06Service line

OT security services for ICS and SCADA environments

Onion Infosec assesses and secures industrial control systems, SCADA and the networks that connect them to IT. Work is planned around availability and safety: passive methods first, changes inside agreed maintenance windows, and coordination with the vendors who maintain the equipment.

Line
06 of 07 · OT
Shape
Assess → See → Segment → Monitor → Respond → Align
Delivery
Project, retainer or managed service

01Context

What the OT service line covers

Operational technology is the hardware and software that monitors and controls physical processes: PLCs, RTUs, DCS controllers, HMIs, engineering workstations, historians, safety instrumented systems and SCADA servers. It runs factories, utilities, building services and hospital facilities. The OT line covers assessment, asset visibility, network architecture, remote access, monitoring, incident response and alignment with IEC 62443 and NIST SP 800-82.

OT security differs from IT security in its priorities and its constraints. Availability and safety come before confidentiality. Many devices cannot be patched, cannot run an agent and may fail if scanned. Some systems are managed by the equipment vendor under support terms. Our methods are chosen to work within those limits, and each finding comes with a compensating control where a direct fix is not possible.

IT and OT networks are now connected
Production data feeds ERP, analytics and cloud platforms, and vendors support equipment remotely. Each connection is a path from the business network or the internet toward control systems, and it needs to be known and controlled.
Legacy equipment stays in service for decades
Controllers and HMIs often run unsupported operating systems and protocols with no authentication. Replacement is rarely possible in the short term, so risk has to be reduced around them through segmentation, access control and monitoring.
Consequences are physical
An OT incident can stop production, damage equipment, harm the environment or endanger people. Regulators, insurers and customers ask operators to show how these risks are assessed and managed.

Architecture

Where IT ends, where the plant begins, and what may cross.

OT security is mostly about one boundary and the levels beneath it. Each control is applied only where it is safe to apply it.

Fig. 01IT, the boundary, and the plant

The Purdue reference model from enterprise IT at the top to the physical process at the bottom. L5 · L4, Enterprise IT: Business systems, email, ERP, internet access. L3.5, Industrial DMZ: The only path between IT and OT: brokered remote access, patch and file staging, historian replicas. L3, Site operations: Historians, engineering workstations, OT domain services, monitoring sensors. L2, Supervisory control: SCADA servers, HMIs and operator stations. L1, Basic control: PLCs, RTUs, DCS controllers and safety systems. L0, Process: Sensors, actuators, drives and the physical process. The industrial DMZ is the boundary between IT and OT. Visibility applies from Site operations to Basic control. Passive asset discovery. Nothing is actively scanned at the control levels. Segmentation applies from Industrial DMZ to Basic control. IEC 62443 zones and conduits, enforced from the DMZ down. Remote access applies from Enterprise IT to Site operations. Vendor and engineer access brokered through the DMZ, recorded and time-limited. Monitoring applies from Industrial DMZ to Basic control. OT-aware detection on a copy of the traffic, watched 24×7. Response applies from Enterprise IT to Process. Incident response planned with operations, with safety and availability first.

  1. L5 · L4Enterprise ITBusiness systems, email, ERP, internet access.Remote accessResponse
  2. L3.5Industrial DMZThe only path between IT and OT: brokered remote access, patch and file staging, historian replicas.SegmentationRemote accessMonitoringResponse
  3. L3Site operationsHistorians, engineering workstations, OT domain services, monitoring sensors.VisibilitySegmentationRemote accessMonitoringResponse
  4. L2Supervisory controlSCADA servers, HMIs and operator stations.VisibilitySegmentationMonitoringResponse
  5. L1Basic controlPLCs, RTUs, DCS controllers and safety systems.VisibilitySegmentationMonitoringResponse
  6. L0ProcessSensors, actuators, drives and the physical process.Response
Visibility
Passive asset discovery. Nothing is actively scanned at the control levels.
Segmentation
IEC 62443 zones and conduits, enforced from the DMZ down.
Remote access
Vendor and engineer access brokered through the DMZ, recorded and time-limited.
Monitoring
OT-aware detection on a copy of the traffic, watched 24×7.
Response
Incident response planned with operations, with safety and availability first.
The Purdue reference model, a public industry model. Each control is drawn over the levels where it applies.
  • IT / OT boundary
  • Levels where a control applies

02Approach

How we work in OT environments

Every engagement begins with the rules of the site. We agree rules of engagement with operations, engineering and safety staff: which networks may be touched, which methods are allowed, who must be present, and what stops the work. Site safety inductions and permit-to-work procedures apply to our staff as they do to any contractor.

