Empty Attestations: OT Lacks the Tools for Cryptographic Readiness
ID: 7b6029a6-bd85-5417-9f7b-f9ad1162df8d
STIX ID: report--7b6029a6-bd85-5417-9f7b-f9ad1162df8d
Feed Name: Dark Reading
**Executive summary:** The report warns that nation-state actors such as Volt Typhoon have maintained long-term access inside US and Canadian OT environments, enabling collection of encrypted traffic and possibly cryptographic keys or firmware signing keys; this creates a harvest-now-decrypt-later and trust-now-forge-later risk for critical infrastructure, while current regulatory attestation frameworks and tooling are ill-suited to OT constraints and may produce false assurance instead of real security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
