Waterfall Security Solutions https://waterfall-security.com Unbreachable OT security, unlimited OT connectivity Wed, 16 Sep 2026 14:01:35 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.4 https://waterfall-security.com/wp-content/uploads/2023/09/cropped-favicon2-2-32x32.png Waterfall Security Solutions https://waterfall-security.com 32 32 Offshore Norge 104: Network Engineering for OT Cybersecurity https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/offshore-norge-104-network-engineering-for-ot-cybersecurity/ Wed, 16 Sep 2026 13:53:17 +0000 https://waterfall-security.com/?p=42150 Recommended guidelines on cyber security baseline requirements for Operational Technology (OT) systems were published in June 2026. I reviewed them...

The post Offshore Norge 104: Network Engineering for OT Cybersecurity appeared first on Waterfall Security Solutions.

]]>

Offshore Norge 104: Network Engineering for OT Cybersecurity

Picture of Andrew Ginter

Andrew Ginter

VP Industrial Security, Waterfall Security

Offshore Norge 104

Revision 7 of Offshore Norge 104 – Recommended guidelines on cyber security baseline requirements for Operational Technology (OT) systems was published in June 2026. I reviewed it, focusing on where the guidance sits on the spectrum of network engineering for OT security, especially regarding hardware-enforced unidirectionality.

Overall, the guidance is better than most I have read in the last 15 years. It recognizes physical separation, unidirectional gateways, dedicated OT infrastructure and the cyber risks introduced by unnecessary network communications. It even relaxes a conventional DMZ requirement when hardware-enforced unidirectional gateways eliminate the attack path that the DMZ was intended to manage.

The secure remote access section is somewhat less forward-looking.

“Shall” Really Does Mean Shall

The document is industry guidance, not a government regulation, but is reads like a standard. It states explicitly that any organization wishing to claim compliance with the guidance/standard must adhere to all “shall” requirements. The word “should” describes a preferred but optional approach.
 
The network sections contain plenty of shall’s:
 
· “OT networks shall be segmented from IT.”
· “OT shall be segmented from supplier and other third-party networks.”
· “Management traffic shall be segmented from other OT traffic.”

Physical Segmentation Matters

ON 104 permits both logical and physical segmentation. VLANs are explicitly recognized as a logical mechanism, while physically separate IT and OT switches provide physical segmentation. Physical segmentation is preferred in several important places, but not universally. For example, at the very important IT/OT interface, “Switches used for OT networks should be dedicated to OT traffic only…” Virtualization gets stronger treatment: “On-premises OT systems shall not live in the same virtualisation infrastructure as IT systems.

VLANs, virtual switches and hypervisors are useful technologies, but they are software. ON 104 recognizes the value of physical segmentation.

Unidirectional Gateways

The guidance requires an OT DMZ with better than average documentation: put a DMZ between enterprise IT and OT networks, terminate communications there, and use at least a firewall to control what passes between networks. There is one interesting exception: “All network traffic between enterprise IT and OT networks shall be terminated in the OT DMZ… This is not applicable if the communication flows from OT to IT traverse hardware-enforced unidirectional gateways.” In other words, the document recognizes that the strength of protection provided by hardware-enforced unidirectionality is already stronger than some of the software-only provisions.

Strictly Necessary / Tolerable Risk

A lot of cybersecurity guidance says only “necessary” communications should cross important boundaries, such as the IT/OT interface. In my experience, however, “necessary” is not defined, and is widely interpreted by readers as any communications that save a little time, or a little money, or buy the organization a little flexibility. More or less any IT/OT communication can be deemed “necessary.”

What ON 104 says for any communications between network segments is that “only network traffic that is strictly necessary and that represents tolerable risk is allowed.” “Strictly” necessary will give some owners and operators pause. “Tolerable risk” is a reminder to look at attack scenarios, acceptable vs. unacceptable consequences and corporate risk tolerance when evaluating connections between networks, especially between OT and IT networks, and even more so between OT networks and the Internet.

Island Mode: Logical or Physical, but No Communications

Requirement CSBR 20 talks about “island mode” — the ability “to prevent any network communication between OT networks and non-OT networks.” This is the topic of my September 2026 webinar. “The OT environment shall have a simple and easily executable mechanism for physically or logically disconnecting OT systems from external networks.” Island mode is something that is activated in a cyber emergency, for example when ransomware is suspected of tampering with the IT network.

Describing the islanding requirement is commendable, but it would have been stronger to have at least a “should” in place to recommend physical separation over logical. As written, the islanding requirement is arguably too strong. In most industrial sites, the biggest cybersecurity priority is preventing cyber-sabotage information from entering safety-critical, critical-infrastructure and high-cost OT networks. Stating this as the requirement would make it clear that unidirectional gateways oriented from OT to IT comply with the islanding requirement.