Discovery is passive first. We collect traffic from SPAN ports or taps, review configurations, drawings and backups, and walk the plant floor. Active queries are used only where the asset owner and the equipment vendor agree, using protocol-native methods, in a test environment or a maintenance window. Recommendations are sequenced around planned outages.

01

Safety and availability first

No test, tool or change goes ahead if it could disturb the process. When in doubt, the work waits for a maintenance window or moves to a test system.

02

Passive before active

Traffic capture and configuration review come first. Active scanning of control networks is the exception, agreed in writing and limited in scope.

03

Compensating controls for what cannot be patched

Where a device cannot be updated, the risk is reduced around it through segmentation, access restriction, protocol filtering and monitoring.

04

Work with vendors and integrators

Vendor-managed systems are assessed and changed in coordination with the OEM or integrator, so that support and warranty terms are respected.

03Capabilities

How OT security work is organized.

  1. Assess

    Establish risk with safety and availability first.

  2. See

    Know what is on the plant network.

  3. Segment

    Zones, conduits and controlled ways in.

  4. Monitor

    Detect threats without disturbing the process.

  5. Respond

    Incident response planned around operations.

  6. Align

    Map the program to industrial standards.

OT security assessment and risk

A structured view of where an industrial environment stands and what to do first. Assessments combine document review, interviews, site walkdowns and passive network analysis.

  • OT security assessmentReview of architecture, network traffic, device configurations, access paths and procedures at one or more sites. Output is a findings report with a prioritized plan sequenced around maintenance windows.
  • IEC 62443 risk assessmentHigh-level and detailed risk assessment following IEC 62443-3-2: define the system under consideration, partition it into zones and conduits, and set a target security level for each.
  • Consequence-based risk analysisWorkshops with process and safety engineers that tie cyber scenarios to physical consequences, drawing on existing HAZOP and LOPA studies where available.
  • Site walkdown and physical reviewOn-site inspection of cabinets, network equipment, removable media practice, physical access and undocumented connections such as modems and wireless links.
  • OT security program reviewAssessment of governance, roles, policies, supplier management and training against IEC 62443-2-1, with a maturity rating and a roadmap.
  • OT penetration testingTesting of the IT/OT boundary, remote access paths and, where agreed, control system components in a test bed or during an outage. Live production controllers are not tested actively.

Asset discovery and visibility

An accurate inventory is the basis for every other OT control. We build it without putting fragile devices at risk.

  • Passive asset discoveryTraffic capture from SPAN ports and network taps, parsed for industrial protocols to identify devices, vendors, models, firmware and communication pairs.
  • Configuration and project file analysisExtraction of asset detail from PLC project files, switch and firewall configurations, and backups. This finds devices that are silent on the network.
  • Selective active queryingProtocol-native queries that confirm firmware and module detail, used only with asset owner and vendor agreement and outside sensitive operating periods.
  • OT asset inventoryA maintained inventory with location, function, criticality, owner, firmware, network zone and support status, delivered in a format your CMDB or maintenance system can import.
  • Network and data flow mappingLogical and physical diagrams of the control network with data flows between Purdue levels, including connections that are missing from the drawings.
  • Vulnerability mappingMatching of the inventory against vendor advisories and public vulnerability data. Each item is rated by exposure and process criticality as well as by CVSS score.

Network architecture and segmentation

Design of OT networks that limit how far a fault or an intruder can travel. Designs follow the Purdue model and the zones and conduits concept in IEC 62443.

  • OT reference architectureTarget network architecture by Purdue level, from field devices and control up to site operations, the industrial DMZ and the enterprise network.
  • Zones and conduits designGrouping of assets into security zones by function, criticality and consequence. Each conduit between zones is documented and assigned a target security level.
  • Industrial DMZ designA buffer network between IT and OT that terminates all cross-boundary traffic and hosts historian replicas, patch and antivirus servers, jump hosts and file transfer.
  • Firewall rule design and reviewLeast-privilege rule sets for industrial firewalls, including deep packet inspection of protocols such as Modbus, DNP3 and EtherNet/IP where the firewall supports it.
  • Segmentation migration planningA staged plan for moving from a flat network to the target design. Each step is tied to a change window, a test plan and a rollback.
  • Unidirectional gateways and data transferDesign of one-way data paths for historian replication, and secure file transfer procedures for cases where two-way connectivity is unnecessary.
  • Industrial wireless and remote site connectivitySecurity design for plant wireless, cellular and satellite links to remote stations, including encryption, authentication and failover.

