
Bart Feenstra
Founder and principal security consultant
Writes about the place where OT security, AI governance and NIS2 arrive at the same question: who carries this decision, what is it based on, and when do we look again. Works as an interim CISO and takes boards through cyber crisis exercises.
Topics
- OT security
- ICS security
- IEC 62443
- NIS2
- Cyberbeveiligingswet
- AI governance
- ISO/IEC 42001
- EU AI Act
- ISO/IEC 27001
- cyber crisis management
- incident response
- interim CISO
Articles (24)
- OT vulnerability management is not IT patch management
From CVE to a defensible patch, mitigate, monitor or accept decision. Why CVSS alone is not enough in OT, and how to weigh exposure, exploitability and the operational risk of the fix itself.
- Your AI inventory is probably larger than your chatbot list
Most AI in your organisation was never a decision. How to inventory AI use cases, data flows, autonomy and risk before you build AI governance.
- Your PLC should not be on the Internet: the IEC 62443 lesson from the Siemens S7 threat
AI-assisted attacks are targeting Siemens S7 PLCs. The bigger OT security lesson is architectural: PLCs should not be directly exposed to the Internet.
- A VLAN is not an IEC 62443 segmentation strategy
A VLAN separates traffic, but it does not explain what you are protecting. How to move from OT risk to zones, conduits, required data flows and security levels.
- Cyber Crisis Exercise: We Thought We Knew What to Do - Until the Exercise
Discover how a realistic cyber crisis exercise with a unique injection system can prepare your organization for real cyberattacks and save your company millions.
- The rules are in force. But do you know what to do when something goes wrong?
A practical 15-minute resilience test for management, security and operations. Fifteen simple questions about decisions, suppliers, AI, OT and recovery.
- The Dutch Cybersecurity Act is in force: from knowledge to demonstrable resilience
The Dutch Cybersecurity Act entered into force on 15 August 2026. How do you move from understanding NIS2 to implementation and demonstrable cyber resilience?
- A Private Cellular Network Became the Attack Path into a Polish Power Plant
Attackers pivoted through a private cellular APN into the OT environment of a Polish power plant. The attack path, and the practical IEC 62443 lessons for industrial environments.
- AI Is Changing the Attacker. Why IEC 62443 Matters More Than Ever
AI lowers the expertise, time and cost needed to attack an industrial environment. Why ISA/IEC 62443 architecture, zones and Security Levels matter more than ever in OT.
- Why OT Security is Essential: Because Availability Comes First
A senior OT/ICS cybersecurity consultant explains why true operational availability depends on robust security, and how to align security with the realities of industrial environments.
- Cyber Hygiene: The Basics of a Safe Business
In today's digital age, strong cyber hygiene is essential for protecting your business against various cyber threats. Discover the essential steps and how CyberBusters can help secure your digital environment.
- IT Security Audit: How to Know If Your Business Is Really Secure
An IT Security Audit helps you identify vulnerabilities in your business and prevent cyber threats. Learn how to maintain your IT security.
- Zero Trust in Small and Medium Businesses
Learn how the Zero Trust model can protect your SMB against cyber threats. Discover how to implement an effective strategy and secure your data.
- What to do in case of a hack?
Discover essential steps for damage control, quick recovery, and preventing future attacks. CyberBusters offers professional assistance with incident response.
- The Importance of Timely Patching
Learn how regular updates and security patches protect your business from cyber threats and vulnerabilities. Discover how to implement an effective patch management process.
- Protect Your Business with a Layered Cybersecurity Approach
Discover how a layered approach to cybersecurity is essential for your business's safety. Learn more about the benefits of multiple security layers.
- DeepSeek (Chinese Artificial Intelligence): Benefits and Risks for SMEs
DeepSeek, a Chinese AI solution, offers powerful data analysis but also brings privacy and cybersecurity risks. Read this blog to find out when DeepSeek is suitable for your SME and when it is not.
- How secure is your business? Test it with a baseline assessment
Discover how a baseline assessment can help your organization identify vulnerabilities and improve your cybersecurity. Learn how CyberBusters can support you with comprehensive evaluations.
- Cybersecurity Awareness Training: How Employees Prevent Cyber Threats
Employees often pose the greatest risk in cybersecurity. Learn how awareness training helps prevent phishing and data breaches.
- How to Respond to a Data Breach: Steps and Responsibilities
Learn how to effectively respond to a data breach. Discover a practical step-by-step plan to mitigate damage, comply with reporting obligations, and strengthen your security.
- QR Codes in Practice: Efficiency vs. Cyber Threats
QR codes are convenient but also pose cybersecurity risks. Discover how criminals exploit QR codes and how you can protect yourself against phishing, malware, and payment fraud.
- Cybersecurity for SMEs - The 10 Measures You Must Take
Cyber threats are becoming increasingly sophisticated, and SMEs are a prime target. Discover the 10 essential measures to protect your business.
- Enhance Your Security with Strong Passwords and Multi-Factor Authentication
In today's digital world, protecting your business against cyber threats is essential. Discover how strong passwords and Multi-Factor Authentication (MFA) can significantly improve your business security.
- Common Techniques Hackers Use to Crack Passwords
Learn how hackers crack passwords using methods like brute-force attacks, dictionary attacks, and rainbow tables. Discover how to better protect your accounts.