Cybersecurity is no longer just an IT concern hidden behind firewalls and technical reports. It has become a business-critical responsibility that directly impacts operations, reputation, investor confidence, and growth. For organizations that rely on complex digital ecosystems and industrial environments, the real challenge is gaining the visibility needed to understand where risks exist before they become costly disruptions.In an era where cyberattacks are growing more sophisticated and industrial systems are increasingly connected, clarity has become one of the most valuable assets a business can possess.
This is where Atumcell is making a meaningful difference. Recognized as a “Leading OT & ICS Cybersecurity Company 2026” by CIO Bulletin, Atumcell is helping organizations replace uncertainty with confidence by delivering deep visibility across their cybersecurity landscape. The company specializes in identifying, preventing, and responding to cyber threats ranging from domain spoofing and exposed digital assets to infrastructure misconfigurations and vulnerabilities within critical operational environments.
What sets Atumcell apart is its ability to view security through a broader lens, bridging traditional IT networks, Operational Technology (OT), Industrial Control Systems (ICS), and supply chain ecosystems into one comprehensive picture of risk. By understanding what attackers can see before they strike, Atumcell enables organizations to take proactive action rather than react to incidents after the damage is done. Guided by a mission to empower secure growth in an interconnected world, the company combines trusted expertise, strategic insight, and advanced technology to help businesses, investors, and industries operate with greater resilience. Through this approach, Atumcell is not only strengthening cybersecurity defenses but also giving organizations the confidence to innovate, expand, and grow without fear.
At CIO Bulletin, we had the distinct honor of interviewing Matthew Carr, Co-Founder and CTO/CISO of Atumcell. During the conversation, he shared profound insights into how Atumcell, guided by its core promise to “Stop Guessing. Start Knowing,” gives businesses the clarity to operate securely, across traditional IT networks and complex industrial control systems alike.
Interview Highlights
What was the defining moment that led to Atumcell's inception, and what gap in cybersecurity did you set out to solve?
In 2019, I led a controlled cyberphysical research project with Ford to determine whether an attacker could combine a physical break-in with a custom device to halt a live production line without detection. The answer was yes. We gained access, mapped the network, deployed a device resembling a legitimate controller, and stopped the line in under ten minutes. In a real scenario, this would have cost the manufacturer millions per hour. A former Metropolitan Police investigator later reviewed the exercise and found that almost none of the activity was traceable.
The research received significant media attention and influenced my next steps. After each presentation, operators consistently asked, “How do we defend against this?” Initially, my response was, “That's not really my job; I break things.” Over time, I recognized the need to help address these vulnerabilities. Atumcell was founded to close the gap where most OT and ICS security solutions are adapted from IT and do not account for the unique challenges of industrial environments. My guiding principle is: to understand how to break something, first learn how it is built.
Could you brief us on the products and services Atumcell offers today, and what they enable that traditional cybersecurity approaches often miss?
Atumcell combines offensive security services and creates intrusion detection rules tailored for OT and ICS. Our services include penetration testing and red-team assessments for OT, ICS, and associated IT and web systems. Insights gained from these engagements inform our development of deployable intrusion detection rules, supported by continuous assessment and monitoring to ensure ongoing relevance. We primarily serve private-equity firms, their portfolio companies, and midsized industrial operators without extensive in-house security teams.
Traditional approaches often lack context. For example, a standard IT scanner may flag a missing patch on a controller and recommend a reboot, which in a plant could halt production or trigger a safety system. We consider operational realities, evaluating device functions, connections, and potential physical impacts. Our assessments provide a prioritized view of potential attacker actions, with each finding validated in practice.
“Stop Guessing. Start Knowing” is a strikingly clear positioning. How does that philosophy shape the way you design both your products and client engagements?
Much security spending is based on the assumption that controls are effective simply because they are in place. “Stop Guessing. Start Knowing” reflects our commitment to evidence-based security. We independently verify client segmentation and demonstrate its effectiveness. Each engagement is structured to replace assumptions with evidence. Our continuous assessment ensures that security insights remain current as environments and threats evolve.
In an industry still dominated by IT-centric thinking, how is Atumcell changing the conversation around OT and ICS security for boards and operators who cannot afford downtime?
The industry often frames OT security as a concern only for nation-state targets, leading many midsized operators to believe they are not at risk. This assumption is outdated. Security through obscurity doesn’t work, as increased internet connectivity and AI have lowered barriers for attackers. Our discussions with boards focus on current exposure: organizations are now more accessible than before, and attackers require less expertise to pose a threat.
The other aspect of our conversation is reassurance. We do not promote fear. In OT, causing physical harm requires specific knowledge of the target; generic exploits are unlikely to cause major incidents. Fundamental controls remain effective when properly implemented. Many incidents still result from unchanged default passwords. Boards should understand that implementing a few essential controls correctly can mitigate most risks.
How does your approach to OT penetration testing and network monitoring balance deep technical rigor with zero tolerance for production disruption?
This is the most challenging aspect of OT testing and is often misunderstood by IT-trained testers. In corporate IT,disruptions during testing can typically be resolved with a restart. In a plant, disruptions can halt production or impact safety. We begin by thoroughly understanding the operational process and its tolerances before any testing. We prioritize observation over stressing live systems and schedule intrusive work according to the plant's operational needs. The deep knowledge required for effective attacks also helps us test safely because we understand the precise impact of each action. In OT, technical rigor and operational restraint are inseparable.
Looking at the OT and ICS landscape heading into 2026, which emerging risks are you preparing clients for that most organizations still underestimate?
There are two key risks. First, remote-management exposure: the convenience of remote OT management has connected many devices originally designed to be isolated, and many operators are unaware of how much of their environment is now accessible. Second, AI-assisted attackers: AI accelerates attackers’ capabilities, from reconnaissance to scripting, reducing the protection once provided by system obscurity.
However, I caution against a narrative of inevitable disaster. The real risk is the gradual erosion of the belief that obscurity provides protection. Organizations that succeed will be those that move beyond obscurity and focus on implementing fundamental security measures effectively.
As Atumcell looks to the future, what bold ambitions or strategic moves are set to shape the company's next chapter?
Our goal is to make robust OT security accessible to operators excluded by cost or complexity. This includes mid-market organizations and private-equity portfolio companies, where vulnerabilities at one site can impact the entire group. Much of today's OT security is either a compliance formality or an enterprise solution unsuitable for midsized operators. We aim to provide a practical, evidence-based, and operationally focused alternative.
Are there new capabilities or service models in the pipeline that OT and ICS clients should be particularly excited about?
Currently, I am focused on an open-access initiative that makes OT vulnerability research, CVE-level knowledge, and detection rules available to the broader community, rather than restricting them to vendor reports. Industrial system defenders often lack the information available to attackers, and addressing this gap is more valuable than any single product. This initiative also supports our work, as the intrusion detection rules we develop from real OT research become actionable for clients. Additionally, we are integrating AI into our assessment and monitoring processes to identify and prioritize risks more efficiently across client environments while maintaining the operational judgment necessary for safe OT testing.
About | Matthew Carr
Matthew Carr is Co-Founder and CTO/CISO of Atumcell, where he leads research and technology. A zero-day researcher who moved into OT and ICS security before it was an established field, he is CISSP-certified and holds an OT-specific security certification.
He is also a Freeman of the Worshipful Company of Information Technologists (WCIT), one of the City of London's livery companies, the modern successors to the medieval trade guilds and a recognized mark of professional standing in the UK technology community. His controlled cyberphysical research, including a widely reported project demonstrating how an industrial production line could be halted through a combined physical and network attack, has been featured across major outlets, including BBC One, ITV, The Telegraph, the Financial Times, and SVT, and presented at leading security conferences, including DEF CON, BSides, and SteelCon.
He has also chaired the secure-data-transfer committee of the Public Safety Technology Alliance. At Atumcell, he brings that offensive research background to defending industrial and critical-infrastructure operators.







