Secure ICS OT 

@Secure_ICS_OT@infosec.exchange
458 Followers
245 Following
1,012 Posts

ICS/OT posts from a GICSP. ISA member working on ISA 62443 Certs. Canadian.

My posts are my own and are not a reflection of my place of work or employer.

Twitter: @Secure_ICS_OT

Bluesky: @secure-ics-ot.bsky.social

#ICS #OT #GICSP #IEC62443

JoinedNov 10, 2022
CertsGICSP, 62443 Cert 1 and 2.

Standardization is awesome and it helps reduce surface area and effort.

But you should not standardize equipment between ICS/OT and IT as you now share CVEs.

Think of it using the Swiss cheese model.

You would never expose a firewall management interface to the internet.

So don't expose an ICS/OT management interface to the Corporate network or internet.

IT and ICS/OT are not the same:

IT is concerned about data that is in databases.

ICS/OT is concerned about real time sensor data.

Canadian telecom hacked by suspected China state group

Maximum-security Cisco vulnerability was patched Oct. 2023 and exploited Feb. 2025.

Ars Technica
Jack White – Archbishop Harold Holmes (Official Video)

YouTube

Pro tip: For securing an ICS/OT.

Visit it and the people operating it.

×