[{"data":1,"prerenderedAt":1741},["ShallowReactive",2],{"{\"cv\":1786552317925,\"version\":\"published\"}widgets\u002Fnavigation-bar":3,"{\"cv\":1786552317925,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}\u002Fblog\u002Fare-critical-ztna-mistakes-compromising-your-network":66},{"data":4,"headers":45},{"story":5,"cv":42,"rels":43,"links":44},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":32,"full_slug":33,"sort_by_date":22,"position":34,"tag_list":35,"is_startpage":15,"parent_id":36,"meta_data":22,"group_id":37,"first_published_at":38,"release_id":22,"lang":39,"path":40,"alternates":41,"default_full_slug":22,"translated_slugs":22},"Navigation Bar","2026-08-05T05:55:49.585Z","2026-08-07T15:41:09.255Z","2026-08-07T15:41:09.269Z",205700094329908,"be34732b-2155-45e7-8ee2-86e1157a8cb4",{"_uid":13,"component":14,"showMarketingBanner":15,"marketingBannerContent":16},"e7a8d72d-8af8-452e-87b2-de4098162fb9","NavigationBar",false,{"type":17,"content":18},"doc",[19],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26,"marks":27},"See us at Black Hat booth #7505","text",[28],{"type":29,"attrs":30},"textStyle",{"color":31},"#000000","navigation-bar","widgets\u002Fnavigation-bar",0,[],205696803161001,"e116d2fb-7cac-4697-9dcb-91d9283aecc3","2026-08-05T06:19:33.200Z","default","\u002F",[],1786551603,[],[],{"cache-control":46,"connection":47,"content-length":48,"content-type":49,"date":50,"etag":51,"referrer-policy":52,"sb-be-version":53,"server":54,"vary":55,"via":56,"x-amz-cf-id":57,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":63,"x-runtime":64,"x-xss-protection":65},"max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","986","application\u002Fjson; charset=utf-8","Wed, 12 Aug 2026 16:32:27 GMT","W\u002F\"5c1166e3d4b6a105ebbda45ba4aa4e70\"","strict-origin-when-cross-origin","5.941.0","nginx\u002F1.29.1","Origin","1.1 bf30f50cfbcc4e619604398d6a02d0c6.cloudfront.net (CloudFront)","BxS1-t-mt55vovN5i_D80UGCjlCDOVoWo76cWplGCqmsNDlPxxL_hA==","CMH68-P7","Miss from cloudfront","nosniff","SAMEORIGIN","none","0e5e5ccd-b8e3-4878-ae43-1cf015dee002","0.023397","0",{"data":67,"headers":1731},{"story":68,"cv":42,"rels":1172,"links":1730},{"name":69,"created_at":70,"published_at":71,"updated_at":72,"id":73,"uuid":74,"content":75,"slug":1164,"full_slug":1165,"sort_by_date":1166,"position":1167,"tag_list":1168,"is_startpage":15,"parent_id":1156,"meta_data":22,"group_id":1169,"first_published_at":1170,"release_id":22,"lang":39,"path":22,"alternates":1171,"default_full_slug":22,"translated_slugs":22},"Are critical ZTNA mistakes compromising your network?","2026-06-15T21:40:32.433Z","2026-07-27T21:13:44.969Z","2026-07-27T21:13:44.984Z",187883652863151,"bcb4724d-49d8-4252-870f-7da4f64e42f8",{"Tags":76,"_uid":77,"body":78,"title":69,"content":79,"component":423,"seoOgImage":424,"keyTakeaways":429,"previewImage":463,"previewTitle":69,"relatedContent":465,"seoDescription":1163,"previewDescription":1163},"","69a52ed9-008b-4441-a3c4-57b32d15254b",[],{"type":17,"content":80},[81,90,134,146,156,176,184,192,205,224,233,241,249,257,276,295,304,312,320,328,338,346,365,390,399,407,415],{"type":20,"attrs":82,"content":83},{"textAlign":22},[84],{"text":85,"type":26,"marks":86},"Zero Trust Network Access (ZTNA) is often hailed as a “magic bullet” for network security, and done right, it can be a dramatic improvement from perimeter network security. Unfortunately, ZTNA deployments commonly suffer from some major, yet easy-to-overlook vulnerabilities. Namely,",[87],{"type":29,"attrs":88},{"color":89},"#003B5C",{"type":91,"content":92},"bullet_list",[93,104,114,124],{"type":94,"content":95},"list_item",[96],{"type":20,"attrs":97,"content":98},{"textAlign":22},[99],{"text":100,"type":26,"marks":101},"Keeping Inbound Ports Open",[102],{"type":29,"attrs":103},{"color":89},{"type":94,"content":105},[106],{"type":20,"attrs":107,"content":108},{"textAlign":22},[109],{"text":110,"type":26,"marks":111},"An Over-Reliance on VPNs",[112],{"type":29,"attrs":113},{"color":89},{"type":94,"content":115},[116],{"type":20,"attrs":117,"content":118},{"textAlign":22},[119],{"text":120,"type":26,"marks":121},"Using Machine-to-Machine Connections",[122],{"type":29,"attrs":123},{"color":89},{"type":94,"content":125},[126],{"type":20,"attrs":127,"content":128},{"textAlign":22},[129],{"text":130,"type":26,"marks":131},"Trusting “Break-and-Inspect” Services",[132],{"type":29,"attrs":133},{"color":89},{"type":135,"attrs":136,"content":138},"heading",{"level":137,"textAlign":22},2,[139],{"text":140,"type":26,"marks":141},"Common Vulnerabilities for ZTNA Deployments",[142,144],{"type":29,"attrs":143},{"color":89},{"type":145},"bold",{"type":135,"attrs":147,"content":149},{"level":148,"textAlign":22},3,[150],{"text":151,"type":26,"marks":152},"Mistake #1: Keeping Inbound Ports Open",[153,155],{"type":29,"attrs":154},{"color":89},{"type":145},{"type":20,"attrs":157,"content":158},{"textAlign":22},[159,164,171],{"text":160,"type":26,"marks":161},"Many organizations are so used to configuring firewalls with complex rules controlling open ports that this configuration game actually becomes ",[162],{"type":29,"attrs":163},{"color":89},{"text":165,"type":26,"marks":166},"what network security is",[167,169],{"type":29,"attrs":168},{"color":89},{"type":170},"italic",{"text":172,"type":26,"marks":173},", or is simply seen as the “nature of the beast”. Fancy AI products are put into place to set firewall rules, or, traffic is decrypted, inspected, and classified (often incorrectly) as good or bad. One mistake can allow malware, ransomware, and other damaging attacks free-reign across your network.",[174],{"type":29,"attrs":175},{"color":89},{"type":20,"attrs":177,"content":178},{"textAlign":22},[179],{"text":180,"type":26,"marks":181},"The true risk, however, is that there are open inbound ports in the first place.",[182],{"type":29,"attrs":183},{"color":89},{"type":20,"attrs":185,"content":186},{"textAlign":22},[187],{"text":188,"type":26,"marks":189},"As in the famous movie quote, the mistake is playing this dangerous “security” game to begin with.",[190],{"type":29,"attrs":191},{"color":89},{"type":193,"content":194},"blockquote",[195],{"type":20,"attrs":196,"content":197},{"textAlign":22},[198],{"text":199,"type":26,"marks":200},"“The only winning move is not to play.” — WarGames",[201,203,204],{"type":29,"attrs":202},{"color":89},{"type":145},{"type":170},{"type":20,"attrs":206,"content":207},{"textAlign":22},[208,213,219],{"text":209,"type":26,"marks":210},"The truth is, there are new products on the market that make it possible to achieve robust, feature-complete networking and access while blocking ",[211],{"type":29,"attrs":212},{"color":89},{"text":214,"type":26,"marks":215},"all ",[216,218],{"type":29,"attrs":217},{"color":89},{"type":170},{"text":220,"type":26,"marks":221},"inbound traffic on every resource, protecting