OT Cybersecurity: Protecting Industrial Control Systems From Modern Threats
Industrial Services

OT Cybersecurity: Protecting Industrial Control Systems From Modern Threats

Avatar photo
Robert Smith October 5, 2026 17 min read

The first time I watched a ransomware note pop up on an HMI, the operators did not panic about the files. Instead, they panicked about the kiln. Nobody could see the temperature trend anymore, so the line had to come down by hand while we figured out how far the infection had reached. In my experience, that is the moment OT cybersecurity stops being a slide in a board deck and becomes a very physical, very expensive problem.

I have spent most of my career on plant floors, substations, and pump stations, walking cabinets with a laptop and a serial cable more often than sitting in a SOC. For that reason, what follows is not a vendor pitch. Rather, it is how I think about protecting industrial control systems today, what the threat data is actually telling us, and the controls I push for first when a site asks me where to start.

If you run a plant, manage maintenance, or own the engineering budget, this is written for you. Of course, you do not need to become a security expert. However, you do need to understand why the old assumption that “our control network is isolated” no longer holds, and what a realistic, affordable defense looks like.

Why OT Cybersecurity Is Not Just IT Security on the Plant Floor

What Counts as Operational Technology

Operational technology is the hardware and software that monitors and moves physical things. For example, PLCs, RTUs, DCS controllers, safety instrumented systems, HMIs, historians, drives, and the engineering workstations that program them all sit in this world. Increasingly, so do networked CNC machines and the additive manufacturing systems that now share the same plant network. As a result, when something goes wrong here, the consequence is not a leaked spreadsheet. Instead, it is a spill, a fire, a contaminated batch, or a person getting hurt.

That, in turn, changes the priorities completely. In corporate IT, the classic order is confidentiality, integrity, availability. On a plant floor, however, I flip it. Safety comes first, then availability and integrity of the process, and confidentiality usually lands last. In other words, a controller that leaks its ladder logic is a problem, but a controller that silently writes a bad setpoint is a disaster.

The Realities That Make OT Different

In addition, a few realities make OT cybersecurity its own discipline:

  • Assets live for decades. I still find Windows XP machines running HMI software because the vendor never certified anything newer. Similarly, a PLC installed in 2005 may run until 2035.
  • Downtime is the enemy. You cannot reboot a reactor control system on a Tuesday afternoon just because a patch came out. In fact, many sites get one maintenance window a year.
  • Protocols were built for trust. Modbus, DNP3, and older versions of EtherNet/IP and Profinet were designed for closed networks. Consequently, most have no authentication at all. If you can reach the device, you can usually talk to it.
  • Active scanning can break things. I have personally seen an aggressive network scan knock a fragile controller into fault. Therefore, IT tools that are harmless in an office can be dangerous here.
  • Ownership is split. Engineering owns the process, IT owns the network, and meanwhile an outside integrator often holds the passwords. Unsurprisingly, security falls into the gaps between them.

To be clear, the point is not that IT practices are wrong. On the contrary, many of them translate well. Even so, they have to be adapted by people who understand what a control loop is and what happens when it breaks.

What the Threat Picture Looks Like in 2026

For years, the honest answer to “who is actually attacking control systems?” was a short list of nation states and a lot of theory. Today, however, that answer has changed, and the numbers back it up.

Ransomware Has Moved Onto the Plant Floor

The Dragos 2026 OT Cybersecurity Year in Review tracked 119 ransomware groups hitting roughly 3,300 industrial organizations during 2025, up from 80 groups the year before. Notably, manufacturing made up more than two thirds of those victims. Beyond that, the same report flagged something that worries me more than the raw count: average ransomware dwell time inside OT environments was about 42 days. Put simply, that is six weeks of someone sitting in your network before anyone notices.

Furthermore, Dragos reported that, for the first time, two of the three new threat groups it named were already operating inside OT networks with the ability to interact with specific control technologies. In plain terms, attackers are no longer just knocking on the door between IT and OT. Instead, some are already inside, mapping control loops and learning how the process behaves.

Low Skill Attackers Are Finding Easy Targets

At the other end of the skill spectrum, CISA, the FBI, EPA, and DOE have spent the last two years warning about unsophisticated actors. These groups simply find HMIs and PLCs exposed to the internet, log in with default passwords, and then start changing values. Accordingly, their joint guidance on primary OT mitigations makes the point bluntly: internet connected OT devices are easy targets, and the tools needed to find them are available to anyone with a browser.

