The most destructive cyberattacks over the last years have used vulnerabilities that were either unknown or known, but still unpatched. Particularly in industrial environments where patch management is slow and difficult, the risk exposure remains – even years after zero day vulnerabilities became public. Klaus Mochalski explains how ICS monitoring with anomaly detection closes this prevailing security gap.