your network from intrusion.",[222],{"type":29,"attrs":223},{"color":89},{"type":135,"attrs":225,"content":226},{"level":148,"textAlign":22},[227],{"text":228,"type":26,"marks":229},"Mistake #2: An Over-Reliance on VPNs",[230,232],{"type":29,"attrs":231},{"color":89},{"type":145},{"type":20,"attrs":234,"content":235},{"textAlign":22},[236],{"text":237,"type":26,"marks":238},"VPNs are often used to connect remote offices or workers to corporate headquarters or data centers, and are used without considering other alternatives. Similar to creating complex firewall rules, the “it’s always been done this way” mentality leads to most companies extensively using VPNs without hesitation.",[239],{"type":29,"attrs":240},{"color":89},{"type":20,"attrs":242,"content":243},{"textAlign":22},[244],{"text":245,"type":26,"marks":246},"This is playing with fire: VPNs are, essentially, holes through the firewall!",[247],{"type":29,"attrs":248},{"color":89},{"type":20,"attrs":250,"content":251},{"textAlign":22},[252],{"text":253,"type":26,"marks":254},"Inbound traffic, allowed by the VPN, can (and often is) exploited by attackers or compromised devices. VPNs also introduce performance and scalability issues as they require encryption and decryption of all traffic.",[255],{"type":29,"attrs":256},{"color":89},{"type":20,"attrs":258,"content":259},{"textAlign":22},[260,265,271],{"text":261,"type":26,"marks":262},"VPNs are sometimes justified. For instance, for subnets with servers that need to perform real-time synchronization. Let’s say you had a server cluster with machines all around the world that need to talk to each other frequently. Since the servers are in different LANs, you could create a VPN that comprises ",[263],{"type":29,"attrs":264},{"color":89},{"text":266,"type":26,"marks":267},"only",[268,270],{"type":29,"attrs":269},{"color":89},{"type":170},{"text":272,"type":26,"marks":273}," those synchronizing servers — no clients!",[274],{"type":29,"attrs":275},{"color":89},{"type":20,"attrs":277,"content":278},{"textAlign":22},[279,284,290],{"text":280,"type":26,"marks":281},"Allowing every ",[282],{"type":29,"attrs":283},{"color":89},{"text":285,"type":26,"marks":286},"client",[287,289],{"type":29,"attrs":288},{"color":89},{"type":170},{"text":291,"type":26,"marks":292}," unfettered access to the whole network via VPNs is crazily insecure, and far more secure solutions exist to allow clients to access resources and communicate with each other.",[293],{"type":29,"attrs":294},{"color":89},{"type":135,"attrs":296,"content":297},{"level":148,"textAlign":22},[298],{"text":299,"type":26,"marks":300},"Mistake #3: Using Machine-to-Machine Connections",[301,303],{"type":29,"attrs":302},{"color":89},{"type":145},{"type":20,"attrs":305,"content":306},{"textAlign":22},[307],{"text":308,"type":26,"marks":309},"Since VPNs create machine-to-machine connections, any process on a machine can talk to any other process—including malicious ones! This can lead to widespread ransomware, malware, virus infections, or data exfiltration, since a malicious process on one machine could begin attacking any other resource on the VPN.",[310],{"type":29,"attrs":311},{"color":89},{"type":20,"attrs":313,"content":314},{"textAlign":22},[315],{"text":316,"type":26,"marks":317},"Instead, connections should be restricted to only allow process-to-process communication. This means that only specific processes that are designated and meant to communicate with each other can do so, significantly limiting the potential for the spread of cyberattacks.",[318],{"type":29,"attrs":319},{"color":89},{"type":20,"attrs":321,"content":322},{"textAlign":22},[323],{"text":324,"type":26,"marks":325},"Leaving the scope of communication wide-open is a huge, unnecessary liability.",[326],{"type":29,"attrs":327},{"color":89},{"type":135,"attrs":329,"content":331},{"level":330,"textAlign":22},4,[332],{"text":333,"type":26,"marks":334},"Mistake #4: Trusting “Break-and-Inspect” Services",[335,337],{"type":29,"attrs":336},{"color":89},{"type":145},{"type":20,"attrs":339,"content":340},{"textAlign":22},[341],{"text":342,"type":26,"marks":343},"Using break-and-inspect services to secure your network traffic introduces a massive security backdoor into your network.",[344],{"type":29,"attrs":345},{"color":89},{"type":20,"attrs":347,"content":348},{"textAlign":22},[349,354,360],{"text":350,"type":26,"marks":351},"When you rely on a third-party service or appliance that aims to keep you safe by breaking and inspecting your traffic, you’re sharing all your traffic in clear with that entity and trusting them with ",[352],{"type":29,"attrs":353},{"color":89},{"text":355,"type":26,"marks":356},"everything",[357,359],{"type":29,"attrs":358},{"color":89},{"type":170},{"text":361,"type":26,"marks":362},". You’re trusting their software or hardware with your entire network traffic in clear. Company secrets. Credentials. Emails. Customer data. Everything. This approach undermines the spirit of Zero Trust across your network.",[363],{"type":29,"attrs":364},{"color":89},{"type":20,"attrs":366,"content":367},{"textAlign":22},[368,373,385],{"text":369,"type":26,"marks":370},"Although some large organizations may make the (extremely risky) security trade-off to use these services for employee surveillance, other solutions such as application-aware ",[371],{"type":29,"attrs":372},{"color":89},{"text":374,"type":26,"marks":375},"Smart Hybrid Protocols",[376,381,383],{"type":377,"attrs":378},"link",{"href":379,"uuid":22,"anchor":22,"target":22,"linktype":380},"https:\u002F\u002Fwww.xiid.com\u002Fproducts","url",{"type":29,"attrs":382},{"color":89},{"type":384},"underline",{"text":386,"type":26,"marks":387}," already exist on the market that guard against malicious code injection without compromising network security.",[388],{"type":29,"attrs":389},{"color":89},{"type":135,"attrs":391,"content":392},{"level":148,"textAlign":22},[393],{"text":394,"type":26,"marks":395},"What now?",[396,398],{"type":29,"attrs":397},{"color":89},{"type":145},{"type":20,"attrs":400,"content":401},{"textAlign":22},[402],{"text":403,"type":26,"marks":404},"Implementing ZTNA can provide enormous benefits for organizations, but successful deployments require careful planning and execution to avoid these and other common mistakes that undermine its effectiveness.",[405],{"type":29,"attrs":406},{"color":89},{"type":20,"attrs":408,"content":409},{"textAlign":22},[410],{"text":411,"type":26,"marks":412},"If you already have an existing deployment, it’s possible (or even likely) that your network suffers from these key, exploitable vulnerabilities — and it’s certainly not your fault, since most major ZTNA vendors’ products are susceptible to some or all of these.",[413],{"type":29,"attrs":414},{"color":89},{"type":20,"attrs":416,"content":417},{"textAlign":22},[418],{"text":419,"type":26,"marks":420},"A