# Sten Eikrem > Cybersecurity governance and risk management for industry and energy. Sten Eikrem writes about security governance, enterprise risk management, business continuity, and IT/OT security in manufacturing and energy environments. ## Main sections - [Writing](https://sten.eikrem.org/blog/): Practitioner perspectives and analysis. - [Portfolio](https://sten.eikrem.org/portfolio/): Working security-governance frameworks and methods. - [Research](https://sten.eikrem.org/research/): Open questions and ongoing analysis. - [Topic Navigator](https://sten.eikrem.org/explore/): Relationships between published pages and topics. - [About](https://sten.eikrem.org/about/): Professional background and contact details. - [Privacy](https://sten.eikrem.org/privacy/): Analytics and machine-readable content-use information. ## Published writing - [CRA: The CE mark will not tell you what you bought](https://sten.eikrem.org/blog/cra-ce-mark-will-not-tell-you-what-you-bought/): Seventeen draft standards now show what a CRA claim will consist of. The manufacturer declares its own scope, some requirements are handed to your environment, and for operational technology no standard exists yet. - [Business Resilience Lives in the Interdependencies](https://sten.eikrem.org/blog/business-resilience-interdependencies/): Business continuity plans and disaster recovery plans are not the same thing, and the interdependencies between business, IT and OT decide whether you pay for resilience up front or during the incident. - [Manufacturing's Vulnerability Management Problem Isn't a Vulnerability Management Problem](https://sten.eikrem.org/blog/manufacturing-vm-problem-isnt-a-vm-problem/): Faster patching is the wrong investment for most legacy OT, because the supplier controls the calendar and the plant operator controls the change window. The money goes into compensating controls and into procurement. - [Supplier lock-in is a governance problem, not a security problem](https://sten.eikrem.org/blog/supplier-lock-in-is-a-governance-problem/): The system owner carries the security risk for the OT estate and mostly doesn't govern like it. The access restrictions were inherited from a build project where cybersecurity wasn't on the requirements list, and the aftermarket business model is what keeps them in place. - [An AI model broke containment to cheat a test. The lesson is older than AI.](https://sten.eikrem.org/blog/ai-broke-containment-to-cheat-a-test/): Two OpenAI models escaped a sandboxed evaluation and hacked Hugging Face to steal the answer key for their own test. The AI is the headline, but the failure is older: a boundary that was assumed to hold, rather than proven to hold, did not hold. What that means for anyone signing agents into production. - [Your certificate signals. It doesn't tell you what to protect](https://sten.eikrem.org/blog/certificate-signals-not-what-to-protect/): A certificate signals that you follow a recognised process. It won't tell you your risk context, or what your security programme should cover and what it shouldn't. That decision is yours, and it is the part that actually reduces risk. - [OT telemetry in the SOC is the easy part](https://sten.eikrem.org/blog/ot-telemetry-soc-easy-part/): Chinna Botla's piece on integrating OT telemetry into enterprise SOCs gets the direction right. The harder part it understates is organisational. The automation teams own the assets, and detection only becomes response when the integration reaches the people who can act. - [AI in your business: the decision is yours, not the model's](https://sten.eikrem.org/blog/ai-in-your-business/): The value of AI and its risk are the same feature: it acts without you scripting every step. You cannot control that decision yet, only what AI is allowed to do, and the controls that would change that are still a promise. So the question is not whether to deploy AI, but where you can afford the trade. - [Sizing cyber for the company you actually are](https://sten.eikrem.org/blog/cyber-for-a-standalone-business/): A cyber programme for a newly standalone business should be dimensioned from its market position, management's actual intentions, and the mandatory floor. Not scaled down from the parent's programme. Here is the planning discipline that gets it right at the start. - [Risk appetite is not where you think it is](https://sten.eikrem.org/blog/risk-appetite-not-where-you-think/): Most organisations confuse risk appetite with risk tolerance. Between the two sits governance, and almost nobody manages that gap. Here is why it stays open. - [Business-aligned security in major projects](https://sten.eikrem.org/blog/security-concepts-in-major-projects/): Most projects treat security as a late-stage constraint. The system security concept, aligned to buy-build-run phases, makes it a business input from the start. - [The OTI Score Needs a Partner: Organisational Resilience](https://sten.eikrem.org/blog/oti-score-response/): Dale Peterson's OTI Impact Score addresses the industry signal problem. The partner it needs is organisational resilience, the ability to coordinate internally before communicating externally. - [The ISMS beyond the certificate](https://sten.eikrem.org/blog/the-isms-beyond-the-certificate/): Every organisation has an ISMS. Most of them don't have a management system. Here's the difference, and why it matters under NIS2. - [Response to Dale Peterson: asset inventory isn't premature consensus, it's operational necessity](https://sten.eikrem.org/blog/dale-peterson-response/): Dale Peterson asks where the evidence is that OT asset inventory reduces incidents. From building a global OT security programme across 40+ manufacturing sites, here are the