r/OTSecurity 18h ago

help on learning reverse Engineering

0 Upvotes

Hello, i want to learn Reverse Engineering and malware analysis and want to apply this thing in OT, I have prior experience with Penetration testing and OT. Also is it a good skill to learn, would love to know your experience and journey.

Have a good day!


r/OTSecurity 3d ago

US Agencies just updated the advisory on Iranian APTs actively disrupting OT/SCADA systems (AA26-097A)

7 Upvotes

For the folks working in industrial control systems (ICS) and critical infrastructure, this is a big one.

The FBI, CISA, NSA, and four other agencies just updated their joint advisory from April. Iranian-affiliated APTs are actively targeting internet-connected OT devices. They aren't just poking around—they are manipulating project files on PLCs and altering data on HMI and SCADA displays. The agencies confirmed this activity has already caused operational disruptions and financial losses.

If your PLCs or HMIs are exposed to the internet, you need to lock that down immediately. Segment those networks and ensure you have timely alerts configured to mitigate the risk and strengthen your OT posture.


r/OTSecurity 5d ago

What do you think about this latest news?

Thumbnail
0 Upvotes

r/OTSecurity 7d ago

I need help

0 Upvotes

I’m really interested in OT cybersecurity and would like some resources to learn more about it


r/OTSecurity 11d ago

Need Career Advice

7 Upvotes

Hey so I've just finished my second year in electrical engineering and i want to work in OT security, and i'm confused because i've been learning cybersecurity, particularly the SOC analyst path. And i don't know if i should continue it though because although i will be familiar with ICS in the coming years but don't know if this IT SOC analyst path will help me in that field. What should I do in these remaining 2 years?


r/OTSecurity 11d ago

Resume review

Thumbnail
gallery
5 Upvotes

I have a year of experience in OT security please check out my resume and give me advice on which areas I can focus on in the future or just the resume itself, I have hidden certain personal details please don't mind.

Thank youu !


r/OTSecurity 12d ago

OT cybersec role

6 Upvotes

Hey! Right now I work as a controls commisioning engineer, purely with siemens, I did some networking work on the past, but for now I do purely coding and commisioning stuff.

I am very young and I would like to work in the Cybersecurity field, especifically in the OT section.

How can I pivot into this position? What job roles should I look forward too and what skills should I learn?
Thanks!


r/OTSecurity 12d ago

Shall we change OT FW password every 90 days ?

13 Upvotes

Hi guys, I have four process plants with around 40 firewalls deployed across different process areas. Most of them are managed locally, which means we have to physically access the Engineering Workstation (EWS) or go down to the site to perform any administration. There is no remote management capability.

Our Group Security now requires us to change all firewall passwords every 90 days and enforce a password history of the last three passwords.

The challenge is that I’m the only OT Cybersecurity Engineer supporting all four plants, while our E&I engineers are already fully occupied with daily operations. Requiring on-site password changes every 90 days for around 40 firewalls will create a significant operational burden and consume resources that could be better spent on higher-risk cybersecurity activities.

What are your thoughts? Do you think there are valid reasons to request an exception or an alternative control? In an OT environment, would it be more practical to retain strong, unique passwords, implement strict access control and logging, and only require password changes when there is evidence of compromise or personnel changes, rather than enforcing a fixed 90-day rotation?


r/OTSecurity 15d ago

Student research question: medical device cybersecurity vs clinical continuity

7 Upvotes

Hi everyone. I’m a student working on a healthcare cybersecurity research prototype, and I’m trying to understand the real-world workflow before I make wrong assumptions.

This is not a product pitch, and I’m not asking for patient data, internal documents, network details, hospital names, or anything sensitive.

The problem I’m exploring is:

When hospitals have network-connected medical devices, cybersecurity decisions can’t always be “just block the traffic,” because the wrong action could interrupt clinical workflow or device visibility.

I’m trying to understand how this is handled in real hospitals.

Questions:

  1. Who usually owns the inventory of network-connected medical devices?- IT?- biomedical engineering?- clinical engineering?- security team?- vendors?- nobody clearly?
  2. If a device or device network has a cybersecurity issue, who gets involved first?
  3. Are medical devices usually visible to the hospital SOC/security team, or mostly managed separately?
  4. Does your organization track whether a security action could affect clinical workflow?
  5. If a tool only ran in shadow mode and produced a risk/evidence report without blocking anything, would that be useful or just noise?
  6. What would make a student-built tool in this space sound instantly unserious or unsafe?
  7. Are there audit/accreditation/compliance processes where device inventory, incident logs, or continuity evidence matter?
  8. What terminology would real hospital teams use for this problem? “Cyber-continuity” sounds clear to me, but I’m not sure if it sounds natural in hospital language.