new network access control platform, Terniion, provides the same functionality as typical ZTNA deployments, but is architected from the ground-up by security experts to be free of these and other common pitfalls that hamstring network security.",[421],{"type":29,"attrs":422},{"color":89},"BlogPost",{"id":425,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":426,"copyright":76,"fieldtype":427,"meta_data":428,"is_external_url":15},187885103287046,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F6400x4267\u002Fdf1da80b01\u002Ftop-view-hand-entering-box.jpg","asset",{},{"type":17,"content":430},[431],{"type":91,"content":432},[433,443,453],{"type":94,"content":434},[435],{"type":20,"attrs":436,"content":437},{"textAlign":22},[438],{"text":439,"type":26,"marks":440},"The four most common ZTNA deployment failures: keeping inbound ports open, over-reliance on VPNs, machine-to-machine connections instead of process-to-process, and trusting break-and-inspect services.",[441],{"type":29,"attrs":442},{"color":89},{"type":94,"content":444},[445],{"type":20,"attrs":446,"content":447},{"textAlign":22},[448],{"text":449,"type":26,"marks":450},"Break-and-inspect services fundamentally contradict Zero Trust as they require handing all network traffic to a third party in cleartext.",[451],{"type":29,"attrs":452},{"color":89},{"type":94,"content":454},[455],{"type":20,"attrs":456,"content":457},{"textAlign":22},[458],{"text":459,"type":26,"marks":460},"Terniion is built from the ground up to avoid all four mistakes: all inbound ports closed, no VPN dependency, process-to-process only, and there is no third-party traffic inspection.",[461],{"type":29,"attrs":462},{"color":89},{"id":425,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":426,"copyright":76,"fieldtype":427,"meta_data":464,"is_external_url":15},{},[466],{"_uid":467,"variant":468,"resource":469,"component":1161,"hideLabel":15,"background":1162},"ca415f5c-523a-4c26-b9a2-1bff0246a9ec","oneThirdLeftPhoto",[470],{"name":471,"created_at":472,"published_at":473,"updated_at":474,"id":475,"uuid":476,"content":477,"slug":1151,"full_slug":1152,"sort_by_date":1153,"position":1154,"tag_list":1155,"is_startpage":15,"parent_id":1156,"meta_data":22,"group_id":1157,"first_published_at":1158,"release_id":22,"lang":39,"path":22,"alternates":1159,"default_full_slug":22,"translated_slugs":22,"_stopResolving":1160},"Beyond the Patching Treadmill","2026-06-15T23:03:08.937Z","2026-07-27T21:06:46.260Z","2026-07-27T21:06:46.278Z",187903954703432,"bdf953c8-27d5-4a09-ba8f-3a288ce08cfd",{"Tags":76,"_uid":77,"body":478,"title":479,"content":480,"component":423,"seoOgImage":1116,"keyTakeaways":1120,"previewImage":1145,"previewTitle":1147,"relatedContent":1148,"seoDescription":1149,"previewDescription":1150},[],"Beyond the patching treadmill",{"type":17,"content":481},[482,495,502,519,524,531,536,543,548,555,564,594,599,610,617,622,627,634,641,646,651,674,681,686,709,714,721,728,733,756,761,768,773,778,801,806,811,816,823,828,835,840,845,850,857,862,873,883,890,895,906,929,934,941,946,951,958,965,975,982,987,994,999,1004,1011,1016,1023,1028,1058,1063,1068,1076],{"type":20,"attrs":483,"content":484},{"textAlign":22},[485,489],{"text":486,"type":26,"marks":487},"Key Takeaway: ",[488],{"type":145},{"text":490,"type":26,"marks":491},"Siemens has appeared in over a dozen CISA advisories in early 2026—not because of engineering failures, but because their massive market share creates an unavoidable attack surface. With unplanned downtime costing $260,000\u002Fhour and patch windows often stretching quarterly, traditional “patch and pray” security is failing. The solution isn’t better patching. It’s architectural invisibility that entirely eliminates the attack surface.",[492],{"type":29,"attrs":493},{"color":494},"#002A3A",{"type":135,"attrs":496,"content":497},{"level":137,"textAlign":22},[498],{"text":499,"type":26,"marks":500},"The Siemens Paradox: Market Dominance as Attack Surface",[501],{"type":145},{"type":20,"attrs":503,"content":504},{"textAlign":22},[505,507,511,513,517],{"text":506,"type":26},"If you monitor CISA’s ICS advisories, you’ve noticed a pattern: Siemens keeps appearing. SINEC NMS. RUGGEDCOM. SIMATIC. SCALANCE. The advisory IDs pile up like shipping manifests. But this is actually a ",{"text":508,"type":26,"marks":509},"math",[510],{"type":170},{"text":512,"type":26}," problem, not necessarily a ",{"text":514,"type":26,"marks":515},"quality",[516],{"type":170},{"text":518,"type":26}," problem. ",{"type":20,"attrs":520,"content":521},{"textAlign":22},[522],{"text":523,"type":26},"The industrial automation market has grown to an estimated $257.73 billionin 2026, with Siemens holding dominant positions in digital industries and smart infrastructure. When you’re the backbone of global manufacturing, every vulnerability you disclose has immediate implications for critical infrastructure worldwide.",{"type":135,"attrs":525,"content":526},{"level":148,"textAlign":22},[527],{"text":528,"type":26,"marks":529},"Recent High-Impact Advisories (Q1 2026)",[530],{"type":145},{"type":20,"attrs":532,"content":533},{"textAlign":22},[534],{"text":535,"type":26},"The pattern reveals a strategic shift in attacker targeting. Rather than focusing solely on edge PLCs, threat actors are now targeting the management and monitoring layer, which is the software designed to secure the environment, and it is becoming the primary infection vector.",{"type":135,"attrs":537,"content":538},{"level":137,"textAlign":22},[539],{"text":540,"type":26,"marks":541},"The Economics of the Patching Treadmill ",[542],{"type":145},{"type":20,"attrs":544,"content":545},{"textAlign":22},[546],{"text":547,"type":26},"The central tension that gets repeated over and over again is that CISA releases advisories, then vendors release patches, and finally, manufacturers, wait. . . often can’t deploy them? ",{"type":135,"attrs":549,"content":550},{"level":148,"textAlign":22},[551],{"text":552,"type":26,"marks":553},"2026 Downtime Costs by Industry ",[554],{"type":145},{"type":20,"attrs":556,"content":557},{"textAlign":22},[558,562],{"text":559,"type":26,"marks":560},"S",[561],{"type":145},{"text":563,"type":26},"ector Hourly Cost Reality Check ",{"type":91,"content":565},[566,573,580,587],{"type":94,"content":567},[568],{"type":20,"attrs":569,"content":570},{"textAlign":22},[571],{"text":572,"type":26},"Semiconductor Fab  |  $10,000,000+   |   A single contamination event wipes a week of production. ",{"type":94,"content":574},[575],{"type":20,"attrs":576,"content":577},{"textAlign":22},[578],{"text":579,"type":26},"Automotive  |  $2,300,000   |  One robotic cell failure stops the entire line. ",{"type":94,"content":581},[582],{"type":20,"attrs":583,"content":584},{"textAlign":22},[585],{"text":586,"type":26},"Oil & Gas  |  $500,000   |   Safety interlocks don’t negotiate with