The Entry Points I See Most Often

When I map incidents I have worked against this data, the same entry points show up again and again:

  • IT compromise that spills into OT. First, phishing or a stolen VPN credential lands on the corporate side. Then flat networks or shared domain accounts let the attacker walk into the control environment.
  • Remote access that nobody governs. For instance, a vendor TeamViewer session left running, a modem bolted to a panel years ago, or a jump box with a shared password.
  • Exposed devices. HMIs, gateways, and controllers are reachable straight from the internet and, in many cases, still use factory credentials.
  • Virtualization and shared infrastructure. Ransomware crews now go after the hypervisors that host historians, SCADA servers, and HMI clients. Thus, encrypting one host can take down a dozen operator screens at once.
  • Supply chain. Integrators, OEMs, and engineering firms carry access into many plants. So when they get breached, their customers inherit the risk.

Notice, above all, that most of these do not require exotic ICS malware. Granted, the Stuxnets and Tritons of the world exist, and they matter. Nevertheless, the majority of real disruption I see comes from ordinary intrusions meeting an OT environment that was never built to contain them.

The Controls I Push for First

When a plant manager asks me where to spend the first dollar, I do not hand them a 300 page framework. Instead, I walk them through a short list, in roughly this order. Not by coincidence, it lines up closely with the SANS Five ICS Cybersecurity Critical Controls, which I like precisely because they came from studying real attacks rather than a compliance wish list.

1. Know What You Actually Have

You cannot defend a controller you do not know exists. Yet on almost every first site visit, the asset list I am handed is wrong. Typically, there is a forgotten PLC in a utility building, a cellular gateway an integrator installed, or a laptop that “only gets plugged in during shutdowns.” Lately, I also find printers from the R&D lab that were bought for prototyping and then moved into production 3D printing without anyone adding them to the list.

So build the inventory carefully. To begin with, use drawings, panel walkdowns, and conversations with the technicians who know the plant. After that, add passive network monitoring that listens to industrial protocols without sending traffic to fragile devices. Capture make, model, firmware, network address, what it controls, and who owns it. Admittedly, that last field sounds minor, but it matters more than people think. After all, if nobody owns an asset, nobody will patch it or notice when it changes.

2. Build a Defensible Architecture

Flat networks are the single biggest reason a simple IT intrusion becomes a plant shutdown. Therefore, the goal is to make it hard for an attacker to move from the business network to the control network, and equally hard to move between process areas once inside.

In practice, that means:

  • An industrial DMZ between IT and OT, so nothing talks directly across the boundary. That way, historian and MES data gets replicated out rather than letting business users reach in.
  • Firewalls with rules written by someone who understands the process, allowing only the specific hosts, ports, and protocols that the operation needs.
  • Separate zones for safety systems, each process area, and engineering workstations, following the zones and conduits concept from ISA/IEC 62443.
  • No shared Active Directory between IT and OT or, at minimum, a separate OT domain with no trust that lets corporate credentials work on the plant floor.

Likewise, where one way data flow is enough, such as sending production numbers to your manufacturing ERP, a unidirectional gateway is worth serious consideration. After all, it is one of the few controls that physically cannot be talked out of its job.

3. Lock Down Remote Access

Remote access is where convenience and risk collide hardest. On one hand, vendors need to support equipment, and engineers want to check a trend from home at 2 a.m. On the other hand, every one of those paths is also a path for an attacker.

With that in mind, here is my baseline for any site:

  • Every remote session goes through one controlled entry point, never a modem or vendor box directly on the control network.
  • Phishing resistant multifactor authentication applies to every user, including vendors.
  • Sessions are approved, time boxed, and recorded. Similarly, vendor access stays off by default, gets turned on for the job, and is then turned off again.
  • No shared accounts. Otherwise, if five integrator techs use one login, you have no idea who did what.

On top of that, I ask for a quarterly review of every remote path. Almost always, I find at least one that nobody remembered.

4. Watch the Network With OT Eyes

Traditional antivirus and IT intrusion detection do not understand a Modbus write or a PLC program download. By contrast, OT network monitoring tools decode those protocols. As a result, they can tell you when someone pushes new logic to a controller, changes a setpoint outside normal ranges, or when a new device suddenly appears.

Still, the tool alone is not the answer. Someone has to look at the alerts, and that someone needs enough process knowledge to tell a technician doing scheduled work from an intruder doing the same thing at 3 a.m. For this reason, tie alerts to your maintenance schedule and the work orders in your CMMS. In my experience, that one habit cuts false positives dramatically.

