enaxy.bsky.social
@enaxy.bsky.social
The wrong assessment can give you the wrong picture of OT risk.

Our new series explores threat and vulnerability assessments in OT starting with how vulnerability assessments can identify risks.

Intro: enaxy.com/2026/10/thre...

1st post: enaxy.com/2026/10/vuln...

#OTSecurity #ICS #Enaxy
October 7, 2026 at 8:55 PM
Not every OT threat has to break in. Some already have access.

Juan Negrete explores why insider risk goes beyond malicious intent and how mistakes, misconfigurations, and unmanaged access can impact OT.

enaxy.com/2026/09/myth...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 30, 2026 at 5:07 PM
How do you improve network segmentation when you can’t start from scratch?

Brandon Workentin explores practical ways to strengthen segmentation in brownfield OT environments without putting operations at risk.

enaxy.com/2026/09/impl...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 23, 2026 at 6:03 PM
Network segmentation sounds simple, until you have to make it work in OT.

Juan Negrete explores how to strengthen segmentation without disrupting operations and the common pitfalls to avoid.

enaxy.com/2026/09/netw...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 17, 2026 at 2:57 PM
Your OT environment may be secure—but what about your vendors?

Kyle Byrum explores how third-party and supply chain compromises can create operational risk and how organizations can reduce exposure.

enaxy.com/2026/09/cybe...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 9, 2026 at 9:11 PM
When everything is “critical,” what gets patched first?

Brandon Workentin explores how CVSS, EPSS, and KEV can help OT teams prioritize vulnerabilities using real operational context.

enaxy.com/2026/09/beyo...

#OTSecurity #ICS #Cybersecurity #Enaxy
September 2, 2026 at 8:32 PM
In OT, cyber incidents don't just affect data, they can impact operations.

Juan Negrete explores why cyber and operational risk are deeply connected and how organizations can better prepare.

enaxy.com/2026/08/myth...

#OTSecurity #ICS #Cybersecurity #Enaxy
August 26, 2026 at 8:07 PM
Privileged access looks different in OT.

Brandon Workentin explores how Privileged Access Workstations can help secure OT identities and engineering workflows without getting in the way of operations.

enaxy.com/2026/08/usin...

#OTSecurity #ICS #Cybersecurity #Enaxy
August 19, 2026 at 5:25 PM
Backups are only part of disaster recovery.

Kyle Byrum explores why recovering industrial operations requires IT and OT teams to plan, prioritize, and test together.

enaxy.com/2026/08/cybe...

#OTSecurity #ICS #Cybersecurity #Enaxy
August 12, 2026 at 5:38 PM
One firewall isn't always enough.

Juan Negrete explores when a multi-firewall architecture makes sense for OT/ICS environments and how layered segmentation can improve security and resilience.

enaxy.com/2026/08/deci...

#OTSecurity #ICS #Cybersecurity #Enaxy
August 5, 2026 at 8:40 PM
"We can't patch our OT systems."

Brandon Workentin explores why effective OT patch management isn't about patching everything, it's about balancing cybersecurity with operational reliability.

enaxy.com/2026/07/myth...

#OTSecurity #ICS #Cybersecurity #Enaxy
July 29, 2026 at 3:55 PM
Frameworks don't stop attacks but they can reveal where your visibility falls short.

Brandon Workentin explores how MITRE DeTT&CT helps organizations evaluate detection coverage and strengthen OT/ICS security.

enaxy.com/2026/07/usin...

#OTSecurity #ICS #Cybersecurity #Enaxy
July 22, 2026 at 5:27 PM
We're launching a new blog series on Cyber and Operational Risk Convergence.

The first post explores how AI tools are changing not just cybersecurity, but operational risk as well.

Series intro: enaxy.com/2026/07/intr...

First post: enaxy.com/2026/07/cybe...

#Cybersecurity #OTSecurity #Enaxy
July 15, 2026 at 10:16 PM
You can't detect what you can't see.