patch schedules. ",{"type":94,"content":588},[589],{"type":20,"attrs":590,"content":591},{"textAlign":22},[592],{"text":593,"type":26},"Pharmaceuticals  |  $200,000  |  Patching requires full process re-validation. ",{"type":20,"attrs":595,"content":596},{"textAlign":22},[597],{"text":598,"type":26},"The average per hour cost across manufacturing is $260,000. Meanwhile, the average time from advisory to patch deployment — the “patch lag” — now stretches quarterly or longer for 85% of organizations. ",{"type":20,"attrs":600,"content":601},{"textAlign":22},[602,604,608],{"text":603,"type":26},"The economic math doesn’t make sense. You can’t stop a $2.3M\u002Fhour production line to patch a vulnerability that ",{"text":605,"type":26,"marks":606},"might ",[607],{"type":170},{"text":609,"type":26},"be exploited. So you don’t. And the window stays open. ",{"type":135,"attrs":611,"content":612},{"level":148,"textAlign":22},[613],{"text":614,"type":26,"marks":615},"The Compounding Problem ",[616],{"type":145},{"type":20,"attrs":618,"content":619},{"textAlign":22},[620],{"text":621,"type":26},"Cyberattack-induced downtime now averages 24 hours per incident which far exceeds typical maintenance windows. When an attack hits, it’s not just a brief interruption; it’s operational paralysis that lasts. ",{"type":20,"attrs":623,"content":624},{"textAlign":22},[625],{"text":626,"type":26},"Attackers know the economic math, too. Nation-state actors like Volt Typhoonhave achieved 5-year dwell timesin US critical infrastructure, gaining entry from unpatched vulnerabilities, then patiently mapping OT networks while waiting for the right moment to act.",{"type":135,"attrs":628,"content":629},{"level":137,"textAlign":22},[630],{"text":631,"type":26,"marks":632},"Why Traditional Security Models Are Failing ",[633],{"type":145},{"type":135,"attrs":635,"content":636},{"level":148,"textAlign":22},[637],{"text":638,"type":26,"marks":639},"The VPN Illusion ",[640],{"type":145},{"type":20,"attrs":642,"content":643},{"textAlign":22},[644],{"text":645,"type":26},"CISA frequently recommends VPNs for remote industrial access. The logic seems sound: encrypt the tunnel, authenticate the user, protect the asset. ",{"type":20,"attrs":647,"content":648},{"textAlign":22},[649],{"text":650,"type":26},"But VPNs have a fundamental architectural flaw: they require exposure to function. ",{"type":91,"content":652},[653,660,667],{"type":94,"content":654},[655],{"type":20,"attrs":656,"content":657},{"textAlign":22},[658],{"text":659,"type":26},"A VPN gateway needs a public IP and open inbound ports which makes it a beacon for scanners",{"type":94,"content":661},[662],{"type":20,"attrs":663,"content":664},{"textAlign":22},[665],{"text":666,"type":26},"Once authenticated, users often receive broad network access, exactly the situation that lateral-movement attackers exploit ",{"type":94,"content":668},[669],{"type":20,"attrs":670,"content":671},{"textAlign":22},[672],{"text":673,"type":26},"VPN appliances themselves become targets (see: Fortinet, Ivanti vulnerabilities 2025-2026) The VPN model is “trust, then verify.” In 2026, that’s backwards. ",{"type":135,"attrs":675,"content":676},{"level":148,"textAlign":22},[677],{"text":678,"type":26,"marks":679},"The Segmentation Struggle ",[680],{"type":145},{"type":20,"attrs":682,"content":683},{"textAlign":22},[684],{"text":685,"type":26},"Traditional network segmentation (VLANs, firewall rules) is theoretically sound but practically brittle in OT environments: ",{"type":91,"content":687},[688,695,702],{"type":94,"content":689},[690],{"type":20,"attrs":691,"content":692},{"textAlign":22},[693],{"text":694,"type":26},"Interoperability demands: Mixed-vendor environments often require “flatter” networks than security teams would prefer. ",{"type":94,"content":696},[697],{"type":20,"attrs":698,"content":699},{"textAlign":22},[700],{"text":701,"type":26},"Static rules: IP-based firewall rules can be bypassed once an attacker gains a foothold in a “trusted” segment. ",{"type":94,"content":703},[704],{"type":20,"attrs":705,"content":706},{"textAlign":22},[707],{"text":708,"type":26},"Implementation cost: Redesigning network architecture requires significant downtime, which is the very thing manufacturers can’t afford. ",{"type":20,"attrs":710,"content":711},{"textAlign":22},[712],{"text":713,"type":26},"The 2026 reality: perimeter defense is one-and-done. If an attacker bypasses the initial gate, there are few internal controls to stop lateral movement to the PLCs and switches that control production. ",{"type":135,"attrs":715,"content":716},{"level":137,"textAlign":22},[717],{"text":718,"type":26,"marks":719},"The 2026 Threat Landscape: Why This Is Urgent ",[720],{"type":145},{"type":135,"attrs":722,"content":723},{"level":148,"textAlign":22},[724],{"text":725,"type":26,"marks":726},"Nation-State Pre-Positioning ",[727],{"type":145},{"type":20,"attrs":729,"content":730},{"textAlign":22},[731],{"text":732,"type":26},"The VOLTZITE group (linked to China’s Volt Typhoon) spent 2025 and early 2026 positioning within Western critical infrastructure. Their tactics: ",{"type":91,"content":734},[735,742,749],{"type":94,"content":736},[737],{"type":20,"attrs":738,"content":739},{"textAlign":22},[740],{"text":741,"type":26},"Living-off-the-land (LotL): Using netsh, wmic, and PowerShell instead of custom malware",{"type":94,"content":743},[744],{"type":20,"attrs":745,"content":746},{"textAlign":22},[747],{"text":748,"type":26},"SOHO router compromise: The KV Botnet turns home routers into relay points ",{"type":94,"content":750},[751],{"type":20,"attrs":752,"content":753},{"textAlign":22},[754],{"text":755,"type":26},"IT-to-OT lateral movement: Mapping network diagrams for future activation ",{"type":20,"attrs":757,"content":758},{"textAlign":22},[759],{"text":760,"type":26},"These actorsare  establishing long-term access for use during a potential geopolitical crisis, not just immediate disruption.",{"type":135,"attrs":762,"content":763},{"level":148,"textAlign":22},[764],{"text":765,"type":26,"marks":766},"AI-Accelerated Reconnaissance: The Shrinking Window ",[767],{"type":145},{"type":20,"attrs":769,"content":770},{"textAlign":22},[771],{"text":772,"type":26},"In 2026, the most significant shift is the one that everyone sees, hears, and feels—speed. Why is this being felt so ubiquitously? ",{"type":20,"attrs":774,"content":775},{"textAlign":22},[776],{"text":777,"type":26},"One reason is attackers now deploy AI-powered reconnaissance tools that can scan, identify, and classify exposed industrial systems in minutes rather than days. What used to require manual enumeration and expert analysis is now automated: ",{"type":91,"content":779},[780,787,794],{"type":94,"content":781},[782],{"type":20,"attrs":783,"content":784},{"textAlign":22},[785],{"text":786,"type":26},"Automated CVE correlation: