Cybersecurity has a tired old mantra: you cannot protect what you don't know.
Yet across critical infrastructure, Operational Technology (OT) networks remain riddled with ghost assets, undocumented connections, unmanaged remote access and decades of legacy blind spots. Adversaries know this, and they are banking on it.
For years, cybersecurity programmes have often been driven by compliance frameworks, audits and routine vulnerability scans. While these remain important foundations, they can distract from a more fundamental question.
This challenge was a central theme of our recent webinar, Why IT Security Tooling Fails in OT Environments.
If a threat actor were already moving quietly through your operational environment, would your team know?
We still see organisations taking the same security tools they use in IT and deploying them into OT, assuming they'll deliver the same results. In reality, OT environments are completely different. The wrong approach can impact performance, create downtime and, in some cases, introduce more risk than it removes. The first step is understanding the environment and adopting security controls designed specifically for OT.
Dave Burley, Senior OT Security Consultant, Nomios UK&I
From disruption to silent reconnaissance
Cyber threats have evolved considerably over the last decade.
The days of opportunistic malware randomly hitting industrial targets are over. Nation states, ransomware syndicates, and organised criminal groups are treating critical infrastructure like a strategic chessboard. The objective is rarely immediate sabotage. Instead, they seek to gain access, establish persistence and learn how industrial processes work before taking action.
This behaviour aligns closely with the tactics outlined within MITRE ATT&CK for ICS.
Common techniques include:
- Initial access through remote services by exploiting unmanaged third-party or vendor connections.
- Discovery and lateral movement between corporate IT systems and operational networks.
- Engineering workstation compromise subverting the very tools used to program PLCs and RTUs.
In modern OT security, the initial breach is not always the primary threat. The real threat is how long the adversary moves undetected as they begin to map out and understand your environment.
Why enterprise SOCs go blind in OT
One of the most common findings in an OT security assessment is not malware or evidence of compromise. It is uncertainty.
Many organisations struggle to answer some fundamental questions about their operational environment:
- What assets are actually on the plant floor right now?
- What remote access methods are available today?
- Which PLCs are critical to continuous production versus legacy systems?
- Who holds active remote access credentials right now?
- Which assets are communicating with external IPs?
- Are your security tools actually tuned to detect ICS-specific anomalies, or are they generic enterprise tooling?
As Dave highlights in the webinar, these visibility gaps are often the result of years of operational change, system upgrades and legacy infrastructure, rather than poor security practice.
This lack of visibility is not simply a technical challenge. As OT environments become increasingly connected and threat actors grow more sophisticated, the consequences of poor asset visibility extend beyond the plant floor and into the boardroom.
The Boardroom Reality
Cybersecurity is no longer just a concern for IT and security teams. Disruption to industrial systems can affect production, service delivery, supply chains and, in some environments, safety.
At the same time, regulatory expectations continue to evolve. Initiatives such as the UK's Cyber Security and Resilience Bill reflect a growing focus on protecting critical services and strengthening organisational resilience, reinforcing the link between cyber security and national security.
For organisations operating OT environments, securing these systems is no longer driven solely by compliance requirements. It is a fundamental part of managing operational risk, maintaining business continuity and protecting critical operations.
Five questions every OT operator should be able to answer
Organisations that have achieved a higher level of OT security maturity can typically answer a small number of critical questions with confidence. If any of the following are difficult to answer, there may be gaps in visibility, governance or operational resilience.
What frameworks are we aligned to, and when did we last conduct a dedicated OT assessment? What level of network visibility do we actually have, and is our asset list genuinely up to date? If an asset is not mapped, it cannot be defended. Passive asset discovery tools like Armis, Claroty, or Nozomi map industrial communications, protocols, and dependencies safely without risking production downtime. Asset discovery is not a regulatory checkbox. It is your operational baseline.
Third-party vendors, remote maintenance engineers, and system integrators are the weak link of OT security. If you cannot audit who has remote access, why they have it, and what they are touching, every unmanaged connection is an open invitation for lateral movement.
Traditional Enterprise SOCs are built for IT. They look for Windows logs, active directory anomalies, and HTTP traffic. Drop those same analysts into an OT environment, and they are staring at a foreign language. Detecting an attacker manipulating Modbus, BACnet, or DNP3 commands requires telemetry tailored specifically to industrial protocols. Visibility creates awareness. Monitoring creates alerts. Resilience requires both.
Visibility provides understanding. Monitoring provides detection. Resilience requires both.
A high vulnerability score means nothing if patching it means shutting down a critical assembly line. Mature organisations do not chase CVSS numbers. They map risk directly to physical safety, process continuity, and business impact.
Feeding OT telemetry into a SIEM achieves little if the SOC lacks the context to interpret it. In OT environments, attackers often blend into legitimate operations by abusing trusted tools and remote access methods.
Unless security teams understand normal operational behaviour, they will struggle to distinguish routine activity from malicious actions. You need to understand normal before you can detect abnormal.
From Discovery to Defence
Asset discovery is the starting line, not the finish.
Understanding what exists across your operational environment provides the foundation for every other security activity. From there, organisations can build OT-specific monitoring, strengthen remote access controls, improve incident response readiness and develop a more accurate understanding of risk.
Industrial environments are attracting increasing attention from threat actors because they support services that organisations and societies depend upon. Manufacturing, energy, transportation and logistics operators all face a similar challenge: protecting complex environments without disrupting operations.
An ISA/IEC 62443 risk assessment provides a structured way to understand security posture, identify gaps and build a pragmatic roadmap for improvement, often without requiring operational downtime.
Attackers are becoming increasingly patient. Many spend more time studying industrial environments than organisations spend documenting them.
Before investing in additional security tooling or pursuing the next compliance objective, organisations should ask a simpler question:
Do we truly understand what is operating across our OT environment today?
Without that foundation, every other security decision is made with incomplete information.
Learn more about securing OT environments
Watch Why IT Security Tooling Fails in OT Environments to learn why many security tools struggle in OT settings and discover practical ways to strengthen security without impacting operations.







