And it’s over 16,000 words.While the rest of the cybersecurity world moves on with AI and next generation technologies, the OT cybersecurity community is oft left behind, dealing with increasingly unique legacy challenges and tech debt. One of the biggest issues we have had to start tackling is the discovery of deep, embedded commodity malware infections on old Windows OT and critical infrastructure systems.This seems like such an easy problem to fix for IT cybersecurity people. “Just update the operating system!” “Just patch it!” “Just run EDR!”. It’s way more difficult to solve in reality. Companies are typically getting network detection into these environments for the first time in years, and it’s not uncommon to uncover 10-70 discrete worms across the network and offline and online devices. The computers in question are too old to support modern agents, or even centralised antivirus. They can’t be taken out of production in the near future because they’re essential to operations and too dangerous and costly to remove. To make matters worse, the infections can’t just be ignored even though they’re over a decade old, because of new legislation and the ageing and destabilising of the devices. So, Jan Hoff at Dragos Germany and I wrote a paper on the topic. A big one. It discusses risk management and decision criteria for how to assess and remediate these catastrophic messes, reviews the most common malware we see, and describes forensic and remediation tools that might be applicable for various eras of Windows. Nobody has tackled this issue comprehensively, so we tried to get something out there that is applicable to a variety of legacy deployments that can’t be upgraded, from OT to hospitals. We’ve seen this handled so catastrophically wrong it’s almost shuttered businesses.I spoke about this paper with the Decipher podcast if you want a quick overview:You can download the paper we are debuting at OTCEP Singapore tomorrow, here: Click to access dragos-2026-otcep-ir-whitepaper.pdfI will be presenting this paper at CyberCon in Melbourne, this October as well.