Zero trust (ZT) offers a modern, adaptive approach to cybersecurity by eliminating implicit trust and continuously validating access based on identity, context, and risk. ZT principles assume a breach has already occurred and are designed to limit threat actor movement and potential damage.
For operational technology (OT), applying ZT requires careful consideration because OT systems interact with the physical environment and are constrained by availability and safety requirements, as well as legacy technology with long lifespans. The blanket application of traditional information technology (IT)-focused ZT capabilities to OT is neither reasonable nor feasible and requires continuous collaboration between OT engineers, IT architects, and cybersecurity professionals. This collaboration should include clear communication channels, joint development of policies and controls, and a shared understanding of both mission objectives and technical limitations.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Fortinet Releases Security Advisory for Authentication Bypass Vulnerability
August 12, 2025
An authentication bypass using an alternate path or channel vulnerability in FortiOS, FortiProxy & FortiPAM may allow an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager’s serial number. Read more… Source: Fortinet Sign up for the Cyber ...
- WinRAR vulnerability exploited by two different groups
August 12, 2025
On July 30, 2025, WinRAR released a new version (7.13 Final) to patch a vulnerability which was used in two separate malware campaigns. WinRAR is a popular file archiving and data compression tool that allows users to compress files into smaller archives, like RAR and ZIP, and can also unpack various archive formats. The vulnerability, tracked ...
- Cyber’s Focus On Prevention Hasn’t Worked, Making Cyber Resilience Elusive
August 12, 2025
We’ve spent decades chasing the illusion of “perfecting prevention.” The industry has poured billions into digital walls, endpoint solutions, SIEM, SOAR and user awareness training—all to build a world in which breaches don’t happen. However, that world doesn’t exist. The cloud-first shift, SaaS sprawl and identity-driven access have fragmented the enterprise environment and expanded the attack ...
- How NATO Is Building Resilience Against Disruptive Cyber Technologies
August 12, 2025
The mission of NATO (North Atlantic Treaty Organization) is to safeguard the freedom and security of its member countries through political and military means. “We look out for our members by combining smart diplomacy with strong defense, and that includes risk management and cyber resilience,” said Konrad Wrona, Security Expert, NATO Communications and Information (NCI) Agency. ...
- An Earth-Shattering Kaboom: Bringing a Physical ICS Penetration Testing Environment to Life
August 6, 2025
Whether it’s in the water we drink, the medicines we take, or the electricity we use to read blog posts on the internet, Industrial Control Systems (ICS) are part of our daily lives. There’s so much that relies on these systems, you’d like to assume they’re engineered and tested to guard against cyberattacks. You’d be wrong. ...
- Denmark energy cyber attack highlights infrastructure security gaps
August 4, 2025
November 2023 saw an unprecedented cyber attack on Denmark’s energy infrastructure. In a co-ordinated breach of 22 companies, criminal gangs gained access to industrial control systems. Investigators believe at least one of the attackers was acting on behalf of a state. Michael Murphy, who heads Fortinet’s APAC Operational Technology group from the company’s Sydney office, says ...
