(TLP:CLEAR) Gate 15 White Paper: “15 from 15” Cybersecurity Mitigation & Resilience Fundamentals
Created: Thursday, September 10, 2026 - 14:58
Categories: Cybersecurity, OT-ICS Security, Security Preparedness
Summary: Gate 15 has published a new white paper, “15 from 15: Cybersecurity Mitigation & Resilience Fundamentals,” which lays out 15 practical areas organizations can focus on to improve security, preparedness, and resilience. The paper frames these as the “blocking and tackling” of cybersecurity: durable fundamentals that remain effective even as threats, technologies, and products change. The 15 areas are Assess, People, Organizational Culture, Security Stack, Information Sharing, Multi-Factor Authentication (MFA), Network Segmentation, Patching, Backups & Encryption, Planning, Out-of-Band (OOB) Communications, Train, Test, Exercise, and Post-Mortems.
Each fundamental is explained in terms of what it is, what an organization can do about it, and why it matters, with supporting government guidance and real-world examples. Gate 15 emphasizes that the list is not exhaustive and not a substitute for a mature cybersecurity program or established frameworks, but rather a set of achievable, high-value actions that apply at the individual, team, operational, executive, and board levels.
Analyst Note: Gate 15, a WaterISAC Champion, provides expertise in cyber and physical threat intelligence, analysis, operations, and preparedness. Notably, the Gate 15 team led the development and subsequent refresh of WaterISAC’s Cybersecurity Fundamentals for Water and Wastewater Utilities, so the thinking behind this paper is directly familiar to the water sector.
Several of the 15 fundamentals map closely to the pressures water and wastewater utilities face today. The paper’s treatment of network segmentation stresses separating IT from OT and building only the isolation an organization can actually maintain, since segmentation without upkeep creates false confidence. Its patching section points to CISA’s Known Exploited Vulnerabilities Catalog as a standing input and acknowledges the operational reality that immediate patching is sometimes unsafe in OT or legacy environments, where compensating controls and documented residual risk become the practical path. The out-of-band communications section reinforces a theme WaterISAC has been highlighting: utilities that isolate a compromised network still need a trusted, rehearsed way to coordinate the response, identified and tested before an incident rather than improvised during one.
The paper also makes a resource-conscious case that resonates for smaller utilities with limited staff, encouraging deliberate progress over trying to mature every area at once. WaterISAC occasionally shares Gate 15 reporting for additional insight into the evolving all-hazards threat landscape, and members can use “15 from 15” as a self-assessment starting point to identify where a single practical improvement would meaningfully reduce risk.
Original Source: Access the full report below.
Additional Reading:
