An experienced IT security team turned loose on a control network with their usual toolkit can cause an outage before lunch. The methods are sound; the assumptions behind them do not hold. Understanding which assumptions break is what separates a useful OT assessment from a dangerous one.
The Priorities Are Inverted
IT security is generally taught confidentiality first, then integrity, then availability. In an operational environment the order reverses. A process that stops has immediate physical and financial consequences — and in some settings, safety consequences. A control that improves confidentiality at any risk to availability will be rejected by the plant, correctly.
Active Scanning Can Take Devices Down
Many controllers and field devices have small network stacks that were never designed to tolerate aggressive probing. A standard port scan can be enough to make one stop responding. This is not hypothetical — it is the reason OT assessments lean on passive traffic monitoring, configuration review and interviews, and treat any active testing as something scheduled, agreed, and ideally performed on a maintenance window or a test bench.
Patching Is Governed by the Vendor and the Calendar
“Patch promptly” assumes you may patch. In OT, applying an update can void a vendor support agreement or invalidate a validated configuration, and the only opportunity to touch the system may be an annual shutdown. Recommendations that ignore this get filed and forgotten. Realistic OT findings prioritize compensating controls — segmentation, access restriction, monitoring — for the long stretches when patching is not available.
The Equipment Outlives the Software Support
Industrial assets are bought on twenty- and thirty-year horizons. Operating systems and controller firmware reach end of support long before the equipment reaches end of life, and replacement is a capital project rather than a maintenance task. “Upgrade it” is not a finding; it is a budget cycle.
What a Good OT Assessment Actually Produces
- An accurate asset inventory. Most sites do not have one, and nothing else can be prioritized without it.
- A real network picture — including the connections nobody documented: a vendor modem, an engineering laptop that moves between networks, a temporary link that became permanent.
- Segmentation findings. Whether the boundary between business and control networks is what people believe it is, and what actually traverses it.
- Remote access review. Vendor and contractor access is one of the most common serious findings, and one of the most fixable.
- Recommendations that survive contact with operations — sequenced, costed, and compatible with the shutdown calendar.
Bring Operations With You
The plant engineers know things no scan will reveal: which device is unreliable, which link was temporary three years ago, which cabinet has a laptop permanently plugged in. Assessments run without them find less and are trusted less. The people who will implement the recommendations should be in the room when they are formed.
The Short Version
OT security is not IT security with different acronyms. Availability comes first, active testing is a scheduled and negotiated activity rather than a default, and any recommendation that ignores the patch and shutdown reality will not be implemented. Assessments are performed only on systems whose owner has authorized the work in writing.
Related service: OT and ICS security assessment