OT Security: The Complete Reference by Kai London
Industrial networks were built for availability and safety, then connected to everything. This is the single volume that takes an operator from asset inventory to architecture to detection to recovery — written for plants that cannot be taken offline to be secured.
Available on Amazon.
What is inside
ICS and SCADA foundations
Purdue levels, protocols, safety systems and the engineering realities that decide which controls are actually deployable.
Asset visibility
Passive and active discovery, configuration baselines and the vulnerability triage that fits a maintenance window.
Segmentation that holds
Zones, conduits, DMZ design and remote access — enforced boundaries rather than a diagram nobody maintains.
Detection and monitoring
OT telemetry, protocol-aware detection and an operations model that respects the control room's priorities.
Incident response and recovery
Containment without tripping the process, engineering-led restoration, and safe return to production.
Governance and evidence
Standards alignment, risk assessment and the documentation an auditor or regulator will ask to see.
Who it is for: OT security leaders, control and automation engineers, plant and site managers, and CISOs taking ownership of industrial estates.
Safety and security are the same argument made twice — once to the engineer, once to the board.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.