<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" generatedBy="WIX">
<url>
<loc>https://www.qbitsnetworks.com/post/ot-patching-compensating-controls</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_5f6edbe39fae42f8a7df94e35c5e30f6~mv2.png</image:loc>
<image:title>Diagram: exposure, exploitability (CISA KEV) and consequence combine into a priority; high priority gets compensating controls now and a patch in the next window</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/remote-access-number-one-way-into-ot</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_db5b917137b3442a9a08b691716d2f3b~mv2.png</image:loc>
<image:title>Diagram: vendors and remote staff connect through the internet to a remote access gateway in the industrial DMZ with MFA, then a jump host, then only approved OT systems; direct paths are blocked</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/is-the-purdue-model-still-relevant</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_8b27c4f7b50a4d2dbb6ad1f66a39aa71~mv2.png</image:loc>
<image:title>Diagram: site historian sends data out through a DMZ data gateway to vendor cloud; remote users enter through a DMZ remote access gateway with MFA; IIoT sensors sit in their own zone</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/iec-62443-vs-nist-800-82-vs-nerc-cip</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_8ddcef7adcb24b3485beefa87df2b275~mv2.png</image:loc>
<image:title>Table comparing IEC 62443, NIST SP 800-82 Revision 3 and NERC CIP by type, publisher, whether mandatory, scope and best use</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/real-cost-of-an-ot-cyber-incident</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_c1f5563cc94b43298fbb01d038d0d0f2~mv2.png</image:loc>
<image:title>Iceberg-style stack: ransom at the top, then lost production, recovery, safety and environmental, regulatory, contractual and insurance, and reputation below</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/purdue-model-explained-level-by-level</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_42e16bb639774fc5a95fc2446af2864c~mv2.png</image:loc>
<image:title>Diagram of the Purdue Model showing Levels 5 to 0 with the industrial DMZ at Level 3.5 between IT and OT</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/zones-and-conduits-iec-62443</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_0e07481da13148b3afdababfa9febb93~mv2.png</image:loc>
<image:title>Diagram of example IEC 62443 zones: enterprise, industrial DMZ, supervisory, two process control areas and a safety system zone, connected by conduits</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/colonial-pipeline-it-ransomware-ot</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_d853b9820bfe40e48eeb5f56ac095116~mv2.png</image:loc>
<image:title>Five-step flow: legacy VPN account without MFA, DarkSide ransomware on IT network, business systems encrypted, precautionary pipeline shutdown, fuel shortages</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/backups-and-recovery-for-plcs-and-hmis</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_2aca4b5564b744b690d5b80a2bb820ac~mv2.png</image:loc>
<image:title>Diagram: running controller logic compared against an approved golden copy; backups kept offline or immutable in two locations; restores tested on spare hardware</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/passive-first-ot-assessments</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_f6fef530d7944f709e566d4a870c8549~mv2.png</image:loc>
<image:title>Diagram: PLCs, HMIs and SCADA connect to a switch; the switch mirror port copies traffic one-way to a listen-only capture sensor that builds the asset and flow picture</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/water-utilities-exposed-plcs-default-passwords</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_44efc239e4514b41878e1571fb5b8a32~mv2.png</image:loc>
<image:title>Before and after comparison: internet-exposed PLC with default password versus PLC behind a firewall with secure, MFA-protected remote access</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/volt-typhoon-prepositioning</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_2395b90327224aad8ecf28f8675aa146~mv2.png</image:loc>
<image:title>Four-step flow: compromised edge devices, living-off-the-land in IT networks, long-term hidden access, positioned to disrupt operations</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/ukraine-power-grid-attacks</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_04912bb15ae14ebdbfd30a22971a964e~mv2.png</image:loc>
<image:title>Two-column comparison of the December 2015 and December 2016 Ukraine power grid attacks: method, target, impact and recovery</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/it-vs-ot-securing-a-plant</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_722c7ac4450e492b9a8ee522abd15c1d~mv2.png</image:loc>
<image:title>Side-by-side comparison of IT and OT security priorities, lifecycles, patching, scanning and consequences</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/ot-network-segmentation-without-stopping-production</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_5ac7f8fa11f54c7e8b617ee933426641~mv2.png</image:loc>