This is an issue with the American TSA rail and pipeline security directives as well. While not explicitly documented, I’m told by pipeline customers that TSA auditors accept unidirectional connections as legitimate islanding (TSA calls it “isolation”), even though the directive/regulation neither requires nor recommends hardware-enforced unidirectionality.

This is important, because unidirectional gateway technology is arguably the least costly form of islanding in terms of lifecycle cost. The gateways enable businesses to continue to reap the material benefits of OT data flowing to IT business automation and third-party providers, even while islanded, without the risk of OT cyber-sabotage propagating back into the OT network.

More Conventional Remote Access

The secure remote access section is another place where ON 104 could go further. The guidance requires the usual: MFA, encryption, least privilege, time-limited sessions, explicit approval, logging, monitoring and gateway inspection. But while the requirements do not say so explicitly, they clearly assume software “secure” remote access (SRA), exclusively.

There is no discussion of hardware-enforced unidirectional remote screen view, which is arguably the strongest form of attended remote access. Nor is there discussion of unattended hardware-enforced unidirectional remote access architectures. In contrast, both of these technologies are highlighted in the now two-year-old 2024 CISA and partners guidance, Modern Approaches to Network Access Security.

More surprisingly, ON 104 says interactive remote access solutions shall support “secure file transfer with malware scanning.” Malware scanning is useful, but it is not deterministic protection, and file transfers, especially of complex or executable files, are a huge attack vector. The guidance/standard should not say that all remote access shall support this dangerous feature.

Better Than Most

In terms of network engineering, Offshore Norge 104 gets a lot right. ON 104 already recognizes the value of hardware-enforced unidirectionality at the IT/OT boundary. Applying the same network-engineering principle to remote access would make the document even stronger.

Want to talk through what hardware-enforced network security could look like in your OT environment? Book a demo here >>

About the author
Picture of Andrew Ginter

Andrew Ginter

VP Industrial Security, Waterfall Security

Andrew Ginter is the most widely-read author in the industrial security space, with over 23,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Offshore Norge 104: Network Engineering for OT Cybersecurity appeared first on Waterfall Security Solutions.

]]>
Multi-national CI Fortify Guidance at a Glance https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/multi-national-ci-fortify-guidance-at-a-glance/ Thu, 27 Aug 2026 11:16:43 +0000 https://waterfall-security.com/?p=42079 Four governments just advised critical infrastructure operators to prepare to isolate their most important OT systems. Here’s what that means, who should care, and what to do about it.

The post Multi-national CI Fortify Guidance at a Glance appeared first on Waterfall Security Solutions.

]]>
The post Multi-national CI Fortify Guidance at a Glance appeared first on Waterfall Security Solutions.

]]>
Keeping OT Going When IT Goes Dark https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/keeping-ot-going-when-it-goes-dark-failsafe-designs-for-cyber-emergencies/ Sun, 23 Aug 2026 10:20:48 +0000 https://waterfall-security.com/?p=41982 This webinar reviews recent government directives, clears up the controversy, and introduces practical approaches to islanding. We evaluate islanding advice in the context of the emerging era of AI-based zero-day exploits.

The post Keeping OT Going When IT Goes Dark appeared first on Waterfall Security Solutions.

]]>

Keeping OT Going When IT Goes Dark

September 2026 Webinar

Join us on Tuesday September 29th
10am (NYC) / 3pm (London) / 6pm (Dubai)

A consortium of governments behind the CI-Fortify initiative are advising critical infrastructures to isolate / island in cyber emergencies – separate IT entirely from OT networks – for up to 3 months at a time. And the debate starts:

arrow red right CI-Fortify notes that physical separation is better than logical, but experts disagree.

arrow red right Many people complain that isolation is expensive, because it defeats the cost savings that come from IT/OT integration.

arrow red right CI-Fortify itself and other voices note that IT/OT dependencies are problematic, but give only IT examples. What do dependencies look like in OT?

arrow red right Legal experts are saying isolation risks becoming the new “reasonable” in civil lawsuits post-breach.

And more…

This webinar reviews recent government directives, clears up the controversy, and introduces practical approaches to islanding.

We’ll evaluate islanding advice in the context of the emerging era of AI-based zero-day exploits, and we’ll review Waterfall’s new islanding operator planning and self-assessment guides, and explore tools and approaches to reduce the cost and operational impact of extended islanded operations.

NB:
This is yet another example of why and how OT security programs must be stronger than IT – critical OT functions must survive IT cyber and other emergencies.

About the Speaker

Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Register Now

Share

The post Keeping OT Going When IT Goes Dark appeared first on Waterfall Security Solutions.

]]>
Making OT Security Stronger Than IT https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/making-ot-security-stronger-than-it/ Tue, 21 Jul 2026 12:20:58 +0000 https://waterfall-security.com/?p=41894 OT security is “hard” – engineering change control (ECC) makes patching slow and expensive, many OT devices and systems have no real support for zero trust (ZT)...

