@hacks4pancakes good to know, thanks. I should probably push more detailed recommendations than I have been on that front (monitoring is something I've been slacking on in general; I'm behind on it).
any pointers on specifics I should direct them towards, beyond the basic "suricata and snort are free and well supported"? are there any good baseline rulesets for ICS environments? any guides you tend to poke clients towards? (I appreciate that this subject is an entire job's worth of complexity)