<image:title>Six-step flow for OT network segmentation: map flows, define zones and conduits, secure the IT/OT boundary and DMZ, monitor-mode rules, enforce in a maintenance window, close bypass paths</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/what-is-an-ics-plcs-rtus-hmis-scada-dcs</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_8b06bc91e2ed430f90bdcedabe1409df~mv2.png</image:loc>
<image:title>Diagram of ICS components: HMI, SCADA server, historian and programming workstation above PLC, RTU and safety system, above field instruments</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/insider-and-contractor-risk-usb-laptops</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_49676dda4c474b4294d643d225df5b8f~mv2.png</image:loc>
<image:title>Five-step flow: device or USB arrives, scanned at kiosk, transfer to approved company media or site laptop, supervised connection, logged and reviewed</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/cybersecurity-oil-gas-pipeline-operators</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_82ee7d8beda34874996562db76de4a2d~mv2.png</image:loc>
<image:title>Three columns describing upstream, midstream and downstream oil and gas assets, their control systems and key security concerns</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/incident-response-for-ot</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_3a447dd5432d4eb9836b6ede5417e5d2~mv2.png</image:loc>
<image:title>Six-step OT incident response flow: confirm safety, convene roles, preserve evidence, contain with operations approval, run manually or shut down safely, recover from known-good copies</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/stuxnet-code-can-break-machines</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_8c96ebe32aea4d7e8282bbee82c48849~mv2.png</image:loc>
<image:title>Five-step flow: removable media, isolated Windows computers, Siemens Step 7 software, S7-300 PLCs, frequency converters altering centrifuge speeds</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/iec-62443-security-levels-explained</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_1c5effb686784069b9327077d7a3c8b3~mv2.png</image:loc>
<image:title>Stacked diagram of IEC 62443 security levels SL4 down to SL1 with the attacker capability each one assumes</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/frostygoop-pipedream-ics-malware</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_a5be1dc618b348c2b0940b51b0dfcc9d~mv2.png</image:loc>
<image:title>Timeline: April 2022 PIPEDREAM/INCONTROLLER disclosed; January 2024 Lviv heating attack; July 2024 FrostyGoop disclosed</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/building-an-accurate-ot-asset-inventory</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_5b568e39322c4411bdd6ee52fb76444d~mv2.png</image:loc>
<image:title>Diagram: six sources feed a central OT asset inventory, which supports vulnerability management, segmentation and incident response</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/nist-cybersecurity-framework-for-ot</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_4c216aa80ce14b218f4a7117450b4df6~mv2.png</image:loc>
<image:title>Circular diagram of NIST CSF 2.0 with Govern in the centre surrounded by Identify, Protect, Detect, Respond and Recover, each with an OT example</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/plant-manager-ot-security-questions</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_a0c818f6d40e48fba5b836e24e388f41~mv2.png</image:loc>
<image:title>Grid of twelve OT security questions grouped into knowing what you have, controlling access and change, readiness, and ownership</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/industrial-protocols-101</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_1404f7066d1c4775af1a39695f5db92c~mv2.png</image:loc>
<image:title>Table comparing Modbus, DNP3, OPC UA, EtherNet/IP and PROFINET by origin, typical use and built-in security</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/iec-62443-in-plain-english</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_75338c1956354c7986a1a0e9d7f0f368~mv2.png</image:loc>
<image:title>Four columns showing IEC 62443 groups: General, Policies and Procedures, System, and Component, with key parts and audiences</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/triton-trisis-safety-systems</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_c6395935aeb64f5b8c0030eccbcce27d~mv2.png</image:loc>
<image:title>Layered diagram showing corporate IT, the process control network and an isolated safety instrumented system zone with a key switch in RUN position</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/cybersecurity-water-wastewater-utilities</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_ac171b4602a14db8a3c6ba0ec16f6fc2~mv2.png</image:loc>
<image:title>Grid of eight priority cybersecurity actions for small water utilities</image:title>
</image:image>
</url>
<url>
<loc>https://www.qbitsnetworks.com/post/cybersecurity-power-utilities</loc>
<lastmod>2026-10-09</lastmod>
<image:image>
<image:loc>https://static.wixstatic.com/media/fd79a6_0901aae6380c4596927e4acc139a1bcd~mv2.png</image:loc>
<image:title>Diagram of the power system from generation and transmission through substations to distribution and distributed energy resources, with NERC CIP scope covering the bulk electric system</image:title>
</image:image>
</url>
</urlset>