The post Making OT Security Stronger Than IT appeared first on Waterfall Security Solutions.

]]>

Making OT Security Stronger Than IT

Making OT Security Stronger Than IT

OT security is “hard” – engineering change control (ECC) makes patching slow and expensive, many OT devices and systems have no real support for zero trust (ZT), and most OT systems have large subsystems that operate without encrypted or authenticated communications. But imagine – imagine we could “wave a magic wand” and solve all of this, instantly. With one gesture, we patch everything, encrypt everything and ZT everything. Would we be “done?”


No. IT networks have near-universal security updates, ZT and encryption. If with a “magic wand” we could make our OT networks exactly as strong as our IT networks, then for most OT networks this would be a material improvement over the present-day, but would not be enough. From first principles, most OT networks must be materially better protected than most IT networks. The severity of worst credible consequences of cyber compromise drives the strength of security program that any network or system needs.

How Can We Make OT Stronger?

One way to make OT stronger than IT is to make OT security programs reflect OT rather than IT priorities. In most IT systems, information is the asset we protect and preventing espionage is the priority – encrypt the information and otherwise control the ability of adversaries to read the information. In most OT systems, on the other hand, physical operations are the asset, preventing sabotage is the priority, and information is the threat – the only way an OT system can change from a normal to a compromised state is if attack information enters the system, somehow. In OT it is therefore vital to control the movement of information, because all information flows can contain attacks.

How do we do that? Some examples:

  • The humble “deny by default” rule – do not allow connections through the IT/OT firewall to email servers, Google, nor the Internet at large. We cannot afford to pull attack information into OT,
  • More powerful unidirectional gateways at the IT/OT interface are hardware components that enable real-time server synchronization outbound from OT to IT, and allows no attack information at all to flow back into OT from IT, nor from the Internet, and
  • Strict procedural, software and sometimes hardware controls over the use of removable media, such as DVD’s and USB thumb drives.


In most OT networks there are less than a dozen kinds of ways that information can enter the network. Lock them down. Lock them hard.

Cyber-Informed Engineering

More generally, the emerging Cyber-Informed Engineering (CIE) discipline, among other things, points out how to use “unhackable” engineering tools to both eliminate physical risk and to deterministically control the movement of attack information. What is “unhackable?” These are tools that behave deterministically, often without any CPU built in, or a monitor-only CPU, unable to alter the behavior of the device. These engineering-grade mitigations range from electromechanical overpressure relief valves to digital hardware such as FPGA’s and ASICs.


CIE is still under development. The most recent innovation is a database of some 62,000 records. Each record describes an “unhackable” mitigation that can be applied in a particular industry. And again, of all the engineering-grade mitigations in the database, deterministic network engineering tools such as unidirectional gateways and hardware-enforced network traffic filtering are by far the most universally applicable.

Anomaly Detection

Another way to make OT networks stronger than IT is with anomaly-based monitoring and intrusion detection systems. Most industrial networks change much less frequently than do IT networks, and are used very predictably, day after day. This means that we can tune our OT-aware anomaly-based IDS systems to be more aggressive about alerting on even small changes from “normal,” without introducing unmanageable numbers of false alarms.


That said, we must be careful not to confuse the pillars of the NIST Cybersecurity Framework (NIST CSF). For example, if a new bridge is designed with hydraulic dampers to counteract harmonic frequencies, it is not enough for the design engineer to “hope” that if a cyber attack targets the control system for the dampers, “hope” that we can detect the attack before the dampers are crippled and the bridge tears itself apart. “Hope” is not what we expect of design engineers – we expect bridges that carry a specified load, in a specified operating environment, for a specified number of decades, with a large margin for error – deterministically.
We do need the CSF detect, respond and recover pillars, and it is good that we can design our OT detection tools to be stronger than IT, but we must not confuse detection with protection.

Looking Forward

In short, how can we make OT security stronger than IT? With sabotage-focused deterministic network engineering, Cyber-Informed Engineering, and OT-aware anomaly detection. And yes, use IT tools as well – they “raise the floor” by bringing OT systems closer to the strength of IT systems, but cannot go beyond IT.
For more examples of how and why to make OT systems stronger than IT, please join our webinar on July 29, or access the recording afterwards at the same URL.

 

Register Now

About the author
Picture of Andrew Ginter

Andrew Ginter

VP Industrial Security, Waterfall Security

Andrew Ginter is the most widely-read author in the industrial security space, with over 23,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Making OT Security Stronger Than IT appeared first on Waterfall Security Solutions.

