{"id":5880,"date":"2026-09-13T13:43:34","date_gmt":"2026-09-13T18:43:34","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5880"},"modified":"2026-09-13T13:43:34","modified_gmt":"2026-09-13T18:43:34","slug":"it-ot-security-weekly-september-13-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5880","title":{"rendered":"IT\/OT Security Weekly &mdash; September 13, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#334155;background:linear-gradient(135deg,#334155 0%,#b45309 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">September 13, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">IT\/OT Security<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">The CVE traffic, the CISA advisories and the malware campaigns went to Malware Analysis this week. What is left is the operating model &mdash; budgets, headcounts, deadlines and who actually pays. The EU Cyber Resilience Act&rsquo;s Article 71 reporting clock started on September 11 and now runs against every manufacturer of a product with digital elements, PLCs and protocol gateways included. DOE opened a 30-day comment window on foreign equipment in the bulk-power system that closes October 9, with a webinar on September 16. CISA published an Insider Threat Mitigation Guide it says scales down to the smallest utility. State CIOs told NASCIO and GDIT that 22% of them have no dedicated critical-infrastructure cyber funding at all and only 31% fund anything below the executive branch. Boston Scientific came back up after roughly seventeen days and expects to miss guidance. And one Fortinet survey produced two articles in the same trade outlet on the same day.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>Two clocks started this week and both of them belong to people who build equipment rather than people who run it. The first is the EU Cyber Resilience Act. From September 11, Article 71 obliges manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents on a three-stage schedule: early warning within 24 hours of awareness, full notification within 72 hours, a final report within 14 days of a corrective measure becoming available for an exploited vulnerability, or within one month of the 72-hour notification for a severe incident. Filings go to the CRA Single Reporting Platform. Neither of the two write-ups this week is written from an industrial angle &mdash; &ldquo;manufacturer&rdquo; is the CRA&rsquo;s legal term, not a factory-floor one &mdash; but if your company ships a PLC, an RTU, a protocol gateway, an HMI or a historian into the EU, the 24-hour clock is now yours, and Dark Reading supplies the number OpenSSF omits: up to EUR 15 million or 2.5% of annual worldwide revenue. The second clock is DOE&rsquo;s. Federal Register notice 2026-18370, published September 9, opens a 30-day Request for Information on securing the bulk-power system from foreign equipment and supply-chain risk under Executive Order 14420. Comments close October 9; a public webinar is set for September 16. The equipment list is the part to read twice &mdash; grid-connected inverters, battery energy storage, UPS systems, generators and industrial control systems &mdash; because it reaches distributed energy and storage assets, not just transmission-class gear. Patrick Miller of Ampyx Cyber gives the practical read: whether or not you file, this is a reasonable prompt to start equipment-provenance inventory work now.<\/p>\n<p>Around those two deadlines, the week was about capacity and who funds it. A joint NASCIO and GDIT report found 90% of state CIOs rank attacks on critical infrastructure a high concern and 73% have folded critical-infrastructure protection into a whole-of-state plan &mdash; and then found the hole underneath: 65% of state CIO budgets fund critical-infrastructure cyber for executive-branch agencies, only 31% push funding down to local governments and special districts, and 22% have no dedicated critical-infrastructure cyber funding at all. Water districts and small co-ops sit precisely in that gap. The report&rsquo;s sample size and the number of states it represents are not disclosed anywhere in the coverage, which limits how hard those percentages can be leaned on. New York State is the counter-example, with $9 million in grants announced in early August for 153 local drinking-water and wastewater utilities. Two reprints from Tribune Content Agency put numbers on the same problem from below: Idaho runs its Cyber Resilience Operation Center on four full-time employees plus part-time staff while planning 24\/7 operations by June 2027, and a state representative who used to red-team for the Navy could not get a funding bill drafted in the 2026 session. In Washington, National Cyber Director Sean Cairncross used the Billington Cybersecurity Summit to position Project Watershed 250 &mdash; a 60-day pilot that began in San Antonio on August 31 &mdash; as a national blueprint, with no utility count, no dollar figures and no named vendor partners disclosed, and no published results yet.<\/p>\n<p>The sector news carried the sharpest operational detail. Boston Scientific detected an intrusion on August 25, contained it the same day, and reported full restoration on September 11 &mdash; roughly seventeen days in which manufacturing plants and distribution centres worldwide, plus order processing, fulfilment and shipping, were down. No threat actor was named and none claimed responsibility. The consequence that matters for anyone who builds product on a schedule is downstream: procedures were lost because hospitals ran short, and hospitals plausibly bought from competitors during the outage. The company expects to miss both Q3 and full-year guidance and will say more on October 28. Elsewhere, CISA published its Insider Threat Mitigation Guide with a five-phase program model and an explicit claim that the framework is scale-independent; Sandia National Laboratories and DOE described C2E2, a research-stage grid detection pipeline whose widely quoted 95% accuracy figure is self-reported, laboratory-stage and attached to no named testbed, no dataset and no utility field trial; and Cyware announced support for NRECA&rsquo;s ICS-REC research program for electric cooperatives, with the participating-utility count undisclosed. Two pieces of this week&rsquo;s survey material need handling with care. Manufacturing Business Technology ran two separate articles on the same day drawn from one dataset &mdash; the 2026 Fortinet State of Operational Technology and Cybersecurity Report &mdash; one bylined a Fortinet marketing director without his employer shown, the other carrying no author name at all. They are treated here as one dataset viewed twice, not two findings.<\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>The DOE bulk-power RFI comment deadline of October 9.