Today’s briefing covers five OT/IoT developments: maritime operational-technology monitoring challenges, expanded U.S. critical-infrastructure support, the start of EU Cyber Resilience Act vulnerability reporting for actively exploited flaws, a U.S. Department of Energy request for input on bulk-power system risks, and Boston Scientific’s operational recovery after a cybersecurity incident.
Watching What Cannot be Stopped: Maritime’s OT Blind Spot
Cybersecurity Insiders reports that maritime operational technology is often not continuously monitored because ships cannot tolerate intrusive tooling, legacy and vendor-specific systems are difficult to change, and vessels face intermittent connectivity and crew rotation. The piece recommends passive, non-intrusive monitoring that observes controller, navigation and cargo-system traffic, stores data locally when links are unavailable, and provides continuous visibility across ships, ports and shore rather than relying only on periodic audits.
Source: Cybersecurity Insiders
White House, CISA Ramp Up Critical Infrastructure Security Efforts
GovCIO Media reports the White House and CISA are seeking closer government–industry cooperation to identify and prioritize critical-infrastructure vulnerabilities, deploy technology, and scale security solutions. A six-month Project Watershed 250 pilot launched Aug. 31 with Texas connects participating water utilities to no-cost cybersecurity resources, will assess vulnerabilities, and aims to develop scalable practices while CISA fills roles across cybersecurity, infrastructure security, and emergency communications.
Source: GovCIO Media
EU Cyber Resilience Act Reporting Obligations Begin for Actively Exploited Product Vulnerabilities
Industrial Cyber reported that the EU Cyber Resilience Act’s vulnerability-reporting obligations began Sept. 11, 2026, requiring manufacturers to submit an early warning within 24 hours of becoming aware that a vulnerability in a product with digital elements is actively exploited, followed by a 72-hour notification and a final report within 14 days after a corrective measure is available; these reporting deadlines apply when active exploitation is identified. The article highlights firmware inventory and code-reachability evidence as central to determining which shipped products are affected and whether notification is required.
Source: Industrial Cyber
U.S. DOE Seeks Industry Input on Securing Bulk-Power Systems from Foreign Equipment, Supply-Chain and Cybersecurity Risks
Industrial Cyber reports the U.S. Department of Energy is soliciting stakeholder input on securing bulk-power systems from foreign-related supply-chain and cybersecurity risks under the Aug. 26, 2026 executive order, covering foreign-produced grid equipment and associated components, software, firmware, digital and maintenance services, remote access, existing equipment, licensing, domestic manufacturing, and procurement. Responses are due Oct. 9, 2026, DOE plans a Sept. 16 webinar, and DOE states that the request is for informational and planning purposes and is not itself a proposed rule, order, directive, license, or determination.
Source: Industrial Cyber
Boston Scientific Fully Restores Operations After Cyberattack
MedTech Dive reports that Boston Scientific fully restored manufacturing, order-fulfillment, and shipping operations after identifying a cybersecurity incident on Aug. 25; its distribution network was operating at or above normal levels while the company worked through backlogs. The company and third-party experts had found no evidence of ongoing threat activity or product compromise since containment, and the CEO said the disruption had shut plants and distribution centers globally and likely contributed to lost procedures because of hospital supply constraints.
Source: MedTech Dive
For OT/IoT defenders: prioritize nondisruptive visibility, maintain current firmware and credential inventories, and plan evidence-preserving processes to support timely triage and stakeholder reporting.