about-agilicus

Defence In Depth: What We Practice

We practice what we preach. Zero Trust is part of a complete defence in depth strategy.

Overview

Defence In Depth. The principle is simple. Assume each layer of your security will be breached. Think about how to delay the attacker, how to increase their costs.

The more you can delay the attacker, the more you have a chance of observing and reacting before its too late.

The more you can shift cost from you (the defender) to the attacker, the more likely it is they will go elsewhere.

Defense in depth means defending at each stage of a pipeline. From SAST through simple orthogonal security techniques like fail to ban to zero-trust techniques like splitting identity from authorisation.

  • The Air Gap is Dead: Water Utilities Must Embrace Zero Trust for OT Security

    The Air Gap is Dead: Water Utilities Must Embrace Zero Trust for OT Security

    As water utilities enter Industry 4.0, the traditional air gap has become a dangerous myth. With 80 per cent of cyberattacks exploiting identity weaknesses, critical infrastructure must move beyond legacy virtual private networks. Adopting a Zero Trust framework through Identity-Aware Proxies secures legacy equipment incrementally, boosting productivity and uptime while protecting our essential water infrastructure.

  • Defence in Depth: Zero Trust is a Critical Layer, Not a Panacea

    Defence in Depth: Zero Trust is a Critical Layer, Not a Panacea

    “Defence in Depth” strategy, explaining why zero trust is a critical layer in protecting critical infrastructure. From the medieval castle analogy to the “lizard brain” risks of AI-amplified human engineering, learn why layered security and strong authentication are more important than ever in 2026.

  • Cyber Security Is Physical Safety: Lessons From a Thermal Runaway

    Cyber Security Is Physical Safety: Lessons From a Thermal Runaway

    A report on a recent B.C. EV charger fire reveals the danger of relying on software for physical safety. Learn why hardware interlocks and zero trust are non-negotiable for remote maintenance.

  • A Pragmatic Blueprint for Industrial Cyber Security

    A Pragmatic Blueprint for Industrial Cyber Security

    A strong cyber security posture is built on orthogonal defences. Review the five key dimensions of our best practices program and take the assessment to measure your resilience.

  • Visibility and Detection: Illuminating the Industrial Network

    Visibility and Detection: Illuminating the Industrial Network

    You cannot protect what you cannot see. Discover how to deploy effective visibility and detection mechanisms to identify threats early in hybrid environments.

  • System Hardening: Fortifying Industrial Infrastructure

    System Hardening: Fortifying Industrial Infrastructure

    Ensuring your control systems are resilient to attack is paramount. This post delves into system hardening practices that minimise vulnerabilities in operational technology.

  • Halting Lateral Movement in Operational Technology

    Halting Lateral Movement in Operational Technology

    If the perimeter fails, preventing lateral movement is your last line of defence. Uncover strategies for network micro-segmentation and eradicating legacy protocols.

  • Identity and Credentials: The New Air Gap

    Identity and Credentials: The New Air Gap

    Identity is the most critical perimeter in hybrid operational environments. Explore why phishing-resistant multi-factor authentication and unified identity are essential for security.

  • Boundary Defence: The First Layer of Industrial Cyber Security

    Boundary Defence: The First Layer of Industrial Cyber Security

    Modern operational technology environments require robust boundary defence. Learn how to eliminate inbound ports, enforce multi-layer boundaries, and modernise remote access.

  • Assessing Your Industrial Cyber Security Posture

    Assessing Your Industrial Cyber Security Posture

    The convergence of operational technology and information technology demands a pragmatic approach. Discover our five-dimensional scorecard to evaluate and improve your industrial cyber security posture.

  • Time To Exploit Approaches Zero

    Time To Exploit Approaches Zero

    The time between a vulnerability being detected to exploited has been declining. This web site https://zerodayclock.com has a great graph, below. It shows that in 2018 you had 2.5 years from detection to get a fix deployed. This worked its way through your supply chain and you updated. Think of a ‘log4j‘ type vulnerability, its a library inside a component inside a larger component inside a product you buy. The ‘gear lash’ speed takes a bit of time, but eventually…

  • Agilicus Ready for the Quantum Leap: Securing Today’s Gear from Tomorrow’s Threats

    Agilicus Ready for the Quantum Leap: Securing Today’s Gear from Tomorrow’s Threats

    It’s a tale as old as time: we build a better lock, and someone, somewhere, starts building a better lock-pick. In the digital world, we’re on the cusp of a monumental leap in lock-picking technology: quantum computing. The cryptographic locks we rely on for everything from banking to binge-watching are in danger of becoming as effective as a screen door on a submarine. But fear not, because the future of digital security is already taking shape, and it’s called Post-Quantum…

  • Apache Tomcat: Stealthy Risk Vector

    Apache Tomcat: Stealthy Risk Vector

    Apache Tomcat. It is an everywhere middleware. And, quelle surprise, the time from disclosure to use is a day. Like log4j it will be with us for some time, so, time for some defence in depth.

