<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Windlass Consulting</title><description>Operational technology, industrial control systems, and AI security advisory for pipeline, energy, and critical-infrastructure operators. Houston, Texas.</description><link>https://windlassconsulting.com/</link><item><title>Active vs. passive vulnerability assessment in OT</title><link>https://windlassconsulting.com/blog/active-vs-passive-vulnerability-assessment-ot/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/active-vs-passive-vulnerability-assessment-ot/</guid><description>Active scanning finds vulnerabilities by interacting with a target. Passive assessment finds them by watching what&apos;s already there. In OT, the choice between the two isn&apos;t a preference, it&apos;s a constraint, and each has real blind spots.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Cybersecurity Assessment Plan: preparing for the annual cycle</title><link>https://windlassconsulting.com/blog/cybersecurity-assessment-plan-annual-cycle/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/cybersecurity-assessment-plan-annual-cycle/</guid><description>SD Pipeline-2021-02G requires a Cybersecurity Assessment Plan, submitted annually, that proves the Implementation Plan actually works. What the schedule requires, what counts as an assessment method, and what the annual report has to say.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>What a Pipeline Cybersecurity Coordinator is actually responsible for</title><link>https://windlassconsulting.com/blog/cybersecurity-coordinator-responsibilities/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/cybersecurity-coordinator-responsibilities/</guid><description>SD Pipeline-2021-01G requires a named Cybersecurity Coordinator and an alternate. The designation itself is administrative. What the role does afterward is where programs succeed or stall.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Cybersecurity Implementation Plan: what operators must maintain</title><link>https://windlassconsulting.com/blog/cybersecurity-implementation-plan-maintenance/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/cybersecurity-implementation-plan-maintenance/</guid><description>TSA approval of a Cybersecurity Implementation Plan isn&apos;t the finish line. SD Pipeline-2021-02G requires the plan to stay current, and sets specific deadlines for reporting the changes that keep it that way.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>IT/OT segmentation for pipeline environments</title><link>https://windlassconsulting.com/blog/it-ot-segmentation-pipeline-environments/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/it-ot-segmentation-pipeline-environments/</guid><description>Most pipeline networks aren&apos;t unsegmented on paper. They&apos;re unsegmented in practice, one historian export or remote-access jump host at a time. What the zone-and-conduit model actually requires, and where real segmentation projects usually find the gap.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Pipeline cybersecurity incident response: IT and OT considerations</title><link>https://windlassconsulting.com/blog/pipeline-cybersecurity-incident-response-it-ot/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/pipeline-cybersecurity-incident-response-it-ot/</guid><description>SD Pipeline-2021-02G requires an Incident Response Plan built around four specific objectives, one of them explicitly about isolating IT from OT. What that means in practice, and why the same containment step reads differently on each side of the boundary.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>How to prepare leadership for a TSA cybersecurity assessment</title><link>https://windlassconsulting.com/blog/preparing-leadership-tsa-cybersecurity-assessment/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/preparing-leadership-tsa-cybersecurity-assessment/</guid><description>The Cybersecurity Coordinator can produce every document TSA asks for and the meeting can still go sideways if the executives in the room can&apos;t speak to the program behind the paperwork. What leadership actually needs to know going in.</description><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Why a routine IT scan can take down an RTU</title><link>https://windlassconsulting.com/blog/it-vs-ot/</link><guid isPermaLink="true">https://windlassconsulting.com/blog/it-vs-ot/</guid><description>Active vulnerability scanning is standard IT hygiene. Pointed at an OT network, the same scan can trip a control outage, and NIST 800-82r3 explains why the two environments need different playbooks.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate></item></channel></rss>