OT CT (Ep. 19): The Current OT/ICS Threat Landscape w/ the Drago Year in Review Report

OT CT (Ep. 19): The Current OT/ICS Threat Landscape w/ the Drago Year in Review Report

🎙 Mike Holcomb 👥 27K 📅 March 4, 2026 ⏱ 61 min 👁 461 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICSthreat landscapeDragosYear in Reviewcybersecurity

Summary

In this episode of OT Cyber Tuesday, Mike Holcomb discusses the current OT/ICS threat landscape, focusing on the Dragos Year in Review report. He begins by sharing his experiences at S4 and BSides ICS conferences, highlighting the community and the importance of staying informed. He then introduces the Dragos report as the equivalent of the Verizon DBIR for OT, praising its practical insights and the fact that it is freely available. Mike summarizes key sections of the report, including new attack groups, updates to existing ones, and vulnerabilities. He emphasizes the trend of attackers moving faster to reverse engineer OT processes, and discusses the implications of state-sponsored actors like Sandworm. He also touches on the role of AI in accelerating attacks. Throughout, he provides practical advice for defenders, such as monitoring threat intelligence and implementing the SANS five critical controls. The video is a valuable resource for OT/ICS professionals seeking to understand the current threat landscape.

156 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the OT/ICS threat landscape, drawing from the Dragos Year in Review report and the speaker’s extensive experience. The argumentation is solid, as it is based on a reputable industry report and practical examples. The speaker effectively communicates the importance of understanding attacker behaviors and the need for proactive defense. However, the analysis is somewhat subjective, and the speaker’s personal anecdotes, while engaging, may not be universally applicable. The discussion of specific attack groups and their tactics is informative, but the lack of detailed technical depth may limit its value for advanced practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by referencing the Dragos Year in Review report, a well-regarded source in the OT/ICS cybersecurity community. The speaker also mentions the Verizon DBIR for comparison, adding credibility. However, the video does not provide direct citations or links to the report within the description, which may hinder verification. The title accurately reflects the content, focusing on the threat landscape and the report. The speaker’s personal experiences and opinions are clearly distinguished from factual information, maintaining a reasonable level of objectivity. Overall, the sources are credible, and the content aligns with the title.

209 words

Title / Content Match

The title accurately reflects the content, which focuses on the current OT/ICS threat landscape and the Dragos Year in Review report.

Quality & Reliability

7/10

The video is an expert commentary on the Dragos Year in Review report, providing practical insights and personal experiences. The information is based on a reputable industry report, but the analysis is subjective and lacks independent verification.

Key Moments

Cited Sources

  • Dragos Year in Review Report — The main report discussed in the video, providing insights into OT/ICS threats.
  • Mike Holcomb's Newsletter — Newsletter for OT/ICS cybersecurity content.
  • Free OT/ICS Cyber Learning Videos — Free resources for learning OT/ICS cybersecurity.

Concurring Sources

Contribution & Novelties

The video provides a practical and accessible overview of the current OT/ICS threat landscape, based on the Dragos Year in Review report. It highlights key trends, such as the increasing speed of attackers in reverse engineering OT processes and the potential impact of AI. The speaker’s personal experiences and practical advice add value for defenders. However, the content is largely a summary of existing information, with limited novel analysis.

Pour aller plus loin :

  • SANS ICS Five Critical Controls — Relevant for understanding the recommended security measures.
  • Sandworm Team — Background on the threat actor group mentioned in the video.
  • Dragos Year in Review — The primary source for the video’s content.

112 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quality and reliability, reflecting the use of a reputable source and practical insights. The lower score in technical depth indicates that the content is more accessible to a broader audience rather than deeply technical.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'a pu être identifiée.