Roberto Caviglia1, Daniyar Aliaskharov2, Alessio Aceti1, Mila Dalla Preda3, Paola Girdinio2, Giovanni Battista Gaggero2,*
CMC-Computers, Materials & Continua, Vol.85, No.3, pp. 5327-5340, 2025, DOI:10.32604/cmc.2025.068509
- 23 October 2025
Abstract Industrial Control Systems (ICS) in Operational Technology (OT) environments face unique cybersecurity challenges due to legacy systems, critical operational needs, and incompatibility with standard IT security practices. To address these challenges, this paper presents the Security Operation and Event Management (SOEM) platform, a software designed to support Security Operations Centers (SOCs) in reaching full visibility of OT environments. SOEM integrates diverse log sources and intrusion detection systems, including logs generated by the control system itself and additional on-the-shelf products, to enhance situational awareness and enable rapid incident response. The pilot project was carried out within More >