as a Lateral Attack Vector from IT to OT

Industrial process historians collect data from PLCs and expose it to business systems. This makes them a natural bridge between IT and OT, and a prime vector for lateral movement.

6 min read
Technical diagram of hardware TAP and SPAN port on an industrial switch in an OT Purdue network

Cybersecurity

TAP vs SPAN Port in OT Environments: How to Choose Where to Place Sensors

Passive OT traffic monitoring depends on where and how traffic is captured. Hardware TAPs and SPAN ports have very different characteristics in industrial environments: a wrong choice means incomplete data or operational risks.

6 min read
Water treatment plant with SCADA systems and field IoT sensors

Cybersecurity

Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure

Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.

3 min read
Power grid control panel in the dark during a blackout

Cybersecurity

The Iberian Blackout: Lessons for Critical Energy Infrastructure

The blackout that brought Spain and Portugal to a standstill shows how fragile energy grids are and why visibility into OT assets is decisive.

2 min read
MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna
© 2026 MON5 · All rights reserved