Back to glossary

OT and ICS security

2 min read

In industrial security, OT and ICS security covers the protection of operational technology and industrial control systems: the equipment that runs physical processes in factories, utilities and infrastructure. It is the vocabulary of the industrial client who buys IoT testing and who falls under NIS2, and where safety and availability outrank confidentiality.

July 29, 2026
Compartir:

How it works

Operational technology is the equipment that monitors and controls physical processes: the controllers, sensors and actuators on a production line or in a utility. Industrial control systems is the broader term for the systems that supervise and coordinate them; SCADA is one common type of such a system, used for wide-area supervisory control, and the Purdue model is the reference architecture that describes how these layers should be arranged and separated. The defining feature of this world is that the priority order is inverted from corporate IT: availability and safety come first, because stopping the process can be dangerous or hugely costly, and confidentiality comes last. Many of the protocols involved were designed for isolated networks and carry no authentication at all, trusting any device that can reach them.

What goes wrong

The core weakness is convergence without protection. These systems were built to be isolated and are now connected to corporate networks and the internet, but the protocols never gained authentication, so a device that can reach a controller can often command it directly. The failure we find most is weak network segmentation between the corporate and industrial zones, so a compromise on the office side reaches equipment that runs a physical process. From an attacker’s side this is the high-consequence path, and the difficulty is not technical, it is operational: the systems cannot be casually tested because the process they control is real and the equipment may be fragile.

Where this shows up in an audit

Testing an industrial environment is scoped for safety first: the aim is to assess exposure without disturbing the process, so the boundary between corporate and OT is where much of the work sits. We check that segmentation genuinely isolates the industrial zone, that remote access into it is controlled, and that the devices verify what they run through controls such as secure boot and hold up under firmware analysis. The relevant control framework is usually IEC 62443, and the reporting obligations align with NIS2. This is part of how we test an industrial environment safely.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.