Secure remote access

Remote access for staff, vendors and integrators that is approved, brokered, recorded and time-limited. Direct connections from the internet or the business network to control systems are removed.

  • Remote access assessmentIdentification of every remote path into OT, including VPNs, vendor appliances, remote desktop tools, cellular modems and cloud-connected equipment.
  • Remote access architectureA brokered design through the industrial DMZ with jump hosts, protocol break, multi-factor authentication and no direct route to control devices.
  • Vendor and third-party access controlPer-session approval, time-bound accounts, named users and access limited to the specific assets within the vendor’s support scope.
  • Privileged session monitoringRecording and live oversight of remote sessions, with the ability for site staff to terminate a session.
  • Multi-factor authentication for OTMFA at the boundary and on jump hosts, designed so that local emergency operation does not depend on external identity services.
  • Remote access proceduresWritten procedures for request, approval, supervision and revocation, aligned with permit-to-work and management of change.

OT monitoring and threat detection

Visibility of the control network without touching it. Sensors listen passively, detections are mapped to MITRE ATT&CK for ICS, and alerts are triaged by people who understand the process context.

OT incident response

Preparation for and response to cyber incidents that affect industrial systems. Decisions to isolate, shut down or keep running belong to operations, and response plans are written that way.

Standards and regulatory alignment

Gap assessment, implementation support and audit support against the standards that apply to industrial environments. We prepare organizations for assessment and do not certify.

  • IEC 62443 gap assessmentAssessment of the security program against IEC 62443-2-1 and of systems against IEC 62443-3-3 requirements, with gaps rated and mapped to a roadmap.
  • NIST SP 800-82 alignmentMapping of current controls to NIST SP 800-82 guidance and its OT overlay for NIST SP 800-53, with recommendations suited to the architecture of the site.
  • OT security policies and proceduresPolicies, standards and procedures for OT covering access, removable media, change management, patching, backup and supplier security.
  • Supplier and integrator requirementsSecurity requirements for procurement and for system integrators, based on IEC 62443-2-4 and IEC 62443-3-3, for use in tenders and factory acceptance tests.
  • Regulatory mappingMapping of OT controls to sector and regional obligations. NIS2 in the European Union and NERC CIP for North American bulk power are two examples.
  • Audit and assessment supportEvidence preparation, control walkthroughs and remediation tracking before and during customer, insurer or regulator assessments.

04Process

How an OT security engagement runs.

  1. Scope and rules of engagement

    Agree sites, systems, methods, safety requirements, vendor involvement and stop conditions with operations and engineering.

  2. Discover

    Collect documents, configurations and passive traffic. Walk the site. Build the inventory and the network map.

  3. Assess

    Analyze architecture, access paths, vulnerabilities and procedures. Rate risk by physical consequence and exposure.

  4. Design

    Produce the target architecture, zones and conduits, remote access design and monitoring plan, with compensating controls for equipment that cannot change.

  5. Implement in change windows

    Carry out network, access and monitoring changes in stages, inside approved windows, with test and rollback plans and the vendors concerned.

  6. Monitor and review

    Operate detection, exercise the response plan and reassess after significant plant or network changes.

What you receive

  • OT asset inventory with criticality, firmware and support status
  • Network and data flow diagrams by Purdue level
  • Assessment report with findings rated by consequence and exposure
  • Zones and conduits model with target security levels
  • Target architecture, industrial DMZ and remote access designs
  • Roadmap sequenced around maintenance windows and planned outages
  • OT incident response plan and scenario playbooks
  • Gap assessment against IEC 62443 and NIST SP 800-82

05Technical depth

Typical OT security engagements, technology and methods.

  • OT security assessment

    A fixed-scope engagement per site that combines remote document review with time on site. Ends with a findings report and a roadmap sequenced around planned outages.

