Operational technology security, usually called OT security, is the practice of protecting the hardware and software that monitor and control physical processes. That includes industrial control systems on a factory floor, building management systems for heating, cooling and lighting, and production, packaging and utility equipment. Where traditional IT security focuses on protecting data, OT security puts safety and continuous operation first, because an outage or a tampered setting can stop production, damage equipment or put people at risk.
At a glance
- OT covers systems that control physical processes; IT covers systems that handle data.
- OT equipment often runs for decades, on older operating systems that can’t easily be patched or run security agents.
- Safety and uptime usually come first, so security changes are planned around production schedules.
- Core measures include asset inventory, separating OT from IT networks, controlled remote access and passive monitoring.
- Attacks on office IT systems can stop OT operations even without reaching the controllers themselves.
What problem it solves
For years, many control systems were isolated, or assumed to be. Today most plants and buildings connect OT to the business network for reporting, remote vendor support, inventory systems and cloud dashboards. That connection brings efficiency, and it also brings risk. Equipment designed decades ago often lacks basic protections such as authentication, encrypted communication or the ability to run modern security software, and patching may require a production shutdown or the manufacturer’s approval.
The result is a set of exposures that IT tools and processes don’t cover well: flat networks where an infected office laptop can reach a controller, shared passwords on engineering workstations, vendor remote access tools left permanently open, and no reliable list of what is actually connected. Ransomware incidents at manufacturers often stop production because the business systems production depends on are encrypted, or because the company shuts OT down as a precaution. OT security gives these environments their own plan.
How it works
Asset inventory. The first step is knowing what is on the OT network: controllers, human-machine interfaces, engineering workstations, sensors and the network equipment connecting them. Specialized tools often build this list by passively listening to network traffic rather than actively probing devices.
Segmentation. OT networks are separated from the business network, and often into zones within OT, using network segmentation and network firewalls at the boundaries. A common pattern is a buffer zone between IT and OT through which approved data and connections pass.
Controlled remote access. Vendors and engineers often need remote access. Routing it through a single managed gateway with multi-factor authentication, approval steps and session recording replaces ad hoc tools left running on plant machines.
Monitoring. Passive monitoring tools, similar in principle to an intrusion detection system (IDS) but built to understand industrial protocols, watch for unusual commands, new devices or unexpected connections.
Vulnerability and change management. Patches are applied where the manufacturer supports them and production allows. Where they can’t be, compensating controls such as isolation and monitoring fill the gap. Changes to controller logic or settings are tracked.
Recovery planning. Backups of controller configurations and engineering files, plus tested procedures for running or restarting operations, limit downtime after an incident.
When it matters for buyers
- When connecting plants or buildings to the cloud. New monitoring, analytics and IoT projects often create new paths into OT.
- When a customer or insurer asks. Larger customers, especially in regulated or critical industries, increasingly include OT security in supplier reviews.
- After a ransomware incident at your company or a peer. Production stoppages tend to push OT security up the agenda.
- When renewing remote access arrangements with equipment vendors. This is a natural moment to consolidate and control them.
- When refreshing network equipment at a site. It’s the easiest time to separate OT from IT properly.
Our network firewalls overview covers the equipment that usually enforces the boundary between OT and IT networks.
Questions to ask vendors
- Do your tools discover OT assets passively, and which industrial protocols do they understand?
- Have your tools and methods been tested with our equipment manufacturers, and do they support our controllers?
- How do you propose separating our OT and IT networks without disrupting production?
- How will vendor and engineer remote access be controlled, approved and recorded?
- What changes require a maintenance window, and how do you coordinate with our operations team?
- Who responds if monitoring detects something unusual on the plant floor, and how fast?
How it differs from IoT security
IoT security covers connected devices in general, such as cameras, sensors, smart building gear and consumer-style devices, many of which are relatively new, cloud-connected and replaced every few years. OT security focuses on systems that control physical operations, where availability and safety come first and equipment often runs for decades on industrial protocols. The two overlap, since industrial sensors are sometimes called industrial IoT, and similar controls such as inventory and segmentation apply to both. The difference is mainly in consequences and constraints: in OT, a security tool that disrupts a controller can stop a production line.
