Have you remembered to thank AI today?
You're not going to survive the AI apocalypse if you forget to thank the AI. /s
Remote
Secure ICS OT 
@Secure_ICS_OT@infosec.exchange
Unsolicited posts from an ICS/OT Professional with both GICSP and ISA 62443 Expert. GIAC Advisory and ISA member.
0 Followers
0 Following
50 Posts
Joined November 11, 2022
Joined:
Nov 10, 2022
Certs:
GICSP, 62443 Cert 1 and 2.
Open post
Teams is the worst communications medium in the field for me.
I can't handle poor LTE coverage inside of buildings.
Messages can get out of order and it will just spontaneously reorganize messages.
SMS is still superior.
1
0
1
0
Open post
Australia Health services should pursue legal or criminal action against Sam Altman and OpenAI.
0
0
0
0
Open post
Another great read for ICS/OT security is the joint government document: "Principles of Operational Technology Cyber Security"
https://www.cyber.gov.au/sites/default/files/2026-06/Principles%20of%20operational%20technology%20cyber%20security%20%28October%202024%29.pdf
0
0
0
0
Open post
Please pray for me this morning while I struggle with the desire to reply all, and correct the "project manager".
0
0
0
0
Open post
Replying to
@plzupgrademe@fedi.txw.ca I was thinking the same thing. My package arrived at 2:30pm but was reported as 4:30pm. The issue seems to be between the subcontractor and Amazon.
0
0
0
0
Open post
Amazon's package tracking updates are so good they can see into the future.
0
1
0
0
Open post
Just because it's a standard doesn't mean it won't break your business.
0
0
0
0
Open post
If you're an ICS/OT engineer you should learn how to configure firewalls.
It is easier than configuring a PLC so you should pick it up pretty quick.
0
0
0
0
Open post
Once again
Just because you can
Doesn't mean you should
0
0
0
0
Open post
The problem with vendor work is they bring their personal "solution". You then end up with a patch work of various "solutions" that creates more surface area and more stuff to manage.
0
0
0
0
Open post
Restoring from backups isn't necessarily going to be a free pass in the ICS/OT.
Even restoring from a golden backup in a critical environment, any engineer worth their mustard is going to insist on functional testing prior to putting their license on the line.
Just saying.
0
0
0
0
Open post
With the MTBF so high on most equipment, having redundancy generally seems like a complete waste of money and only makes things more complicated than they need to be.
I'd rather have cold spares on hand, save money and reduce system complexity.
0
0
0
0
Open post
You need to educate yourself on ICS/OT security.
Before someone that is not educated on ICS/OT security takes you in the wrong fucking direction.
0
0
0
0
Open post
This landed in my YouTube feed:
https://youtu.be/hVmbWMS3W4I?si=Q1S1VTTu0AothnTh
BIG DATA - "Put Me To Work"
0
0
0
0
Open post
One of the biggest threats to ICS/OT.
"IT/OT convergence"
IYKYK
0
0
0
0
Open post
If you don't know about virustotal, you should totally check it out. Great tool for scanning files.
Just don't be stupid and upload sensitive configuration files or documents.
https://www.virustotal.com/gui/home/upload
0
0
0
0
Open post
Sorry I didn't mean to like that post.
I was just slapping a mosquito.
0
0
0
0
Open post
If you have ICS/OT firewall alarms going to your inbox.
We can be friends.
0
0
0
0
Open post
So back in the day I had to defend having a router segregating the ICS/OT from the IT network.
Some time later the IT department accidentally exposed the routers WAN to the internet.
I discovered this because I was able to access it without using their VPN first.
0
0
0
0
Open post
The current top firewall alert is from my few Windows machines trying to check on updates.
0
0
0
0
Open post
I'm not sure why anyone still uses Adobe Acrobat.
Just saying.
0
0
0
0
Open post
Look at this fucking awesomeness!
https://www.cisa.gov/resources-tools/services/malcolm
0
0
0
0
Open post
Replying to
This is the book I'm trying to get managers to read.
0
0
0
0
Open post
You can't do effective ICS/OT security from behind a desk.
You have to put on some steel toes and leave the office.
Visit operations.
Walk down the plant(s).
Get to know managers, operators and the various trades.
Put eyes on the situation.
0
0
0
0
Open post
You have to put in the time to secure new projects.
It's very hard to make significant changes once things are in production.
0
0
0
0
Open post
Look at this shit people post on LinkedIn!
This is f'n horrible!
0
0
0
0
Open post
This shouldn't have to be said but
-
Nobody should be able to browse the internet from the ICS/OT environment.
-
Nobody should be able to send or receive e-mails in the ICS/OT environment.
0
0
0
0
Open post
Wasn't long ago IT and Cisco was trying to sell me on VXLAN.
Most definitely don't need VXLAN in my environment.
I'm not even sure the corporate needs VXLAN.
VXLAN is for datacenters.
0
0
0
0