  • It’s Been 0-Days Since The Last Municipal Cyber Security Attack

    It’s Been 0-Days Since The Last Municipal Cyber Security Attack

    Asymmetric warfare: Big governments attack little governments. Attackers need to be right once, defenders need to be right 24x7x365. Municipalities continue to be a target.

  • FTC To GoDaddy: Heal Thyself

    FTC To GoDaddy: Heal Thyself

    FTC orders GoDaddy to improve security, marking an expansion in supply chain hardening tactics of government regulators.

  • Krooked Kriminals Krack Krispy Kreme

    Krooked Kriminals Krack Krispy Kreme

    Krispy Kreme materially impacted by cyber security issue, files SEC-8K disclosure.

  • Windows Update Breaks VPN, Good Riddance #zerotrust

    Windows Update Breaks VPN, Good Riddance #zerotrust

    Microsoft Windows Update Breaks VPN for Windows 10 and 11. 3rd party VPN’s have known exploited vulnerabilities. Let’s talk about VPN alternatives!

  • Industrial Supply Chain Matryoshka Risk

    Industrial Supply Chain Matryoshka Risk

    Last weeks hyper-critical NGFW vulnerability is this weeks embedded operational technology challenge due to nested risk and supply chain.

  • Quis custodiet ipsos custodes: When Good Firewalls Go Bad

    Quis custodiet ipsos custodes: When Good Firewalls Go Bad

    Recently Palo Alto announced a 10.0 CVE in the Global Protect feature of their PAN-OS firewall. “Unauthenticated attacker [can] execute arbitrary code with root privileges on the firewall”. Well, that is not good. But, how “not good” is it? It’s terrifyingly bad ungood in fact.

  • Three Strategies To Help: Cisco ASA AnyConnect and WebVPN added to CISA Known Exploits

    Three Strategies To Help: Cisco ASA AnyConnect and WebVPN added to CISA Known Exploits

    Cisco ASA AnyConnect and WebVPN added to CISA Known Exploits. Do you have one running on autopilot in your plant somewhere? Maybe between the IT and OT network? Maybe running the DMZ?

  • Ground Hog Day: Fortinet VPN Edition

    Ground Hog Day: Fortinet VPN Edition

    Another day, another VPN letting the world in to snoop around and fondle your crown jewels: Fortinet edition.

  • Dutch Defence Detail Dastardly Dirty Deed

    Dutch Defence Detail Dastardly Dirty Deed

    The Netherlands ministry of defence just published the cliff-hanger document TLP:CLEAR MIVD AIVD Advisory COATHANGER regarding a remote access attack of their Fortinet FortiGate VPN by “a state-sponsored actor from the People’s Republic of China”. CVE-2022-42475 was the weakness. One thing that is unusual about the report is the direct attribution: this is rare.

  • Howto: Open Source Intelligence and your Digital Footprint

    Howto: Open Source Intelligence and your Digital Footprint

    Let me show you a very simple means of Open Source Intelligence (OSINT) on yourself. If I can do this, anyone can do this, and if anyone can do this, someone bad can do this.

  • Off-Grid Agricultural Cyber Physical Systems

    Off-Grid Agricultural Cyber Physical Systems

    The “John Deere Business Model” of taking something traditional and making it subscription. Starlink and its complex remote access needs due to CGNAT. And, cybersecurity, notably Cyber Physical Systems with their scary downsides of being able to move and cause damage.

  • Hard Industrial Cybersecurity is hardly secure, nuclear waste edition

    Hard Industrial Cybersecurity is hardly secure, nuclear waste edition

    One thing all industrial control installations have in common, they straddle the complexity of modern information technology with the dangers of operational technology and its inherent control of things which can go bump and boom. Hard Industrial Cybersecurity

  • Avoid Exploitation of Unitronics PLCs used in Public Water Systems

    Avoid Exploitation of Unitronics PLCs used in Public Water Systems

    Exploitation of Unitronics PLCs used in Public Water Systems for political purposes. Recommendations.

  • Attainable Municipal Zero Trust

    Attainable Municipal Zero Trust

    Attainable Municipal Zero Trust: Key insights from recent Zero Trust implementations by Municipalities. Why, How, What ROI, Lead use cases.

  • CISA Cyber Scan Water

    CISA Cyber Scan Water

    CISA has announced a free (as in beer) service to scan water systems for vulnerabilities. Agilicus has used this scan for a year, receiving weekly reports.

  • Terminator Becomes National Standard

    Terminator Becomes National Standard

    I’ll be back. Iconic line foreshadows rise of cyber-physical-systems. Terminator trifecta of physical machines, artificial intelligence, cyber-security awry.

  • Another Day, Another Exploit – Protecting Against the ProxyNotShell Exchange Server Zero-Day Vulnerability

    Another Day, Another Exploit – Protecting Against the ProxyNotShell Exchange Server Zero-Day Vulnerability

    Learn how zero trust protects against the new Microsoft Exchange Server zero-day exploit affecting Outlook Web Access (OWA), ProxyNotShell. With Agilicus, you’ll block lateral traversal and prevent unauthorised traffic from arriving at your resources while ensuring they are still accessible to legitimate users.