<\/strong> Federal Register 2026-18370 opened a 30-day window on foreign equipment and supply-chain risk in the bulk-power system under Executive Order 14420. A public webinar is scheduled for September 16. Watching what the comment record shows about how asset owners describe their own inverter, storage, UPS and ICS provenance &mdash; and whether DOE names equipment categories more precisely in whatever follows.<\/li>\n<li><strong>The CRA&rsquo;s second date: Article 24 steward obligations on December 11, 2027.<\/strong> The September 11 Article 71 reporting duty is the one that landed this week, but open-source stewards get their own obligations fifteen months out. Watching whether any industrial vendor publicly maps which of its embedded components fall under steward rather than manufacturer duties, because that determination decides who files.<\/li>\n<li><strong>What a Single Reporting Platform filing actually looks like for a PLC.<\/strong> The 24-hour early warning was written with software products in mind. Watching for the first published examples of an SRP submission covering deployed field equipment &mdash; particularly how firmware version scope, installed-base uncertainty and a distributor channel get expressed in a filing that must go out before the investigation is finished.<\/li>\n<li><strong>Whether Project Watershed 250 publishes results from its 60-day pilot.<\/strong> The pilot launched in San Antonio on August 31 and is already being described as a national blueprint. Watching for a utility count, a cost figure, the names of the private-sector partners, and any finding at all &mdash; the 60 days run out in late October, which is the first honest checkpoint.<\/li>\n<li><strong>Boston Scientific&rsquo;s October 28 earnings call.<\/strong> The company says it will likely miss both Q3 and full-year sales and earnings guidance but has not put a number on it. Watching for the dollar figure, for any disclosure of how much of the loss is permanent share rather than deferred orders, and for whether the recovery timeline gets broken down by plant or product line.<\/li>\n<li><strong>Whether Idaho gets a funding bill drafted in the next legislative session.<\/strong> The state&rsquo;s Cyber Resilience Operation Center runs on four full-time employees plus part-time staff, with 24\/7 operations and regional teams in Moscow and Twin Falls planned for June 2027. A funding bill failed to reach drafting in the 2026 session. Watching whether a bill is introduced, and what headcount it actually buys.<\/li>\n<li><strong>The NASCIO and GDIT report&rsquo;s undisclosed methodology.<\/strong> The 90%, 73%, 65%, 31% and 22% figures are being quoted widely, and neither the sample size nor the number of states represented appears anywhere in the coverage. Watching for the full report or a methodology note. Until one appears, treat the funding-gap percentages as directional.<\/li>\n<li><strong>Whether Sandia&rsquo;s C2E2 reaches a utility field trial.<\/strong> The project is roughly two years into DOE CESER funding under AI-FORTS, and the researchers say they aim eventually to test with a utility company. The next research phase is devoted to understanding and preventing hallucinations. Watching for a named utility, a named testbed, and a definition of what the accuracy metric measures.<\/li>\n<li><strong>The ICS-REC participating-utility count.<\/strong> NRECA represents nearly 900 electric cooperatives and the program is DOE-funded, but neither the number of participating utilities nor the amount of funding is disclosed, and the claimed measurable improvements are unquantified. Watching for a program report with denominators in it.<\/li>\n<li><strong>Whether state water-cyber funding models spread.<\/strong> New York has first-in-the-nation water cyber rules and put $9 million into 153 local utilities; the Texas Water Development Board added cybersecurity scoring to its revolving fund. Watching whether other states attach cyber criteria to state revolving fund scoring, which reaches small systems in a way grant programs do not.<\/li>\n<li><strong>Whether Fortinet publishes the survey methodology behind this week&rsquo;s two articles.<\/strong> Respondent countries and job titles are not broken out for the 700-plus global sample, and the maturity model whose Level 0 to Level 4 scale produced the headline collapse is never identified. Watching for a methodology appendix, because a maturity distribution that moves this far in one year usually means the question changed.<\/li>\n<li><strong>Enforcement reaching maritime OT monitoring.<\/strong> IACS Unified Requirements E26 and E27 took effect in July 2024 for newbuilds, IMO Resolution MSC.428(98) sits above them, and EU NIS2 pulls port and terminal operators in as essential entities. Watching for the first port-state control or class findings that turn continuous OT monitoring from a design requirement into an operational one.<\/li>\n<\/ul><\/div>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/09\/topic-map-it-ot-security-2026-09-13.png\" alt=\"Topic map of this week's IT\/OT Security themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&rsquo;s topic map &mdash; programs, policy and sectors rather than CVEs. The EU Cyber Resilience Act sits with Article 71, Article 24 and the Single Reporting Platform against manufacturing and the European Union; the DOE bulk-power RFI ties Executive Order 14420 to equipment provenance and the electric grid; Project Watershed 250 links ONCD, Sean Cairncross, Texas Cyber Command and the water sector, with CISA and its Insider Threat Mitigation Guide alongside; a state-capacity thread runs from NASCIO and GDIT through whole-of-state funding to New York, Idaho and the Roanoke Valley; Sandia&rsquo;s C2E2 sits with CESER and AI-FORTS beside NRECA&rsquo;s ICS-REC program for electric cooperatives; and a sector band carries the Fortinet State of OT report into manufacturing and OT visibility, Boston Scientific into medical device manufacturing, Food and Ag-ISAC into food and agriculture, and IMO MSC.428(98) and IACS E26\/E27 into maritime OT.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5879\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#334155;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>The CRA clock and product security obligations<\/h3>\n<div class=\"cluster-intro\">The September 11 Article 71 deadline covered twice, from two directions, neither of them industrial. They are merged into one write-up below, framed for the companies that build plant equipment rather than the ones that run it. The monthly ICS patch roundup sits here as an index row only &mdash; the CVE and advisory material it covers went to Malware Analysis this week.