OT Security All-in-One · Volume 2

Industrial Cyber Defence and Engineering Controls by Kai London

This is the build volume. Segmentation you can maintain, an industrial DMZ that survives a site upgrade, remote access nobody has to work around, and a vulnerability process that accounts for the fact that most of your estate cannot be patched this quarter.

Available on Amazon.

What is inside

Segmentation that survives

Zones, conduits and enforcement points designed so the next plant change does not quietly undo them.

The industrial DMZ

Brokered data flows, historians, replication and update paths between enterprise and control networks.

Remote access and PAM

Engineers, contractors and OEMs — time-bound, brokered, recorded, and workable at three in the morning.

Vendor and supply chain risk

Assessing integrators and OEMs, security requirements in contracts, and firmware provenance.

Vulnerability management in OT

Prioritisation by consequence, compensating controls, and outage-window realism.

Detection and monitoring

Passive visibility, protocol-aware detection and integration with an enterprise SOC without breaking the boundary.

Who it is for: OT security and network engineers, control system engineers and integrators, vendor management teams, and security architects designing industrial defence.

IEC 62443NIST SP 800-82Purdue modelZero TrustMITRE ATT&CK for ICS

A control the engineers route around was never a control. Design for the way the plant really works.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.