Critical Infrastructure Security · Lateos

OT/ICS/SCADA security grounded in threat intel and real-world tactics.

Evidence-based analysis of industrial control system attack surfaces, protocol-layer vulnerabilities, and defensive architectures. Informed by CISA advisories, APT TTPs, and 8+ years of healthcare infrastructure hardening experience in mission-critical environments.

Read Articles About the Author

Why this research matters.

CISA reported over 2,100 CVEs in 2025 alone — a record year for ICS vulnerabilities. But the dominant attack paths into operational technology networks aren't novel exploits. They're the fundamentals: unauthenticated protocols, default credentials on internet-facing devices, compromised remote-access tooling, and phished operator credentials. The gap between what defenders know matters and what they actually prioritize remains the defining vulnerability in most ICS environments.

This research track provides structured threat intelligence — grounded in CISA advisories, NSA/FBI/DOE joint statements, and documented APT tradecraft — to help architects make better defensibility decisions. The goal is clarity on what actually moves the needle in OT security, not hype or speculation.

Security grounded in healthcare infrastructure.

Eight years at Philips Healthcare integrating mission-critical patient monitoring systems (PIIC ix, IntelliVue, Tempus) across regulated hospital environments governed by NFPA 99, TJC, and AAMI standards. Formal security credentials: CISSP (#551678), CEH, CCNA Security. This research reflects the architectural discipline required when system failures have real-world consequences.

OT security in healthcare and industrial settings shares the same constraint landscape — legacy systems, uptime requirements that rule out disruptive changes, and the reality that failures don't stay isolated. The analysis here applies that operational lens to the broader OT/ICS threat model.

Published research.