answers. - [Your Recovery Targets Are Probably Right. Your Ability to Meet Them Probably Isn't.](https://sten.eikrem.org/blog/recovery-targets-vs-reality/): Recovery targets derived from a solid BIA are the right foundation. But five realities sit outside that formal scope, and they're where plans actually break down in practice. - [Is Your Manufacturing Company's Vulnerability Management Ready for What Comes Next?](https://sten.eikrem.org/blog/vulnerability-management-ready-for-what-comes-next/): AI-driven vulnerability discovery is outpacing OT remediation cycles. What manufacturing security teams need to know about software composition visibility, response planning, and the growing gap between known and fixed. - [Security concepts: bridging the gap between risk and reality](https://sten.eikrem.org/blog/security-concepts-bridging-risk-and-reality/): Without understanding the full system context, risk assessments default to compliance control catalogue validation. Security concepts, widely used in military classified systems, offer a better path. - [Your EU supply chain just changed - what manufacturing leaders need to know about the Cyber Resilience Act (CRA)](https://sten.eikrem.org/blog/cra-for-manufacturing-companies-in-europe/): How new EU regulations reshape supplier relationships and procurement strategy, even if you don't manufacture digital products - [Control Frameworks Built Backwards](https://sten.eikrem.org/blog/control-frameworks-built-backwards/): Most organisations start with standardised control catalogues and work backwards to justify coverage. Few start with business context, threat landscape, and actual vulnerabilities to determine which controls reduce risk and which waste resources. - [You can outsource the work, but never the accountability](https://sten.eikrem.org/blog/outsource-work-not-accountability/): A Norwegian court case delivers a €5.6 million lesson on business continuity, supplier management, and why manufacturing executives can't outsource operational accountability - [Governance that actually governs](https://sten.eikrem.org/blog/governance-that-actually-governs/): Most security governance is theatre. Committees that rubber-stamp, decisions that decide nothing, metrics that measure activity not outcomes. Here's how to build governance that actually works. - [Root cause analysis and the risk decisions we never knew we made](https://sten.eikrem.org/blog/root-cause-hidden-risk-decisions/): Most cybersecurity incidents trace back to implicit risk acceptances hidden in everyday business choices. The hardest root causes to analyse are those buried in decisions we never understood we were making. - [Three insurance renewal tips beyond coverage limits](https://sten.eikrem.org/blog/cyber-insurance-renewal-tips/): Threshold-based IR coverage, pre-approved suppliers, and using preventative services strategically ## Portfolio - [Core ISMS Capability Model](https://sten.eikrem.org/portfolio/core-isms-capability-model/): Seven interdependent capabilities for building an ISMS that drives security decisions rather than merely satisfying an audit. - [System Security Concepts](https://sten.eikrem.org/portfolio/system-security-concepts/): A 7-article series on implementing systematic security documentation within ISMS frameworks, from foundational concepts to practical implementation templates. - [System Security Concepts - The foundation of security governance](https://sten.eikrem.org/portfolio/system-security-concepts/article-01-security-concepts-foundation/): System Security Concepts - The foundation of security governance, published by Sten Eikrem. - [Core Components - What Makes a Security Concept Effective](https://sten.eikrem.org/portfolio/system-security-concepts/article-02-core-components/): Core Components - What Makes a Security Concept Effective, published by Sten Eikrem. - [Control Selection and Security Frameworks - Building Your Control Library](https://sten.eikrem.org/portfolio/system-security-concepts/article-03-control-selection-and-frameworks/): Control Selection and Security Frameworks - Building Your Control Library, published by Sten Eikrem. - [The Living Document - Lifecycle and Change Management](https://sten.eikrem.org/portfolio/system-security-concepts/article-04-living-document-lifecycle/): The Living Document - Lifecycle and Change Management, published by Sten Eikrem. - [Enterprise Security Capabilities - The Integration Challenge](https://sten.eikrem.org/portfolio/system-security-concepts/article-05-enterprise-security-capabilities/): Enterprise Security Capabilities - The Integration Challenge, published by Sten Eikrem. - [Access Control and Data Protection - Getting the Details Right](https://sten.eikrem.org/portfolio/system-security-concepts/article-06-access-control-data-protection/): Access Control and Data Protection - Getting the Details Right, published by Sten Eikrem. - [Implementation Guide - Templates, Tools, and Getting Started](https://sten.eikrem.org/portfolio/system-security-concepts/article-07-implementation-guide/): Implementation Guide - Templates, Tools, and Getting Started, published by Sten Eikrem. ## Research - [Open questions in security governance practice](https://sten.eikrem.org/research/open-questions/): Why security governance behaves differently in practice than the frameworks predict, and what the difference is doing for the organisations that sustain it. ## Feeds and discovery - [RSS feed](https://sten.eikrem.org/rss.xml) - [Sitemap](https://sten.eikrem.org/sitemap-index.xml) ## Contact - Email: sv@eikrem.org - LinkedIn: https://www.linkedin.com/in/sten-eikrem - Mastodon: https://infosec.space/@StoreSteinen - Bluesky: https://bsky.app/profile/storesteinen.bsky.social