  • Asset discovery and visibility baseline

    A short engagement that runs passive collection for a defined period and delivers an inventory, a network map and a list of unexpected connections.

  • Segmentation design and implementation

    A phased project: target architecture, zones and conduits, then staged implementation in change windows with site engineering and the vendors involved.

  • Secure remote access program

    A project that finds existing remote paths, builds a brokered access design and retires the paths it replaces.

  • OT monitoring service

    Sensor deployment and tuning delivered as a project, followed by 24×7 monitoring as a managed service.

  • IEC 62443 readiness program

    A multi-phase program covering gap assessment, risk assessment, policy and procedure development, and support through remediation.

Technology areas

Control systems in scope

  • PLCs and RTUs
  • Distributed control systems
  • SCADA servers
  • HMIs and engineering workstations
  • Historians
  • Safety instrumented systems
  • Building management systems

Industrial protocols

  • Modbus
  • DNP3
  • EtherNet/IP and CIP
  • PROFINET
  • OPC UA and OPC DA
  • IEC 60870-5-104
  • IEC 61850
  • BACnet

OT monitoring and analysis

  • Nozomi Networks
  • Claroty
  • Dragos
  • Microsoft Defender for IoT
  • Zeek
  • Suricata
  • Wireshark

Network and boundary

  • Industrial firewalls
  • Industrial DMZ
  • Unidirectional gateways
  • Managed industrial switches
  • Network taps and SPAN ports

Access and security operations

  • Jump hosts
  • Privileged access management
  • Multi-factor authentication
  • Microsoft Sentinel
  • Splunk
  • Wazuh

Technologies are named to describe the work. Naming a product does not indicate a commercial partnership.

Frameworks and methods

IEC 62443

Primary standard series. Used for program requirements (2-1), supplier requirements (2-4), risk assessment with zones and conduits (3-2) and system security requirements (3-3).

NIST SP 800-82

Guide to OT security. Used for architecture guidance and as a control overlay where NIST SP 800-53 or NIST CSF is the enterprise framework.

MITRE ATT&CK for ICS

Knowledge base of adversary behavior in industrial environments. Used to design detections, plan tests and describe incidents.

Purdue Enterprise Reference Architecture

Level model used to structure network architecture, the industrial DMZ and data flow reviews.

NIST Cybersecurity Framework

Outcome framework used to report OT security alongside IT in a single view for leadership.

ISO/IEC 27001 and ISO/IEC 27019

Applied where OT falls inside the scope of an information security management system. ISO/IEC 27019 adds guidance for energy utilities.

NIS2 Directive

Example of a regional regulation, covering essential and important entities in the European Union. Used for obligation mapping where it applies.

NERC CIP

Example of a regional sector regulation, covering bulk power in North America. Controls are mapped to it where it applies.

06Across lines

The engineering to implement what an OT assessment recommends.

Most OT findings are fixed with network, identity and infrastructure work, and Onion Infosec can carry it out. Our IT team builds the industrial DMZ, firewalls, switching and jump hosts. Our cloud team builds secure paths for historian and telemetry data to cloud platforms. Our security operations team runs the monitoring. All changes follow site change control and are scheduled with plant engineering.

07Questions

OT: questions we are asked

It is designed not to. Discovery relies on passive traffic capture, configuration review and site walkdowns. Any active method is agreed in writing with operations and the equipment vendor, and is limited to test systems or maintenance windows. Site staff can stop the work at any time.

This is normal in OT. Risk is reduced around the device: place it in a tightly scoped zone, restrict which hosts and protocols can reach it, remove remote paths, monitor its traffic and keep a tested backup of its program. Replacement is planned with the asset lifecycle.

Not by default. Conventional IT vulnerability scanners can crash or stall controllers. We use passive analysis first, then protocol-native queries where the owner and vendor agree. Conventional scanning is limited to IT-type systems in the upper levels and the DMZ, in agreed windows.

Many control systems are maintained by the vendor, and unapproved changes can affect support or warranty. We involve the vendor or integrator when planning assessments and changes, and we write security requirements that can be included in future contracts and acceptance tests.

No. We provide gap assessment, risk assessment, implementation support and audit support aligned with IEC 62443 and NIST SP 800-82. Certification, where it is sought, is issued by accredited certification bodies.