ALT Graphic for the CIP-015 Compliance on a Budget blog shows a scene inside a warm, bustling fantasy tavern lit by lanterns and fireplaces, where a group of adventurers gathers around a large wooden table covered with maps, notes, dice, and planning tools. One character points at the map while the others study routes and discuss strategy, symbolizing collaborative planning and phased execution. A glowing phoenix perched above the group illuminates the room with EmberOT’s signature orange glow. The tavern is filled with additional travelers, wooden beams, banners, clocks, and intricate fantasy décor, creating the feeling of a central planning hub before a major quest.
The future OT analyst needs more than cyber fundamentals.
They need OT/ICS depth, protocol fluency, & enough AI literacy to challenge model output instead of trusting it blindly.
New article by @CSecDaemon on why the cross-disciplinary OT analyst wins:
emberot.com/resources/blog/o…
ALT A futuristic industrial environment where a technician stands inside a dark OT facility surrounded by electrical equipment, control systems, and glowing instrumentation. In front of the operator is a large holographic-style network visualization composed of orange data lines, diagrams, and connected nodes forming the shape of a phoenix. The technician reaches toward the glowing display as if interacting with a live OT monitoring or analytics system.
The most dangerous AI take in cybersecurity right now isn't "AI will replace us."
It's "AI will up-skill us."
A thread on what most leaders are missing about AI in cyber.
The pitch: AI will up-skill your team. Juniors will operate like seniors.
The reality: AI gives juniors access to senior-shaped output. Not the same thing.
The senior can interrogate the output. The junior often can't yet.
Foundations first. AI second. The order matters more than people realize.
Without the craft, AI is a confidence amplifier with no validation layer underneath. With the craft, it's a real multiplier.
Full article here: linkedin.com/pulse/most-dang…#cybersecurity#AI
CIP-015 is not a loot drop.
A matrix full of green checkmarks won’t help if you’re still blind at Levels 1 and 2.
The real question: if an attacker were already inside your ESP, would you know?
I wrote about the compliance trap here:emberot.com/resources/blog/c…
CIP-015 is not a loot drop.
Checking every R1 through R3 box does not guarantee real detection. You can be compliant on paper and still stay blind where it counts.
@CSecDaemon on alert floods, tool mismatch, and visibility gaps at Levels 1 and 2:
emberot.com/resources/blog/c…
ALT A dark, fantasy-themed scene set in an underground stone chamber where three adventurers cautiously approach a large, ornate treasure chest. The chest is reinforced with metal bands, gears, and glowing orange seams, suggesting both mechanical complexity and hidden danger. One character reaches toward the chest while another holds up a lantern, casting warm light across the scene. A third figure stands behind with a glowing, phoenix-like creature perched on their shoulder. The atmosphere is tense and mysterious, implying that opening the chest may trigger a trap rather than reward—visually reinforcing the idea that compliance or security outcomes are not simple “loot drops,” but require careful effort and awareness. The treasure chest is a mimic with sharp teeth waiting to attack the adventurers, but the Phoenix is there to protect them.
When remote OT environments span hundreds (or thousands) of miles, teams need usable data they can act on. Better visibility helps operators reduce blind spots, improve detection, & support safer, more reliable operations.
New article from @CSecDaemonemberot.com/resources/blog/p…
ALT An orange-tinted image of large industrial pipelines running through a wooded outdoor area, extending into the distance. Overlaid text reads “Pipeline Security, Visibility, and Detection at the OT Edge.” A circular headshot of Jori VanAntwerp appears on the left, labeled “EmberOT Founder & CEO.” The EmberOT logo is displayed in the bottom right corner.
#BSidesICS & #S4x26 week felt like the right time to share this...
I wrote a bit of a manifesto about how I think OT security should be practiced, focusing on one idea:
“No Noise. Just Signal.”
Clear thinking. Respect for operations. Awareness of real-world impact.🤘🔥
IT lets you move fast.
OT requires you to move carefully.
Vendor contracts, validation cycles, legacy PLCs, and operators who know every edge case. Security changes can affect real-world processes.
Part 2 of our OT Curious series:
emberot.com/resources/blog/v…
More IT defenders are becoming “OT curious,” but #OTsecurity isn't just IT with different gear.
OT systems run for decades, control physical processes, and come with very different constraints and consequences.
emberot.com/resources/blog/a…
Join us for an exclusive #S4x26 evening social with #cybersecurity & tech leaders. Connect w/ peers, continue conference convos, & unwind in a relaxed setting.