]]>
How Should OT Security Be Stronger Than IT? https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/webinar-how-should-ot-security-be-stronger-than-it/ Thu, 02 Jul 2026 10:31:03 +0000 https://waterfall-security.com/?p=41831 In this webinar we connect first principles to modern practice: Biba, SEC-OT, CIE mitigations, UK NCSC connectivity guidance and modern "islanding" requirements all lead to OT designs whose security materially exceeds that of conventional IT networks.

The post How Should OT Security Be Stronger Than IT? appeared first on Waterfall Security Solutions.

]]>

How Should OT Security Be Stronger Than IT?

If our OT security strategy looks like our IT security strategy... we may have a problem

Now available to watch on demand

Worst credible consequences mean OT security programs must be materially stronger than IT programs, but the most frequent differences between OT and IT programs – difficulty patching, encrypting, anti-virusing – make OT programs weaker, not stronger. And – a lot of people encourage Zero Trust, encryption and patch programs on OT – but this is what we do on IT isn’t it? These tools make OT networks as strong as IT networks, but not stronger. 

In this webinar we connect first principles to modern practice: Biba, SEC-OT, CIE mitigations, UK NCSC connectivity guidance and modern “islanding” requirements all lead to OT designs whose security materially exceeds that of conventional IT networks. 

Webinar Key Takeaways:

arrow red right Why & how OT security must be materially stronger than IT security  

arrow red right Where traditional IT security approaches fall short in OT environments  

arrow red right How first principles like Biba, SEC-OT, and CIE mitigations shape stronger OT security  

arrow red right How to design OT architectures that better protect critical infrastructure 

Who Should Attend?

arrow red right OT and ICS cybersecurity professionals   

arrow red right OT, ICS, and SCADA engineers  

arrow red right IT security teams responsible for OT environments    

arrow red right Security architects designing industrial networks  

arrow red right CISOs and cybersecurity leaders responsible for critical infrastructure 

arrow red right Plant managers and operations leaders evaluating OT security investments 

About the Speaker

Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Watch Now

Share

The post How Should OT Security Be Stronger Than IT? appeared first on Waterfall Security Solutions.

]]>
Big OT Security, Smaller Footprint – Meet DiodeCore! https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/big-ot-security-smaller-footprint-meet-diodecore/ Wed, 24 Jun 2026 07:50:40 +0000 https://waterfall-security.com/?p=41650 Two decades ago, we founded Waterfall with one purpose: to defeat nation-state attacks impacting OT environments and critical infrastructure.

The post Big OT Security, Smaller Footprint – Meet DiodeCore! appeared first on Waterfall Security Solutions.

]]>

Big OT Security, Smaller Footprint – Meet DiodeCore!

Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

DiodeCore Launch
Two decades ago, we founded Waterfall with one purpose: to defeat nation-state attacks impacting OT environments and critical infrastructure. We benchmarked our technology against so-called Advanced Persistent Threats (APTs) and other nation-state classes of attacks, then refined our technology, and then did it again. From our first Unidirectional Gateway to the WF-600 Performance, the Flip, and HERA Hardware-Enforced Remote Access™ - this is what we do.

And now, DiodeCore™

New, Advanced Cyber Threats

The fact that AI found hundreds of vulnerabilities in the Firefox open-source browser is really alarming. Firefox is a veteran, relatively highly secured open-source product that has been pen tested and code reviewed by governments, cyber companies and experts, multiple times. The Mythos AI found 250+ zero days in Firefox despite all this. 

What about products that are not open source, not as widely used, and not as seasoned. AI tools will find thousands of vulnerabilities, develop exploits, and chain those exploits together in ways that would have taken years for humans to figure out, code and test.

AI is taking nation-state grade tools and techniques and democratizing them, making nation-state grade attack capabilities available to a much wider audience, a much wider set of potential attackers. Within 12 or 24 months, I believe we are going to see fully automated and autonomous attacks on OT networks.

What is DiodeCore?

What can be done about this? The answer to these threats is not more software, but stronger hardware. Today we are officially launching the WF-600 DiodeCore, our newest addition to the WF-600 family. DiodeCore is a modern Unidirectional Gateway designed for simpler deployment scenarios: entry-level or simpler needs, smaller sites, and larger numbers of sites.

DiodeCore’s level of security, cybersecurity concepts, and unidirectionality are at the same hardware-enforced standard of protection Waterfall has always provided. And DiodeCore is a product that fits a different use case. I am very proud to introduce this to the market.

How DiodeCore Works

The hardware is a small, half-depth 1U rack-mount device. Open it up and there is a transmit circuit board, a receive circuit board, and a fiber between them. That fiber is the only physical connection between the two sides. The hardware is physically able to send information in only one direction. There is no laser in the receiving circuit board, and no photocell on the sending. It does not matter how clever the enemy is, and it does not matter if they are a human or an AI or a nation state. All cyber sabotage is based on information passing. The only way a control system can change from a normal state to a compromised state is if attack information enters the system. Interrupt the flow of attack information and you interrupt the attack.