5. Patch by Risk, Not by Calendar

In OT, “patch everything” is not realistic, and I stopped pretending it was a long time ago. Instead, I sort vulnerabilities into three buckets: fix now, fix at the next outage, and mitigate because we will never patch it.

The questions I ask are simple. First, is this device reachable from anywhere an attacker could plausibly be? Second, is the flaw being exploited in the wild? Finally, what happens to the process if this asset is compromised? For example, a critical score on a controller buried three zones deep behind tight firewall rules may matter less than a medium score on an internet facing remote access gateway. Moreover, when patching is not possible, compensating controls such as tighter rules, application allowlisting, and disabling unused services do the heavy lifting.

6. Plan for the Bad Day, and Practice It

This is the control most sites skip, and yet it is the one that decides how long you stay down. An ICS incident response plan is not simply the corporate IT plan with a few words changed. Rather, it has to answer questions only operations can answer. Who has the authority to isolate the plant network? At what point do we move to manual operation? Which controllers do we trust, and how do we verify their logic is clean?

To prepare, keep offline, tested backups of PLC programs, HMI projects, historian configurations, and engineering workstation images. Also, store known good copies with hash values so you can prove they were not altered. Then run tabletop exercises with engineers, operators, IT, and leadership in the same room. Naturally, the first one is always uncomfortable. Indeed, that discomfort is the point.

Along the same lines, CISA’s guidance makes a related point I fully agree with: make sure the plant can run in manual mode. After all, if the only way to operate is through the screens, an attacker who takes the screens takes the plant.

7. Invest in People Across the IT and OT Divide

Even the best technical design falls apart if the control engineers and the security team do not trust each other. For instance, I have seen IT push a domain policy that rebooted every HMI on a line during production. Conversely, I have also seen engineers bypass a firewall with a spare switch because a rule slowed down their troubleshooting.

So fix the relationship before you buy more tools. Specifically, cross train your teams. Put an OT engineer on the security team and a security person on the plant’s management of change board. Above all, make it normal for both groups to review changes together.

The Standards Worth Knowing

Frameworks will not secure a plant on their own. Nonetheless, they give you a shared language with auditors, insurers, vendors, and leadership. In particular, three come up in almost every project I work on.

ISA/IEC 62443

This is the international family of standards built specifically for industrial automation and control systems. Broadly, it covers the asset owner’s security program, system level requirements, and requirements for the products vendors build. The idea I use most is zones and conduits. In short, you group assets by function and risk, define exactly how those groups are allowed to communicate, and then assign each zone a target security level based on what a compromise would actually cost. Additionally, IEC designated the series a horizontal standard, so it applies whether you run a refinery, a food plant, or a water utility.

NIST SP 800-82 Revision 3

Published in September 2023, the Guide to Operational Technology Security broadened its scope from ICS to OT as a whole, including building automation and physical access systems. Beyond that, it includes an OT overlay for the NIST SP 800-53 control catalog with tailored baselines for low, moderate, and high impact systems. So if your organization already lives in the NIST world, this is the bridge into the plant.

The SANS Five ICS Cybersecurity Critical Controls

Strictly speaking, this is not a standard. Even so, it is the most practical starting point I know: an ICS incident response plan, defensible architecture, ICS network visibility and monitoring, secure remote access, and risk based vulnerability management. Smaller organizations can use it as a roadmap. Meanwhile, larger ones can use it to measure whether their big framework investment is producing results.

Ultimately, my advice is to pick one framework as the backbone and map the others to it. That way, you avoid running three separate compliance programs that never talk to each other.

Where to Start on Monday Morning

If all of this feels like a lot, that is because it is. Realistically, nobody fixes OT cybersecurity in a quarter. Even so, you can make real progress in a month with a few focused moves:

  1. First, search for anything of yours exposed to the internet and get it off. Along the way, change every default password you find.
  2. Next, walk the plant and list every remote access path, including the ones vendors set up. Then shut down what you do not need.
  3. After that, confirm you have offline copies of your PLC programs and HMI projects, and that someone has actually restored one recently.
  4. Finally, sit your lead control engineer and your IT security lead down together and agree on who makes the call to isolate the plant during an incident.

