OT Lab · Platform
Platform
OT Lab, the controlled laboratory in which the framework is instantiated and scenarios are evaluated.
In preparation
LB-2026-05 · Briefing · July 2026
Passive and active are not rivals but tools with different reaches. OT changes the calculation: devices are fragile, unplanned outages are intolerable, equipment runs for decades. Active reaches what stays silent; passive disturbs nothing but goes blind under encryption. Guidance makes passive the baseline; the mature pattern is hybrid.
Read briefingLB-2026-04 · Briefing · July 2026
Siemens S7 communication is encrypted by default on current controllers, yet the installed base is dominated by readable regimes: cleartext S7comm on the S7-300 and S7-400, and application-encrypted S7CommPlus, alongside TLS on current hardware. The gap persists through the economics of brownfield migration, not ignorance. For a passive observer, most of the deployed estate stays legible; encryption marks the boundary of the vantage.
Read briefingLTR-2026-05 · Technical report · July 2026
OPC UA offers three message security modes rather than a binary. The mode, not the policy, decides what a passive observer recovers: None and Sign leave the exchange fully legible, SignAndEncrypt only the envelope. Sign is the intermediate case, integrity without confidentiality, that a transport such as TLS cannot express.
Read reportLB-2026-03 · Briefing · July 2026
A plain-language reference map of how industrial systems communicate: the layers of an OT environment, the protocols that dominate each layer, the major controller vendors, and how vendors and protocols relate. Informational by design.
Read briefingLB-2026-02 · Briefing · July 2026
A survey of encryption across the dominant OT protocol classes: standardised mechanisms, measured adoption, and the observation vantage each class permits. Establishes that encryption capability and activation diverge persistently, and that OT standards deliberately prefer authenticated readability over confidentiality for real-time control data.
Read briefingLTR-2026-04 · Technical report · July 2026
Characterising an encrypted OT channel, a Web API over TLS 1.3, against the requirements of contextual evaluation. The passive observer is blind to the payload; what encryption changes is the observation vantage, not the evaluation core.
Read reportLTR-2026-03 · Technical report · July 2026
Contextual evaluation of industrial control actions validated on physical hardware, across three increments: observed context, robust phase inference, and an operational grammar learned from observation.
Read reportLTR-2026-02 · Technical report · June 2026
A protocol-agnostic chain for evaluating an industrial action across four dimensions: protocol operation, automation artefact, operational context, and policy constraint.
Read reportLTR-2026-01 · Technical report · June 2026
A Modbus/TCP control pair in which the same sensitive write returns an alert in production and an allow during a declared maintenance window.
Read reportLB-2026-01 · Briefing · May 2026
A briefing on why the centre of gravity in OT attacks has moved from gaining access to issuing valid commands, and the gap that leaves for defenders.
Read briefingOT Lab · Platform
OT Lab, the controlled laboratory in which the framework is instantiated and scenarios are evaluated.
In preparation