OT & ICS Security in India — Segmentation, Asset Discovery, IEC 62443

  • Home
  • OT & ICS Security in India — Segmentation, Asset Discovery, IEC 62443
OT & ICS Security in India — Segmentation, Asset Discovery, IEC 62443
OT & ICS Security in India — Segmentation, Asset Discovery, IEC 62443
OT & ICS Security in India — Segmentation, Asset Discovery, IEC 62443
OT & ICS Security in India — Segmentation, Asset Discovery, IEC 62443

A buyer’s guide · Operating since 2002

OT and ICS securityIndustrial security that respects what a plant can actually tolerate

Most OT security programmes fail in the same way. Someone applies IT security practice to a control network — scan everything, patch monthly, install the agent, isolate the suspicious host — and either causes an outage or is refused by operations. Both outcomes end the programme.

The systems below the DMZ move physical things. Safety and availability outrank confidentiality, equipment stays in service for decades, and several routine IT practices are not merely unavailable but actively dangerous. This page is about working within that.

The first thing we will tell you. Your plant is probably not air-gapped. There is nearly always a path — a vendor support link, an engineering laptop, USB media, a historian replicating to the corporate side, a cellular modem fitted for a project and never removed. The belief is more dangerous than the connection, because it is the reason nobody looks.
3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

The model

The Purdue model, and the boundary that matters

A shared vocabulary for reasoning about what should be allowed to talk to what. The levels matter less than the line through the middle of them.

Level 5Enterprise networkITLevel 4Site business systemsITLevel 3.5Industrial DMZLevel 3Site operations, historiansOTLevel 2Supervisory — SCADA, HMIOTLevel 1Basic control — PLC, RTUOTLevel 0Process — sensors, actuatorsOTPatch monthly. Reboot at will.Confidentiality comes first.The only crossing point.Everything passes here, or not at all.Availability and safety come first.Patching may need a plant shutdown.Active scanning can stop a process.Kit older than network security itself.The Purdue model, and why the halves need opposite posturesApplying IT security practice unchanged below the DMZ is how OT programmes cause outages.

The industrial DMZ is the architecture

Done properly, no session originates on one side and terminates on the other. Data is brokered, historians replicate into the DMZ rather than through it, and remote access terminates there.

That converts an unbounded question — what can reach the plant? — into a bounded, reviewable one: what crosses the DMZ, and why? The list of permitted flows is the design, and it is short enough to read.

Why segmentation is done in stages

Start with what actually communicates today, which is invariably more than the documentation claims. Then enforce gradually: monitor, then alert on violations, then block — beginning with flows nobody can justify.

Designing policy from a network diagram rather than from observed traffic is the reliable way to break something at cutover, and one broken cutover ends the appetite for the whole programme.

The inversion

Seven ways OT is the opposite of IT

Not differences of degree. Straight inversions, each with a concrete reason behind it — and each one a place where transplanted IT practice gets refused by operations, correctly.

Seven IT assumptions, and what each becomes in a plantThis is why an IT playbook applied unchanged to OT is dangerous, not just wrong.WHAT IT SECURITY ASSUMESWHAT OT ACTUALLY REQUIRESPatch promptlyPatch during a shutdown window, months outConfidentiality firstAvailability and safety first, alwaysReboot to fixA reboot can stop a process worth more than the fixScan the networkAn active scan can halt a PLC3-5 year refreshEquipment older than the engineer running itEncrypt everythingLatency budgets measured in millisecondsMFA on every accountA shared console operators must reach in secondsPassive by default is not caution in OT. It is the only responsible starting position.

Every row is a place where an IT security programme applied unchanged does harm rather than nothing. That is why the default posture in OT is passive.

Scroll the table sideways →

Practice In IT In OT Why
Priority order Confidentiality, then integrity, then availability. Safety, then availability, then integrity. Confidentiality last. A stopped line costs money by the minute. A stopped safety system costs limbs.
Patching Monthly, automated, rebooted overnight. Possibly annually, during a planned shutdown, if the vendor has certified the patch at all. Vendor certification frequently lags years behind release, and applying an uncertified patch can void support on the whole line.
Vulnerability scanning Active scanning across the estate, routinely. Passive only, by default. Active scanning is a change requiring approval. Legacy controllers can and do fault on unexpected traffic. A scan has stopped production more than once.
Asset inventory Agent-based, self-updating. Passive network observation and physical walkdowns. You cannot install an agent on a PLC, and much of the estate predates the idea.
Endpoint protection Agents everywhere. Only where the vendor supports it, which is a minority of the estate. Unsupported agents on an HMI void the support contract and can affect real-time behaviour.
Downtime for security A maintenance window. A production decision made by operations, not by IT. The authority to stop a plant does not sit with the security team, and should not.
Lifecycle Three to five years. Fifteen to thirty years, sometimes longer. The equipment was commissioned before network security was a discipline, and it will outlast several of your security tools.

