Industrial systems were designed to be safe and to keep running, not to be attacked. What is actually there is mapped, along with where the exposure lies and which measures are feasible without affecting production or safety.
Operational technology drives physical processes: valves, pumps, motors, boilers, conveyors. Where an IT outage means people cannot work, an OT outage means nothing is produced, distributed or treated, and sometimes that an unsafe situation arises. That different consequence leads to different design choices, and therefore to a security practice that runs counter to IT conventions on several important points.
The result: an IT security policy laid over the OT environment is in practice ignored or quietly circumvented. Not out of reluctance, but because it cannot be carried out without affecting production.
Almost every OT environment we encounter turns out to contain more connected equipment than the drawings show. Maintenance laptops, temporary connections that became permanent, vendor modems for remote support, a legacy link to the office network laid years ago for reporting. None of it was deliberately concealed. It exists because somebody had a problem to solve.
An asset inventory is therefore not an administrative exercise but the first real security measure. You cannot protect what you do not know exists, and you cannot report what you cannot see. This is mapped passively: without active scanning, because active scanning in an OT network is itself a risk.
If there is one technical measure that genuinely limits the impact of an incident, it is network segmentation. Separating the office environment from the process environment, and subdividing the process environment into zones with controlled interfaces, ensures that a compromise in one place does not take the entire installation with it.
The Purdue model and the zone-and-conduit approach from IEC 62443 provide the framework. The skill lies not in drawing the model but in determining which connections are genuinely required, which grew historically, and which can be removed without halting a process. That takes in-depth conversations with the people who operate the installation.
IEC 62443 is the international standards series for the security of industrial automation and control systems. Its value lies in its structured concepts: security levels, zones and conduits, and a clear division of responsibility between asset owner, system integrator and product supplier.
That division is the most usable part in practice. It makes it possible to discuss what you may expect from your supplier and what you must arrange yourself: a conversation that has to happen under the Cyber Security Act's duty of care in any case, because that duty extends to the supply chain.
The standard is applied in a risk-driven way. Not every zone needs to reach the highest security level 3; the aim is a justified choice per zone, not a maximum score on paper.
Most organisations we speak to face not a technical challenge but an organisational one. IT holds the mandate and the budget for security; OT holds the process knowledge and the responsibility for continuity. As long as those two alternately ignore and overrule each other, little changes.
What works is a shared risk picture and an explicit allocation of decision rights: who decides on a change in the process environment, who assesses the security risk, and who breaks the tie when availability and safety pull against each other. Documenting that is less exciting than a technical project, but it determines whether that technical project holds up.
This is the work Blom Risk Advisory is experienced in. At several large operators, international OT security teams were built and led, carrying significant budget responsibility and contributing to the then-new IEC 62443 standard. More about Casper Blom's background.
An OT assessment starts with visibility: which assets exist, how they are connected and where the real exposure lies. Schedule an introductory call.
Schedule an introductory call