The DiodeCore uses the same software as is used in the WF-600 Performance series, with the DiodeCore software delivered as a closed virtual machine image. This image can run on any standard customer virtualization infrastructure, from a VM server to a workstation, running Windows, Linux, ESXi and similar platforms. There is one virtual image for the OT network side, and another for the external network side. There’s no need for any dedicated wiring any more, directly connected servers or hosts. A lot of modern automation systems use virtualization – this is the modern method of deploying this technology.

The hardware in DiodeCore is the smallest amount of hardware you can have to still get the ultimate security value of a Unidirectional Gateway. DiodeCore has a small footprint, half the depth of a standard 1U appliance. DiodeCore is easy to deploy, easy to install and manage, and easy to purchase.

Hardware-Enforced Protection Anywhere You Need It

Today, customers can use our flagship WF-600 Performance where they need high-end performance, resilience, throughput, scale, and capability, while DiodeCore is designed to support:

  • Smaller and simpler sites
  • Distributed facilities
  • Large scale rollouts across many locations


We already have customers saying: “Okay, okay, launch it already. We want these!” And so, I am pleased to say today, DiodeCore is available now!

Talk to an OT Security Expert

If you are securing a smaller site, scaling protection across distributed facilities, or modernizing a virtualized OT environment, and you are wondering where a Unidirectional Gateway can fit in your architecture, please reach out to Waterfall.

There is no cost for a consultation – let our experts surprise you with strong unidirectional designs.

About the author
Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

Lior Frenkel is a cybersecurity entrepreneur, author, and global expert in OT and critical infrastructure security with more than 25 years of industry experience. As the CEO and co-founder of Waterfall Security Solutions, he has led the deployment of innovative unidirectional security technologies protecting critical infrastructure worldwide. Lior is a recognized thought leader who contributes to international cybersecurity policy, regulatory initiatives, and industry strategy. He also serves in leadership roles across major Israeli technology and manufacturing organizations, helping advance the global cybersecurity industry.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Big OT Security, Smaller Footprint – Meet DiodeCore! appeared first on Waterfall Security Solutions.

]]>
Mythos, Zero Days and OT Cybersecurity https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/mythos-zero-days-and-ot-cybersecurity/ Mon, 15 Jun 2026 14:09:11 +0000 https://waterfall-security.com/?p=40467 Anthropic’s Claude Mythos is the latest example of a trend many of us in industrial cybersecurity have been warning about for years.

The post Mythos, Zero Days and OT Cybersecurity appeared first on Waterfall Security Solutions.

]]>

Mythos, Zero Days and OT Cybersecurity

Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

Mythos, Zero Days and OT Cybersecurity
The advent of Anthropic’s Claude Mythos is the latest example of a trend many of us in industrial cybersecurity have been warning about for years. Sophisticated offensive cyber capabilities are no longer confined to elite nation-state teams with enormous budgets and years of specialized expertise. AI is “democratizing” cyber attacks, including attacks on operational technology (OT) systems.

Public reports describe Mythos as capable of discovering zero-day vulnerabilities, chaining together exploits of otherwise low-severity vulnerabilities into powerful attacks, reverse engineering proprietary systems, and automating large portions of advanced attack workflows.

Whether every public claim proves accurate is almost beside the point. The trajectory is unmistakable. Frontier AI models are reducing the cost, time, and expertise needed to conduct sophisticated cyber operations.

Watch our webinar on-demand
as we explore the impact of AI-driven cyber threats on OT security
and introduce Waterfall’s newest Unidirectional Gateway.

OT Targets

For OT environments, this matters enormously.

OT systems are intrinsically vulnerable. Rapid patching of OT systems is extraordinarily expensive and difficult. In safety-critical and reliability-critical environments, patches cannot simply be deployed overnight. Engineering change control processes that minimize safety and reliability risks require testing, validation, outage coordination, safety review, and operational acceptance. 

In many facilities, those processes take months or years. Worse, patching (hopefully) remediates only known defects, and again, AI’s have proven adept at finding previously unknown vulnerabilities. Even with a patching “magic wand,” IT and OT systems would still be intrinsically vulnerable.

Remember Fuzzing?

That said, the discovery of large numbers of zero-day vulnerabilities is not entirely new. A decade+ ago, fuzzing technologies dramatically increased the rate of discovering vulnerabilities in both IT and OT systems. Automated fuzzing campaigns uncovered large numbers of latent defects in industrial protocols, embedded devices, operating systems, and applications.

What is different today is the scale, exploitability and sophistication of zero-day attacks. Again:

  • The volume of vulnerabilities being discovered is increasing dramatically,
  • Systems like Mythos are able to chain together low-severity vulnerabilities into much more dangerous attacks, and
  • Perhaps most important, AI systems are increasingly capable of automating sophisticated offensive workflows.