The row that catches people is scanning. Active vulnerability scanning is so routine in IT that it is rarely thought of as a change at all. On a control network it is a change with a real chance of faulting a legacy controller, and it belongs behind an approval and a window like any other.

Straight answers

What buyers get wrong about OT security

Fact

The air gap is almost always a myth

Plants described as air-gapped nearly always have a path: a vendor support link, an engineer’s laptop that moves between networks, a USB drive carrying recipes, a historian replicating to the corporate side, a cellular modem installed for a project and never removed. The belief is more dangerous than the connection, because it justifies leaving the connection unexamined.

Fact

Active scanning can stop production

Legacy controllers were built to be reliable on a predictable network, not resilient to unexpected traffic. Malformed or simply unfamiliar packets have caused controllers to fault. This is why passive discovery is the default in OT and why any active work is a change with an approval and a window.

Ask

“Can we just install the agent?”

Usually no. Vendor support agreements frequently prohibit unapproved software on HMIs and engineering workstations, and installing it can void support on the entire line. The constraint is commercial as much as technical, and it is not negotiable by the security team.

Fact

The CIA triad inverts

In IT, confidentiality usually leads. In OT, safety leads, then availability, and confidentiality comes last — the setpoint on a mixing tank is not a secret. Security programmes that carry the IT ordering into a plant recommend things operations will reject, and they will be right to reject them.

Ask

“Who can authorise stopping the line?”

Not the security team, and not the provider. Containment in OT is a production decision with commercial and safety consequences. Establish that before an incident, because during one there is no time to discover the answer.

Fact

IEC 62443 is a family, not a certificate

It is a set of standards addressing different audiences — asset owners, system integrators, product suppliers — at different security levels. “62443 compliant” on its own means very little without saying which part, whose role and which security level.

Before you sign

Ten questions for any OT security provider

Use these on us and on everyone else. Question one and question nine together will tell you within a minute whether a provider has stood on a production floor.

Discovery

Is asset discovery passive by default?

Ask explicitly. Active scanning of an OT network is a change with a real chance of stopping production, and any provider treating it as routine has not worked on a live plant.

Safety

How do you treat safety instrumented systems?

The correct answer is that SIS is out of scope for anything intrusive and is addressed through isolation and process rather than through tooling.

Segmentation

What does the DMZ design look like, and what crosses it?

The industrial DMZ is the whole architecture. Ask for the data-flow list — historian replication, remote support, patch distribution — because that list is the design.

Remote access

How do vendors get in today, and how would they under your design?

Almost every plant has a vendor support path nobody documented. It is the most common real entry point and the most common thing missing from an inventory.

Downtime

What in this programme requires production downtime, and when?

Get it stated up front and agreed with operations. A security plan that assumes windows it has not secured is a plan that stalls at implementation.

Standards

How do you use IEC 62443 — as a structure or as a certification target?

Both are legitimate. They cost very differently, and conflating them is how budgets get set wrong.

Legacy

What do you do about equipment that cannot be patched or protected?

Compensating controls, documented and accepted. Every real plant has this, and a provider with no answer has not seen one.

Monitoring

Can you monitor OT without touching the control network?

Span or tap based collection into a passive sensor should be the default. Anything requiring an in-line device needs a much stronger justification.

People

Who on your team has worked in a plant?

OT security done by IT security people who have never stood on a production floor produces recommendations operations will refuse, correctly.

Response

What happens when something is found at 2 a.m. on a running line?

The answer must involve operations, not an isolation action taken unilaterally. Containment that stops production is a business decision.

Working with us

How we run this

We have built and secured plant networks for Indian manufacturers since 2002, and we run the operations centre that watches them. That means we are used to being told no by operations, and to designing around it rather than escalating.

Passive by default

Discovery listens rather than probes. Anything active is a change, with an approval and a window, like any other plant change.

Safety systems untouched

SIS is out of scope for anything intrusive, addressed through isolation and process. That is not caution; it is the correct engineering answer.

Vendor access first

The undocumented support path is usually the most important finding, and it is almost never in the asset register.

Realistic about legacy

Compensating controls and a recorded acceptance for what cannot be patched, rather than a finding nobody can action.

Escalation to operations

Containment that stops a line is a production decision. That path is agreed before go-live, not discovered during an incident.

Watched continuously

Passive OT monitoring into the same 24×7 floor as the rest of your estate — see managed SOC services.

3K+
Projects delivered
1,000+
Enterprises protected
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — SOC in scope

Questions we get asked

OT and ICS security, answered

What is OT security?

