men work in control room

OT network security

09.09.2026

Operational Technology (OT) keeps factories, power plants, cargo ships and other critical infrastructure operational. If something goes wrong, the impact is not limited to a broken application or unavailable office service. It can affect production, safety and business continuity directly.

Key facts: OT network security
  • OT security must protect production continuity, not disrupt it. Availability and safety remain the primary priorities in industrial environments.
  • Visibility comes first. You need to know what assets exist, how they communicate and where meaningful logs can be collected before security can be improved effectively.
  • Passive monitoring is often the safest approach. Tools such as Microsoft Defender for IoT can identify assets, communication paths and risks without active scanning of production systems.
  • Legacy systems are part of the reality. Unsupported operating systems, proprietary protocols and devices without modern security features may still be critical to production.

For a long time, security was not the highest priority during OT system design. One of the reasons for this is that the OT networks have been traditionally separated from the internet and corporate IT networks. They also used proprietary protocols and vendor-specific systems that were not commonly exposed outside the production environment.

That world has changed.

OT networks are no longer completely isolated. Remote access, centralized monitoring, production reporting, cloud connectivity and vendor maintenance have destroyed the wall separating IT from OT. This has also brought IT-related security problems into OT environments that were never designed to handle them in the same way as traditional IT systems. OT environments may have been built on legacy OS versions, legacy hardware and the devices might not even support encryption.

These are few reasons why OT networks can be difficult environments for IT security specialists. In the IT world, systems are patched, rebooted and replaced regularly. As for the OT worl, a system may be running because production depends on it, even if the operating system is old, unsupported or difficult to harden.

Sometimes the reality is very simple:

  • Any interruption causes monetary losses and of the maintenance breaks needs to be planned moths ahead (and all the OT device suppliers are updating their devices at the same time)
  • Encryption not used since legacy systems do not support it (or it dangers the visibility of the production process).
  • The Windows 7 machine is still there because it runs something critical (and it just works and no feasible alternatives at reasonable cost available).
  • Nobody wants to touch a system that has been working for ten years (Stability over security).
  • The network documentation is not always as complete as expected (and some it is in plant engineers heads).

This is not because OT environments are badly managed. It is because the priorities have traditionally been different. In OT, availability and safety come first. Security improvements must respect that.

Why OT security matters today?

  1. OT is now part of cyber resilience expectations
    Critical production environments can no longer be treated as exceptions outside normal security requirements. OT security is now a business continuity topic.
  2. OT networks are more connected than before
    Remote access, centralized monitoring, vendor connections and IT integrations have brought OT environments closer to corporate networks. This exposes production environments to threats they were not originally designed to handle.
  3. Legacy systems still control critical processes
    Typical OT environments contain systems with very long lifetimes. Old operating systems, proprietary protocols and unsupported devices may still be necessary for production and making it difficult to secure with normal IT methods.
  4. Geopolitical tensions and cyberattacks have increased the pressure
    Critical infrastructure and industrial environments are more interesting targets than before. Cyberattacks are no longer only an IT problem, because disruption in OT can directly affect production, logistics, energy, safety and society.
  5. European regulation is raising the requirements
    New and developing European cybersecurity regulations (NIS2, CRA) are pushing organizations to improve resilience, risk management and incident preparedness. For OT environments this means that visibility, monitoring and practical security controls are expected.

A practical approach to OT network security

man working with multiple computer screens

In OT network security there is no a one-size-fits-all solution.

A practical OT security concept starts with visibility. The organization needs to know what assets exist, how they communicate and where useful logs can be collected. Log collection is especially important, because it helps detect signs of compromise, technical faults and unexpected behavior. If OT logging capability is still missing or very limited, it is one of the clearest places to improve.

The Purdue model gives a useful structure for this work. It separates the OT environment into layers, from field devices and controllers to process networks, operations and corporate IT. When firewalls and access paths are designed properly, this creates an onion-like model where each layer has its own role and protection.

Detection should be added in a way that respects production. Passive monitoring and tools like Microsoft Defender for IoT can help observe traffic without disturbing the process. OT logging agents can collect relevant events from systems where logging is possible. Honeypots tailored to look like real OT devices can act as tripwires, giving early warnings if something starts scanning or touching systems it should not.

After visibility and detection, the next step is assessment and hardening. The assessment shows where the real weaknesses are, and hardening turns that information into practical improvements. This can mean better segmentation, safer access paths, improved logging, or removing unnecessary communication. The same monitoring and log data can also support the automatic discovery, documentation, and management of network assets and topology. Keeping this information up to date significantly improves security assessments, network planning, and change management. The goal is not to force IT-style security into OT, but to improve security in a way that keeps production running.

