Evolve is BlueFort’s unique, outcome-driven cybersecurity services ecosystem.
Platform and Enterprise Security solutions to protect all your human and non-human identities.
OT security focuses on protecting the specialised systems that control industrial operations.
Safeguard your cloud environments with solutions that protect data, workloads, and infrastructure across your cloud estate.
Enable your organisation to embrace AI securely.
These programs provide structured ways for ethical hackers and researchers to report security flaws.
API security involves securing the interfaces that allow software systems to communicate with each other.
From darkness to defence: Mapping your attack surface for ultimate visibility.
Secure access for every user, device and location without compromising control or visibility.
As phishing, BEC, and supply-chain attacks evolve beyond legacy defences, learn how AI based email protection can block threats before they hit inboxes.
By Steve Wood, CNI Lead, BlueFort Security
Challenges around the vulnerability and resilience of Operational Technology (OT) are never far from the minds of critical infrastructure leaders. That was certainly reflected in the conversations we had at this year’s European Cyber Security for Critical Assets Summit (CS4CA).
It was timely, then, that Honeywell Technologies released its 2026 Operational Technology Cybersecurity Benchmark Report on the eve of the event. The report highlighted the operational consequences of cyber incidents, with more than half of respondents reporting downtime or production disruption, alongside significant incident levels across several OT-heavy industries.
Those figures provided useful context for CS4CA. But what stood out on the exhibition floor was less about a single new threat and more about the practical questions organisations are working through as they try to make OT environments more resilient.
A lot of the conversations were familiar, and that matters. Securely getting files, software, and data into OT is still a very live problem. Removable media remains a fact of life in many OT environments, third-party laptops remain difficult to trust, and several organisations described processes that still rely on IT teams manually scanning files before moving them across the boundary.
The discussion was less about any particular technology, and more about creating a controlled, repeatable process at the OT boundary: checking removable media and transferred files properly, reducing reliance on manual handling, and giving teams greater confidence in what is being allowed into an operational environment.
Third-party and contractor access came up repeatedly too. The concern was broader than individual files: organisations are looking for greater confidence in the devices and systems that are allowed to interact with sensitive operational environments, without making legitimate engineering and maintenance activity unworkable.
None of those are particularly theoretical problems. They are the everyday realities of operating environments where engineers, suppliers,, and maintainers still need to move data and connect devices, even when the security policy would ideally prefer neither.
The biggest change in our conversations this year was the amount of discussion around data diodes and unidirectional traffic. There were lots of different use cases, but the common theme was simple: organisations increasingly want data to cross an OT boundary without automatically creating an equivalent route back in.
That came through in conversations about telemetry, remote services, external platforms and connections between operational environments and third parties. The individual requirements varied, but the principle was remarkably consistent: where information only needs to travel one way, why maintain a two-way path at all?
That feels like a subtle but important change in emphasis. Rather than starting with ‘how do we secure this connection?’, more teams appeared to be asking whether the connection needs to be bidirectional in the first place. It is a more deliberate way of thinking about connectivity, starting with the minimum flow the operational requirement actually needs.
A second theme around the wider conference was islanding: the ability for critical infrastructure to reduce external dependencies or effectively ‘pull up the drawbridge’ if the threat environment changes.
Against the wider discussion about heightened threats to critical national infrastructure, this felt less like a conversation about routine disconnection and more about preparedness. If the risk level changed quickly, could critical operations reduce their exposure to external systems and continue to function safely?
That puts the more tactical conversations into a broader context. File movement, removable media, third-party access, and the direction of data flows are all part of the same resilience question: how much dependency and connectivity is necessary, how well is it controlled, and how quickly could it be reduced if circumstances demanded it?
My main takeaway from CS4CA wasn’t that the established OT security problems have disappeared. Quite the opposite. Secure file movement, removable media, and third-party access were still among the most common themes we heard. These are persistent operational challenges because critical environments still have to exchange information, accept updates, and support engineers and suppliers.
What felt different was the increased focus on the architecture around those controls: not just checking what crosses a boundary, but being more deliberate about which connections are necessary, which direction information should be allowed to travel, and how an environment could become more isolated if circumstances demanded it.
That is where the OPSWAT conversation fits. Kiosk, MetaDefender Core , and MetaDefender Drive address the familiar challenge of validating files, removable media, and devices before they interact with critical environments. Secure file transfer and data diode capabilities extend that thinking to how information is moved and how the direction of communication is controlled.
The common thread is control: knowing what is entering, knowing what is connecting, being deliberate about how information moves, and retaining the ability to reduce connectivity when operational resilience requires it.
If some of the challenges we heard at CS4CA sound familiar, we’ve explored one important part of the picture in more detail in our Tech Talk Tuesday with OPSWAT.
Hosted by BlueFort CTO Josh Neame, the session looks at how OPSWAT Deep CDR helps organisations safely handle files entering sensitive environments by disarming potentially malicious content while preserving the usable information organisations need.
For heavily regulated, OT-rich and high-profile organisations, it’s a practical look at how stronger control over content entering the environment can help reduce cyber risk, protect operational availability, and support regulatory requirements.
And if you’re working through any of the OT security challenges discussed here, whether that’s secure file movement, removable media, third-party access, data flows, or wider resilience, you can also book some time with me to talk through your current challenges and requirements.