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/openssf.org\/blog\/2026\/09\/11\/a-community-guide-to-the-eu-cra-september-11-deadline-for-manufacturers\/\">A Community Guide to the EU CRA September 11 Deadline for Manufacturers<\/a><\/td>\n<td class=\"src\">OpenSSF<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/eu-cyber-resilience-act-reporting-requirements\">EU Cyber Resilience Act to Enforce New Reporting Requirements<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Sep 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.securityweek.com\/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws\/\">ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Sep 9, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Federal programs and the operating model<\/h3>\n<div class=\"cluster-intro\">A 30-day comment window with a real equipment list, a new CISA program guide, and one 60-day water pilot reported twice from the same summit stage. The two Billington items are paired into a single write-up below.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/us-doe-seeks-industry-input-on-securing-bulk-power-systems-from-foreign-equipment-supply-chain-cybersecurity-risks\/\">US DOE seeks industry input on securing bulk-power systems from foreign equipment, supply chain, cybersecurity risks<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/industrialcyber.co\/soc-incident-response\/cisa-urges-critical-infrastructure-to-strengthen-insider-threat-programs-against-cyberattacks-data-theft-and-sabotage\/\">CISA urges critical infrastructure to strengthen insider threat programs against cyberattacks, data theft and sabotage<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/water-cybersecurity-white-house-oncd-texas-partnership-cairncross\/830029\/\">White House sees water cybersecurity partnership in Texas as national blueprint<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Sep 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/govciomedia.com\/white-house-cisa-ramp-up-critical-infrastructure-security-efforts\/\">White House, CISA Ramp Up Critical Infrastructure Security Efforts<\/a><\/td>\n<td class=\"src\">GovCIO Media<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Grid and cooperative defence R&amp;D<\/h3>\n<div class=\"cluster-intro\">Two DOE-funded programs at very different stages of maturity, and both headlines run ahead of what has been demonstrated. Sandia&rsquo;s accuracy figure is laboratory-stage and self-reported; the Cyware item is a vendor announcement about research in progress, not a result.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/doe-and-sandia-national-lab-use-ai-to-boost-electric-grid-cybersecurity-detect-threats-with-95-accuracy\/\">DOE and Sandia National Lab use AI to boost electric grid cybersecurity, detect threats with 95% accuracy<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 8, 2026<\/td>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/industrialcyber.co\/news\/cyware-supports-nreca-research-to-improve-ot-monitoring-threat-detection-across-electric-cooperatives\/\">Cyware supports NRECA research to improve OT monitoring, threat detection across electric cooperatives<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>State and local capacity: who actually pays<\/h3>\n<div class=\"cluster-intro\">The funding structure below the executive branch is the week&rsquo;s clearest finding, and three local stories put faces on it. Two of them are Tribune Content Agency reprints rather than fresh national reporting &mdash; the Idaho piece carries the better hard number, a Cyber Resilience Operation Center running on four full-time employees. The fourth item is a CyberScoop op-ed carrying an editor&rsquo;s note we repeat here: its author, Mike Searight, is the former CIO of Waco, Texas and is now a senior adviser to Elisity, which sells the network segmentation technology he advocates, and Waco bought Elisity while he was CIO. His underlying facts are useful &mdash; CISA identified more than 100 compromised water and wastewater systems in July 2026, the FBI and EPA reported incidents across at least seven states since July 27, a Clayton County, Georgia pump station failed that same day, and Waco segmented five treatment plants in 43 days &mdash; but the recommendation and the commercial interest travel together.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/state-infrastructure-resources-cyberthreats\/830178\/\">State authorities warn they lack resources to address cyber threat to critical sectors<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/www.govtech.com\/security\/in-roanoke-valley-va-water-cybersecurity-changed-post-9-11\">In Roanoke Valley, Va., Water Cybersecurity Changed Post-9\/11<\/a><\/td>\n<td class=\"src\">GovTech<\/td>\n<td class=\"dt\">Sep 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.govtech.com\/security\/idaho-officials-contemplate-cyber-threat-to-utilities-systems\">Idaho Officials Contemplate Cyber Threat to Utilities, Systems<\/a><\/td>\n<td class=\"src\">GovTech<\/td>\n<td class=\"dt\">Sep 8, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/cyberscoop.com\/water-utility-cybersecurity-network-segmentation-op-ed\/\">In most cities, nobody owns the whole network (water utility OT segmentation)<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Sep 8, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Sector risk: manufacturing, food and agriculture, maritime, medtech<\/h3>\n<div class=\"cluster-intro\">One real outage with a measurable downstream cost, one survey published twice, one ISAC dataset with strong numbers behind it, and one founder&rsquo;s byline arguing for the product category his company sells. The provenance is stated in each write-up and index note rather than left to the reader.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/www.medtechdive.com\/news\/boston-scientific-fully-restores-operations-after-cyberattack\/830182\/\">Boston Scientific fully restores operations after cyberattack<\/a><\/td>\n<td class=\"src\">MedTech Dive<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.mbtmag.com\/cybersecurity\/blog\/22974107\/while-ot-security-is-maturing-risk-is-not-slowing-down\">While OT Security Is Maturing, Risk Is Not Slowing Down<\/a><\/td>\n<td class=\"src\">Manufacturing Business Technology<\/td>\n<td class=\"dt\">Sep 9, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.mbtmag.com\/cybersecurity\/blog\/22974120\/the-manufacturing-ot-security-imperative\">The Manufacturing OT Security Imperative<\/a><\/td>\n<td class=\"src\">Manufacturing Business Technology<\/td>\n<td class=\"dt\">Sep 9, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/industrialcyber.co\/features\/cyberattacks-on-food-and-agriculture-can-turn-disruptions-into-safety-crises-threatening-public-health-and-supply-chains\/\">Cyberattacks on food and agriculture can turn disruptions into safety crises, threatening public health and supply chains<\/a><\/td>\n<td class=\"src\">Industrial Cyber<\/td>\n<td class=\"dt\">Sep 11, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/www.cybersecurity-insiders.com\/watching-what-cannot-be-stopped-maritimes-ot-blind-spot\">Watching What Cannot be Stopped: Maritime&rsquo;s OT Blind Spot<\/a><\/td>\n<td class=\"src\">Cybersecurity Insiders<\/td>\n<td class=\"dt\">Sep 12, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>What AI actually changes in the OT stack<\/h3>\n<div class=\"cluster-intro\">Both foundational pieces this week are vendor marketing and should be read as such. The Dragos post is by one of its distinguished engineers and its figures are Dragos telemetry; the Claroty post is unsigned, its statistics are scoped to its own product estate, and it ends in a demo call to action. The observations are still useful &mdash; the attribution just has to travel with them.