Today those workflows still involve human oversight. Tomorrow they will not!

The Perimeter Is Dead? No…

All this means OT perimeter protection becomes increasingly important – hardening the interior to zero-day attacks was and is simply not achievable – not for IT systems and not for OT systems. This problem is precisely why Waterfall’s Unidirectional Gateways were invented almost 20 years ago. Waterfall’s gateways were designed from the beginning to withstand nation-state-grade attacks against OT targets, including sophisticated attacks exploiting zero-day vulnerabilities.

In contrast, conventional firewalls depend on software correctness. Even “next generation” firewalls ultimately rely on operating systems, protocol stacks, parsing engines, authentication systems, and millions of lines of software behaving perfectly correctly under hostile conditions. Zero-day vulnerabilities undermine all of these assumptions – exploit a zero-day, or a sequence of zero-days, and completely take over the CPU / software in an ultra-sophisticated next-gen firewall, and the device does the attackers’ bidding, not the defenders’.

Waterfall’s Unidirectional Gateways – “Immune” to Zero-Days

Waterfall’s gateways are a combination of hardware and software. The hardware is physically able to send information in only one direction – usually from the OT network out to the IT network, so that the business can profit from access to OT information. The hardware, however, is not physically able to send any information nor cyber-sabotage attack information back into OT networks. There is no return path, physically.

This is why Waterfall’s Gateways are fundamentally immune to network-based zero-day exploits aimed at crossing the protection boundary. Even if the gateways’ IT-exposed software is compromised, there is physically no way for that software to send attack information back into the OT network.

As a side note, yes, comprehensive OT security programs are still important in unidirectionally-protected networks. Intrusion detection, security monitoring, asset inventory, vulnerability management, and capable incident response are all needed to address residual risks. But detection and response take time. Human investigation takes time. Escalation takes time. Remediation takes time. In a future of highly automated AI-driven attacks, we will not have that time – we urgently need to block AI’s from simply reaching across networks and into critical OT systems.

Looking Forward

Over the next 2-3 years, we are entering one of the most dangerous periods OT security has faced. In that environment, deterministic protection is essential. Unidirectional gateways are not the only control we need, but they are one of the few technologies specifically engineered from the beginning to remain effective, even when sophisticated attackers possess zero-days, advanced malware, and increasingly powerful AI assistance.

Waterfall’s The gateways are exactly the kind of deterministic, engineering-grade protections we need for the difficult years ahead.

About the author
Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

Lior Frenkel is a cybersecurity entrepreneur, author, and global expert in OT and critical infrastructure security with more than 25 years of industry experience. As the CEO and co-founder of Waterfall Security Solutions, he has led the deployment of innovative unidirectional security technologies protecting critical infrastructure worldwide. Lior is a recognized thought leader who contributes to international cybersecurity policy, regulatory initiatives, and industry strategy. He also serves in leadership roles across major Israeli technology and manufacturing organizations, helping advance the global cybersecurity industry.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Mythos, Zero Days and OT Cybersecurity appeared first on Waterfall Security Solutions.

]]>
Webinar: AI Is Democratizing Nation-State Cyber Attacks. How Do We Defend OT? https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/webinar-ai-is-democratizing-nation-state-cyber-attacks-how-do-we-defend-ot/ Sun, 31 May 2026 09:45:09 +0000 https://waterfall-security.com/?p=40441 Introducing a new, 'entry-level' unidirectional solution

The post Webinar: AI Is Democratizing Nation-State Cyber Attacks. How Do We Defend OT? appeared first on Waterfall Security Solutions.

]]>

Webinar: AI Is Democratizing Nation-State Cyber Attacks. How Do We Defend OT?

Now available to watch on demand

How is AI Impacting Operational Technology (OT) Security?

With the advent of Anthropic’s Claude Mythos, sophisticated offensive cyber capabilities are no longer confined to elite nation-state teams. AI’s are bringing powerful cyber attacks into the hands of a wide array of adversaries: automatically finding zero-days, chaining low-severity vulnerabilities into high-severity exploits, and outright automating part or all of sophisticated attacks themselves. In this webinar, Lior Frenkel, CEO and Co-Founder of Waterfall Security and an expert on the global threat environment joins us to discuss modern threats and how to address them. 

Securing OT Environments Against AI and Modern Threats

In the context of these nation-state-grade threats, Lior will introduce the newest addition to Waterfall’s family of OT security offering: an entry-level Unidirectional Gateway. The new gateway extends Waterfall’s long-standing hardware-enforced foundation to a broader range of budgets and operational environments. 
 