What Resilient Plants Have in Common

Interestingly, the plants that recover fastest from an incident are rarely the ones with the most expensive tools. Instead, they are the ones where engineering and security already know each other, already practiced the bad day, and already know which systems they can trust. In the end, protecting industrial control systems is about keeping the process safe and running. Everything else is in service of that.

I have watched operators run a line by hand while the screens were dark. They could do it because someone, years earlier, insisted they keep that skill. That, more than anything, is what good OT security looks like: not perfection, but a plant that can take a hit and keep its people safe.

Frequently Asked Questions About OT Cybersecurity

What is OT cybersecurity?

OT cybersecurity is the practice of protecting the systems that monitor and control physical processes, such as PLCs, SCADA, DCS, safety systems, and HMIs, from cyber threats. Above all, its goals are keeping people safe and keeping the process available and accurate. For the federal scope, see NIST’s announcement of SP 800-82 Rev. 3.

How is OT cybersecurity different from IT cybersecurity?

IT security focuses first on protecting data, whereas OT security focuses first on safety and uptime. Moreover, OT assets run for decades, often cannot be patched or rebooted on demand, and use industrial protocols with little or no authentication. The Dragos guide to ISA/IEC 62443 explains how these differences shape OT specific architecture.

What is the biggest OT cybersecurity threat right now?

Currently, it is ransomware. Dragos tracked 119 ransomware groups affecting about 3,300 industrial organizations in 2025, and manufacturing was hit hardest. For the full details, read the Dragos 2026 OT Cybersecurity Year in Review.

What is ISA/IEC 62443?

It is the international series of standards for securing industrial automation and control systems. Specifically, it covers asset owner programs, system design using zones and conduits, and secure product development for vendors. In addition, ISA explains how it fits alongside ISO 27001 in Two Standards, One Integrated Industrial Cybersecurity Plan.

Where should a small plant begin with OT security?

To start, remove any OT devices from the public internet and change default passwords. Then secure remote access with multifactor authentication and segment IT from OT. These are the first steps in CISA’s Primary Mitigations to Reduce Cyber Threats to Operational Technology.

Can you use normal IT security tools in an OT network?

Some, but carefully. Active scanners and aggressive endpoint tools can disrupt fragile controllers. Therefore, passive, protocol aware monitoring built for industrial networks is the safer choice. The SANS Five ICS Cybersecurity Critical Controls explain how to build visibility without risking the process.

References

  1. Dragos. 2026 OT Cybersecurity Year in Review. https://www.dragos.com/ot-cybersecurity-year-in-review
  2. Dragos. Dragos 2026 OT Report Shows Surge in Threat Groups and Ransomware (press release, February 17, 2026). https://www.dragos.com/resources/press-release/dragos-2026-year-in-review-new-ot-threats-ransomware
  3. Cyber Magazine. Dragos: Operational Tech Under Increasing Risk of Attack. https://cybermagazine.com/news/dragos-ot-ics-cybersecurity-report
  4. Cyber Magazine. Dragos: Putting Operational Technology Risks in Perspective. https://cybermagazine.com/news/dragos-putting-operational-technology-risk-in-perspective
  5. Infosecurity Magazine. Significant Rise in Ransomware Attacks Targeting Industrial Operations. https://www.infosecurity-magazine.com/news/rise-in-ransomware-targeting/
  6. CISA, FBI, EPA, DOE. Primary Mitigations to Reduce Cyber Threats to Operational Technology. https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology
  7. CISA. Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure (AA25-343A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
  8. NIST. NIST Publishes Guide to Operational Technology (OT) Security, SP 800-82r3. https://www.nist.gov/news-events/news/2023/09/nist-publishes-guide-operational-technology-ot-security
  9. Dragos. Understanding ISA/IEC 62443: A Guide for OT Security Teams. https://www.dragos.com/blog/isa-iec-62443-concepts
  10. ISA InTech. Two Standards, One Integrated Industrial Cybersecurity Plan. https://www.isa.org/intech-home/2021/december-2021/departments/two-standards-one-integrated-industrial-cybersecur
  11. Dragos. SANS ICS Five Critical Controls. https://www.dragos.com/insights/five-critical-controls
  12. SANS Institute. ICS Assessments: The Good, the Bad, and the Ugly. https://www.sans.org/blog/ics-assessments-good-bad-ugly
  13. Claroty. The SANS Five ICS Cybersecurity Critical Controls: What They Are and How to Apply Them. https://claroty.com/blog/the-sans-five-ics-cybersecurity-critical-controls-what-they-are-how-to-apply-them