Operational technology, which runs the physical world most people never have to think of until it breaks down, is the systems that run our water treatment plants, manufacturing assembly lines, power grids, and innumerable other processes in which a cyberattack means not just lost data but stopped production, compromised safety, or even much worse. Seamlessly securing this sort of technology is a very different kind of challenge from what most organizations face when securing a typical office network, and to grasp why that is the case, we need to look beyond generic cybersecurity principles toward the specific realities in environments where uptime and physical safety routinely trump security fundamentals.
For decades, most of these systems operated in a bubble, physically isolated from the corporate network and the rest of the internet. This isolation was almost a sort of protection by accident. But as industrial environments added connectivity to corporate IT networks, in pursuit of both efficiency gains and remote monitoring capabilities, accidental protection has dwindled, exposing systems that were often never designed to face modern-day cybersecurity threats.
Defining the Practical Scope
Understanding what is OT security in practice begins with acknowledging that operational technology encompasses a far broader range of systems than the industrial control systems most people think of first. All building automation systems, transport infrastructure, physical access controls, and environmental monitoring equipment fall under the same umbrella because they directly monitor or control physical processes and/or equipment.
Why this breadth and the need (or obligation?) for OT security not to be a siloed practice with a single playbook? Both would be of the same type, but protecting a water treatment plant’s control systems is a different consideration than protecting a robotics assembly line for manufacturing plants. What binds them together is a tug-of-war between security practices and operational priorities that simply do not align in the same way on a typical enterprise IT network.
Traditional IT Security And Why It Doesn’t Transfer Generally
Generally, when sensitive data is involved, corporate IT security prioritizes confidentiality. It is that priority structure that OT environments turn on its head. Availability and security are usually priorities because an unplanned shutdown of a manufacturing line or a power distribution system has repercussions far beyond those of a typical data breach. A security control that is utterly understandable on a corporate network, such as automatically rebooting a system to apply a patch, can in fact pose a real nightmare in the OT context if it interrupts an ongoing process that must remain operational.
This is compounded considerably by issues of legacy equipment as well. Because many OT environments run hardware and software that has not changed in over a decade, they are often running an operating system that cannot be patched or updated, as doing so could create incompatibility with the actual equipment being controlled. Because systems most desperate for security updates tend to be the least prepared to accept them safely, this creates a perennial tension.
Federal recommendations regarding this very challenge have changed significantly over the past two years as OT environments have become increasingly connected. Even comprehensive recommendations, such as the recently revised recommendation on operational technology security from a national standards body, are not specific regarding how security controls must be implemented differently for OT systems in consideration of critical aspects of performance, reliability, and safety unique to OT environments versus more traditional IT systems.
Core Implementation Strategies
For realistic OT security, network segmentation is often the first step. Instead of treating OT and IT networks as a single interconnected environment, organizations create defined fences around each network so that traffic crossing those boundaries is controlled and monitored, rather than allowing unrestricted flow between the corporate and operational networks. That segmentation restricts an attacker who gains control of one environment from moving into the other.
The first practical step after segmentation is ensuring your assets are visible. Another common realization during a security assessment is that organizations don’t have an inventory of every device on their OT network, including legacy systems put in place long before cybersecurity was top of mind. Having this visibility is a prerequisite for nearly every other security control to be effective, as it is hard to protect systems that an organization does not know exist.
The core implementation method also includes continuous monitoring for anomalous behavior. Because a large percentage of OT environments operate in highly predictable, repetitive activity patterns, it is possible to extract a baseline and deviations from that baseline can be an early indicator of compromise, increasingly being able to catch intrusion well before operational disruption manifests visibly.
Working With Existing Constraints
In almost every OT environment, implementation compromises on best secure practices for the sake of operational reality. Patching schedules generally have to fit within scheduled maintenance windows, not the more aggressive patching cadence very often seen in IT. Pick security tools carefully, in environments where continuous uptime is critical as anything that adds latency or stops the system for restarts introduces real operational risk.
With the convergence of these environments, there is a need for coordination between IT security teams and OT operations staff. Traditionally, these two groups have followed distinct but very limited paths with different priorities and in some cases reference points/words for describing the same constructs. This need for closer collaboration, illustrated by efforts such as those established through the advances of the federal industrial control systems program to protect critical infrastructure, is reflected in some sector-specific guidance and resources from relevant agencies that offer frameworks, advisories and training intended to help bridge that historical divide between IT teams and OT (operational technology) teams.
The Path Forward
Implementing OT security is not a project you complete and cross off your to-do list in October 2022. The breaking point Industrial environments are in a recruitment phase; with more and more connected devices and remote monitoring capabilities being integrated into these spaces, each addition increases the attack surface, along with the operational benefits that connectivity provides. Those organizations that view OT security as an ongoing program built around segmentation, visibility, monitoring and tight coordination between security and operations teams are much better equipped to handle the growing risk than those that treat it like a checklist item to check off once and forget.
Frequently Asked Questions
Notice the distinction of OT security from regular IT cybersecurity.
Given the focus is on availability and even physical safety rather than confidentiality, OT security needs to accommodate elements like legacy equipment and operational constraints such as maintenance windows and mandatory uptime requirements, which are not issues that affect typical IT environments.
Network segmentation is one of the core OT security best practices for a good reason.
Segmentation enforces boundaries on how attackers can traverse between corporate IT networks and operational technology systems, restricting the chance that a given compromise in one environment propagates into the other.
How Legacy Equipment Adds Complexity to OT Security
Compensating Controls Instead of Remediation — Legacy systems often cannot be patched or updated without risking compatibility with the physical equipment they control, which means organizations are left to rely on compensating controls like segmentation and monitoring instead.