Home/Insights/Security
Security · 11 Mar 2025

Operational technology security in energy and utilities

IT security practice applied unmodified to operational technology causes outages. The constraints are genuinely different.

Operational technology environments — control systems, industrial networks, plant instrumentation — are increasingly connected and increasingly targeted. They are also poorly served by security practice developed for corporate IT, and applying that practice unmodified is a reliable way to cause the outage you were trying to prevent.

Why the standard playbook does not transfer

Availability outranks confidentiality. In corporate IT a compromised system can often be isolated immediately. In a process environment, stopping a controller can stop production or create a safety condition. The response calculus is different and the safety case governs.

Patching windows are rare and expensive. Systems may have scheduled outages once a year or less. The assumption of a monthly patch cycle does not apply.

Equipment lifetimes are measured in decades. Controllers running unsupported software are not negligence, they are the normal condition, and replacement is a capital project rather than a maintenance task.

Active scanning can cause failures. Network discovery tools that are routine in IT can crash industrial controllers that were never designed to tolerate unexpected traffic. Passive monitoring is the default in OT for good reason.

What works instead

Segmentation as the primary control. A defined boundary between corporate and operational networks, with a small number of documented, monitored crossing points. This is the highest-value intervention and it is architectural rather than product-led.

Passive asset discovery. Establish what is actually on the network by observing traffic rather than probing it. Most organizations find devices nobody knew were connected.

Compensating controls where patching is not possible. If a controller cannot be updated, restrict what can reach it. Network-level protection substitutes for host-level protection.

Remote access discipline. Vendor and contractor access is the most common route in. Time-limited, individually attributed, monitored, and closed when the work finishes.

Joint governance. Incidents in these environments require both IT and operations judgement simultaneously. Agreeing the escalation path and decision authority in advance is the difference between a coordinated response and an argument during one.

Is this a live question for you?

We are happy to talk it through — no proposal attached.