Operational technology has a different value system to IT. A control system is judged on availability and determinism; an unplanned reboot is a production loss, and a patch window may be measured in years. Those priorities were formed when the network was genuinely isolated.
Then remote vendor support arrived, then plant dashboards for head office, then a laptop that moves between the office network and the line. The isolation assumption quietly expired, and in many plants the security model never caught up.
Nobody owns it, which is the actual problem
IT owns the corporate network and does not have change authority on the line. Engineering owns the line and is measured on uptime. The gap between them is where unpatched engineering workstations and flat control networks live. Naming a single accountable owner for OT security is the change that unlocks the rest.
Start with an inventory, because you do not have one
Almost no plant has an accurate list of what is connected to the control network. Passive discovery — listening rather than scanning, since active scans can upset older controllers — usually surfaces devices nobody expected, including forgotten test equipment and vendor gear installed during a commissioning years ago.
The measures worth doing first
- Segment. Separate control networks from corporate ones, and separate lines or cells from each other, so an incident is contained rather than plant-wide.
- Control remote access. Vendor support through a brokered, logged, time-limited session rather than a standing tunnel.
- Back up the programmes. Current PLC and HMI project files, stored off the line, tested by actually restoring one. This is as much a continuity measure as a security one.
- Manage removable media. USB remains a genuine route into control systems, usually with entirely innocent intent.
- Monitor. Even basic alerting on new devices and unexpected connections beats the current position of finding out later.
Modernisation is the opportunity
The practical moment to fix all of this is when a line is being upgraded anyway — a controller migration, a SCADA version change, a new MES interface. The engineering downtime is already scheduled and the vendor is already on site. Retrofitting segmentation into a running plant afterwards costs several times more.
What good looks like
An accurate device inventory, a documented network architecture the plant manager and the IT lead have both signed, tested restores of every controller programme, and brokered remote access. None of it is exotic. All of it is difficult to arrange after an incident.