OT & ICS cyberattacks.
Where each incident crossed the network — and what network-layer detection can see before it reaches the process.
Operational technology runs the physical world — manufacturing lines, power generation, building controls, industrial processes. The same network that lets engineers monitor and adjust these systems is the path an attacker takes to reach them. OT cyberattacks cross the network before they cross into the process: from a connected IT asset, through the boundary, into the controllers that move real things.
North Star Labs detects that crossing — the network-layer movement between where the business runs and where the process runs — so teams see an attacker traveling before they reach the PLC. This tracker collects our technical position pieces on OT and ICS incidents — what happened, where the network exposure is, and what network-layer detection can and cannot do about it.
What changes about detection
OT visibility today is split between endpoint agents that controllers will not tolerate and passive taps that see traffic but not meaning. North Star Labs reads the network in between — the sessions, the lateral movement, the connections that show an attacker already inside the OT segment and moving toward the process. It is a high-fidelity input to the security stack you already have, not a replacement for it.
See the detection on your own telemetry
Talk to North Star Labs about a retrospective test on OT or ICS network traffic, or a capability briefing on network-layer detection across the IT/OT boundary.
Talk to North Star Labs