ot-security
Safeguard articles tagged "ot-security" — guides, analysis, and best practices for software supply chain and application security.
14 articles
Five Years of DELMIA Apriso Releases Share the Same Two Confirmed-Exploited Bugs
A missing authorization flaw and a code injection vulnerability in Dassault Systèmes' manufacturing execution system span every release from 2020 through 2025.
Building Automation Security: The OT Category Facilities Teams Deploy Outside IT's View
HVAC, access control, and elevator systems increasingly share a building's IP network — procured and maintained by facilities teams with limited coordination with conventional IT security.
Mining Security: Autonomous Haul Trucks and the Problem of Remote-Site Incident Response
Mining sites run some of the most physically remote OT in any industry, where incident response measured in days changes what a realistic security architecture has to assume.
Industrial Robotics Security: When ROS Meets the Factory Floor
Robots built on research-oriented frameworks like ROS bring a larger, more dynamic behavioral envelope than traditional PLCs — and collaborative robots remove the physical safety cage that once contained failures.
Water Utility Cybersecurity: Securing SCADA When Most Operators Are Small
Water sector cybersecurity oversight has to account for an operator population that ranges from major metro utilities to small municipal districts with no dedicated security staff.
Semiconductor Fab Security: Where Precision Manufacturing Meets Export Control
Fab operational technology tuned to nanometer tolerances, IP worth more than any ransom, and an expanding export control regime — what makes semiconductor security a distinct discipline.
CFATS and Chemical Facility Cybersecurity: Where Safety Instrumented Systems Fit
The Chemical Facility Anti-Terrorism Standards program pairs cybersecurity with physical and personnel security in one framework. Why safety instrumented systems, not just control systems, are the real stakes.
Oil and Gas Pipeline Cybersecurity: TSA Directives Meet IEC 62443
Mandatory TSA cybersecurity directives since 2021, layered on IEC 62443's technical framework — what pipeline operators actually need to demonstrate, and where IT/OT boundary uncertainty causes real operational impact.
Maritime Cybersecurity: What the IMO's ISM Code Requirement Actually Asks Vessel Operators to Do
Since 2021, cyber risk management has been a required part of a ship's Safety Management System under the ISM Code. What that means for onboard OT and how auditors actually evaluate it.
Lantronix EDS5000's Failed-Login Logging Was Itself the Vulnerability
CVE-2025-67038 triggers on a failed login attempt alone: the device server shells out to write a log entry, concatenating the attacker-supplied username unsanitised into the command.
SBOM requirements for industrial control systems (ICS/SCADA)
ICS/SCADA SBOM requirements are colliding with 20-year-old control systems that predate software transparency mandates. Here's what's required, why, and how to close the gap.
Eppendorf BioFlo 320 Bioreactor: A Hard-Coded VNC Password Earns CVSS 9.8 (CISA ICSMA-26-146-01, May 2026)
CISA's May 26, 2026 medical advisory flags CVE-2026-7251, a hard-coded VNC password in all versions of the Eppendorf BioFlo 320 bioreactor. A remote attacker who reaches the device gets full control of cell-culture and bioprocess parameters. We break down the flaw and the fix.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.