Levels of network
Figure: The point is not to monitor every layer similarly. The point of OT network monitoring is find the right controls at the right levels: passive visibility close to the production process, local logging where events are generated, and sending to centralized observation where it helps in awareness of the whole OT network.

Key steps to improving OT security without disrupting production

Defender for IoT gives visibility without disturbing the process

Before hardening the network, it is necessary to understand what is actually happening inside it. In some cases this information might be buried in some employee’s brain or lost documentation. When scanning an OT environment, it should usually be done passively where possible. The goal is to observe the traffic and identify assets, communication patterns and risks without disturbing production.

Microsoft Defender for IoT is useful in this role because it can listen to OT network traffic and provide visibility into the environment. It helps answer questions such as what devices exist, what they communicate with and where suspicious or unnecessary communication may exist.

For Wapice, Defender for IoT is one of the core concepts for OT network security assessment and hardening. A typical process for our solution consists of following setup: Wapice uses Microsoft Defender for IoT to provide visibility into OT environments without active scanning or disruption. Only a capture of the target network’s traffic is needed. The solution helps identify assets, communication paths and potential risks in a safe and controlled way. If the Defender for IoT suits your organization it can be installed in the network permanently to provide continuous threat information.

A typical assessment with Defender for IoT can support:

  • Asset visibility
  • Identification of unexpected events and assets
  • Identification of risky communication paths
  • Support for segmentation planning
  • Better understanding of legacy or exposed systems
  • Input for hardening recommendations

The output should not only be a technical report. It should help decision makers understand which risks matter most, and help engineers understand what can be changed safely. Additionally, if the solution is found suitable for permanent installation during the assesment, it is also an option.

Logging for OT environments

One of the most important parts of OT security is log collection. Without logs, it is difficult to conduct computer forencics upon compromise, recognize misconfiguration or solve unexpected network behavior. In many OT environments, logging is still not at the level where it should be. Some devices do not produce useful logs. Meaningful may be available locally but not delivered anywhere. Some sites are geographically separated and managed.

Wapice has developed a concept for OT site logging where each site can operate independently, but the data can still be collected to one central point for observation. The central node does not have to be online at every moment, because the site-level logging continues to work also independently. When the site is back online, the buffered logs are synchronized to the central node again. At the core of the solution is air-gapped deployment, with auxiliary services to support such logging stack. This approach is useful especially when there are many production sites or when connectivity between sites is not guaranteed or the visibility needs to be at the site-engineering level as well. This architecture has been designed specifically for industrial environments where connectivity can limited, production sites are distributed and continuous central availability cannot be always guaranteed.

The practical benefits of such architecture are:

  • Local sites continue collecting logs independently.
  • Central monitoring gives a wider view across production sites.
  • The architecture does not depend on perfect connectivity.
  • Deployment can be automated once the hosts are ready.
  • The same concept can support security monitoring and operational analysis.

Wapice does not enforce a single logging platform. We design and implement the logging stack based on customer needs, using technologies such as Elastic, OpenSearch, Wazuh or Loki, and automate deployment using Infrastructure as Code.

Honeypots

Honeypots are commonly used in IT environments as decoy systems to detect unauthorized activity. However the same principle can also be applied to OT assets as well. OT honeypots can be running either their own devices or utilize existing infrastructure. OT honeypots differ from their IT counterpart with few key details:

  • Customized flags – Honeypot needs to look like it belongs to the target environment
  • Extreme hardening – The OT networks may not have similar hardening as their IT counterparts. Therefore a honeypot must not be the reason for a system compromise.
  • Zero interference with other systems – OT honeypots are designed to be passive and they should not interact with other devices.

The goal of having honeypots in OT networking will act as a single early-warning mechanism, a tripwire that sends an early warning if something unexpected happens in the network and it should not be treated as a replacement for SOC. Setting up a generic honeypot is easy, but having customized flagging is necessary for a credible bait.

Risks, Assessment and Testing

OT cybersecurity can reuse most of the IT world concepts such as Threat Modeling, Penetration Testing and various workflows related to risk management and sceure development. However, the involved security specialists are required to have sufficient understanding of the OT environment. As a partner, Wapice is able to combine both worlds and provide a full portfolio of cybersecurity services also in the OT domain.

Cybersecurity regulations and standards often feel overwhelming for OT networks, where unencrypted communications and legacy solutions are still present. Luckily most regulations are essentially risk-based and mitigations can often be designed considering the whole system instead of a single component. Also here, real-world experience from OT networks is crucial.

Regardless the OT cybersecurity challenge you are facing, Wapice is ready to analyze it and to propose the best approach.

Written by

Samuli Tolvanen

Wapice Oy

Samuli Tolvanen

Security Specialist