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/www.dragos.com\/blog\/ai-ot-threat-landscape\">What AI Actually Changes for OT Security: Observations from the Field<\/a><\/td>\n<td class=\"src\">Dragos<\/td>\n<td class=\"dt\">Sep 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/claroty.com\/blog\/understanding-ai-powered-cybersecurity-in-ot-environments\">Understanding AI-Powered Cybersecurity in OT Environments<\/a><\/td>\n<td class=\"src\">Claroty<\/td>\n<td class=\"dt\">Sep 10, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. The CRA clock started on September 11, and equipment manufacturers are in scope<\/h4>\n<p class=\"meta\">OpenSSF &middot; Dark Reading &middot; September 10&ndash;11, 2026<\/p>\n<p>Two pieces published a day apart cover the same obligation, and neither is written for a factory floor. Together they are the complete picture, so read them as one. As of September 11, 2026, manufacturers of &ldquo;products with digital elements&rdquo; must report actively exploited vulnerabilities and severe incidents under Article 71 of the EU Cyber Resilience Act, the regulation published at Official Journal reference L_202402847. The clock has three stages. An early warning is due within 24 hours of awareness. A full notification is due within 72 hours. A final report is due within 14 days of a corrective measure becoming available for an actively exploited vulnerability, or within one month of the 72-hour notification for a severe incident. Mandatory reports go to the CRA Single Reporting Platform; ENISA and coordinating CSIRTs also receive voluntary reports under Article 15. The OpenSSF guide, written by Madalin Neag, Sally Cooper and Steve Winslow, is organisation-authored policy explanation rather than journalism, and it omits penalties entirely. Dark Reading supplies them: up to EUR 15 million or 2.5% of annual worldwide revenue, with carve-outs meaning microenterprises under 10 staff or EUR 2 million and small enterprises under 50 staff or EUR 10 million cannot be fined for missing the 24-hour deadline. Dark Reading&rsquo;s quoted expert is Dr. Aram Hovsepyan, CEO and founder of Codific.<\/p>\n<p>&ldquo;Manufacturer&rdquo; here is a legal term, and that is the trap. It is not a factory-floor framing, and neither article carries industrial, OT or embedded-specific guidance &mdash; but the definition captures the companies that build the equipment in your plant. If your organisation ships a PLC, an RTU, a protocol gateway, an HMI, a historian appliance, a VFD with a network stack or a cellular router into the European Union, you are a manufacturer under this regulation and the 24-hour clock is now yours. Asset owners are not directly obliged, which is why this reads as somebody else&rsquo;s problem until you notice that it changes what your vendors will tell you and when.<\/p>\n<p>The organisational question is who holds the clock. Twenty-four hours from awareness is a duty-officer obligation, not a quarterly compliance activity, and it will usually be triggered by an engineer or a support desk noticing something rather than by a formal disclosure arriving. In a plant vendor&rsquo;s org chart the realistic owners are the product security team or PSIRT, with legal and regulatory affairs on the filing itself, and the escalation path from field observation to submitted notification is the part that has to exist before it is needed. The harder half is scope. An SRP filing for a PLC or a gateway has to describe which firmware versions are affected across an installed base the manufacturer often cannot enumerate, shipped through distributors and integrators, in equipment that may have been commissioned a decade ago. That uncertainty has to be expressed in a notification that goes out before the investigation is complete, and then refined at 72 hours and again at 14 days. Nobody has published a worked example of one yet.<\/p>\n<p>The practical steps are unglamorous. Determine which of your product lines are in scope and whether any part of your organisation qualifies for the small-entity carve-out. Diary December 11, 2027, when Article 24 steward obligations begin &mdash; a second deadline for anyone whose products embed open-source components they also maintain; Article 13(6) covers the manufacturer-maintainer collaboration in between. Publish a security.md or its equivalent for every product line, because an obligation that starts at &ldquo;awareness&rdquo; is much harder to meet when there is no documented route for a researcher or a customer&rsquo;s SOC to reach you. And use the three free artefacts OpenSSF published rather than commissioning a gap assessment to tell you the same thing: the CRA Stewards Playbook, the CRA Readiness Guide for Maintainers and Developers, and the CRA Manufacturer Checklist.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/openssf.org\/blog\/2026\/09\/11\/a-community-guide-to-the-eu-cra-september-11-deadline-for-manufacturers\/\">OpenSSF<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/eu-cyber-resilience-act-reporting-requirements\">Dark Reading<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. DOE opens a 30-day window on foreign equipment in the bulk-power system<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; September 11, 2026<\/p>\n<p>The Department of Energy has issued a Request for Information on securing the bulk-power system from foreign equipment and supply-chain cybersecurity risk. The Federal Register citation is 2026-18370, published September 9; comments close October 9, a 30-day window, and a public webinar was scheduled for September 16. The RFI implements Executive Order 14420, issued August 26, which declared a national emergency. No foreign adversary country is named in the coverage of the RFI, and no dollar figures are attached to it.<\/p>\n<p>The equipment list is where this stops being a policy story. In scope are grid-connected inverters, battery energy storage systems, UPS systems, generators and industrial control systems. That reaches distributed energy resources and storage assets, not just transmission-class gear &mdash; which means the population of affected owners includes co-ops, municipal utilities, independent power producers, campus and industrial sites with behind-the-meter storage, and anyone who has put an inverter fleet on a network in the last five years. If your risk register has treated supply-chain provenance as a transmission problem, this is the notice that it is not.