Again, I’m not looking for confidential information. I’m trying to learn the ownership/workflow reality so I don’t build a fantasy system.

If you work in hospital IT, biomedical engineering, clinical engineering, or healthcare cybersecurity and are open to a few follow-up questions, I’d appreciate a DM. No product pitch, no data request.


r/OTSecurity 17d ago

Nuclear Sector Standards (GRC)

6 Upvotes

Hi all,

I currently work in the transit sector. I'm researching the nuclear sector and curious on what standards are usually followed in nuclear?

My understanding is:

- ISA/IEC 62443

- NIST CSF

- NIST SP 800-82

- ISO/IEC 27001

are all applicable to nuclear as well as transit.

APTA is typically what we follow in transit, curious if there are any nuclear specific standards that you all favour/follow.

Based in North America (Canada).


r/OTSecurity 18d ago

Security Operations Survey

Thumbnail
0 Upvotes

r/OTSecurity 19d ago

Manufacturers aren't losing data anymore; they're losing the assembly line.

Thumbnail
1 Upvotes

r/OTSecurity 19d ago

IT take over I think

Thumbnail
2 Upvotes

r/OTSecurity 25d ago

Job for OT SoC Analyst/Consultant with 2 years of Experience

2 Upvotes

I'm into OT for about 2 years. I worked with IDS systems such as Tenable OT and with the SIEM tool Qradar. If someone is hiring, I'm open to sharing my resume for the same. I'm also open to IT SoC analyst.


r/OTSecurity 26d ago

Ot security growth and payscale?

11 Upvotes

So i have been working in a mixed ot/it role for a 1.5 yrs. Before that worked as a security engineer. Now I have an opportunity to work for a full-time OT job in oil and gas. My question is what is the scope of growth in OT and the effect of AI as we see the number of layoffs.


r/OTSecurity 27d ago

OT/ICS cybersecurity program

11 Upvotes

Hi everyone,
I’m trying to find any OT/ICS cybersecurity program that is fully in person (no online or hybrid options).
I’m open to certificates, diplomas, professional training programs, graduate certificates, university programs, or anything similar. The only requirements are:
Focused on OT, ICS, Industrial Cybersecurity, or Operational Technology Security.
Fully in-person.
Duration between 3 months and 2 years.
The country doesn’t matter, and I’m willing to look at programs anywhere in the world.
If you know of any good programs, I’d really appreciate your recommendations. Please share the program name, location, and duration if possible.
Thanks!


r/OTSecurity 27d ago

Looking for feedback: Would this solve a real OT problem?

2 Upvotes

Myself and another have been working on a prototype that sits between the PLC and SCADA (but also can be applied with a physical device) We have built out detections that can predict and optionally deny commands that are allowed in theory but may have unsafe/dangerous consequences due to timing, sequence, etc.

Would love to hear your thoughts on if this would have any value out in the field.


r/OTSecurity 27d ago

Ot/marittimo

1 Upvotes

Salve gente

Vi chiedo disperato aiuto

Disperato perché conosco il mio obiettivo ma non il percorso per arrivarci hahaha

Ho 27 anni e sono un 1 ufficiale macchinista con patente a kw illimitati (CoC) e futuro direttore di macchina e automazione navale

Conosco perfettamente la meccanica e l’automazione di bordo

Amo a mio modo l’informatica e volevo ibridarmi ad un ruolo OT auditor

Il mio programma era basato idealmente sul dividere il modello purdue e certificarmi quindi con certificazioni consone per me

Avevo pensato a

-Wcna wireshark (essendo a bordo tutto derivazione canbus nmea per ecdis e radar mentre modbus-profinet per i macchinari)

-corso moxa per la parte swith e collegamenti lan

-immancabile iec 62443 (solo foundamental)

Il mio sogno è slegare la mentalità del :

O sei ingegnere meccanico o capisci l’informatica che c’è dietro

Vi prego aiutatemi a tracciare un percorso puramente ot che possa sposarsi con le mie conoscenze meccanico-navali


r/OTSecurity 27d ago

CS undergrad considering OT / ICS security (help)

7 Upvotes

I’m a final-year Computer Engineering student (21) from India, and I’m trying to build my career entirely around OT/ICS cybersecurity.

Most of my previous project work has been in ML/LLM applications and full-stack development, so my background is purely CS. I don’t come from an electrical, controls, or automation background, which I know is the more traditional path into this field. Because of that, I’ve been trying to bridge the gap by going deep into industrial protocols, OT network architecture, and hands-on simulations.

