Never Trust the Network by Kai London
Zero Trust assumes identity, policy and verification at every hop. Industrial networks were built on the opposite assumption — flat, implicit trust, protocols with no authentication, and devices that must respond deterministically. This book works through how to apply the principles anyway, safely and in stages.
What the book covers
Principles, honestly applied
Which Zero Trust tenets transfer to OT unchanged, which need adaptation, and which do not apply.
Identity for devices and people
Engineer authentication, workstation posture and device identity where certificates are not always possible.
Segmentation and enforcement
Microsegmentation aligned to IEC 62443 zones and conduits, with policy points that do not add unacceptable latency.
Safety and determinism first
Failure modes, fail-safe behaviour and the constraints safety cases impose on security controls.
Legacy and brownfield
Wrapping unauthenticated protocols and unsupported controllers rather than pretending they can be replaced.
Staged migration
A sequencing plan that delivers risk reduction early and survives plant realities.
Who it is for
Security and network architects, OT engineering and automation leads, CISOs with industrial estates, and integrators designing plant network refreshes.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.