Revision 7 of Offshore Norge 104, published in June 2026, updates the recommended cybersecurity baseline for operational-technology environments. The guidance requires segmentation among OT, IT, supplier, third-party, management, and other OT traffic; recognizes logical and physical segmentation; and prefers dedicated OT infrastructure in critical areas. It also aligns with modern network-access-security principles by emphasizing controlled separation of environments rather than broad network connectivity.
The revision allows an exception to OT-DMZ traffic-termination requirements where OT-to-IT communications pass through hardware-enforced unidirectional gateways. Waterfall Security welcomed the recognition of physical isolation and unidirectionality, but urged stronger endorsement of such architectures for island-mode operations and secure remote access. The review also cautioned that requiring interactive remote-access platforms to support malware-scanned file transfers may preserve a significant attack path into OT networks.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Offshore Norge published Revision 7 of Offshore Norge 104, its recommended cybersecurity baseline requirements for operational technology systems. The revision requires segmentation of OT networks from IT, suppliers, third parties, and management traffic, and recognizes hardware-enforced unidirectional gateways as an exception to OT-DMZ traffic-termination requirements.
CISA and partner guidance titled Modern Approaches to Network Access Security was published, highlighting hardware-enforced unidirectional remote-access technologies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.