<\/p>\n<p>The hard part is answering the question at all. Most asset registers record a model number and a purchase order, not a country of manufacture, and certainly not the origin of the components inside the enclosure. Binary and firmware analysis is raised in the coverage as the practical method for establishing component provenance in deployed equipment &mdash; which is a real technique with real cost, and a reason to scope the work to the categories DOE actually names rather than the whole estate. Patrick Miller, President and CEO of Ampyx Cyber, gives the sensible framing: &ldquo;Whether or not you plan to file comments, this is a reasonable prompt to start&rdquo; inventory work now.<\/p>\n<p>Two decisions are worth making this week. First, whether you comment &mdash; thirty days is short for anything needing legal review, so if the answer is yes, name the drafter and the reviewer now and find out which trade association is coordinating a filing you can join. Second, and regardless of the first, start the inventory: the five named categories, manufacturer, established country of manufacture where you can determine it, firmware version, and the supplier of record. That list is useful whatever DOE does next, and it is the artefact every subsequent version of this policy will ask you for.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/us-doe-seeks-industry-input-on-securing-bulk-power-systems-from-foreign-equipment-supply-chain-cybersecurity-risks\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. CISA&rsquo;s Insider Threat Mitigation Guide, and the claim that it scales down<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; September 10, 2026<\/p>\n<p>CISA published an Insider Threat Mitigation Guide in September 2026 and is the sole issuing agency. The recommended program model runs five phases &mdash; prevention, detection, assessment, response and continuous improvement &mdash; operated by a multidisciplinary threat management team. The mechanics are specific enough to copy: risk rubrics that categorise cases low, medium or high; a dedicated insider-threat incident response plan defining scope, roles, phases, reporting and escalation; and regular exercises, audits and independent compliance assessments. Scott Breor, Acting Executive Assistant Director for Infrastructure Security, frames it as a response to threats that &ldquo;continue to evolve as technology becomes more advanced.&rdquo;<\/p>\n<p>The anchor case is an energy-sector one from 2011, and it is worth carrying into a board conversation because the loss was not operational. A competitor&rsquo;s product was found to contain 20% stolen code; the victim company lost more than $1 billion in shareholder equity and roughly 700 jobs, over 50% of its global workforce. That is the intellectual-property end of the insider problem rather than the sabotage end, and it is the end most industrial firms underweight. CISA also folds workplace violence into its definition of insider threat, with context that explains why the guide reads as it does: roughly 2 million workplace violence reports annually with an estimated further 25% unreported, about 25,000 nonfatal incidents a year, one workplace homicide per day in the US, and 1 in 7 Americans not feeling safe at work. On the small-business side, 42% of small businesses hit by a cyber incident suffered revenue loss and 32% suffered loss of customer trust and employee turnover.<\/p>\n<p>The claim that matters operationally is that the framework is scale-independent &mdash; explicitly adaptable to organisations of any size. That is the line to test rather than dismiss. A small water system or a rural co-op will never staff a threat management team in the sense a federal agency means it, but the five phases collapse into a page: who reviews access changes, what triggers a conversation, who is in the room when it happens, what gets written down, and what the plant does in the meantime. The version that fits on a page is the one that will exist in a year.<\/p>\n<p>For OT specifically, the single most productive question is narrower than anything in the guide: who can change a setpoint without a second pair of eyes? That is answerable this week from access control lists and engineering-workstation permissions, and it produces a concrete list of people and stations. Everything else &mdash; behavioural indicators, case rubrics, exercise programmes &mdash; is easier to justify once that list exists and somebody senior has looked at it.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/soc-incident-response\/cisa-urges-critical-infrastructure-to-strengthen-insider-threat-programs-against-cyberattacks-data-theft-and-sabotage\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Sandia&rsquo;s C2E2: a research-stage grid detector, and a headline that outruns it<\/h4>\n<p class=\"meta\">Industrial Cyber &middot; September 8, 2026<\/p>\n<p>The system is C2E2 &mdash; Communications and Cybersecurity for the Energy Edge &mdash; built at Sandia National Laboratories and funded by DOE&rsquo;s Office of Cybersecurity, Energy Security, and Emergency Response under the AI-FORTS program. Funding began in 2024, putting the project roughly 18 months in as of July 2026. No dollar figure is disclosed. The named team is Georgios Fragkos, AI researcher and C2E2 team leader, with Sidney Wright and Birk Jones. Architecturally, the pipeline feeds data into a large language model that automates the data engineering, then hands a cleaned dataset to a machine-learning model; the stated capability is to determine whether a threat exists and to identify where it is occurring. Fragkos puts the design goal plainly: &ldquo;Localizing a threat is key to shutting it down.&rdquo;<\/p>\n<p>The 95% accuracy figure in the headline needs every one of its conditions attached, and they are substantial. It is a Sandia self-reported claim at laboratory and research stage, not a field-validated result. The wording is that &ldquo;the training process takes a couple of hours and has achieved a 95% accuracy rate.&rdquo; Neither the trade write-up nor Sandia&rsquo;s own July 2026 Lab News piece specifies what the metric measures &mdash; detection rate, classification accuracy, localisation precision, something else &mdash; nor the testbed, nor the dataset, nor whether the data was simulated or derived from a real utility. No utility field trial has taken place. The researchers say they aim eventually to test C2E2 with a utility company. Quoting the number without that context turns an early-stage research result into a procurement claim, and the headline already does exactly that.<\/p>\n<p>The most honest signal in the whole item is what comes next: the team&rsquo;s next research phase is explicitly about understanding and preventing AI hallucinations. That is a straightforward admission that the current output is not yet trustworthy enough for operational use, and it is more useful to a utility than the accuracy figure is. It is also a fair benchmark to hold commercial products to. If a national laboratory two years into DOE funding is still working on whether its LLM component invents things, a vendor claiming a settled answer on the same architecture is claiming to be well ahead of Sandia.