Built to reduce noise, not multiply it.
A severe CVE is not automatically an industrial emergency, and a dramatic headline is never evidence of exploitation. Every signal passes the same transparent decision model.
Explore the frameworkEvery ranking can explain itself.
The base score is always measured on the same 100-point model. Open “Priority” on any intelligence card to inspect the exact contribution of every factor.
Source confidence
Tier 1 evidence comes from government agencies, NIST/NVD and vendor PSIRTs. Tier 2 adds established research and transparent reporting for context.
Exploit gate
Active exploitation is reserved for KEV inclusion, explicit government or vendor confirmation, or equivalent authoritative evidence.
OT relevance
Signals gain weight when they affect PLCs, HMIs, SCADA, DCS, industrial networking, remote engineering or pathways into operations.
Operational context
Recommendations consider process safety, availability, redundancy, maintenance windows and compensating controls before urgency becomes action.
A triage aid, with explicit limits.
Priority ranges from 0 to 110: a 100-point base plus up to 10 EPSS points. It is a ranking, not a percentage or a measurement of risk to your plant.
OT relevance is a heuristic
Text matching starts at 15 points, adds 18 per distinct industrial term and 7 per adjacent technology term, and caps at 100. Terms match word boundaries to avoid unrelated substrings. The result is not proof that an asset is affected.
Missing data stays explicit
When CVSS is unavailable, severity uses a proxy: Critical 10, High 8, Medium 5.5, Low 2.5 and Info 0. Missing EPSS adds no points; it does not mean zero exploitation probability. Tier 1 contributes 15 points and Tier 2 contributes 9.
Preferred public intelligence sources.
CISA KEV, CISA ICS advisories, NIST NVD, Microsoft MSRC, Cisco PSIRT, Siemens ProductCERT, Schneider Electric, Rockwell Automation, ABB and Honeywell product-security advisories.
View CISA KEVDragos, Google Threat Intelligence / Mandiant, Palo Alto Unit 42, Cisco Talos, SecurityWeek ICS/OT and other established outlets with transparent sourcing.
What actually feeds the brief today.
Traceability note. “Items analyzed” on the daily header refers to one edition. Analytics totals are cumulative across every available edition in the selected 7- or 30-day view. Preferred sources listed above are the trust register; only sources in this live register are currently automated collectors. CISA ICS and Siemens ProductCERT are primary OT sources; Siemens publishes its vendor advisories through a CSAF feed.
Built from an OT practitioner's point of view.
OT Daily Brief was created by Israel Teran, a cybersecurity practitioner focused on SOC operations, industrial visibility and evidence-led vulnerability triage. The project translates public intelligence into decisions that respect safety, availability and real plant-floor constraints.