critical-infrastructure
Safeguard articles tagged "critical-infrastructure" — guides, analysis, and best practices for software supply chain and application security.
24 articles
Colonial Pipeline (2021): A Single Compromised VPN Password
A factual retrospective on the May 2021 Colonial Pipeline ransomware attack, traced to a single compromised VPN account password with no multi-factor authentication, and its effect on U.S. critical infrastructure fuel supply.
Mining Security: Autonomous Haul Trucks and the Problem of Remote-Site Incident Response
Mining sites run some of the most physically remote OT in any industry, where incident response measured in days changes what a realistic security architecture has to assume.
Precision Agriculture Security: An Industrial Control Problem With No Regulatory Framework Yet
GPS-guided tractors, sensor networks, and cloud farm management platforms have made agriculture an IoT and ICS security question — without the sector-specific framework other critical industries have.
Water Utility Cybersecurity: Securing SCADA When Most Operators Are Small
Water sector cybersecurity oversight has to account for an operator population that ranges from major metro utilities to small municipal districts with no dedicated security staff.
CFATS and Chemical Facility Cybersecurity: Where Safety Instrumented Systems Fit
The Chemical Facility Anti-Terrorism Standards program pairs cybersecurity with physical and personnel security in one framework. Why safety instrumented systems, not just control systems, are the real stakes.
Oil and Gas Pipeline Cybersecurity: TSA Directives Meet IEC 62443
Mandatory TSA cybersecurity directives since 2021, layered on IEC 62443's technical framework — what pipeline operators actually need to demonstrate, and where IT/OT boundary uncertainty causes real operational impact.
Maritime Cybersecurity: What the IMO's ISM Code Requirement Actually Asks Vessel Operators to Do
Since 2021, cyber risk management has been a required part of a ship's Safety Management System under the ISM Code. What that means for onboard OT and how auditors actually evaluate it.
Software supply chain security for telecom network infras...
Why telecom network software supply chain security demands continuous SBOMs and vendor risk oversight — from 5G base stations to core networks — and how carriers are closing the gap.
NERC CIP-013 compliance and software supply chain risk ma...
NERC CIP-013 turned vendor risk management into a mandatory grid compliance obligation. Here's what it requires, who it covers, and how to build an audit-ready supply chain plan.
SBOM requirements for industrial control systems (ICS/SCADA)
ICS/SCADA SBOM requirements are colliding with 20-year-old control systems that predate software transparency mandates. Here's what's required, why, and how to close the gap.
Securing smart grid and advanced metering infrastructure ...
How AMI firmware, smart meters, and grid modernization projects create software supply chain risk for utilities — and what closing that gap actually requires.
Third-party risk management for OT/ICS vendors in utilities
A step-by-step guide to OT ICS vendor risk management for utilities: assessing, auditing, and monitoring SCADA and industrial control system vendors.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.