AI agents cross-reference exposed services with known vulnerabilities in real-time, prioritizing targets by exploitability ",{"type":94,"content":788},[789],{"type":20,"attrs":790,"content":791},{"textAlign":22},[792],{"text":793,"type":26},"Credential inference: Machine learning models predict default and weak credentials based on device fingerprints and deployment patterns ",{"type":94,"content":795},[796],{"type":20,"attrs":797,"content":798},{"textAlign":22},[799],{"text":800,"type":26},"Mass exploitation frameworks: Once a vulnerability is disclosed, AI-driven botnets can weaponize it and begin scanning globally within hours ",{"type":20,"attrs":802,"content":803},{"textAlign":22},[804],{"text":805,"type":26},"The stats tell the same speed story. In 2024, the average time from vulnerability disclosure to active exploitation was 15 days. By late 2025, that window had collapsed to under 72 hours for high-value ICS targets. In 2026, we’re seeing exploitation attempts within 24 hours of CISA advisory publication. ",{"type":20,"attrs":807,"content":808},{"textAlign":22},[809],{"text":810,"type":26},"This isn’t hypothetical. Shodan, Censys, and their darker equivalents now index industrial protocols in near real-time. An exposed SINEC NMS portal or RUGGEDCOM management interface can be discovered, fingerprinted, and added to an attack queue before your security team has finished reading the advisory. ",{"type":20,"attrs":812,"content":813},{"textAlign":22},[814],{"text":815,"type":26},"The brutal truth is that AI makes offense faster while your main defense tools—patching—still happens at the same speed. ",{"type":135,"attrs":817,"content":818},{"level":137,"textAlign":22},[819],{"text":820,"type":26,"marks":821},"The February 2026 Hacktivist Surge ",[822],{"type":145},{"type":20,"attrs":824,"content":825},{"textAlign":22},[826],{"text":827,"type":26},"When Iran-US tensions escalated on February 28, 2026, over 60 Iranian-aligned hacktivist groups mobilized within hours, specifically targeting internet-exposed ICS devices across the United States. ",{"type":135,"attrs":829,"content":830},{"level":148,"textAlign":22},[831],{"text":832,"type":26,"marks":833},"Group Target Tactic ",[834],{"type":145},{"type":20,"attrs":836,"content":837},{"textAlign":22},[838],{"text":839,"type":26},"CyberAv3ngers Unitronics PLCs Default credential exploitation APT33 \u002F Elfin Electric\u002FOil\u002FGas SCADA High-volume password spraying MuddyWater Telecoms & Energy Initial access broker operations Handala Hack Team Manufacturing MSPs Supply chain compromise",{"type":20,"attrs":841,"content":842},{"textAlign":22},[843],{"text":844,"type":26}," The attack surface mapping revealed that ports associated with industrial protocols — Port 102 (S7comm), Port 502 (Modbus), Port 44818 (EtherNet\u002FIP) — remained widely accessible despite years of CISA warnings. ",{"type":20,"attrs":846,"content":847},{"textAlign":22},[848],{"text":849,"type":26},"“Internet-exposed” is now synonymous with “compromised” during active conflict.",{"type":135,"attrs":851,"content":852},{"level":137,"textAlign":22},[853],{"text":854,"type":26,"marks":855},"The Architectural Shift: From Defense to Unreachability ",[856],{"type":145},{"type":20,"attrs":858,"content":859},{"textAlign":22},[860],{"text":861,"type":26},"The Zero Trust model — “never trust, always verify” — is a prudent evolution from perimeter security. But for industrial environments, Zero Trust may not be enough. ",{"type":20,"attrs":863,"content":864},{"textAlign":22},[865,867,871],{"text":866,"type":26},"The question isn’t “",{"text":868,"type":26,"marks":869},"how do we verify every connection?",[870],{"type":170},{"text":872,"type":26},"” ",{"type":20,"attrs":874,"content":875},{"textAlign":22},[876,878,882],{"text":877,"type":26},"It’s “",{"text":879,"type":26,"marks":880},"why are we allowing connections in the first place?",[881],{"type":170},{"text":872,"type":26},{"type":135,"attrs":884,"content":885},{"level":148,"textAlign":22},[886],{"text":887,"type":26,"marks":888},"The Principle of Deterministic Unreachability ",[889],{"type":145},{"type":20,"attrs":891,"content":892},{"textAlign":22},[893],{"text":894,"type":26},"If a resource cannot be seen, it cannot be attacked. ",{"type":20,"attrs":896,"content":897},{"textAlign":22},[898,900,904],{"text":899,"type":26},"Traditional industrial communication requires devices to ",{"text":901,"type":26,"marks":902},"listen ",[903],{"type":170},{"text":905,"type":26},"for incoming connections on specific ports. These listening ports are the pathways attackers exploit. Every open port is an invitation. The architectural alternative: outbound-only connections. ",{"type":91,"content":907},[908,915,922],{"type":94,"content":909},[910],{"type":20,"attrs":911,"content":912},{"textAlign":22},[913],{"text":914,"type":26},"No inbound ports listening = no attack surface to scan ",{"type":94,"content":916},[917],{"type":20,"attrs":918,"content":919},{"textAlign":22},[920],{"text":921,"type":26},"No public IPs = no beacon for reconnaissance ",{"type":94,"content":923},[924],{"type":20,"attrs":925,"content":926},{"textAlign":22},[927],{"text":928,"type":26},"Process-to-process tunnels = no network to traverse laterally ",{"type":20,"attrs":930,"content":931},{"textAlign":22},[932],{"text":933,"type":26},"This isn’t defense-in-depth. It’s erasure of the attack surface entirely. ",{"type":135,"attrs":935,"content":936},{"level":148,"textAlign":22},[937],{"text":938,"type":26,"marks":939},"Securing Legacy Systems Without Patching ",[940],{"type":145},{"type":20,"attrs":942,"content":943},{"textAlign":22},[944],{"text":945,"type":26},"This architectural approach is most valuable where patching is most painful: legacy Siemens hardware that cannot be easily updated. ",{"type":20,"attrs":947,"content":948},{"textAlign":22},[949],{"text":950,"type":26},"The key insight is that you don’t need to patch what can’t be reached. ",{"type":135,"attrs":952,"content":953},{"level":137,"textAlign":22},[954],{"text":955,"type":26,"marks":956},"Practical Steps Toward Infrastructure Invisibility ",[957],{"type":145},{"type":135,"attrs":959,"content":960},{"level":148,"textAlign":22},[961],{"text":962,"type":26,"marks":963},"Step 1: Inventory and Exposure Assessment ",[964],{"type":145},{"type":20,"attrs":966,"content":968},{"textAlign":967},"justify",[969,971],{"text":970,"type":26},"Map every SIMATIC PLC, RUGGEDCOM switch, and SCALANCE access point. Use automated discovery to find any management interface reachable from the public internet — these are your highest-priority targets for “sealing.”",{"text":972,"type":26,"marks":973}," ",[974],{"type":145},{"type":135,"attrs":976,"content":977},{"level":148,"textAlign":22},[978],{"text":979,"type":26,"marks":980},"Step 2: Seal Critical Management Planes ",[981],{"type":145},{"type":20,"attrs":983,"content":984},{"textAlign":967},[985],{"text":986,"type":26},"Management systems like SINEC NMS are high-value targets because they provide control over the entire network. Deploy outbound-only access overlays to make management portals invisible to unauthorized scanners. Once verified, close inbound ports at the firewall. ",{"type":135,"attrs":988,"content":989},{"level":148,"textAlign":22},[990],{"text":991,"type":26,"marks":992},"Step 3: Implement Identity-Aware Access Control ",[993],{"type":145},{"type":20,"attrs":995,"content":996},{"textAlign":22},[997],{"text":998,"type":26},"Transition from IP-based trust to cryptographically verified identity. Every operator — internal technician or third-party vendor — must authenticate through the secure overlay, not just the network perimeter. ",{"type":20,"attrs":1000,"content":1001},{"textAlign":22},[1002],{"text":1003,"type":26},"Just-in-Time (JIT) access: Provide temporary, least-privilege access for specific maintenance tasks. When the task completes, the tunnel dissolves — leaving no persistent path for attackers. ",{"type":135,"attrs":1005,"content":1006},{"level":148,"textAlign":22},[1007],{"text":1008,"type":26,"marks":1009},"Step 4: Continuous Monitoring with Perfect Visibility ",[1010],{"type":145},{"type":20,"attrs":1012,"content":1013},{"textAlign":967},[1014],{"text":1015,"type":26},"In an invisibility-secured environment, the network is “dark” to attackers but “crystal clear” to defenders. Every connection is a discrete, logged tunnel — making anomaly detection far simpler than monitoring the noise of a traditional flat network. ",{"type":135,"attrs":1017,"content":1018},{"level":137,"textAlign":22},[1019],{"text":1020,"type":26,"marks":1021},"Clear data trend drives new strategies ",[1022],{"type":145},{"type":20,"attrs":1024,"content":1025},{"textAlign":22},[1026],{"text":1027,"type":26},"The data from 2026 is unambiguous: ",{"type":91,"content":1029},[1030,1037,1044,1051],{"type":94,"content":1031},[1032],{"type":20,"attrs":1033,"content":1034},{"textAlign":22},[1035],{"text":1036,"type":26},"$260,000\u002Fhour downtime costs make patching windows economically prohibitive. ",{"type":94,"content":1038},[1039],{"type":20,"attrs":1040,"content":1041},{"textAlign":22},[1042],{"text":1043,"type":26},"24-hour average cyber incident duration exceeds typical maintenance windows. ",{"type":94,"content":1045},[1046],{"type":20,"attrs":1047,"content":1048},{"textAlign":22},[1049],{"text":1050,"type":26},"5-year nation-state dwell times mean attackers are already inside. ",{"type":94,"content":1052},[1053],{"type":20,"attrs":1054,"content":1055},{"textAlign":22},[1056],{"text":1057,"type":26},"85% of organizations have quarterly-or-longer patch lags. ",{"type":20,"attrs":1059,"content":1060},{"textAlign":22},[1061],{"text":1062,"type":26},"The patching treadmill is a recipe for operational failure. Traditional defense-in-depth assumed you could always run fast enough. In 2026, the treadmill is accelerating faster than anyone can sprint. ",{"type":20,"attrs":1064,"content":1065},{"textAlign":22},[1066],{"text":1067,"type":26},"The only viable path forward is to make your infrastructure unreachable to eliminate the attack surface by erasing the network pathways. This allows you to stop running on the treadmill and step off it entirely. In a world where you cannot patch fast enough, the only solution is to ensure you cannot be seen at all.",{"type":20,"attrs":1069,"content":1070},{"textAlign":22},[1071],{"text":1072,"type":26,"marks":1073},"References ",[1074,1075],{"type":145},{"type":170},{"type":1077,"attrs":1078,"content":1080},"ordered_list",{"order":1079},1,[1081,1095,1102,1109],{"type":94,"content":1082},[1083],{"type":20,"attrs":1084,"content":1085},{"textAlign":22},[1086,1088,1094],{"text":1087,"type":26},"CISA ICS Advisories: ",{"text":1089,"type":26,"marks":1090},"cisa.gov\u002Fnews-events\u002Fics-advisories",[1091],{"type":377,"attrs":1092},{"href":1093,"uuid":22,"anchor":22,"target":22,"linktype":380},"http:\u002F\u002Fcisa.gov\u002Fnews-events\u002Fics-advisories",{"text":972,"type":26},{"type":94,"content":1096},[1097],{"type":20,"attrs":1098,"content":1099},{"textAlign":22},[1100],{"text":1101,"type":26},"CISA Zero Trust Maturity Model: cisa.gov\u002Fzero-trust-maturity-model ",{"type":94,"content":1103},[1104],{"type":20,"attrs":1105,"content":1106},{"textAlign":22},[1107],{"text":1108,"type":26},"IBM Cost of a Data Breach Report 2024 ",{"type":94,"content":1110},[1111],{"type":20,"attrs":1112,"content":1113},{"textAlign":22},[1114],{"text":1115,"type":26},"Deloitte Manufacturing Industry Outlook 2026 ",{"id":1117,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":1118,"copyright":76,"fieldtype":427,"meta_data":1119,"is_external_url":15},201614223195199,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F3456x1944\u002Ff9235af9ee\u002Fdeveloper-identifying-server-issues.jpg",{},{"type":17,"content":1121},[1122],{"type":91,"content":1123},[1124,1131,1138],{"type":94,"content":1125},[1126],{"type":20,"attrs":1127,"content":1128},{"textAlign":22},[1129],{"text":1130,"type":26},"The patching cycle is reactive by design since many times vulnerabilities are exploited for months before patches exist, and organizations are perpetually behind.",{"type":94,"content":1132},[1133],{"type":20,"attrs":1134,"content":1135},{"textAlign":22},[1136],{"text":1137,"type":26},"Patching treats symptoms: if infrastructure has no reachable attack surface, a vulnerability can't be exploited regardless of patch status.",{"type":94,"content":1139},[1140],{"type":20,"attrs":1141,"content":1142},{"textAlign":22},[1143],{"text":1144,"type":26},"Outbound-only, portless architecture makes most CVEs irrelevant because there's nothing for remote attackers to reach.",{"id":1117,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":1118,"copyright":76,"fieldtype":427,"meta_data":1146,"is_external_url":15},{},"Beyond the Patching Treadmill: Why Industrial Security Requires Architectural Invisibility",[],"Siemens ICS keeps landing in CISA advisories. Learn how changing OT network architecture cuts attack surface, dwell time, and seven-figure downtime risk.","Siemens appears in CISA advisories constantly — not due to poor engineering, but massive market share. Learn why patching fails in OT environments and how architectural invisibility eliminates the attack surface entirely.","siemens-ics-vulnerabilities-architectural-invisibility","blog\u002Fsiemens-ics-vulnerabilities-architectural-invisibility","2026-03-26",70,[],193139877037850,"dda33b6b-8233-4aaa-8cd0-2521789356fb","2026-03-26T06:36:00.000Z",[],true,"ResourceFeatureCard","white","The Terniion platform avoids the four most common ZTNA deployment