OT/ICS security: when IT gets breached you lose data. When OT gets breached you lose production.
Every hour of unplanned downtime is measured in six figures — and attackers know the plant floor is the soft target. Here is how OT security actually works, which framework applies to you, and how to get one report the plant manager and the CISO can both read.
Why OT security is not IT security
IT security optimises for confidentiality; OT security optimises for one thing: the process keeps running, safely. That single difference breaks most IT instincts. You cannot “just patch” a controller that only stops twice a year. You cannot scan a fragile PLC the way you scan a web server — aggressive scanning has halted production lines by itself. And you cannot bolt an agent onto a 15-year-old device that predates the idea of one.
Meanwhile the two worlds have converged. Remote access reaches the plant floor, historians feed cloud analytics, and AI systems are starting to make operational decisions. The air gap most plants believe they have is usually a diagram, not a fact — and attackers have noticed: manufacturing has ranked among the most-attacked industries for years, precisely because downtime forces fast ransom decisions.
Downtime economics
Ransomware against OT does not need to touch a controller — encrypting the Windows machines around it is enough to stop a line. The ransom is priced against your hourly cost of standing still.
Remote access sprawl
Vendors, integrators and engineers each with their own path into the plant — VPNs, jump boxes, cellular modems nobody documented. The perimeter is a memory.
Legacy protocols
Modbus, DNP3 and friends were designed for isolated networks — no authentication, no encryption. On a converged network, anyone who can speak the protocol can command the device.
Which framework applies to you
| Framework | Who it is for | What it gives you |
|---|---|---|
| IEC 62443 | Industrial operators and equipment builders worldwide — the de facto global OT standard | Zones and conduits segmentation, security levels (SL1–4), and role-based requirements for owners, integrators and vendors |
| NERC CIP | North American bulk electric system — mandatory, with fines for violations | Enforceable controls for critical cyber assets: access, change management, incident response, recovery |
| NIST SP 800-82 | Any organisation running ICS/SCADA — especially public sector and critical infrastructure | A practical guide for adapting IT-grade controls to OT constraints without breaking operations |
Most industrial organisations need a working blend of all three: 62443 as the architecture, 800-82 as the playbook, CIP where regulation demands it. The practical questions are always the same — where are your zones, who can cross your conduits, what watches the traffic, and what happens in the first hour of an incident.
0–5
Everything above maps to the Purdue model — from field devices (Level 0) to enterprise IT (Levels 4–5). A useful OT assessment scores each level separately, because your enterprise firewall says nothing about what can reach a controller. That is exactly how our free OT assessment reports.
How AI changes the plant-floor risk
Two directions at once. Attackers now use AI to find exposed industrial systems and craft convincing lures against engineers — reconnaissance that used to take weeks now takes an afternoon. And defenders are deploying AI into operations — predictive maintenance, quality inspection, copilots for engineers — which creates precisely the agentic risks covered in our agentic AI security guide: systems with credentials and autonomy inside networks that were never designed for either.
If AI is anywhere near your operations, your OT programme and your AI security programme are no longer separate conversations — and regulators (from the EU AI Act to sector rules) increasingly expect evidence covering both.
The IT/OT divide is the real vulnerability
The plant manager answers for uptime; the CISO answers for risk. When their reports do not reconcile, security spend stalls — and gaps persist not for technical reasons but political ones. Our approach is deliberately bilingual: OT maturity scored against IEC 62443, NERC CIP and NIST 800-82, mapped to your Purdue levels, with estimated annual risk exposure in dollars. Downtime economics is the one language both sides of the plant read fluently — the same logic as the Dual Squeeze Diagnostic your CFO will appreciate.
Frequently asked questions
What is OT/ICS security?
How is OT security different from IT security?
Which OT security framework should we use?
How does AI change OT security?
Where do we start with OT security?
One report both sides of the plant can read.
Your OT maturity against three frameworks, mapped to your Purdue levels, with risk exposure in dollars. Free.
