The fastest way to cause an outage in a plant is to apply an IT security playbook to it. Operational technology has different priorities, different lifespans, and different failure modes - and treating it like a data centre is how well-meaning security teams take production offline.
In IT, the priority order is confidentiality, integrity, availability. In OT - the systems that run pumps, turbines, production lines and building controls - it's essentially reversed. Availability and safety come first. A patch that reboots a server is a Tuesday in IT; the same reboot on a controller mid-process can halt production or create a safety event. That single difference explains why so much standard security advice backfires on the plant floor.
Why IT playbooks fail in OT
- You can't just patch. OT devices often run for a decade or more, on software the vendor no longer updates, validated for a specific configuration. “Patch everything now” isn't an option - and forcing it can void warranties or safety certifications.
- You can't just scan. An aggressive vulnerability scan that a modern server shrugs off can knock a fragile PLC offline. Active scanning in OT is a genuine operational risk.
- You can't just reboot to remediate. The IT reflex - reimage, restart, move on - can interrupt a physical process with real-world consequences.
What IEC 62443 changes
IEC 62443 is the international standard for industrial automation and control system security, and its core idea is what makes OT security tractable: zones and conduits. Instead of trying to harden every fragile device individually, you group assets into security zones by function and risk, and tightly control the conduits - the communication paths - between them.
You may not be able to patch the 12-year-old controller. But you can put it in a zone where nothing untrusted can reach it - and that buys you most of the risk reduction, safely.
This flips the strategy from “fix every endpoint” (often impossible in OT) to “control what can talk to what” (achievable without touching the sensitive devices). It's compensating control done properly.
A safe sequence for hardening OT
- See it first. You cannot protect what you can't see, and most sites don't have an accurate OT asset inventory. Build one using passive monitoring - listening to network traffic, not probing devices - so discovery itself doesn't cause an outage.
- Segment IT from OT. The most valuable single step: a real boundary between the corporate network and the plant, so an email compromise can't wander onto the factory floor. Most damaging OT incidents start as ordinary IT intrusions that crossed a flat network.
- Zone and conduit inside OT. Apply IEC 62443 zones so a compromise in one cell can't spread across the site.
- Control remote access. Vendor and maintenance remote access is a top OT attack path. Broker it, log it, and make it time-bound - never a standing VPN into the control network.
- Monitor passively, respond with OT context. Detection in OT has to understand industrial protocols and, crucially, has to respond in a way that never trips the process. Containment that's safe in IT can be dangerous in OT.
The mindset shift
Securing OT isn't about bringing IT rigour to the plant - it's about protecting the process while respecting that it can't stop. The teams that succeed pair security expertise with operational reality, and they measure success partly by a number IT rarely thinks about: zero unplanned downtime caused by the security program itself.
If you're bringing an industrial or critical-infrastructure environment under a security program without risking production, that intersection of safety and security is exactly where our OT/ICS work sits. A scoping call can map a safe first step.
← Back to Insights