A weekly briefing for ICS/OT security practitioners. Active threat actors, prioritized CVEs with OT context, and recommended actions you can run Monday morning. Practitioner-written. Vendor-independent.
Free tier: monthly summary. Paid: the full weekly briefing. No spam, no vendor pitches.
Every briefing is split into two clearly bounded parts: one your leadership can read in three minutes, one your analysts can act on the same day.
For CISOs and security leadership
For analysts and OT admins
This is the actual format, not a marketing rewrite. The briefing is built to be skimmed by leadership and searched by analysts.
If your engineering workstations share a flat network with anything internet-adjacent, this is your patching priority for the week. The vulnerability allows an unauthenticated attacker to push modified project files to the workstation, which in an OT context means logic changes downstream of your change-control process.
Based on the exploitation pattern observed with similar workstation-class vulnerabilities, the realistic window between public PoC and in-the-wild use is two to four weeks. In order to buy time without an emergency patch cycle, the immediate compensating control is...
Vendor reports are annual and have a sales motive. The major OT security vendors publish excellent research once a year, written to position a product. Useful, but not operational, and not weekly.
Free security news is broad and unsorted. The trade press covers everything for everyone. Finding the three items that matter to a water utility or a manufacturing floor is left as an exercise for the reader, every single day.
Critical Exception™ covers one lane, every week. Collected daily from primary sources, scored for OT relevance and severity, and given a practitioner editorial pass before it reaches your inbox. No product to sell you. The briefing is the product.
Break-even on the paid tier is one prevented bad patching decision. Probably less.
A working security practitioner with a background in vulnerability management, threat intelligence, and threat hunting, with a focus on ICS/OT environments. Independent: no vendor employs or sponsors the editorial content. More on the About page.
Primary sources (CISA ICS advisories, NVD, MITRE ATT&CK for ICS, vetted research) are collected daily and machine-scored for OT relevance, severity, and novelty. Every issue then gets a practitioner editorial pass before it ships. The synthesis is AI-assisted; the judgment is not.
A monthly summary on a two-week delay. Enough to judge whether the analysis is worth $20 a month. Paid subscribers get the full briefing every week, while it is still actionable.
The editorial sections will never contain sponsored content. If sponsorship is introduced, it will be a single, clearly labeled slot, separate from the analysis.
Yes. Annual billing exists for exactly this reason. A receipt is issued automatically.
Paid subscribers get the briefing Monday evening — a full day before the public preview posts.
Start free. No credit card. Unsubscribe in one click.
Paid upgrades ($20/mo or $180/yr) are handled on the next screen after you confirm your email.
Prefer the app? Subscribe on Substack →