
Consequence-Based Risk Matrices for IEC 62443-3-2
Andrew Ginter shares a proposed IEC 62443-3-2 Appendix C: consequence-based risk matrices that replace likelihood with credibility for high-impact OT cyber attacks.
Welcome to the resources page! We have compiled a collection of useful information, tools, and resources to help you

Andrew Ginter shares a proposed IEC 62443-3-2 Appendix C: consequence-based risk matrices that replace likelihood with credibility for high-impact OT cyber attacks.

Recommended guidelines on cyber security baseline requirements for Operational Technology (OT) systems were published in June 2026. I reviewed them…

OT security is “hard” – engineering change control (ECC) makes patching slow and expensive, many OT devices and systems have no real support for zero trust (ZT)…

Two decades ago, we founded Waterfall with one purpose: to defeat nation-state attacks impacting OT environments and critical infrastructure.

Anthropic’s Claude Mythos is the latest example of a trend many of us in industrial cybersecurity have been warning about for years.

If only we could wave a magic wand and patch everything and zero-trust everything, just like with our IT networks, then our OT networks would be “secure”

Ask different questions, get different answers. What should you be asking your OT “secure” remote access (SRA) vendor?

Get up to speed on key trends and strategies in industrial security with Andrew Ginter’s favorite webinars of 2024,

Sit back and enjoy Andrew Ginter’s top 3 picks from 2024’s Industrial Security Podcast series.

Spoiler Alert: Yes, investing in OT security is very much “worth it”. It helps prevent financial losses, operational disruptions, and compliance penalties far exceeding initial costs. The average ROI can reach up to 400%, ensuring both protection and operational continuity.