failures.","are-critical-ztna-mistakes-compromising-your-network","blog\u002Fare-critical-ztna-mistakes-compromising-your-network","2025-03-24",170,[],"299a792d-cefe-443c-a43b-80a45aa9aef3","2025-03-24T13:01:00.000Z",[],[1173],{"name":471,"created_at":472,"published_at":473,"updated_at":474,"id":475,"uuid":476,"content":1174,"slug":1151,"full_slug":1152,"sort_by_date":1153,"position":1154,"tag_list":1728,"is_startpage":15,"parent_id":1156,"meta_data":22,"group_id":1157,"first_published_at":1158,"release_id":22,"lang":39,"path":22,"alternates":1729,"default_full_slug":22,"translated_slugs":22},{"Tags":76,"_uid":77,"body":1175,"title":479,"content":1176,"component":423,"seoOgImage":1701,"keyTakeaways":1703,"previewImage":1725,"previewTitle":1147,"relatedContent":1727,"seoDescription":1149,"previewDescription":1150},[],{"type":17,"content":1177},[1178,1188,1194,1206,1210,1216,1220,1226,1230,1236,1243,1269,1273,1281,1287,1291,1295,1301,1307,1311,1315,1335,1341,1345,1365,1369,1375,1381,1385,1405,1409,1415,1419,1423,1443,1447,1451,1455,1461,1465,1471,1475,1479,1483,1489,1493,1501,1509,1515,1519,1527,1547,1551,1557,1561,1565,1571,1577,1584,1590,1594,1600,1604,1608,1614,1618,1624,1628,1654,1658,1662,1669],{"type":20,"attrs":1179,"content":1180},{"textAlign":22},[1181,1184],{"text":486,"type":26,"marks":1182},[1183],{"type":145},{"text":490,"type":26,"marks":1185},[1186],{"type":29,"attrs":1187},{"color":494},{"type":135,"attrs":1189,"content":1190},{"level":137,"textAlign":22},[1191],{"text":499,"type":26,"marks":1192},[1193],{"type":145},{"type":20,"attrs":1195,"content":1196},{"textAlign":22},[1197,1198,1201,1202,1205],{"text":506,"type":26},{"text":508,"type":26,"marks":1199},[1200],{"type":170},{"text":512,"type":26},{"text":514,"type":26,"marks":1203},[1204],{"type":170},{"text":518,"type":26},{"type":20,"attrs":1207,"content":1208},{"textAlign":22},[1209],{"text":523,"type":26},{"type":135,"attrs":1211,"content":1212},{"level":148,"textAlign":22},[1213],{"text":528,"type":26,"marks":1214},[1215],{"type":145},{"type":20,"attrs":1217,"content":1218},{"textAlign":22},[1219],{"text":535,"type":26},{"type":135,"attrs":1221,"content":1222},{"level":137,"textAlign":22},[1223],{"text":540,"type":26,"marks":1224},[1225],{"type":145},{"type":20,"attrs":1227,"content":1228},{"textAlign":22},[1229],{"text":547,"type":26},{"type":135,"attrs":1231,"content":1232},{"level":148,"textAlign":22},[1233],{"text":552,"type":26,"marks":1234},[1235],{"type":145},{"type":20,"attrs":1237,"content":1238},{"textAlign":22},[1239,1242],{"text":559,"type":26,"marks":1240},[1241],{"type":145},{"text":563,"type":26},{"type":91,"content":1244},[1245,1251,1257,1263],{"type":94,"content":1246},[1247],{"type":20,"attrs":1248,"content":1249},{"textAlign":22},[1250],{"text":572,"type":26},{"type":94,"content":1252},[1253],{"type":20,"attrs":1254,"content":1255},{"textAlign":22},[1256],{"text":579,"type":26},{"type":94,"content":1258},[1259],{"type":20,"attrs":1260,"content":1261},{"textAlign":22},[1262],{"text":586,"type":26},{"type":94,"content":1264},[1265],{"type":20,"attrs":1266,"content":1267},{"textAlign":22},[1268],{"text":593,"type":26},{"type":20,"attrs":1270,"content":1271},{"textAlign":22},[1272],{"text":598,"type":26},{"type":20,"attrs":1274,"content":1275},{"textAlign":22},[1276,1277,1280],{"text":603,"type":26},{"text":605,"type":26,"marks":1278},[1279],{"type":170},{"text":609,"type":26},{"type":135,"attrs":1282,"content":1283},{"level":148,"textAlign":22},[1284],{"text":614,"type":26,"marks":1285},[1286],{"type":145},{"type":20,"attrs":1288,"content":1289},{"textAlign":22},[1290],{"text":621,"type":26},{"type":20,"attrs":1292,"content":1293},{"textAlign":22},[1294],{"text":626,"type":26},{"type":135,"attrs":1296,"content":1297},{"level":137,"textAlign":22},[1298],{"text":631,"type":26,"marks":1299},[1300],{"type":145},{"type":135,"attrs":1302,"content":1303},{"level":148,"textAlign":22},[1304],{"text":638,"type":26,"marks":1305},[1306],{"type":145},{"type":20,"attrs":1308,"content":1309},{"textAlign":22},[1310],{"text":645,"type":26},{"type":20,"attrs":1312,"content":1313},{"textAlign":22},[1314],{"text":650,"type":26},{"type":91,"content":1316},[1317,1323,1329],{"type":94,"content":1318},[1319],{"type":20,"attrs":1320,"content":1321},{"textAlign":22},[1322],{"text":659,"type":26},{"type":94,"content":1324},[1325],{"type":20,"attrs":1326,"content":1327},{"textAlign":22},[1328],{"text":666,"type":26},{"type":94,"content":1330},[1331],{"type":20,"attrs":1332,"content":1333},{"textAlign":22},[1334],{"text":673,"type":26},{"type":135,"attrs":1336,"content":1337},{"level":148,"textAlign":22},[1338],{"text":678,"type":26,"marks":1339},[1340],{"type":145},{"type":20,"attrs":1342,"content":1343},{"textAlign":22},[1344],{"text":685,"type":26},{"type":91,"content":1346},[1347,1353,1359],{"type":94,"content":1348},[1349],{"type":20,"attrs":1350,"content":1351},{"textAlign":22},[1352],{"text":694,"type":26},{"type":94,"content":1354},[1355],{"type":20,"attrs":1356,"content":1357},{"textAlign":22},[1358],{"text":701,"type":26},{"type":94,"content":1360},[1361],{"type":20,"attrs":1362,"content":1363},{"textAlign":22},[1364],{"text":708,"type":26},{"type":20,"attrs":1366,"content":1367},{"textAlign":22},[1368],{"text":713,"type":26},{"type":135,"attrs":1370,"content":1371},{"level":137,"textAlign":22},[1372],{"text":718,"type":26,"marks":1373},[1374],{"type":145},{"type":135,"attrs":1376,"content":1377},{"level":148,"textAlign":22},[1378],{"text":725,"type":26,"marks":1379},[1380],{"type":145},{"type":20,"attrs":1382,"content":1383},{"textAlign":22},[1384],{"text":732,"type":26},{"type":91,"content":1386},[1387,1393,1399],{"type":94,"content":1388},[1389],{"type":20,"attrs":1390,"content":1391},{"textAlign":22},[1392],{"text":741,"type":26},{"type":94,"content":1394},[1395],{"type":20,"attrs":1396,"content":1397},{"textAlign":22},[1398],{"text":748,"type":26},{"type":94,"content":1400},[1401],{"type":20,"attrs":1402,"content":1403},{"textAlign":22},[1404],{"text":755,"type":26},{"type":20,"attrs":1406,"content":1407},{"textAlign":22},[1408],{"text":760,"type":26},{"type":135,"attrs":1410,"content":1411},{"level":148,"textAlign":22},[1412],{"text":765,"type":26,"marks":1413},[1414],{"type":145},{"type":20,"attrs":1416,"content":1417},{"textAlign":22},[1418],{"text":772,"type":26},{"type":20,"attrs":1420,"content":1421},{"textAlign":22},[1422],{"text":777,"type":26},{"type":91,"content":1424},[1425,1431,1437],{"type":94,"content":1426},[1427],{"type":20,"attrs":1428,"content":1429},{"textAlign":22},[1430],{"text":786,"type":26},{"type":94,"content":1432},[1433],{"type":20,"attrs":1434,"content":1435},{"textAlign":22},[1436],{"text":793,"type":26},{"type":94,"content":1438},[1439],{"type":20,"attrs":1440,"content":1441},{"textAlign":22},[1442],{"text":800,"type":26},{"type":20,"attrs":1444,"content":1445},{"textAlign":22},[1446],{"text":805,"type":26},{"type":20,"attrs":1448,"content":1449},{"textAlign":22},[1450],{"text":810,"type":26},{"type