Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryOTStandards

OT Security

OT security protects the operational technology that controls physical processes: PLCs, SCADA, HMIs, drives. How it differs from IT security and what typically fails.

Updated This page as Markdown

In short

OT security (operational technology security) protects the systems that monitor and control physical processes: PLCs, SCADA and DCS systems, HMIs, safety systems, drives and the networks between them. It differs from IT security in its priorities (availability and safety first), its lifecycles (15 to 30 years), its protocols (mostly without authentication) and its constraints (no reboots, no agents, patches only with vendor approval). The reference framework is the IEC 62443 series.

What is OT security?

Operational technology (OT) is the hardware and software that monitors and controls physical processes: programmable logic controllers, distributed control systems, SCADA, HMIs, safety instrumented systems, drives, sensors, robots, building automation and the networks that connect them. OT security protects these systems against unauthorised access and manipulation while keeping the process running. NIST SP 800-82 describes OT as programmable systems or devices that interact with the physical environment; IEC 62443 uses the term industrial automation and control systems (IACS).

The priority order is the difference to IT. In OT it is availability and safety first, integrity second, confidentiality last. Devices run 15 to 30 years, patches need vendor approval, reboots need a maintenance window, and protocols were designed for a trusted network that no longer exists.

Where is it defined?

There is no single OT security law. The reference standard is the IEC 62443 series: 1-1 for terminology and concepts, 2-1 for the asset owner’s security programme, 3-2 for risk assessment with zones and conduits, 3-3 for system requirements and security levels, 4-1 for the component vendor’s secure development lifecycle and 4-2 for component requirements. NIST SP 800-82 Rev. 3 is the most complete free guide. In Germany, the IND layer of the BSI IT-Grundschutz Compendium covers control technology.

Regulation reaches OT from two sides. Operators in the sectors of NIS2 Annex I and II must implement the measures of Article 21; German KRITIS operators additionally need attack detection and periodic proof. Manufacturers of controllers, HMIs and industrial network components fall under the Cyber Resilience Act, and machine builders under the Machinery Regulation (EU) 2023/1230, whose Annex III requires protection against corruption of safety-related control systems.

What it means in practice

The findings repeat across industries, from automotive plants to waterworks:

  • Flat networks. Office IT and control network are “separated” by a firewall with any-to-any rules, or connected through a historian, a jump host or an engineering laptop with two network cards.
  • Unauthenticated protocols. Modbus TCP, PROFINET, S7comm and EtherNet/IP accept commands from anyone who can reach the port. A write to a holding register needs no password.
  • Controllers without protection. PLCs with access protection off, program download allowed from any host, web servers with firmware from years ago, default SNMP communities.
  • Remote maintenance. Vendor access through standing VPN tunnels, TeamViewer on HMIs, cellular routers with default credentials reachable from the internet.
  • Legacy hosts. Windows 7 or XP HMIs and engineering stations that cannot be patched because the vendor software is not released for anything newer.
  • No inventory, no monitoring. Nobody can list the controllers in the plant, and nobody sees a write command from an unexpected source.

Testing therefore follows a different method: asset discovery from passive captures, configuration and firmware analysis, active tests only in test cells or maintenance windows, no fuzzing against production. Fixes are mostly architectural: zones and conduits, protocol-aware firewalls, jump hosts with recording, hardened engineering workstations, and monitoring on the control network. Zyberum tests OT environments, runs IEC 62443 gap analyses for operators and component manufacturers, and monitors OT networks with the Zyberdome managed SOC.

Common misunderstandings

The air gap is almost always a myth; the maintenance laptop and the cellular router are the gap. IT tools do not transfer: a standard port scan can stop a controller. Functional safety is not security: a safety PLC protects against random failures, not against an attacker who changes its logic. And OT security is not a firewall purchase; it is an architecture plus monitoring plus a process for the day something is found.

FAQ

Frequently asked questions

What is the difference between OT security and IT security?

The goal. IT security protects data, so confidentiality comes first. OT security protects a physical process, so availability and safety come first: a controller that stops because of a security scan is a worse outcome than a leaked configuration file. That changes everything downstream: no agents on controllers, patching only in maintenance windows, passive monitoring instead of active scanning, and compensating controls such as segmentation where a fix is impossible.

Can you run a penetration test in a running plant?

Only with care and a plan. We start passively: traffic captures, configuration reviews, firmware analysis of spare devices. Active tests run against test cells, spare controllers or during planned downtime, with the operator present. Fuzzing and exploitation never happen against live production. Written authorisation and a defined abort procedure are part of every OT engagement.

Which regulations require OT security?

For operators: NIS2 (Article 21 measures) and in Germany the BSIG with its KRITIS rules. For manufacturers of industrial components: the Cyber Resilience Act and, for machinery, the Machinery Regulation (EU) 2023/1230 with its protection-against-corruption requirements that apply from 20 January 2027. IEC 62443 is the standard everyone uses to show compliance with all of them.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab