OT Security Unplugged – When Cybersecurity Leaves the Server Room

OT Security Unplugged – When Cybersecurity Leaves the Server Room 

 

I think when most people hear the word “cybersecurity”, they probably picture a laptop on a dark blue photoshopped background with a faded padlock off to one side, an email icon and a generic looking bug on the screen, a cloud in the distance with lines coming out of it and perhaps a frustrated generic IT Manager thousand-yard-staring at a screen. I suppose that’s what Google and Getty Images have served us to date, so what can we expect (Google “cybersecurity” if you haven’t and you’ll see what I mean). For years, most cyber conversations have existed in the IT space and for good reason. As fishers fish where the fish are, phishers phish where the… well, let’s maybe not torture that analogy to death.

 

But there's another side to the story that often gets overlooked. A side where cybersecurity isn't just about protecting data but rather protecting systems that keep lights on, production lines moving, water flowing and trains running. 

 

Welcome to the world of Operational Technology, or OT. While it might not get quite as much airtime as AI (what does), OT is arguably one of the most important cybersecurity conversations that organisations can have and, arguably, should be having. 

 

Operational Technology is simply technology that controls physical processes. If IT controls information, OT controls things that move, spin, pump, heat, cool, mix, manufacture or generate. It's where software meets the real world. Think about manufacturing plants, utilities (electricity production and the like), transport networks, pharmaceutical production, food processing, oil and gas, hospitals. Basically, anywhere that computers are controlling machinery rather than spreadsheets and usually involves three-phase power, hard hats and Hi-Viz jackets. 

 

If traditional IT keeps business information flowing, then OT keeps business machines turning. It's the difference between someone being unable to send an email (the horror, imagine!?) and an entire production line grinding to a halt or power not being supplied to the grid. 

 

Similar technology. Very different priorities. 

 

One of the biggest mistakes organisations can make is assuming OT can be secured in exactly the same way as IT. Spoiler alert: it can't. In IT, security is largely about protecting confidentiality, integrity and availability of information. In OT, the priorities shift. Safety comes first. Operational continuity comes second. Everything else follows after that. 

 

A laptop locked by ransomware is definitely a major problem and can be very disruptive for a business, but having to restarting or repair a turbine, shutting down a chemical process or stopping a manufacturing line halfway through production can be genuinely catastrophic.   

 

Downtime in Industrial and Operational Systems isn't just inconvenient. It can be expensive (the least of your worries to be honest), environmentally damaging and, in some cases, genuinely dangerous to life and limb. 

 

Why is OT suddenly such a big topic? 

 

For years, many if not most OT environments were relatively isolated. This is sometimes referred to as ‘air-gapping’ where the systems in question weren't designed to be connected to the outside world (or were designed explicitly not to be – ‘down with that sort of thing’). 

 

Then came the rise and evolution of remote working, cloud platforms, Industrial IoT, predictive maintenance and the perfectly reasonable business desire to see what's happening across multiple sites from a single dashboard. The benefits of these changes are obvious, potentially enormous and a game changer for organisations. 

 

  • Better visibility. 

  • Better efficiency. 

  • Better decision making. 

  • Joined up thinking across your whole organisation, not just the IT bit. 

 

Unfortunately, of course, this means the attack surface has grown. The more connected these environments became, the more important it became to secure them properly. 

 

The challenge isn't just technology. 

 

A lot of OT equipment has been faithfully doing its job for twenty or thirty years. Which is wonderful of course, until someone suggests applying the latest security patch. Unlike IT systems that we’ve become accustomed to, industrial control systems often can't simply be rebooted on a Tuesday afternoon because Microsoft says it’s time. 

 

Add into that mix specialist vendors, proprietary protocols, contractors needing remote access and organisational teams whose priorities and motivations often and naturally differ, and you quickly realise this isn't simply an IT problem. It's an organisational one. 

 

The most successful OT security programmes aren't built on technology alone. They're built on collaboration between engineering, operations, IT, security and leadership. 

 

What does good OT security actually look like? 

 

Thankfully, this isn't a case of starting from scratch. There are well-established approaches and frameworks that have stood the test of time. It starts with understanding what you have – knowing which assets are connected, how they communicate and which ones are critical. 

 

From there, organisations should focus on sensible fundamentals: 

  • Segment OT from IT wherever possible (limit the blast radius for both). 

  • Secure remote access and verify who is connecting (least privilege, zero trust, etc.). 

  • Monitor industrial networks using tools designed for OT environments (many cyber security vendors have good tooling for both – reach out if you need some pointers). 

  • Build incident response plans that reflect operational realities (not unrealistic board-level expectations borne of IT SLAs). 

  • Bring IT and OT teams together rather than expecting each to solve the other's problems (joined up thinking for a connected world). 

 

In other words – layer your defences, understand your risks and plan before something goes wrong. 

 

You don't have to invent the answers. 

 

One of the reassuring things about OT security is that the industry has already developed some excellent guidance. 

 

Frameworks such as ISA/IEC 62443, the NIST Cybersecurity Framework and MITRE ATT&CK for ICS provide practical approaches to managing risk without reinventing the wheel. As Adam points out in the video (go watch it if you haven’t!), they complement one another, combining technical controls, governance and threat-informed defence. 

 

No framework will eliminate risk entirely. But they provide a roadmap that's considerably better than hoping for the best. 

 

The takeaway 

 

So, to sum it all up, OT security isn't simply securing IT with bigger machines. It's about protecting people, production and critical infrastructure. And ultimately, protecting the reputation and resilience of the organisations that keep our world running. 

 

As more businesses embrace digital transformation and IT and OT continue to converge, the question is no longer whether OT belongs in your cybersecurity strategy. It's whether your cybersecurity strategy is ready for OT. And if you're wondering where to begin…well, that's exactly what the video's for.