🗓️ Tues, Feb 24 | 8:00–11:00 PM
📍 Preston’s Terrace and Dining Room, Loews Miami Beach
RSVP at mfcyber.com/s426-social/?utm…
EmberOT announces new partnerships w/ @e2eassure & @PhoenixContact to expand OT visibility, managed detection, and industrial security at scale.
"Together, we are enabling defenders & operators to secure critical systems more effectively."
~@CSecDaemonemberot.com/newsroom/emberot…
If you work in OT, you already know this truth: humor is a coping mechanism.
Asset inventories, Patch Tuesdays, legacy systems that can't be touched, these 17 #OTcybersecurity memes are painfully accurate.
emberot.com/resources/blog/o…
h/t @_mikeholcomb_ for creating many of these!
ALT An orange-tinted image showing several large industrial cooling towers emitting thick plumes of steam into the sky, suggesting a power plant or critical infrastructure facility. Overlaid white text reads: “17 OT Cybersecurity Memes You’ll Feel in Your Soul.” In the bottom right corner, the EmberOT logo is visible. The visual tone is dramatic, matching the emotional punchline of the title, blending industrial imagery with humor-oriented content.
#OpenSource tools in #OT can be powerful, but only if they're selected & deployed w/ discipline.
In this piece, @CSecDaemon shares realistic tips to choose tools that respect operational risk, legacy systems, & real-world constraints in ICS environments.
emberot.com/resources/blog/o…
ALT A pixel art illustration showing a steampunk-style engineer character wearing goggles and holding a wrench while kneeling in front of a large industrial machine with pipes, dials, and steam. The text "Open Source Tools in OT" appears in the top left, with the EmberOT flame logo next to the character. The image has a retro, video game-inspired aesthetic, evoking themes of DIY engineering and hands-on operational technology.
#OT#cybersecurity strength is built through consistent habits that respect uptime & safety.
@CSecDaemon shares helpful #OTsecurity tips with a workout mindset: asset visibility, access control, patching & monitoring that actually fit real operations. 💪
emberot.com/resources/blog/o…
ALT Promotional graphic for an EmberOT blog post titled “Your OT Security Workout Plan: Building Strong Habits in the New Year.” The background features a gym setting with rows of dumbbells and a large barbell resting on the floor, evoking themes of strength and discipline. Text appears over the image with the blog title and attribution to Jori VanAntwerp, identified as “EmberOT Founder & CEO,” alongside a circular headshot of Jori. The EmberOT logo is positioned in the lower right corner.
Quantum is often discussed as a future risk to #OTsecurity. There's also a defender advantage taking shape.
Dr. Rishabh Das shares how #QuantumTech can strengthen encryption, integrity, timing, & anomaly detection in OT environments w/out disrupting ops.
emberot.com/resources/blog/h…
ALT Promotional graphic for an EmberOT blog post titled “How Quantum Will Redefine OT Security.” The background features a high-tech abstract design with swirling blue digital light patterns and data streams, evoking advanced computing or a quantum environment. Text on the image includes the blog title and attribution to Dr. Rishabh Das, identified as a “Critical Infrastructure Cybersecurity researcher” and “Assistant Professor, Ohio University.” A circular headshot of Dr. Das appears in the bottom left corner. The EmberOT logo is positioned in the bottom right corner.
Choosing the right OT tools shouldn’t be guesswork.
In his latest article, @CSecDaemon shares a practical guide to some of the tools operators and defenders actually use to understand their environments and strengthen security.
emberot.com/resources/blog/b…#OTsecurity#ICSsecurity
ALT Visual for an EmberOT blog post featuring a dark background image of a neatly arranged mechanic’s toolbox with various hand tools including sockets, wrenches, and ratchets. Overlaid text reads: “Build Your First OT Toolbox: It’s Dangerous to Go Alone, So Take These Tools!” Below the headline is a circular photo of Jori VanAntwerp with his name and title, “EmberOT Founder & CEO.” The EmberOT logo is positioned in the bottom right corner.
ALT A large wall of stacked paper files fills the background of the image, symbolizing overwhelming documentation. Overlaid text in bold white font reads: "What to Expect When You're Expecting... A NERC-CIP Audit - PART 1." Below, a circular photo of Aaron Crow appears alongside his name and title: "Senior Director, MorganFranklin Cyber." The EmberOT logo is displayed in the bottom right corner.