":20,"attrs":1452,"content":1453},{"textAlign":22},[1454],{"text":815,"type":26},{"type":135,"attrs":1456,"content":1457},{"level":137,"textAlign":22},[1458],{"text":820,"type":26,"marks":1459},[1460],{"type":145},{"type":20,"attrs":1462,"content":1463},{"textAlign":22},[1464],{"text":827,"type":26},{"type":135,"attrs":1466,"content":1467},{"level":148,"textAlign":22},[1468],{"text":832,"type":26,"marks":1469},[1470],{"type":145},{"type":20,"attrs":1472,"content":1473},{"textAlign":22},[1474],{"text":839,"type":26},{"type":20,"attrs":1476,"content":1477},{"textAlign":22},[1478],{"text":844,"type":26},{"type":20,"attrs":1480,"content":1481},{"textAlign":22},[1482],{"text":849,"type":26},{"type":135,"attrs":1484,"content":1485},{"level":137,"textAlign":22},[1486],{"text":854,"type":26,"marks":1487},[1488],{"type":145},{"type":20,"attrs":1490,"content":1491},{"textAlign":22},[1492],{"text":861,"type":26},{"type":20,"attrs":1494,"content":1495},{"textAlign":22},[1496,1497,1500],{"text":866,"type":26},{"text":868,"type":26,"marks":1498},[1499],{"type":170},{"text":872,"type":26},{"type":20,"attrs":1502,"content":1503},{"textAlign":22},[1504,1505,1508],{"text":877,"type":26},{"text":879,"type":26,"marks":1506},[1507],{"type":170},{"text":872,"type":26},{"type":135,"attrs":1510,"content":1511},{"level":148,"textAlign":22},[1512],{"text":887,"type":26,"marks":1513},[1514],{"type":145},{"type":20,"attrs":1516,"content":1517},{"textAlign":22},[1518],{"text":894,"type":26},{"type":20,"attrs":1520,"content":1521},{"textAlign":22},[1522,1523,1526],{"text":899,"type":26},{"text":901,"type":26,"marks":1524},[1525],{"type":170},{"text":905,"type":26},{"type":91,"content":1528},[1529,1535,1541],{"type":94,"content":1530},[1531],{"type":20,"attrs":1532,"content":1533},{"textAlign":22},[1534],{"text":914,"type":26},{"type":94,"content":1536},[1537],{"type":20,"attrs":1538,"content":1539},{"textAlign":22},[1540],{"text":921,"type":26},{"type":94,"content":1542},[1543],{"type":20,"attrs":1544,"content":1545},{"textAlign":22},[1546],{"text":928,"type":26},{"type":20,"attrs":1548,"content":1549},{"textAlign":22},[1550],{"text":933,"type":26},{"type":135,"attrs":1552,"content":1553},{"level":148,"textAlign":22},[1554],{"text":938,"type":26,"marks":1555},[1556],{"type":145},{"type":20,"attrs":1558,"content":1559},{"textAlign":22},[1560],{"text":945,"type":26},{"type":20,"attrs":1562,"content":1563},{"textAlign":22},[1564],{"text":950,"type":26},{"type":135,"attrs":1566,"content":1567},{"level":137,"textAlign":22},[1568],{"text":955,"type":26,"marks":1569},[1570],{"type":145},{"type":135,"attrs":1572,"content":1573},{"level":148,"textAlign":22},[1574],{"text":962,"type":26,"marks":1575},[1576],{"type":145},{"type":20,"attrs":1578,"content":1579},{"textAlign":967},[1580,1581],{"text":970,"type":26},{"text":972,"type":26,"marks":1582},[1583],{"type":145},{"type":135,"attrs":1585,"content":1586},{"level":148,"textAlign":22},[1587],{"text":979,"type":26,"marks":1588},[1589],{"type":145},{"type":20,"attrs":1591,"content":1592},{"textAlign":967},[1593],{"text":986,"type":26},{"type":135,"attrs":1595,"content":1596},{"level":148,"textAlign":22},[1597],{"text":991,"type":26,"marks":1598},[1599],{"type":145},{"type":20,"attrs":1601,"content":1602},{"textAlign":22},[1603],{"text":998,"type":26},{"type":20,"attrs":1605,"content":1606},{"textAlign":22},[1607],{"text":1003,"type":26},{"type":135,"attrs":1609,"content":1610},{"level":148,"textAlign":22},[1611],{"text":1008,"type":26,"marks":1612},[1613],{"type":145},{"type":20,"attrs":1615,"content":1616},{"textAlign":967},[1617],{"text":1015,"type":26},{"type":135,"attrs":1619,"content":1620},{"level":137,"textAlign":22},[1621],{"text":1020,"type":26,"marks":1622},[1623],{"type":145},{"type":20,"attrs":1625,"content":1626},{"textAlign":22},[1627],{"text":1027,"type":26},{"type":91,"content":1629},[1630,1636,1642,1648],{"type":94,"content":1631},[1632],{"type":20,"attrs":1633,"content":1634},{"textAlign":22},[1635],{"text":1036,"type":26},{"type":94,"content":1637},[1638],{"type":20,"attrs":1639,"content":1640},{"textAlign":22},[1641],{"text":1043,"type":26},{"type":94,"content":1643},[1644],{"type":20,"attrs":1645,"content":1646},{"textAlign":22},[1647],{"text":1050,"type":26},{"type":94,"content":1649},[1650],{"type":20,"attrs":1651,"content":1652},{"textAlign":22},[1653],{"text":1057,"type":26},{"type":20,"attrs":1655,"content":1656},{"textAlign":22},[1657],{"text":1062,"type":26},{"type":20,"attrs":1659,"content":1660},{"textAlign":22},[1661],{"text":1067,"type":26},{"type":20,"attrs":1663,"content":1664},{"textAlign":22},[1665],{"text":1072,"type":26,"marks":1666},[1667,1668],{"type":145},{"type":170},{"type":1077,"attrs":1670,"content":1671},{"order":1079},[1672,1683,1689,1695],{"type":94,"content":1673},[1674],{"type":20,"attrs":1675,"content":1676},{"textAlign":22},[1677,1678,1682],{"text":1087,"type":26},{"text":1089,"type":26,"marks":1679},[1680],{"type":377,"attrs":1681},{"href":1093,"uuid":22,"anchor":22,"target":22,"linktype":380},{"text":972,"type":26},{"type":94,"content":1684},[1685],{"type":20,"attrs":1686,"content":1687},{"textAlign":22},[1688],{"text":1101,"type":26},{"type":94,"content":1690},[1691],{"type":20,"attrs":1692,"content":1693},{"textAlign":22},[1694],{"text":1108,"type":26},{"type":94,"content":1696},[1697],{"type":20,"attrs":1698,"content":1699},{"textAlign":22},[1700],{"text":1115,"type":26},{"id":1117,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":1118,"copyright":76,"fieldtype":427,"meta_data":1702,"is_external_url":15},{},{"type":17,"content":1704},[1705],{"type":91,"content":1706},[1707,1713,1719],{"type":94,"content":1708},[1709],{"type":20,"attrs":1710,"content":1711},{"textAlign":22},[1712],{"text":1130,"type":26},{"type":94,"content":1714},[1715],{"type":20,"attrs":1716,"content":1717},{"textAlign":22},[1718],{"text":1137,"type":26},{"type":94,"content":1720},[1721],{"type":20,"attrs":1722,"content":1723},{"textAlign":22},[1724],{"text":1144,"type":26},{"id":1117,"alt":76,"name":76,"focus":76,"title":76,"source":76,"filename":1118,"copyright":76,"fieldtype":427,"meta_data":1726,"is_external_url":15},{},[],[],[],[],{"cache-control":46,"connection":47,"content-encoding":1732,"content-type":49,"date":1733,"etag":1734,"referrer-policy":52,"sb-be-version":53,"server":54,"transfer-encoding":1735,"vary":1736,"via":1737,"x-amz-cf-id":1738,"x-amz-cf-pop":58,"x-cache":59,"x-content-type-options":60,"x-frame-options":61,"x-permitted-cross-domain-policies":62,"x-request-id":1739,"x-runtime":1740,"x-xss-protection":65},"gzip","Wed, 12 Aug 2026 16:32:30 GMT","W\u002F\"30d12be9c1e1c36b276265042427ceda\"","chunked","Origin,Accept-Encoding","1.1 d7417eea51b6155ca5328edbd5ac9b4e.cloudfront.net (CloudFront)","06zExLadpEjGZWqgA7-LE40DUpfoY20UBbnyRMlkP2yeOJafhG-j4A==","046726ef-ee95-4c11-b039-c92a20781eb2","0.039369",1786552350446]