Brandon Workentin explores how NERC CIP-015 is driving greater internal network visibility and why it's becoming a key part of OT cybersecurity.

Read: enaxy.com/2026/07/unde...

#OTSecurity #ICS #Cybersecurity #Enaxy
July 8, 2026 at 3:53 PM
You don't need a zero-day exploit to compromise a PLC.

Kyle Byrum looks at CISA's latest advisory and why exposed PLCs, insecure remote access, and poor visibility continue to put OT environments at risk.

Read 👉 enaxy.com/2026/07/iran...

#OTSecurity #ICS #Cybersecurity #Enaxy
July 1, 2026 at 7:52 PM
“OT cybersecurity is IT’s job.”

Juan Negrete explores why that assumption falls short and why effective OT security depends on collaboration between operations, engineering, IT, and security teams.

Read enaxy.com/2026/06/myth...

#OTSecurity #ICS #Cybersecurity #CyberMyths #Enaxy
June 24, 2026 at 8:59 PM
OT cybersecurity just received a major vote of confidence.

Dennis Distler explores what Accenture’s $4.175B acquisition of Dragos, runZero, and NetRise means for the future of the OT cybersecurity market.

enaxy.com/2026/06/acce...

#OTSecurity #ICS #Cybersecurity #Enaxy
June 22, 2026 at 4:29 PM
Zero Trust looks different in OT.

Kyle Byrum explores the DoD’s roadmap for implementing Zero Trust in industrial environments and why security has to work with operations, not against them.

enaxy.com/2026/06/dod-...

#OTSecurity #ICS #Cybersecurity #Enaxy
June 17, 2026 at 8:28 PM
Dedicated OT SOC or converged IT/OT SOC?

Brandon Workentin explores the strengths and challenges of both approaches and why OT incident response requires a different mindset.

enaxy.com/2026/06/dedi...

#OTSecurity #ICS #Cybersecurity #Enaxy
June 10, 2026 at 3:58 PM
What does an OT SOC analyst actually look like?

Juan Negrete explores the unique blend of cybersecurity, industrial operations, and safety knowledge required to defend OT environments.

enaxy.com/2026/06/what...

#OTSecurity #ICS #Cybersecurity #Enaxy
June 3, 2026 at 8:56 PM
Another OT cybersecurity myth worth challenging: “Compliance = Security.”

We explore why passing an audit doesn’t necessarily mean an environment is resilient and where the gap between compliance and security shows up.

Read enaxy.com/2026/05/myth...

#OTSecurity #Cybersecurity #Compliance #Enaxy
May 27, 2026 at 7:03 PM
Everyone knows Telnet is insecure, yet it still persists across OT environments.

We look at why legacy protocols are so difficult to remove and what organizations can do to reduce risk when replacement isn’t realistic.

Read enaxy.com/2026/05/teln...

#OTSecurity #ICS #LegacySystems #Enaxy
May 20, 2026 at 5:09 PM
“Just use MFA” sounds simple until you’re dealing with OT systems.

In Part 2 of this series, we explore what actually works for password and credential management in OT/ICS environments without disrupting operations.

Read 👉 enaxy.com/2026/05/how-...

#OTSecurity #ICS #Cybersecurity #MFA #Enaxy
May 13, 2026 at 4:08 PM
Password management in OT/ICS isn’t as simple as it sounds.

What works in IT doesn’t always translate to industrial environments. Juan Negrete explores why and what it looks like in practice.

Read enaxy.com/2026/05/why-...

#OTSecurity #ICS #Cybersecurity #Enaxy
May 6, 2026 at 4:02 PM
“Legacy OT systems are too old to be targeted.”

Not quite.

In our latest OT Cybersecurity Myths post, we explain why older systems are often more attractive to attackers—and how to reduce risk without replacing everything.

Read 👉 enaxy.com/2026/04/myth...

#OTSecurity #ICS #Cybersecurity #Enaxy
April 29, 2026 at 6:33 PM