OT Cyber Risk Intelligence Newsletter – September 2026 | DeNexus
This month: the controls that measurably move the loss curve, US water-sector PLC attacks, new bulk-power and CI Fortify guidance, plus DeNexus events.

This month: the controls that measurably move the loss curve, US water-sector PLC attacks, new bulk-power and CI Fortify guidance, plus DeNexus events.

The 26 August 2026 bulk-power emergency order is a supply-chain intervention, not a cyber response. What DOE can now do, and which assets fall in scope.

India's CEA cyber security regulations take force April 1, 2027. How they compare to NERC CIP, where they diverge, and why compliance alone won't answer...

FERC approved CIP-015-2 in August 2026, but the first INSM deadline is still 1 October 2028. Here's the four-phase timeline utilities face through 2031.

A risk number a CFO, underwriter, and operator can all trace to its evidence is one you can defend. Read the DeNexus August OT cyber risk issue.

A worked example of one MITRE ATT&CK for ICS attack path: how the FrostyGoop Modbus compromise unfolded, mapped to T0836, and what that outage actually...

ENISA's 2025 dataset has become the de facto evidence base for NIS2. What 18.2% OT threat share, 53.7% essential-entity incidents, and Article 23...

The July 2026 DeNexus newsletter is out — a practical OT risk playbook (Quantify · Reduce · Transfer), CISA BOD 26-04, the Check Point VPN zero-day, and...

DeNexus's June 2026 OT cybersecurity briefing: underwriting-grade evidence, the five-artifact minimum bundle, and the AI vulnerability final mile.