When a manufacturer gets hit by ransomware, the first call usually goes to IT. That makes sense — IT manages the business network, the email systems, the file servers. But in a manufacturing environment, the most damaging target isn't on the IT network. It's on the plant floor.
PLCs, SCADA systems, HMIs, and the industrial networks that connect them are collectively called Operational Technology — OT. And OT has fundamentally different security requirements than the IT infrastructure your security team knows how to protect.
Understanding that difference is the first step to actually protecting your operation.
What IT Security Is Designed to Do
IT security — the kind your IT team manages — is built around three core principles, often called the CIA triad:
- Confidentiality: Keeping data private and accessible only to authorized users
- Integrity: Ensuring data hasn't been tampered with or corrupted
- Availability: Making sure systems and data are accessible when needed
IT security tools — firewalls, endpoint protection, SIEM platforms, patch management — are designed for environments where systems can be rebooted, patched, and temporarily taken offline for maintenance. The assets being protected are primarily data: files, emails, databases, intellectual property.
When an IT system is compromised, the immediate impact is typically operational disruption: lost access to files, encrypted data, business systems going down. Serious — but recoverable.
Why OT Is Fundamentally Different
OT security has a different priority order. In industrial environments, the triad looks more like this:
- Availability first: Production cannot stop. A PLC that goes offline doesn't just disrupt data — it stops a physical process. That can mean product loss, equipment damage, safety incidents, and significant financial impact.
- Integrity second: The right commands must reach the right equipment. A compromised PLC that receives false inputs — or sends false outputs — can cause equipment to operate outside safe parameters.
- Confidentiality last: While data security matters, it's rarely the primary concern on the plant floor. The bigger risk is system manipulation, not data theft.
This priority reversal matters enormously for how you approach security. An IT security posture that prioritizes confidentiality and assumes systems can be patched or rebooted is genuinely dangerous applied to OT environments.
A critical distinction:
In IT, when you detect a compromise, you isolate the system and remediate. In OT, isolating a PLC mid-process can cause more damage than the attack itself. OT security must account for the physical consequences of security actions — not just the digital ones.
The Unique Challenges of OT Environments
Legacy systems that can't be patched
A Windows 10 workstation can be patched monthly. A 15-year-old HMI running Windows XP, embedded in a production process, often cannot — not without extensive testing to ensure the patch doesn't break the control application. Many OT environments have devices running operating systems and firmware versions that haven't received security updates in years.
IT security's standard response to vulnerabilities — patch it — simply isn't always available in OT.
Protocols designed for reliability, not security
Industrial communication protocols like Modbus, DNP3, EtherNet/IP, and Profinet were designed decades ago for reliability and determinism — not security. Many have no built-in authentication or encryption. A device on the same network segment can often send commands to a PLC without any credential challenge.
IT protocols have evolved to include robust authentication and encryption as standard features. OT protocols largely haven't — and can't be changed without replacing the equipment that uses them.
Operational constraints on security actions
In IT, if a device behaves suspiciously, you quarantine it. In OT, quarantining the wrong device might stop a production line, trip a safety system, or create a hazardous condition. Security teams unfamiliar with OT can cause more damage than an attacker by applying IT security playbooks to industrial environments.
Converged networks creating unexpected exposure
As manufacturers have connected OT systems to business networks for data visibility and remote access, they've inadvertently created pathways from the internet to the plant floor. A flat network — one where IT and OT share the same network segment — means that a compromised laptop on the business network can communicate directly with a PLC.
Most manufacturers have more of this exposure than they realize.
The Most Common OT Security Gaps
In our experience assessing OT environments across multiple industries, the same gaps appear repeatedly:
- Flat IT/OT networks with no segmentation — the single most common and dangerous configuration
- Insecure remote access — VPN connections to OT systems without MFA, session logging, or access controls
- Unmonitored OT networks — no visibility into what devices are communicating with what
- Default credentials on PLCs, HMIs, and network devices — manufacturer default usernames and passwords never changed
- USB and removable media with no controls — a common vector for introducing malware into air-gapped or semi-isolated OT networks
- No incident response plan for OT — IT has a plan; OT doesn't
What Proper OT Security Looks Like
OT security isn't about applying IT security tools to industrial environments. It's about a layered defense strategy that accounts for OT's unique requirements.
Network segmentation and the Purdue model
The foundation of OT security is proper network segmentation — separating IT and OT networks with industrial firewalls and a DMZ (demilitarized zone) that controls what data can pass between them. The Purdue Enterprise Reference Architecture provides a framework for organizing OT network layers, from field devices at Level 0 through enterprise systems at Level 4/5.
Segmentation doesn't mean IT and OT can't communicate — it means that communication is controlled, logged, and restricted to what's necessary.
OT-aware monitoring
OT network monitoring requires tools that understand industrial protocols. A general-purpose network monitoring tool that sees EtherNet/IP traffic as “unknown protocol” isn't useful. OT-specific monitoring solutions can passively observe industrial traffic, build device inventories, detect anomalies, and alert on unauthorized communications — without actively probing devices in ways that could disrupt operations.
Secure remote access
Remote access to OT systems should use dedicated secure access solutions — not the same VPN your employees use to access email. OT remote access should include multi-factor authentication, session recording, role-based access controls (so a vendor can only access their specific equipment), and automatic session timeouts.
Industrial-grade hardware
The equipment protecting OT networks needs to be designed for industrial environments — temperature ranges, vibration tolerance, DIN-rail mounting, and support for industrial protocols. Consumer or data-center-grade hardware often isn't appropriate for plant floor installations.
This is exactly the work our OT cybersecurity engagements focus on — segmentation, monitoring, and secure remote access built around your specific plant floor, not a generic template.
Starting the Conversation in Your Organization
One of the most common barriers to OT security progress is organizational: IT and OT teams often don't communicate well, have different priorities, and sometimes actively distrust each other's motives. IT sees OT as a security liability. OT sees IT as a threat to operational stability.
Getting OT security right requires both teams at the table, with leadership alignment on the priority: protecting the operation, not winning a turf battle.
A practical starting point is an OT security assessment — a structured review of your current OT network topology, device inventory, remote access configurations, and segmentation. A good assessment gives you a clear picture of your actual risk, prioritized by what matters most to your operation. That picture is usually more useful than a generic framework or compliance checklist.
The Bottom Line
OT cybersecurity isn't an IT problem with an industrial flavor. It's a distinct discipline that requires deep understanding of industrial control systems, operational constraints, and the physical consequences of security failures.
The manufacturers who are getting this right aren't waiting for a regulatory requirement or an incident to force their hand. They're taking a proactive, OT-specific approach — segmenting networks, monitoring OT traffic, securing remote access, and building the organizational alignment to sustain it.
The ones who are waiting are, statistically, going to find out why that was a mistake.
Logic Control Systems is a Fortinet OT security partner with 25+ years of industrial automation experience. We offer free OT security assessments for manufacturers — identifying your biggest risks and providing a prioritized remediation roadmap. Call 817-757-9507 or visit logiconsys.com/contact.
