top of page
RubyComm OT Cybersecurity Insights


The Internal Data Center Paradox: Why Enterprise Facilities Are Vulnerable from the Cooling Up
When chief information security officers (CISOs) at major banks, insurance companies, or healthcare networks evaluate their cyber risk, their focus naturally gravitates toward the obvious: cloud configuration, database encryption, endpoint protection, and API security. There is a comforting assumption that if you own the building, control the badge access, and run a private, internal data center, your core infrastructure is securely insulated from the chaotic realities of the

RubyComm Team
Jul 2


The Clinical Blind Spot: Why Healthcare OT is the New Frontline of Patient Safety
When we think of hospital cybersecurity, the conversation usually centers on patient records, data breaches, and traditional IT systems. But there is a quieter, more dangerous vulnerability lurking in the hallways of most modern medical facilities: Operational Technology (OT). The medical gas pipelines, backup generators, water purification systems, and even the HVAC units that regulate operating room airflow were designed for operational reliability, not digital resilience.

RubyComm Team
Jun 4


The Pre-Positioning Era: Rethinking OT Defense for an Adversary Who Is Already Inside
For most of the last two decades, operational technology security has been shaped by a single implicit assumption: that the adversary is outside, trying to get in, and that our job as defenders is to detect the attempt and stop it. Firewalls, intrusion detection systems, security operations centers, and incident response playbooks are all built around this picture. It is a picture that no longer matches the threat. The defining shift of 2026 is not a new malware family or a n

RubyComm Team
May 11


The Backdoor in the Battery: Why Solar Inverters and BESS Are the Grid's New Cybersecurity Frontline
For years, policymakers and the media have focused on the cyber risk to 5G networks and undersea cables. Meanwhile, a different class of connected hardware has quietly been wired into the heart of our power grids: solar inverters and battery energy storage systems (BESS). Recent investigations and government reports suggest these devices are no longer just “dumb” power electronics. They are smart, networked systems whose undocumented capabilities raise hard questions about su

RubyComm Team
Apr 28


The Night the Hospital Nearly Collapsed
February 2024; In the middle of the night, medical teams at thousands of hospitals across the United States discover they cannot access the Change Healthcare payment system. This is not a minor technical glitch. It is the largest cyberattack in the history of the American healthcare system, carried out by the Russian ransomware group BlackCat/ALPHV. The Russian group seized sensitive patient medical data. Some of it was published online in a blatant privacy violation. For oth

RubyComm Team
Mar 30


The Small Utility Paradox: Why the Least-Resourced Water Systems Face the Greatest Threats
When the FBI called Nick Lawler on a Friday afternoon before Thanksgiving 2023 to inform him that Chinese state-sponsored hackers had compromised his utility's network, his first instinct was disbelief. The Littleton Electric Light and Water Department serves approximately 15,000 people in two Massachusetts towns. "You would never think that would be a target of any type of attack," Lawler later told reporters. He was wrong. The hackers, linked to China's Volt Typhoon campaig

RubyComm Team
Mar 4


From Guidance to Enforcement: EPA's Cybersecurity Pivot and What Water Utilities Must Do Before the Next Inspection
When the EPA announced that over 70 percent of water systems inspected since September 2023 failed to comply with basic cybersecurity requirements under the Safe Drinking Water Act, the message was unmistakable: the era of voluntary compliance is ending. For water utility executives and OT security professionals, this statistic represents more than a regulatory concern; it signals a fundamental shift in how the federal government approaches cybersecurity in the water sector.

RubyComm Team
Feb 17


When Pipes Burst and Governments Wake Up: The Denmark Water Utility Attack and What It Means for Critical Infrastructure Security
On December 19, 2025, Denmark's Defence Intelligence Service made an announcement that should concern every critical infrastructure operator worldwide: pro-Russian hackers had successfully attacked a Danish water utility, remotely manipulating water pressure controls. Local officials said this led to pipe bursts affecting several dozen households. And a small waterworks serving several villages south of Copenhagen became the latest example of how state-backed cyber actors are

RubyComm Team
Jan 20


Volt Typhoon's Year-Long Siege: Lessons from the Littleton Utility Breach for OT Security
The recent revelation that Chinese state-sponsored threat actors maintained unauthorized access to a Massachusetts utility's operational technology network for nearly a year serves as a stark reminder of the evolving threat landscape facing critical infrastructure. The Littleton Electric Light & Water Department discovered its systems were breached just before Thanksgiving in 2023, with investigations revealing that Volt Typhoon had been present in their systems since Februar

RubyComm Team
Jan 8


When Cyber Reconnaissance Enables Kinetic Warfare: What OT Security Leaders Must Know
Protecting critical infrastructure from cyber threats is no longer just about preventing operational disruption or data theft. In some cases, it's about preventing your systems from becoming intelligence assets that enable physical military strikes. Recent findings from Amazon Threat Intelligence reveal a disturbing evolution in nation-state tactics: adversaries are systematically compromising operational technology systems not to damage them directly, but to gather real-time

RubyComm Team
Dec 23, 2025


The Hidden OT Attack Surface: How 3D Printers Became the Latest Critical Infrastructure Security Blind Spot
The February 2024 Anycubic incident , where hackers compromised 3D printers worldwide to warn users that their devices were exposed to critical security vulnerabilities through the company's MQTT service API, represents more than just another IoT security breach. It signals a fundamental shift in the operational technology threat landscape, one where additive manufacturing systems have evolved from prototyping tools into critical production infrastructure, yet remain unprotec

RubyComm Team
Dec 4, 2025


Canada's OT Cybersecurity Crisis: What the 2025 State Report Reveals for Industrial Organizations
The Canadian Cybersecurity Network (CCN) just released their comprehensive State of Canada OT Report 2025, and the findings reveal a cybersecurity landscape that should concern every industrial organization operating in North America. With over 45,000 cybersecurity professionals contributing to this analysis, the report paints a lousy picture of escalating threats against Canada's critical infrastructure, threats that extend far beyond national borders. This means that other

RubyComm Team
Nov 26, 2025


The True Cost of OT Cyber Attacks: Lessons from Real-World Incidents
In our highly connected world, Operational Technology (OT) cybersecurity has never been more critical. As essential services like manufacturing, smart buildings, and healthcare increasingly rely on digital systems, they also become vulnerable to cyber attacks. The true cost of these attacks goes beyond initial financial damage; they can lead to significant downtime, safety risks, and lasting harm to an organization's reputation. This post explores the financial implications o

RubyComm Team
Nov 12, 2025


State-Sponsored Cyber Threats to Critical Infrastructure: Insights from the Norwegian Dam Attack
Introduction In recent years, critical infrastructure worldwide has faced escalating threats from state-sponsored cyber actors. These...

RubyComm Team
Oct 22, 2025


State-Sponsored Cyber Threats to Critical Infrastructure: A Growing Global Concern
Critical infrastructure such as power grids, water systems, and industrial control networks have become prime targets for state-sponsored...

RubyComm Team
Oct 8, 2025


Patch Management and Legacy Systems in the Realm of OT Cyber Security
Legacy OT systems are the backbone of many industrial operations, but their age and design make them difficult to secure. Traditional...

RubyComm Team
Sep 24, 2025


Building a Business Case for OT Cybersecurity Budgets
Investing in OT cybersecurity is not just a technical necessity; it is a business imperative. However, securing executive buy-in requires...

RubyComm Team
Sep 10, 2025


Human Factors and Insider Threats in OT Environments
While technology is perceived as having the most critical role in OT security, human factors remain one of the greatest vulnerabilities....

RubyComm Team
Aug 27, 2025


The Importance of Cybersecurity in Operational Technology (OT) Environments
Understanding IT/OT Convergence The ongoing digital transformation of industry has blurred the lines between information technology (IT)...

RubyComm Team
Aug 13, 2025


Ensuring Compliance in Operational Technology Security: A Business Imperative
The Rising Importance of OT Security Compliance As cyber threats to critical infrastructure rise, regulators worldwide are tightening...

RubyComm Team
Jul 29, 2025
bottom of page