<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title>OT Defense Review</title><id>https://otdefensereview.com/</id><updated>2026-07-19T12:00:00.000Z</updated><link href="https://otdefensereview.com/feed.xml" rel="self"/><entry><title>The EU Cyber Resilience Act reaches its first 2026 application milestones</title><id>https://otdefensereview.com/news/eu-cra-application-milestones-2026/</id><link href="https://otdefensereview.com/news/eu-cra-application-milestones-2026/"/><updated>2026-07-19T12:00:00.000Z</updated><published>2026-07-19T12:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>Notified-body provisions began applying in June 2026 and vulnerability-reporting provisions follow in September, while the regulation's general application remains December 2027.</summary></entry><entry><title>Accenture agrees to take a majority stake in Dragos and acquire runZero and NetRise</title><id>https://otdefensereview.com/news/accenture-agrees-dragos-runzero-netrise-transactions-2026/</id><link href="https://otdefensereview.com/news/accenture-agrees-dragos-runzero-netrise-transactions-2026/"/><updated>2026-06-18T13:00:00.000Z</updated><published>2026-06-18T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The June 2026 announcement would combine OT threat detection, asset intelligence, firmware analysis, services, and a large integrator—creating immediate product-boundary, data, neutrality, and roadmap questions.</summary></entry><entry><title>ServiceNow completes its acquisition of Armis</title><id>https://otdefensereview.com/news/servicenow-completes-armis-acquisition-2026/</id><link href="https://otdefensereview.com/news/servicenow-completes-armis-acquisition-2026/"/><updated>2026-04-20T13:00:00.000Z</updated><published>2026-04-20T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The April 2026 close moves a major cyber-asset intelligence platform inside ServiceNow and puts asset identity, exposure, workflow, data use, packaging, and remediation ownership on the diligence agenda.</summary></entry><entry><title>Dragos publishes its 2026 OT cybersecurity year in review</title><id>https://otdefensereview.com/news/dragos-publishes-2026-ot-year-in-review/</id><link href="https://otdefensereview.com/news/dragos-publishes-2026-ot-year-in-review/"/><updated>2026-02-17T13:00:00.000Z</updated><published>2026-02-17T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The provider's annual report supplies threat, vulnerability, ransomware, assessment, and incident-response observations—but its populations and methods must remain attached to every reported number.</summary></entry><entry><title>NIST opens the SP 800-82 Rev. 4 pre-draft process</title><id>https://otdefensereview.com/news/nist-opens-sp-800-82-r4-predraft-process/</id><link href="https://otdefensereview.com/news/nist-opens-sp-800-82-r4-predraft-process/"/><updated>2026-01-22T13:00:00.000Z</updated><published>2026-01-22T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The January 2026 notice begins a revision of the central U.S. OT security guide while leaving Rev. 3 as the current final publication.</summary></entry><entry><title>IEC publishes guidance for applying the 62443 series to IIoT</title><id>https://otdefensereview.com/news/iec-publishes-62443-1-6-for-iiot/</id><link href="https://otdefensereview.com/news/iec-publishes-62443-1-6-for-iiot/"/><updated>2025-12-19T13:00:00.000Z</updated><published>2025-12-19T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>IEC PAS 62443-1-6:2025 addresses changed communication channels and organizational models without treating IIoT as a separate security universe.</summary></entry><entry><title>CISA releases eleven industrial-control-system advisories in one September batch</title><id>https://otdefensereview.com/news/cisa-releases-eleven-ics-advisories-september-2025/</id><link href="https://otdefensereview.com/news/cisa-releases-eleven-ics-advisories-september-2025/"/><updated>2025-09-11T13:00:00.000Z</updated><published>2025-09-11T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The release spans multiple Siemens and Schneider Electric product families and demonstrates why asset identity, version, vendor guidance, exposure, process consequence, and maintenance feasibility must stay connected.</summary></entry><entry><title>CISA and international partners publish OT asset inventory guidance</title><id>https://otdefensereview.com/news/cisa-partners-release-ot-asset-inventory-guidance/</id><link href="https://otdefensereview.com/news/cisa-partners-release-ot-asset-inventory-guidance/"/><updated>2025-08-13T13:00:00.000Z</updated><published>2025-08-13T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The joint guide raises the baseline from a discovered device list to a maintained inventory and taxonomy connected to function, criticality, risk, architecture, and response.</summary></entry><entry><title>FERC approves NERC CIP-015-1 for internal network security monitoring</title><id>https://otdefensereview.com/news/ferc-approves-nerc-cip-015-1/</id><link href="https://otdefensereview.com/news/ferc-approves-nerc-cip-015-1/"/><updated>2025-06-26T13:00:00.000Z</updated><published>2025-06-26T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>Order No. 907 creates a concrete network-data, anomaly-detection, evaluation, escalation, and evidence decision for covered bulk-power-system environments.</summary></entry><entry><title>CISA and partners publish primary mitigations for exposed OT</title><id>https://otdefensereview.com/news/cisa-partners-publish-primary-ot-mitigations/</id><link href="https://otdefensereview.com/news/cisa-partners-publish-primary-ot-mitigations/"/><updated>2025-05-06T13:00:00.000Z</updated><published>2025-05-06T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The May 2025 fact sheet emphasizes internet exposure, credentials, remote access, segmentation, inventory, monitoring, and recovery without turning public guidance into a site-specific response plan.</summary></entry><entry><title>IEC publishes a security-protection-scheme specification for IACS asset owners</title><id>https://otdefensereview.com/news/iec-publishes-62443-2-2-security-protection-scheme/</id><link href="https://otdefensereview.com/news/iec-publishes-62443-2-2-security-protection-scheme/"/><updated>2025-03-11T13:00:00.000Z</updated><published>2025-03-11T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>IEC PAS 62443-2-2:2025 organizes technical, physical, and process measures as a maintained protection scheme rather than a disconnected catalog of security products.</summary></entry><entry><title>CISA partners publish Secure by Demand guidance for OT buyers</title><id>https://otdefensereview.com/news/cisa-partners-publish-secure-by-demand-for-ot-buyers/</id><link href="https://otdefensereview.com/news/cisa-partners-publish-secure-by-demand-for-ot-buyers/"/><updated>2025-01-13T13:00:00.000Z</updated><published>2025-01-13T13:00:00.000Z</published><author><name>OT Defense Review Research Desk</name></author><summary>The guide puts secure configuration, identity, logging, vulnerability handling, updates, support, and buyer evidence into product selection rather than leaving them for post-purchase remediation.</summary></entry></feed>