<\/p>\n<p>The practical takeaway is a procurement habit rather than a technology decision. For any AI-driven OT detection claim, ask four questions before anything else: what does the accuracy metric measure, on what dataset, in which testbed, and has it run anywhere that had a real process behind it. C2E2 is genuinely interesting research and the localisation goal is the right one &mdash; knowing that something is wrong is much less useful on a grid than knowing where. But it is research, and the time to decide how you will evaluate it is before a version of it arrives with a price attached.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/industrialcyber.co\/utilities-energy-power-water-waste\/doe-and-sandia-national-lab-use-ai-to-boost-electric-grid-cybersecurity-detect-threats-with-95-accuracy\/\">Industrial Cyber<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. Washington&rsquo;s water pitch: one 60-day pilot, two speeches, no numbers yet<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; GovCIO Media &middot; September 10&ndash;11, 2026<\/p>\n<p>Two reports from the Billington Cybersecurity Summit in Washington on September 10 centre on the same programme and the same speaker, so they are treated here as one story. National Cyber Director Sean Cairncross presented Project Watershed 250 &mdash; a 60-day pilot in Texas announced in late August, launched August 31 and beginning in San Antonio &mdash; as a model the White House intends to extend to other sectors &ldquo;soon,&rdquo; with no timeline given. The programme is run by the Office of the National Cyber Director with Texas Cyber Command and unnamed private-sector partners; the EPA and WaterISAC do not appear in this coverage. Its stated mechanics are reducing cost for utilities, deploying new defensive technologies and convening industry stakeholders. Cairncross&rsquo;s framing: &ldquo;What we are trying to do is find a specific, concrete solution&rdquo; that can &ldquo;scale off of that.&rdquo;<\/p>\n<p>What is not disclosed is most of it. No utility count, no dollar figures, no named vendor partners, and no published results &mdash; a 60-day pilot with undisclosed scope is being positioned as a national blueprint before anybody outside it can see what it found. That is worth saying plainly without dismissing the programme, because the underlying diagnosis is correct. Water is characterised in the coverage as one of the most poorly defended infrastructure sectors, for reasons that are structural rather than technical: funding shortages, decentralisation and a dearth of technical expertise. No readiness metrics are given for that characterisation either.<\/p>\n<p>The GovCIO account adds the federal capacity side of the same speech. CISA Acting Director Nick Andersen talked about giving asset owners vulnerability-management tools; OPM Director Scott Kupor appeared alongside the U.S. Tech Force talent initiative and the CyberCorps Scholarship for Service; and there is an unquantified promise of &ldquo;hundreds of new CISA employees in the very near future.&rdquo; Read against the state-level funding picture from NASCIO and GDIT this week, that is the same problem approached from the opposite end &mdash; federal talent pipelines and tooling on one side, states unable to push money below the executive branch on the other, and the small utility sitting in the space between them.<\/p>\n<p>For an operator outside Texas, the useful move is not to wait for the blueprint. The pilot&rsquo;s 60 days run out in late October, which is the first honest checkpoint: watch for a utility count, a cost figure and a published finding. In the meantime, the mechanics the programme says it is testing &mdash; reducing cost, deploying defensive technology, convening the sector &mdash; are things state primacy agencies, sector ISACs and revolving-fund scoring already do in some states, and those are reachable now.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cybersecuritydive.com\/news\/water-cybersecurity-white-house-oncd-texas-partnership-cairncross\/830029\/\">Cybersecurity Dive<\/a> &middot; <a href=\"https:\/\/govciomedia.com\/white-house-cisa-ramp-up-critical-infrastructure-security-efforts\/\">GovCIO Media<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. The state funding gap: 65% for agencies, 31% for local government, 22% for nobody<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; September 11, 2026<\/p>\n<p>A joint report from NASCIO and General Dynamics Information Technology, released the week of September 9, found 90% of state CIOs rank cyberattacks on critical infrastructure a high concern and 73% say critical-infrastructure protection is part of their whole-of-state cybersecurity plan. Before going further: the report&rsquo;s sample size and the number of states represented are not disclosed anywhere in the coverage. The percentages are being quoted widely, and without a denominator they are directional rather than precise. That is a real limitation, not a footnote.<\/p>\n<p>With that caveat attached, the funding numbers are the story. 65% of state CIO budgets include critical-infrastructure cyber funding for executive-branch agencies. Only 31% provide funding down to local governments and special districts. And 22% have no dedicated critical-infrastructure cybersecurity funding at all. Water districts and small utilities sit precisely in the gap between the first figure and the second &mdash; they are special districts, not executive-branch agencies, and in most states the money stops before it reaches them. Meredith Ward, NASCIO&rsquo;s Deputy Executive Director, states the mismatch: &ldquo;Attackers don&rsquo;t care where local, county or state lines begin and end.&rdquo; The sectors named as exposed are water utilities, electric and gas, healthcare and hospitals, telecommunications and transportation. States report needing additional funding, personnel and training; no staffing counts or salary figures are given.<\/p>\n<p>New York State is the counter-example worth studying rather than admiring: $9 million in grants announced in early August 2026 for 153 local drinking-water and wastewater utilities. That is roughly $59,000 a utility, which buys an assessment, some segmentation work and perhaps a year of monitoring &mdash; not a programme, but enough to produce a finding and a budget line where neither existed. The mechanism matters more than the amount. Grants reach the utilities that apply; revolving-fund scoring, as Texas has done by adding cybersecurity criteria to its water fund, reaches the ones that were already borrowing for a pump station and did not know cyber was on the scorecard.