If you manage or operate industrial control systems, you’re likely already familiar with a growing tension within the industry. Regulations are written to steer the industry toward using better cyber practices, but companies tend to read those regulations and focus primarily on IT solutions. When those decisions make their way to the operational technology (OT) network, the result can be a set of IT rules that could introduce risk and disruption to the OT system for little to no gain.

This clash is driving owners and operators to re-evaluate how they approach cybersecurity. Instead of simply extending IT policies into the OT domain, they are discovering that a more nuanced strategy is needed — one that respects the unique nature of industrial controls, conforms to regulations, and is built securely from the inside out.

Why OT Security Is Different

When people hear cybersecurity, they tend to think first about protecting data, emails and servers. Securing an OT environment is a different challenge altogether.

These are not typical office networks. OT systems are composed of specialized hardware and software, including programmable logic controllers (PLCs) and human-machine interfaces (HMIs) that directly control the physical processes. An interruption to an OT system is not merely an inconvenience; it can halt production, damage expensive equipment or even create safety hazards.

Unlike IT systems that are frequently updated, OT components can have life cycles measured in decades. The software is often proprietary and tied to specific hardware, making seemingly simple actions, like applying a software patch, more complex and risky. In the OT world, the thinking usually is: if it isn’t broken, don’t fix it.

Common IT Misfires in the OT World

When standard IT security playbooks are applied to the OT environment, the disconnect becomes clear. Several common IT practices can cause significant problems:

  • Aggressive software patching. A routine IT policy of automatically updating operating systems can easily break the delicate software dependencies of HMI or PLC programs. This critical question often goes unasked and can be difficult to answer: Is the patch addressing a vulnerability that is exploitable in the OT application? If not, it may only be adding risk.
  • Restrictive firewalls and port blocking. Corporate and top-down firewalls are often configured to block the specific, nonstandard ports required by industrial protocols like Modbus or proprietary HMI and PLC communications. An update to that firewall can sever communications among control system components.
  • Impractical architecture. IT-focused white papers often describe solutions in a nebulous, abstract manner and offer little or no guidance on how to implement those solutions. Attempting to do so can result in more downtime and create more headaches than peace of mind.

A more constructive approach to the OT network is to bring a Consequence-Driven Cyber-Informed Engineering (CCE) mindset. A CCE review can identify critical consequences and evaluate pathways and mitigation options, helping determine if the consequences are too great to connect an important piece of equipment to the OT network. That helps determine if the equipment is important enough to connect to the network or whether performing a software patch is too risky.

Without that mindset, the core issue is typically a failure to translate IT principles into the OT context. Deciding what applies requires a deep understanding of the industrial process itself, not just networking best practices.

A Different Approach to Protection

A robust OT security posture does not have to be an either/or choice between IT and OT methodologies. Building security directly into the control logic can provide a layer of protection against external and internal threats.

These are some ways to strengthen an OT posture by implementing PLC and HMI programming techniques:

  • Employing setpoint entry validation logic for starting and stopping equipment.
  • Using a hardwired interface to VFDs instead of a communication link.
  • Having an isolated OT sandbox for testing logic changes, firmware updates and software patches prior to working on the live equipment.
  • Leaving programs in “Run” mode.
  • Limiting remote access to one network switch or rack.

Moving Forward

None of this is merely theoretical. These challenges occur in real-world operations every day. As industrial systems become more connected, the need for a thoughtful, OT-centric security strategy becomes increasingly urgent. Simply handing the keys to the IT department without giving consideration to the OT environment is not a viable path forward. The most secure and resilient operations will be those that bridge the gap between IT and OT, leveraging the strengths of both disciplines to build a layered defense that protects the process from the inside out.

By focusing on practical, achievable steps and recognizing the fundamental differences between the plant floor and the office, organizations can build a security posture that enables connectivity without sacrificing the safety and reliability that are the bedrock of all industrial operations. 


by
Derek Fike, PE, works in telecommunications at Burns & McDonnell. He has seven years of PLC and remote terminal unit (RTU) programming experience in the oil and gas industry and an additional six years of programming experience in the aviation industry. He specializes in controls upgrades, new system integration, standards implementation, creation of PLC and HMI standards, and PLC panel design.