OT/ICS security: protecting without stopping the process

IT/OT convergence, segmentation and patching in systems you cannot switch off.

Operational technology — the systems that run production lines, plants, energy and logistics — lives with constraints the IT world rarely knows. A web server can be rebooted; a turbine, a robotic cell or a process control system cannot, not when you feel like it. Here availability and physical safety come before confidentiality, and that inverts many habits born in IT.

For years OT was protected by isolation: separate networks, obscure protocols, machines nobody touched. That isolation has thinned almost everywhere. IT/OT convergence brings connectivity, telemetry and value — and with it an attack surface that simply did not exist before.

Why OT is not treated like IT

Many industrial devices have lifecycles of ten, fifteen, twenty years. They run operating systems no longer supported, use protocols designed when the network was trusted by definition, and do not tolerate aggressive scanning: a port scan that is routine for a server can fault a PLC. The first mistake is applying IT tools to OT without adapting them.

The second mistake is the opposite: declaring OT “too delicate to touch” and doing nothing. The middle path is an approach designed for the process, one that starts by understanding what is there and how it communicates before intervening.

Visibility first

You cannot protect what you do not know you have. In OT, visibility is built passively, by listening to traffic rather than probing devices: which assets exist, on which firmware, which flows are normal and which are not. From this comes a real inventory and a baseline of expected behaviour — the foundation for everything that follows.

That map almost always reveals surprises: forgotten outbound connections, always-on vendor access, undocumented bridges between the office network and the plant network. These are exactly the paths an attacker looks for.

Segmenting between IT and OT (and within OT)

Segmentation is the highest-return control in industrial settings. A layered model — in the spirit of references such as IEC 62443 and the Purdue model — separates the enterprise network from the control network, with explicit zones and conduits between the two worlds. The goal is that a compromise on the office side does not automatically become a compromise on the plant side.

Inside OT, segmentation matters too: isolating cells, lines or subsystems keeps a problem local. And every remote access — indispensable for vendor maintenance — should be channelled through controlled paths, with strong authentication and brokering, not left as a permanent, invisible tunnel.

Vendors deserve their own attention. Much of the plant is designed, installed and maintained by third parties, who often demand connectivity to their systems for diagnostics and support. Every integrator with standing access is a piece of your attack surface living outside your control: it should be inventoried, cut to the minimum, enabled only when needed and watched as if it were internal — because in the impact of an incident, it is.

Patching where you cannot switch off

Vulnerability management in OT is not the IT patch race. Updating can require a plant shutdown, vendor validation and maintenance windows that come only a few times a year. The question is not “how fast do I patch”, but “is this vulnerability actually reachable and exploitable in my context, and what is the least invasive way to reduce its risk?”.

When patching is not immediately practical, you work with compensating mitigations: tighter segmentation around the exposed system, access rules, dedicated monitoring of that flow. It is risk management driven by real exposure, not by the count of CVEs in a report.

A response plan that speaks the plant’s language

Incident response in OT has different priorities: the safety of people, the integrity of the physical process and production continuity come before data recovery. The plan must involve those who know the plant — process and maintenance engineers, not just the IT team — and anticipate scenarios where the hard decision is whether and when to isolate part of production.

It has to be rehearsed in advance, with realistic tabletops. The middle of an incident is not the moment to discover who has the authority to stop a line.

The takeaway

OT security is not about bringing IT into the plant, but about protecting the process with controls designed for its constraints: passive visibility first, then segmentation between and within the two worlds, then vulnerability management driven by exposure and a response that puts safety and continuity first.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.