<\/p>\n<p>Also quoted in the coverage are Dr. Mischa Beckett, Senior Director of Cyber Threat Intelligence at GDIT, and Errol Weiss, Chief Security Officer at Health-ISAC. For a utility manager, the practical use of this report is as a negotiating document: it establishes, from the states&rsquo; own CIOs, that the funding structure below the executive branch is the known weak point. If you are a special district that has been told to align with the state plan, this is the evidence that alignment has not historically come with money &mdash; and the question to put to your state CIO&rsquo;s office is which of the three categories your state falls into.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cybersecuritydive.com\/news\/state-infrastructure-resources-cyberthreats\/830178\/\">Cybersecurity Dive<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>7. Boston Scientific: seventeen days down, and the loss that happened in hospitals<\/h4>\n<p class=\"meta\">MedTech Dive &middot; September 11, 2026<\/p>\n<p>Boston Scientific detected an attack on August 25 and implemented containment the same day. Full restoration was reported on September 11 &mdash; a disruption of roughly seventeen days. What went down was manufacturing plants and distribution centres globally, plus order processing, fulfilment and shipping; specific facilities and product lines have not been identified. No threat actor or ransomware group has been named, no group claimed responsibility, there is no information on a ransom demand or payment, and no SEC 8-K filing is mentioned in the coverage. The company says it has seen no evidence of ongoing threat activity and no evidence of compromise to systems or products since containment, and that it worked with CrowdStrike and other third-party experts on the response.<\/p>\n<p>The financial line is unresolved. Boston Scientific says it will likely miss both Q3 and full-year sales and earnings guidance, with no dollar estimate yet and more detail promised on the October 28 earnings call. CEO Mike Mahoney&rsquo;s assessment is honest and, for anyone who has run a recovery, familiar: &ldquo;It&rsquo;s hard to pinpoint that exact dollar amount at this point.&rdquo;<\/p>\n<p>The detail that makes this an OT story rather than an IT one is downstream. Some procedures were lost because hospitals ran short of supply, and hospitals likely ordered from competitors during the outage. A manufacturing and logistics outage propagated into patient care and into permanent share loss &mdash; deferred orders come back, a clinician who switched to another device and found it acceptable may not. That is the mechanism by which a seventeen-day availability event becomes a multi-quarter revenue event, and it is the argument for treating fulfilment and shipping as part of the operational estate rather than as back-office IT that happens to sit downstream of the plant.<\/p>\n<p>The tabletop this suggests is the one most manufacturers have not run: the control systems are healthy, the lines could run, and you still cannot ship. Work out which lines can run degraded and for how long, what the paper process is, who is authorised to release product without the electronic quality record, how orders are taken and fulfilled when the order system is down, and which customers are told first. For a medtech manufacturer the last question has a clinical answer, not a commercial one, and it should be decided before the week it matters.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.medtechdive.com\/news\/boston-scientific-fully-restores-operations-after-cyberattack\/830182\/\">MedTech Dive<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>8. One Fortinet survey, two articles, same outlet, same day<\/h4>\n<p class=\"meta\">Manufacturing Business Technology &middot; September 9, 2026<\/p>\n<p>Manufacturing Business Technology published two pieces on September 9 built on the same dataset: the 2026 Fortinet State of Operational Technology and Cybersecurity Report. &ldquo;While OT Security Is Maturing, Risk Is Not Slowing Down&rdquo; reports the global sample of more than 700 OT professionals. It is bylined Richard Springer, and the byline shows no employer &mdash; Springer is Senior Director, Marketing, OT Solutions at Fortinet. This is a Fortinet marketing executive reporting Fortinet&rsquo;s own survey in an editorial slot. &ldquo;The Manufacturing OT Security Imperative&rdquo; is the manufacturing cut of the same survey &mdash; n=116, senior-level respondents at organisations of 1,000-plus employees running ICS, SCADA, PLC and IIoT estates, surveyed in January and February 2026 &mdash; it carries no author name at all, and it closes with a Fortinet promotional link. Treat them as one dataset viewed twice. Reporting the two sets of percentages side by side as independent corroboration would double-count a single survey.<\/p>\n<p>With the provenance stated, the global numbers are worth reading because the movement is unusually large. Responsibility for OT cybersecurity sitting with the CISO fell to 60%, down from 69% in 2025, while 81% say they plan to assign OT cyber to the CISO within a year, up from 80% &mdash; intent rising as practice slips. Self-assessed maturity collapsed at the top and swelled at the bottom: Level 4 fell to 17% from 49%, Level 2 rose to 27% from 13%, Level 1 to 17% from 5%, Level 0 to 5% from 1%. The article does not identify which maturity model these levels belong to, and it is not Purdue. A distribution that moves that far in twelve months usually means the instrument changed rather than the estate did, and the absence of a named model makes that impossible to check. Intrusions: 71% reported between one and nine, up from 47% &mdash; but organisations reporting both IT and OT systems compromised fell to 24% from 60%, which is the most interesting number in the set and points at segmentation containing blast radius. Incident types: phishing 76%, ransomware 50% and falling from 54%. Visibility remains the core gap, with only 14% reporting full OT visibility, up from 5%, and 23% at roughly half. Equipment refresh: 40% say their ICS systems are under five years old, double the 20% of 2025. And 89% expect increased regulation within five years, up sharply from 66%.<\/p>\n<p>The manufacturing cut adds budget and adoption figures on its smaller sample: 82% of manufacturers had at least one incident in the past year, 86% rank OT security a top-five business risk, 57% had OT environments directly impacted, 71% are planning OT security budgets above $1 million for 2026, 50% have already deployed AI-driven security tools and 62.1% are prioritising threat detection and monitoring. Those are useful for benchmarking a budget request, provided the request says n=116 senior respondents at large manufacturers &mdash; the number is small and the sample is the top of the market, so it describes what well-resourced plants are doing, not what the sector is doing.<\/p>\n<p>Neither article contains an attributed speaker quote; both are survey-data synthesis throughout. The defensible way to use any of this is as directional vendor-sourced evidence that visibility is still the binding constraint and that segmentation appears to be working where it has been done. If you are putting one number in front of a plant manager, make it the one about scope rather than the ones about maturity: the share of your own OT segments with no passive collection at all. That is a count you own, it does not depend on anybody&rsquo;s survey instrument, and it moves when you spend money.