Waterfall’s family of hardware-enforced unidirectional solutions has expanded over the years to include use cases that once seemed impossible: sending anti-virus and production order updates into OT systems, continuous remote control and even hardware-enforced remote access. The new Waterfall gateway is simpler and smaller, while supporting the family’s powerful Unidirectional Gateway operating system and software connectors.

Democratizing Nation-State-Grade Defenses, as AI's Democratize Nation-State-Grade Attacks

The threat: the next 3 years will be very challenging – AI’s are democratizing nation-state-grade cyber attacks – in a real sense, every industrial operation is now the target of such attacks.  
 
Waterfall’s response: Waterfall Security is democratizing nation-state-grade cyber defenses. Today, every target of nation-state-grade attacks can deploy nation-state-grade defenses.

Webinar Key Takeaways:

  • How Unidirectional Gateways prevent remote cyberattacks, including AI-automated zero-day attacks, from reaching protected OT networks
  • How Unidirectional Gateways address “surprising” use cases, such as anti-virus updates and secure remote access
  • How the gateway product family enables safe OT data sharing with enterprise, cloud, analytics, and even cloud-based AI systems
  • Waterfall’s newest and most flexible entry-level Unidirectional Gateway. 

Who Should Attend?

  • OT/ICS engineers
  • IT security teams taking on OT security
  • CISOs with critical infrastructure assets in their portfolio
  • Plant managers evaluating security and investment

 

About the Speakers

Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Picture of Lior Frenkel

Lior Frenkel

Lior Frenkel is a cybersecurity entrepreneur, author, and global expert in OT and critical infrastructure security with more than 25 years of industry experience. As the CEO and co-founder of Waterfall Security Solutions, he has led the deployment of innovative unidirectional security technologies protecting critical infrastructure worldwide. Lior is a recognized thought leader who contributes to international cybersecurity policy, regulatory initiatives, and industry strategy. He also serves in leadership roles across major Israeli technology and manufacturing organizations, helping advance the global cybersecurity industry.

Watch Now

Share

The post Webinar: AI Is Democratizing Nation-State Cyber Attacks. How Do We Defend OT? appeared first on Waterfall Security Solutions.

]]>
3 OT Security Myths https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/3-ot-security-myths/ Sun, 10 May 2026 06:50:46 +0000 https://waterfall-security.com/?p=39498 If only we could wave a magic wand and patch everything and zero-trust everything, just like with our IT networks, then our OT networks would be “secure”

The post 3 OT Security Myths appeared first on Waterfall Security Solutions.

]]>

3 OT Security Myths

There are many misconceptions and myths in operational technology (OT) security. This is a problem, because when we start with the wrong premises, then we most often draw incorrect conclusions – this is how logic works. Let's look at some OT security myths and misconceptions and see how they lead us astray.
Picture of Andrew Ginter

Andrew Ginter

Everything you Know About OT Security is wrong

1) Information is the asset we protect – protect the confidentiality, integrity and availability (CIA) of the information, in that order, or maybe in AIC order, or IAC, or something.

Information is the asset we protect in most IT networks. In OT networks, in contrast, we most often protect safe, reliable and efficient physical operations. Take a metro for example: safety is first – nobody wants to die on the way to work. Reliability next – the metro needs to get hundreds of thousands of people to work every day, and passengers want their trains to be on time. And then efficiency – it does no good to have the world’s safest, most reliable metro, if the population cannot afford to use it.

So what? Can we not stand on our heads and say there must be information somewhere in the metro’s automation system that we can protect? Well, we can stand on our heads, yes, a lot of people do, but why bother? 50-year-old cybersecurity theory (Bell / La Padula) teaches us how to prevent theft or leakage of important information. Many of us learned this theory in school. What we did not learn is that 2 years after Bell & La Padula came out with their theory, Biba came out with a complementary theory.

Bell / La Padula teach us how to prevent espionage – theft or leakage of important information (eg: how to make a Nuclear Bomb – these researchers were funded by the US DoD in their day). Biba teaches us how to prevent sabotage (eg: changing the targeting coordinates for the missiles delivering The Bomb).

Biba’s theory used exactly the same concepts and terminology as Bell / La Padula but applied the concepts differently. In Biba’s theory, information is not the asset we protect, but the threat. All cyber-sabotage is defined (mathematically) as information. The only way a targeting system or an OT control system can change from a normal state to a compromised state is if attack information enters the system – somehow. The goal with OT systems is not to “protect the information” – the CIA, or IAC, or AIC of the information. The goal is to protect control systems from information – to keep attack information from affecting critical functions, such as safe, reliable and efficient physical operations.

Get this wrong and we fixate on information as the asset, when attack information entering the system is in fact the threat we must defeat.

2) Asset inventory is one of the first steps towards OT security – we cannot protect what we don’t know we have.

