WhoshouldIsee Tracks

Contents

Key Takeaways from CS4CA – Deploying Intelligence-Driven OT Resilience 

By Steve Wood, CNI Lead, BlueFort Security 

Challenges around the vulnerability and resilience of Operational Technology (OT) are never far from the minds of critical infrastructure leaders. That was certainly reflected in the conversations we had at this year’s European Cyber Security for Critical Assets Summit (CS4CA). 

It was timely, then, that Honeywell Technologies released its 2026 Operational Technology Cybersecurity Benchmark Report on the eve of the event. The report highlighted the operational consequences of cyber incidents, with more than half of respondents reporting downtime or production disruption, alongside significant incident levels across several OT-heavy industries. 

Those figures provided useful context for CS4CA. But what stood out on the exhibition floor was less about a single new threat and more about the practical questions organisations are working through as they try to make OT environments more resilient. 

What We Heard at CS4CA 

A lot of the conversations were familiar, and that matters. Securely getting files, software, and data into OT is still a very live problem. Removable media remains a fact of life in many OT environments, third-party laptops remain difficult to trust, and several organisations described processes that still rely on IT teams manually scanning files before moving them across the boundary. 

The discussion was less about any particular technology, and more about creating a controlled, repeatable process at the OT boundary: checking removable media and transferred files properly, reducing reliance on manual handling, and giving teams greater confidence in what is being allowed into an operational environment. 

Third-party and contractor access came up repeatedly too. The concern was broader than individual files: organisations are looking for greater confidence in the devices and systems that are allowed to interact with sensitive operational environments, without making legitimate engineering and maintenance activity unworkable. 

None of those are particularly theoretical problems. They are the everyday realities of operating environments where engineers, suppliers,, and maintainers still need to move data and connect devices, even when the security policy would ideally prefer neither. 

The Noticeable Shift: Controlling the Direction of Data 

The biggest change in our conversations this year was the amount of discussion around data diodes and unidirectional traffic. There were lots of different use cases, but the common theme was simple: organisations increasingly want data to cross an OT boundary without automatically creating an equivalent route back in. 

That came through in conversations about telemetry, remote services, external platforms and connections between operational environments and third parties. The individual requirements varied, but the principle was remarkably consistent: where information only needs to travel one way, why maintain a two-way path at all? 

That feels like a subtle but important change in emphasis. Rather than starting with ‘how do we secure this connection?’, more teams appeared to be asking whether the connection needs to be bidirectional in the first place. It is a more deliberate way of thinking about connectivity, starting with the minimum flow the operational requirement actually needs. 

From File Control to Resilience and Islanding 

A second theme around the wider conference was islanding: the ability for critical infrastructure to reduce external dependencies or effectively ‘pull up the drawbridge’ if the threat environment changes. 

Against the wider discussion about heightened threats to critical national infrastructure, this felt less like a conversation about routine disconnection and more about preparedness. If the risk level changed quickly, could critical operations reduce their exposure to external systems and continue to function safely? 

That puts the more tactical conversations into a broader context. File movement, removable media, third-party access, and the direction of data flows are all part of the same resilience question: how much dependency and connectivity is necessary, how well is it controlled, and how quickly could it be reduced if circumstances demanded it? 

The Takeaway 

My main takeaway from CS4CA wasn’t that the established OT security problems have disappeared. Quite the opposite. Secure file movement, removable media, and third-party access were still among the most common themes we heard. These are persistent operational challenges because critical environments still have to exchange information, accept updates, and support engineers and suppliers. 

What felt different was the increased focus on the architecture around those controls: not just checking what crosses a boundary, but being more deliberate about which connections are necessary, which direction information should be allowed to travel, and how an environment could become more isolated if circumstances demanded it. 

That is where the OPSWAT conversation fits. Kiosk, MetaDefender Core , and MetaDefender Drive address the familiar challenge of validating files, removable media, and devices before they interact with critical environments. Secure file transfer and data diode capabilities extend that thinking to how information is moved and how the direction of communication is controlled. 

The common thread is control: knowing what is entering, knowing what is connecting, being deliberate about how information moves, and retaining the ability to reduce connectivity when operational resilience requires it. 

Continuing the conversation  

If some of the challenges we heard at CS4CA sound familiar, we’ve explored one important part of the picture in more detail in our Tech Talk Tuesday with OPSWAT. 

Hosted by BlueFort CTO Josh Neame, the session looks at how OPSWAT Deep CDR helps organisations safely handle files entering sensitive environments by disarming potentially malicious content while preserving the usable information organisations need.

For heavily regulated, OT-rich and high-profile organisations, it’s a practical look at how stronger control over content entering the environment can help reduce cyber risk, protect operational availability, and support regulatory requirements. 

And if you’re working through any of the OT security challenges discussed here, whether that’s secure file movement, removable media, third-party access, data flows, or wider resilience, you can also book some time with me to talk through your current challenges and requirements. 

Get in touch with BlueFort

Related articles