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.mbtmag.com\/cybersecurity\/blog\/22974107\/while-ot-security-is-maturing-risk-is-not-slowing-down\">Manufacturing Business Technology (global)<\/a> &middot; <a href=\"https:\/\/www.mbtmag.com\/cybersecurity\/blog\/22974120\/the-manufacturing-ot-security-imperative\">Manufacturing Business Technology (manufacturing cut)<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action --><\/p>\n<div class=\"watchlist\">\n<h2>Calls to action<\/h2>\n<ul>\n<li><strong>File or don&rsquo;t file, but start the equipment-provenance inventory this week.<\/strong> DOE&rsquo;s RFI closes October 9 and explicitly covers grid-connected inverters, battery energy storage, UPS systems, generators and industrial control systems. Build the list now: every asset in those five categories, its manufacturer, the country of manufacture where you can establish it, the firmware version running, and who supplied it. Binary and firmware analysis is the practical method where the paperwork does not answer the question.<\/li>\n<li><strong>Put the September 16 DOE webinar and the October 9 deadline in the compliance calendar today.<\/strong> Thirty days is short for anything that needs legal review. If you intend to comment, decide this week who drafts, who reviews and which trade association you are coordinating with &mdash; and if you do not intend to comment, note that decision in writing so nobody has to reconstruct it later.<\/li>\n<li><strong>If your company ships anything with digital elements into the EU, name the person who owns the 24-hour clock.<\/strong> Article 71 has been live since September 11. The early warning is due within 24 hours of awareness, the full notification within 72, the final report within 14 days of a corrective measure for an exploited vulnerability. That is a duty officer&rsquo;s job, not a quarterly compliance task &mdash; decide whether it sits with product security, the PSIRT, legal or the regulatory affairs team, and write down the escalation path that gets an engineer&rsquo;s observation to a filed notification overnight.<\/li>\n<li><strong>Work out which of your products are in CRA scope and whether you qualify for the small-entity carve-out.<\/strong> Microenterprises under 10 staff or EUR 2 million and small enterprises under 50 staff or EUR 10 million cannot be fined for missing the 24-hour deadline; everyone else faces up to EUR 15 million or 2.5% of annual worldwide revenue. Diary December 11, 2027 for Article 24 steward obligations, and pull the free CRA Manufacturer Checklist and Readiness Guide rather than paying for a gap assessment to tell you the same thing.<\/li>\n<li><strong>Publish a security.md, or the equivalent, on every product line.<\/strong> It is the recommended baseline under the CRA guidance and it is a half-day of work. A reporting obligation that starts with &ldquo;awareness&rdquo; is much harder to meet when there is no documented route for a researcher, an integrator or a customer&rsquo;s SOC to tell you something is being exploited.<\/li>\n<li><strong>Run the insider-threat tabletop CISA&rsquo;s guide is built for, at your actual size.<\/strong> The five-phase model &mdash; prevention, detection, assessment, response, continuous improvement &mdash; needs a multidisciplinary threat management team, a risk rubric that sorts cases low, medium and high, and an insider-threat incident response plan that defines scope, roles, reporting and escalation. CISA states the framework is scale-independent. A three-person water utility can produce a one-page version of all of it.<\/li>\n<li><strong>Ask who can change a setpoint without a second pair of eyes.<\/strong> That single question is the operational core of an insider program on a plant floor, and it is answerable this week from your access control lists and your engineering-workstation permissions. Do it before you buy anything labelled insider-threat detection.<\/li>\n<li><strong>Rehearse the outage where your control systems are healthy and you still cannot ship.<\/strong> Boston Scientific&rsquo;s intrusion took down manufacturing plants and distribution centres globally plus order processing, fulfilment and shipping, for roughly seventeen days, and the durable damage was downstream &mdash; procedures lost, customers buying elsewhere. Establish which lines can run degraded, for how long, on what paper process, who may release product without the electronic record, and which customers get told first.<\/li>\n<li><strong>Check what your OT visibility number actually is, not what you assume it is.<\/strong> The Fortinet survey puts full OT visibility at 14% of organisations and Dragos&rsquo;s own telemetry puts environments with visibility and monitoring at under 10%. Both figures are vendor-sourced, and both point the same way. Count the segments where you have no passive collection at all and treat that count, not a percentage, as the metric you report upward.<\/li>\n<li><strong>Get a written answer on who owns segmentation across your municipal network.<\/strong> Where water, traffic, public safety and general IT share one flat network and no single role owns the whole of it, the question is organisational before it is technical. Waco segmented five treatment plants in 43 days, so the work is finite &mdash; but only after somebody is named as accountable for it.<\/li>\n<li><strong>Treat AI detection claims as procurement questions with denominators.<\/strong> For any AI-driven OT detection pitch, ask what the accuracy metric measures, on which dataset, in which testbed, and whether it has run at a utility or a plant rather than a laboratory. Sandia&rsquo;s own next research phase is about preventing hallucinations, which is the honest state of the art and a fair benchmark for anyone selling further along.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">IT\/OT Security<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>September 13, 2026 &middot; Weekly Edition IT\/OT Security The CVE traffic, the CISA advisories and the malware campaigns went to Malware Analysis this week. What is left is the operating model &mdash; budgets, headcounts, deadlines and who actually pays. The EU Cyber Resilience Act&rsquo;s Article 71 reporting clock started on&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[50],"tags":[],"class_list":["post-5880","post","type-post","status-publish","format-standard","hentry","category-it-ot-security"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5880"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5880\/revisions"}],"predecessor-version":[{"id":5891,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5880\/revisions\/5891"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}