Skip to content
All industries
Energy and Critical Infrastructure

Unified visibility across OT and IT. Three new ICS threat groups in 2025.

Dragos tracked three new ICS-focused threat groups in 2025. EU OT-targeted attacks continue to climb. Blacklight gives you a single pane of glass across SCADA, ICS, substation automation, and the corporate IT that sits next to them, agentless and non-disruptive.

Incidents and active campaigns in your sector

The pattern is published.

Notable incidents and active campaigns in your sector. The attacker techniques are documented. The regulator timelines are running. Blacklight contains the same patterns autonomously, before the disclosure window opens.

  • ICS/OT threat groups
    Three new groups actively targeting ICS/OT (Dragos)
    Active campaigns
  • Texas fuel retailer
    Ransomware data breach
    377K impacted
  • Collins Aerospace (MUSE)
    Check-in vendor ransomware, airports downstream
    Arrest made
Case in point

Dragos 2025: three new threat groups targeting ICS/OT

Energy sits at the intersection of the most-targeted, least-monitored infrastructure on the internet. Dragos tracked three new ICS-focused threat groups in 2025 alone. SCADA, substations, and refinery control networks were built in an era when 'air-gapped' meant something. It hasn't for 15 years. Most operators cannot install agents on the control plane. Blacklight baselines every PLC, RTU, and HMI on your network without touching them. Stuxnet-class lateral movement between corporate and operational zones is detected in seconds. Containment respects safety-instrumented-system boundaries: no action that could trip a plant. NERC CIP and NIS2 audit evidence pre-formatted per sub-sector.

The Blacklight difference
  • Correlated against live threat intel in seconds, not hours.
  • Contained autonomously, before the human analyst arrives.
  • Regulator-ready evidence, bundled and pre-drafted.
What Blacklight would do

Four moves,
on autopilot.

Every action is logged, explained, and reversible. The analyst always has the last word, but they get the case ready-made.

  • Baseline every PLC, RTU, and HMI on your network, agentless and non-intrusive
  • Detect Stuxnet-class lateral movement between corporate and operational zones
  • Autonomous containment that respects safety-instrumented-system boundaries
  • NERC CIP and NIS2 audit evidence pre-formatted per sub-sector
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.