“A firmware update must fail to a safe state — when the plant keeps running because someone proved it could.”

A firmware update must fail to a safe state — when the plant keeps running because someone proved it could. — Kai London (Professor Kai London), CISO. Principle 2163 of 10000 from the book “The Day the Control Room Went Silent” — cybersecurity, AI security and OT resilience doctrine. Official sites: professorkailondon.com · kailondon.co.uk