OT security protects the systems that run physical processes — controllers, SCADA, HMIs, sensors and actuators — as distinct from the IT systems that run the business. The difference is not merely technical. Because these systems move physical things, safety and availability outrank confidentiality, equipment stays in service for decades, and many of the routine practices of IT security are either unavailable or actively dangerous.

What is the difference between IT and OT security?

The priorities invert. IT security usually leads with confidentiality; OT leads with safety, then availability. Patching in IT is monthly and automated; in OT it may require vendor certification and a plant shutdown. Vulnerability scanning in IT is routine; in OT active scanning can fault a controller and stop production. Equipment lifecycles are three to five years against fifteen to thirty. The comparison table above sets these out row by row — the summary is that practice transfers badly and principle transfers well.

What is the Purdue model?

A reference architecture dividing an industrial environment into levels, from Level 0 — the sensors and actuators touching the physical process — up through basic control, supervisory systems and site operations, to the enterprise network at Level 5. Between them sits Level 3.5, the industrial DMZ. It is not a rule about how networks must be built; it is a shared vocabulary for reasoning about where a system sits and what should be allowed to talk to it, and that shared vocabulary is most of its value.

What is the industrial DMZ and why does it matter?

It is the buffer between the enterprise network and the control environment, and the only place traffic should cross between them. Done properly, no session originates on one side and terminates on the other — data is brokered, historians replicate into it, remote access terminates in it. It matters because it converts an unbounded question, “what can reach the plant?”, into a bounded and reviewable one: “what crosses the DMZ, and why?”

Do you scan our OT network?

Not actively, not by default, and not without a change approval and a window. Discovery is passive: we observe traffic from a span or tap and build an asset inventory from what the devices already say. Active techniques have caused outages on legacy controllers, and a provider who treats active scanning of a control network as routine has not worked on a running plant.

What is passive asset discovery?

Building an inventory by listening rather than probing. Industrial protocols are chatty and largely unencrypted, so a sensor watching a mirrored port can identify devices, firmware versions, communication relationships and often the process logic itself — without sending a single packet to a controller. It is slower to reach completeness than active scanning and it is the only responsible default in OT.

Is our plant air-gapped?

Almost certainly not, and it is worth checking rather than assuming. In practice there is nearly always a path: a vendor support connection, an engineering laptop that moves between networks, USB media carrying recipes or updates, a historian replicating to the corporate side, or a cellular modem fitted during a project and never removed. The belief in the air gap is more dangerous than any single connection, because it is the reason nobody looks.

Can OT systems be patched?

Sometimes, slowly, and on someone else’s schedule. Many vendors certify patches long after release, and applying an uncertified patch can void support for an entire line. The practical answer is a documented position for each system: patch where certified and a window exists, and where it does not, apply compensating controls — isolate it, restrict what may reach it, monitor it closely — and record the acceptance.

What is IEC 62443?

A family of standards for industrial automation and control system security, addressing different audiences — asset owners, system integrators and product suppliers — across defined security levels. It is useful as a structure for organising a programme and as a certification target, and those are very different pieces of work with very different costs. A claim of “62443 compliance” means little without stating which part, whose role and which security level.

How do we segment IT from OT without stopping production?

Incrementally, and starting with visibility. Establish what actually communicates today — which is invariably more than the documentation says — then enforce in stages: monitor first, then alert on violations, then block, beginning with the flows nobody can justify. Designing a segmentation policy from a network diagram rather than from observed traffic is the reliable way to break something during cutover.

What about remote access for equipment vendors?

It is usually the most important finding of the first assessment and almost never in the asset register. The target design is a single brokered path through the DMZ, authenticated, time-bounded, recorded and approved per session, replacing whatever mixture of persistent VPNs and cellular modems accumulated over the years. Vendors accept this readily; it is usually internal scheduling that makes it difficult.

Can you monitor our OT environment continuously?

Yes, passively, feeding the same 24×7 operations centre that watches the rest of your estate — see managed SOC services. What differs in OT is the response: containment that stops a line is a production decision, so the escalation path runs to operations rather than to an analyst with an isolate button. That path is agreed before go-live, not during an incident.

Do you work on live plants?

Yes, and the constraints that come with it shape everything above: passive by default, changes scheduled with operations, nothing installed on equipment whose vendor has not approved it, and no assumption that a maintenance window is available for the asking.

How is this scoped?

By the number of sites, the rough count of controllers and supervisory systems, which vendors and protocols are in use, whether there is any existing segmentation, and how remote vendor access works today. A first assessment usually pays for itself in the asset inventory alone, because it is rarely the inventory anyone expected.

Next step

Start with what is actually connected

Tell us how many sites, roughly how many controllers and supervisory systems, and which vendors are in use. The first assessment is passive and usually pays for itself in the asset inventory alone — because it is rarely the inventory anyone expected, and the vendor connection nobody documented is usually in it.

sanjay@pjnetworks.com