L-com

Blog

Why Ethernet Surge Protectors Are a Cybersecurity Essential for Industrial Networks
An Ethernet port in a corporate office connects to a cable that runs inside a building, between controlled spaces, with other structured cabling. The cable never leaves the conditioned environment; its exposure to electrical hazards is minimal.... Read more
Top 10 Cybersecurity Risks in Industrial Automation
Industrial automation systems – PLCs, HMIs, and SCADA servers – are high-value targets for a straightforward reason: attacking one can stop a factory, shut down a pipeline, or compromise a power grid. The potential impact is orders of magnitude larger than a typical corporate data breach.... Read more
The Complete Guide to Industrial Cybersecurity for IIoT Networks
Industrial IoT networks are harder to secure than corporate IT networks for one fundamental reason: the devices were never designed to be connected to the internet. A PLC running a cooling system in a chemical plant might be 15 years old. It communicates over Modbus — a serial protocol from 1979 that has no authentication, no encryption, and no concept of access control. That PLC is now connected, through layers of networking, to a corporate environment that itself connects to the cloud. Every connection point is exposed.... Read more
Securing Wireless IIoT Devices: A Complete Field Guide
Wireless in enterprise environments connects laptops, phones, and conference room equipment — devices that are routinely replaced, can run security agents, and operate in controlled indoor environments. Wireless in industrial environments connects sensors bolted to outdoor tanks, gateways mounted on utility poles, and edge devices embedded in equipment that runs continuously for years.... Read more
RF Lightning Protectors for Industrial IIoT: Selection, Specs, and Installation Guide
An outdoor antenna is an intentionally designed RF collector — a metallic structure positioned for maximum exposure to the electromagnetic environment. That exposure is exactly what makes it effective at receiving radio signals. It also makes it an effective collector of lightning energy.... Read more
Physical-Layer Security for Industrial Networks: Surge Protection, Shielding & Isolation
Industrial network security discussions focus heavily on firewalls, encryption, authentication, and monitoring — controls that operate the network and application layers. Physical-layer controls address a different threat model: what happens when the physical infrastructure that all those logical controls run on is electrically compromised, physically accessed, or delivering corrupted data?... Read more
NERC CIP Compliance for OT Networks: A Checklist for Energy Operators
For electric utilities and other organizations responsible for Bulk Electric System (BES) assets, NERC Critical Infrastructure Protection (CIP) compliance is an ongoing operational responsibility—not a one-time project. Maintaining compliance requires documenting security controls, validating configurations, managing physical and electronic access, and demonstrating that required safeguards remain effective as networks evolve. Even well-designed OT environments can fall out of compliance if documentation, asset inventories, or change management processes fail to keep pace with system changes.... Read more
Industrial VPNs Explained: Choosing the Right Remote Access Solution for OT Networks
Remote connectivity has become essential for modern industrial operations. Whether supporting a remote pumping station, troubleshooting a PLC on a production line, or maintaining equipment at a utility substation, engineers and service providers increasingly rely on secure remote access to diagnose issues and reduce costly site visits. However, the networking requirements of operational technology (OT) environments differ significantly from those of traditional enterprise IT, making consumer or enterprise VPN solutions an imperfect fit for industrial applications.... Read more
Industrial Network Security Compliance: IEC 62443, NERC CIP & NIST CSF Explained
Industrial organizations are rarely governed by a single cybersecurity framework. A manufacturer may encounter IEC 62443 requirements from customers, follow the NIST Cybersecurity Framework (CSF) to guide its security program, and support utility operations subject to North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards. Although these frameworks share many common objectives, they differ in scope, terminology, implementation, and compliance requirements, making it difficult to understand where they overlap and how they should be applied.... Read more
IEC 62443 for Manufacturers: What You Need to Know
SL2 is the practical target for most manufacturing environments. The threat actor model — intentional, simple means, low motivation — covers the realistic attacker profile for most manufacturing facilities: opportunistic ransomware operators, disgruntled employees with some technical knowledge, and external attackers using publicly available tools and documented vulnerabilities. It does not assume a sophisticated, targeted attacker with extensive knowledge of the specific plant environment.... Read more

Resources

Search Entries