Back to blog
Sectors

OT and manufacturing security: why IT playbooks fail on the plant floor

Operational technology inverts most IT security assumptions - availability over confidentiality, decade-long lifecycles, safety consequences. What applies, what does not, and how to build a compliance programme that plant engineers will accept.
GRC Copilot Team
OT and manufacturing security: why IT playbooks fail on the plant floor

In IT, the priority is confidentiality, then integrity, then availability. In operational technology it is the reverse - and safety sits above all three. That single inversion explains why IT security programmes imported wholesale into a plant environment fail, and why they generate resistance from engineers who are not being obstructive but are protecting a process that must not stop.

What is genuinely different

  • Availability is non-negotiable. Unplanned downtime can be enormously costly and, in some processes, unsafe. You cannot patch during business hours.
  • Lifecycles run to decades. Equipment commissioned fifteen years ago is normal and cannot simply be replaced.
  • Vendor certification constrains patching. Applying an update can void support or require recertification.
  • Legacy protocols lack security by design - many industrial protocols have no authentication at all.
  • Active scanning can disrupt. Standard vulnerability scanners have knocked over control systems; passive monitoring is the norm.
  • Safety systems are governed separately, and security changes touching them require safety review.

The frameworks that apply

  • IEC 62443 - the principal industrial cybersecurity standard, structured around zones, conduits and security levels, addressing operators, integrators and product suppliers.
  • NIST guidance for OT, widely used as practical reference material.
  • ISO 27001 for the corporate side, extended into OT where scope requires.
  • National frameworks - the NCA ECC and related operational-technology controls where you fall in scope in Saudi Arabia.
  • NIS2 for in-scope manufacturing and industrial entities in the EU.
  • Customer standards such as Aramco SACS where you supply major operators.

Assess IT and OT from one programme

GRC Copilot maps IEC 62443 alongside your ISO 27001 and national framework obligations, so plant and corporate controls are governed together rather than in separate silos.

Controls that work in OT

  1. Segmentation above everything. Zones and conduits, with strictly controlled traffic between IT and OT. This is the highest-value control by a wide margin, because it contains what you cannot patch.
  2. Passive asset discovery. Build the inventory without active scanning; you cannot protect what you have not identified, but you must not disrupt to find it.
  3. Controlled remote access for vendors - brokered, time-limited, monitored and recorded. Permanent vendor VPNs are a recurring root cause.
  4. Removable media control, still a primary infection route in air-gapped-in-theory environments.
  5. Compensating controls, documented. Where patching is impossible, record the alternative protections and the accepted risk explicitly.
  6. Backups of controller configurations, not just servers - and tested restoration.
  7. OT-aware incident response, with plant operations involved and safety implications understood before anything is isolated.
Never isolate an OT segment during an incident without operations in the room. In IT, disconnecting is a safe default. In a process environment it can be the dangerous option.

Working with plant engineering

Programmes succeed or fail on this relationship. What helps:

  • Frame everything in terms of uptime and safety, not confidentiality.
  • Never propose a change to a live process without a maintenance window and engineering sign-off.
  • Start with visibility - passive monitoring gives value without touching anything and builds trust.
  • Accept that some risks will be carried with compensating controls, and document them properly rather than pretending otherwise.

Frequently asked questions

Can we run IT vulnerability scanners on OT?

Generally not on live control networks. Active scanning has caused outages. Use passive monitoring and vendor advisories mapped to your asset inventory instead.

What is IEC 62443 in one line?

A standard that structures industrial security around zones and conduits with defined security levels, covering asset owners, system integrators and product suppliers.

How do we handle unpatchable equipment?

Segment it, restrict access tightly, monitor it, document the compensating controls, and track vendor support timelines as a lifecycle risk with a replacement plan.

Do IT and OT need separate programmes?

Separate controls and practices in places, but one governance programme and one risk register. Splitting governance is how OT risk becomes invisible to leadership.

Key takeaways

  • Availability and safety outrank confidentiality - design controls accordingly.
  • Segmentation is the highest-value control because it contains the unpatchable.
  • Discover passively; active scanning can disrupt live processes.
  • One governance programme, with OT-appropriate controls inside it.
#manufacturing #ot #ics #iec-62443 #safety #sector