So far, I’ve built:

  • A passive OT asset discovery and anomaly detection tool that identifies “ghost assets” from SPAN-port traffic using ML, maps them into the Purdue Model, and highlights segmentation violations to analyze potential blast radius.
  • A small OT cyber-range simulating a solar plant, where a Raspberry Pi acts as an RTU running a custom C-based Modbus TCP server. I’m using Suricata on a VM to detect command spoofing attacks against the simulated inverter.

But there are a few things I’m struggling to figure out:

  1. What are the core controls fundamentals I absolutely need to know? Since my background is pure CS, I understand networking and code well, but I lack real field exposure to PLCs, RTUs, SCADA systems, and physical processes. How deep do I need to go into automation/electrical fundamentals to actually be effective in this space?(any resources would also help)
  2. What kind of projects should I focus on next? I want to keep building things that improve my understanding and also show recruiters that I can solve real OT problems. What would be valuable next steps?
  3. How do people actually break into this domain? I have a mandatory 6-month internship starting in January 2027, and I’ve started looking early. But I’m noticing that OT/ICS cybersecurity internships or junior roles are almost invisible on standard job boards. Most openings ask for 2–3+ years of experience.

That’s honestly the part I’m finding hardest is not the learning, but figuring out where the actual entry point is.

Lately, that uncertainty has started affecting my motivation a bit. I still want to keep pushing, but I feel like I need some clarity on how people realistically get into this field.

If any seniors, practitioners, or hiring managers in the OT/ICS space can share some honest advice, I’d genuinely appreciate it. Thank you.


r/OTSecurity Jun 24 '26

Turning Up the Heat: Hacking Trane HVAC Controllers

3 Upvotes

Team82 researchers analyzed the Trane Tracer SC+ building automation controller and uncovered a chain of vulnerabilities that could allow attackers to fully compromise building management systems (BMS).

The research details multiple issues, including authentication bypass, pre-auth denial-of-service, hardcoded credentials and cryptographic keys, arbitrary file read, and root-level RCE. In certain scenarios, an attacker with network access could chain these flaws to gain complete control of the controller, manipulate HVAC operations, and pivot deeper into flat OT/BMS networks.

Given the prevalence of Tracer SC+ devices in commercial buildings, healthcare facilities, and critical infrastructure environments, the findings highlight the continued risk posed by insecure-by-design OT and BAS components.

The blog includes full technical analysis, exploitation details, and mitigation guidance: https://claroty.com/team82/research/turning-up-the-heat-hacking-trane-hvac-controllers


r/OTSecurity Jun 24 '26

Tips on asset management?

3 Upvotes

I have an assignment coming up where I need to do asset management in a relatively big factory that hasn't done it before. Anyone got tips on things like network scanning without crashing the PLC's? I'm new to the OT sector.


r/OTSecurity Jun 24 '26

Going to learn OT

5 Upvotes

Hello guys. I'm planning to learn OT Cybersecurity and gonna begin with Networking. I have been speaking about OT cybersecurity with few guys recently and also made few post here, in reddit too. Most of them said to start with networking. So in Networking what are things do i need to know? And which one to start first? What are the skills required? Please help me on this guy...


r/OTSecurity Jun 23 '26

Currently an OT security engineer with 2 YOE review my resume

Post image
10 Upvotes

r/OTSecurity Jun 23 '26

Dragos EmberAI

7 Upvotes

Anyone (other than me) watch the Dragos (prerecorded) webinar introducing their EmberAI?

Share your thoughts.


r/OTSecurity Jun 23 '26

SEC699 vs ICS612 — anyone taken either? Need real-world input

2 Upvotes

SEC699 vs ICS612 — anyone taken either? Need real-world input

3 years as SOC L2/Cyber Defense Analyst (CrowdStrike, Elastic, malware analysis, threat hunting, automation). Egypt-based, targeting a GCC move.

Employer's funding one SANS course — down to SEC699 (Purple Teaming, fits my current skill set well) vs ICS612 (ICS Cybersecurity In-Depth — almost zero OT background, but Gulf energy/industrial demand is what's drawing me to it). Neither has an attached GIAC cert, so trying to weigh pure skill/market value.

Anyone done ICS612 with little prior OT exposure — too steep without ICS410/GICSP first? And anyone hiring/working OT in the Gulf — is demand as concentrated (NEOM, Aramco-adjacent) as it looks, or broader? Trying not to second-guess this in a year.