Here is an example of how misinterpreting the asset bites us. If we are to prevent theft or leakage of that information, it is vital that we know what and where that information is. We cannot prevent theft or leakage of information if (a) we do not know it exists or (b) we do not know where it is. An asset / information inventory is therefore one of the very first steps we must carry out if we are to design mechanisms to protect our information assets.

Biba, however, teaches us that information is the threat. This means that one of the very first things we must do is not inventory where our information lives, but rather inventory all of the ways attack information can reach our vulnerable OT systems. We need an inventory of data flows, most importantly those data flows that enter our OT systems from the “outside” – from potentially compromised sources. Understanding our perimeter and data flows that cross the perimeter is much more important than enumerating all of the countless “information assets” inside that perimeter.

Technical note: these perimeter-crossing data flows can be online or offline. Offline means the attack information lives in physical media, like USB thumb drives, laptops, or new computers arriving from our suppliers. We physically carry offline information into contact with our OT systems. Online information is more ephemeral – it is communicated into our systems with the movement of electrons, photons, electric or magnetic fields, or event sound waves – vibrations and quantum “things” rather than the movement of macroscopic physical objects.

Yes, eventually we will probably also benefit from an inventory of computer & information assets, but for most of us, our first priority is to prevent or control the movement of attack information into our systems – not protect that information, for example by encrypting that attack information.

 

3) If only we could wave a magic wand and patch everything and zero-trust everything, just like we do our IT networks, then our OT networks would be “secure.”

In most OT networks, the worst credible consequences of compromise are completely unacceptable: things blow up and people die. Or long-lead-time physical equipment is destroyed, and production / infrastructure is down for months or years, not hours or days. In most IT networks, the worst credible consequences are undesirable, and sometimes material, but will not put us out of business. This is the essential difference between most IT and OT networks: we cannot “restore” human lives nor damaged equipment from backups.

This means that even if we could wave our magic wand and secure OT networks exactly as we secure our IT networks, then our OT security program would still be woefully inadequate. The worst credible consequences (credible = reasonable to expect) define the required strength of our security program. When consequences are unacceptable, we need to protect our OT networks much more thoroughly than we protect our IT networks. Our postulated “magic wand” is not nearly enough.

Summing Up

Don’t get me wrong – I’m not saying information is never an asset (robotic programs in discrete manufacturing can be very valuable), nor that asset inventory is useless, nor that IT-style security mechanisms, where we can manage to apply them in OT, are pointless. What we’re talking about here is priorities. If we apply the world’s very best “protect the information assets” IT security program to OT systems, we might, accidentally, prevent material sabotage of physical operations. And we’ll probably spend an enormous amount of money doing that.

Moreover, no security program is complete until it has all the pillars of the NIST CSF: govern, identify, protect, detect, respond and recover. I’m not saying to ignore any of those pillars. To one extent or another, we most often need to “do it all,” but in which order, and where should the funding / implementation priorities lie?

What I am saying is that if we understand our priorities and constraints more accurately, then we can do a much more effective job of all of the above, for far less money.

About the author
Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.
Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post 3 OT Security Myths appeared first on Waterfall Security Solutions.

]]>
Webinar: Everything You Know About OT Security Is Wrong https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/webinar-everything-you-know-about-ot-security-is-wrong/ Tue, 05 May 2026 11:42:52 +0000 https://waterfall-security.com/?p=39442 Discover why common OT security assumptions are wrong

The post Webinar: Everything You Know About OT Security Is Wrong appeared first on Waterfall Security Solutions.

]]>

Webinar: Everything You Know About OT Security Is Wrong

Misconceptions about OT security run deep and some of them sound reasonable until you test them against how industrial environments actually work.

Why Common OT Security Assumptions Are Wrong

Now available to watch on demand

Common wisdom in OT security is uncommonly mistaken. What’s really going on? Shoe factories are very different from passenger rail switching. Dramatically different worst-case consequences drive important differences between IT and OT security.

IT protection is preoccupied with espionage, while sabotage is the bigger threat in OT. Intrusion detection takes time, depends on human judgment, and by the time a human responds, the physical damage in an OT environment may already done.

Encryption and patching add complexity, uncertainty and cost enormously more in OT than they do in IT.

In this webinar we look at widespread misconceptions about OT security, at their root causes, and at more sensible approaches for teams making architecture and investment decisions today.

Webinar Key Takeaways:

• Why common OT security assumptions break down in practice
• How to present OT security to drive better results across your teams
• How consequence changes the way OT threats should be assessed
• Where IT security approaches fall short in industrial environments
• More defensible approaches to OT security decisions and designs

Who Should Attend?

• OT/ICS engineers
• IT security teams taking on OT security
• CISOs with critical infrastructure assets in their portfolio
• Plant managers evaluating security and investment

About the Speaker

Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Watch Now

Share

The post Webinar: Everything You Know About OT Security Is Wrong appeared first on Waterfall Security Solutions.

]]>