How to secure operational technology for maximum business value

How to secure operational technology for maximum business value

26 June 2026 Consultancy.uk
How to secure operational technology for maximum business value

How do you secure the operational technology in factories, engineering plants and buildings? Experts from Project One explain that there are a surprisingly small number of actions to get the highest value.

Cybersecurity assurance can be a tough job – how much is enough when deciding about the security of your enterprise? Often teams seek answers from the many frameworks on offer, but they can just give huge numbers of non-compliances and then where do you start? But real, effective security on the floorplate can boil down to relatively few high value actions and these can be implemented without large budgets.

Where do you start?

For compliance, it is essential to choose a framework to assess against. A common one for international organisations is NIST, as it ties into the US defence community. The standard for OT is NIST 800-82 and this offers close to 700 controls to assess against. Such a volume of questions matched with a high number of operational technology (OT) assets, that likely will never have been assessed before, will result in thousands of remediation actions. Organisations can then get lost in huge spreadsheets with more actions than they can ever hope to progress.

Quickly the problem becomes worse: suppliers in the UK probably understand IEC62443 rather than NIST, so you need a mapping. Then there is useful guidance from SANS and Mitre, and client or industry specific frameworks also. It is all rather overwhelming.

The key factors to consider

Start by building an inventory of assets – there may be a list in the plant maintenance tools but is this updated every time machines move, or new hardware is added? This baseline inventory is a point-in-time view, and you must get used to regularly reviewing and updating. But assessing OT at asset level is inefficient. Group the OT into logical or geographical systems. Either an entire production line, or the assets in a physical location. Then there is a manageable number of OT systems to run against the framework assessment.

The assessment must create an asset register and capture all the detail like firmware levels and backup locations at the asset level. So, the fidelity goes down to the detail level, even if the assessment is carried out at the systems level. Manufacturers regularly release lists of Common Vulnerabilities and Exposures (CVE) and these must be checked against your assets. This is a simple process if the regular CVE report can run against the captured asset baseline.

Assess the ‘As Is’ risk state along with the compliance against a framework. Then the decisioning on where to go next will be risk-led. Do not follow an assurance process slavishly from left to right. It could take years to achieve compliance that way. Instead, identify where proactive remediations can be delivered and get going with them swiftly. The outcome must be a reduction in the risk being carried by the enterprise – to a level that the Senior Risk Owners and Steering Group feel is tolerable.

There must be one end-to-end OT security project. The same Sponsor, Steering Group and Project Manager owning the process and outcomes and managing across all of the affected functions in the enterprise. Governance, ownership and prioritised planning with a rigorous drive. And engagement of the key actors who own or use each machine and swift at-the-machine action.

Set up a project with five workstreams

OT requires a change project with technology involved. It is not a technology problem, as in the IT world. Human factors are key; the users of the OT equipment have never had to consider the security aspect before. They will have had safety drummed into them and now security must be handled the same way. The sign under the mirror in the washroom today says, “this person is responsible for safety”; now security must be added to that message.

Five streams of intervention are required – miss any of these and you will not have a secure OT estate.

Technical
Starting with the most obvious, and to manufacturing or engineering companies, this will be second nature. Build a bridgehead by identifying two key roles: the PLC engineer (control systems engineer, automation engineer – the person who keeps the production lines running) and the PC engineer (Wintel expertise, and likely from the IT department). You cannot easily recruit for these roles, rather they are more likely grown in the organisation to become the new OT assessment, remediation then business-as-usual cybersecurity technical team.

They must carry out a specific set of tasks on the OT system. The hardest part is scheduling that work, and negotiating for time, perhaps in a maintenance window or factory shutdown period. This immediate short-term work delivers most of the value. And it does not cost much, just the cost of two staff per site.

Do not get distracted by the exciting expensive long-term solutions. Yes, they are needed but the Project Manager must in parallel manage the enterprise level responses to OT security. Such as a dedicated OT network with segregations, industrial strength sheep dip devices, automated monitored remote connections. But these solutions can take time and money to implement. They must be managed so as not to distract from the immediate at-the-machine improvements.

People change
Possibly the hardest stream, as this needs business change expertise. But there is no point in strengthening the technical controls if the people are not bought into the journey. Security is only as strong as the people who have to live with it. If new security measures are irksome to the workforce, they will find ways to circumvent them. So, discuss how the new measures will work in practice. If a robot has never had an operator password in the past, does it need one now? Can enough control be exercised just by having the admin password set, and if this has to be shared by more than one person, for instance to cover shifts, how to control such that knowledge does not proliferate. Perhaps a robot can be caged with badge access rather than password protected – if that answers the security need, but in a manner that does not slow down the operators.

Making the business change job simple, the project team must firstly drive Awareness into the workforce. Bring the operators, supervisors, manufacturing managers, shift leaders together to brief them on the new world threats and the reasons why security is now part of everyone’s jobs. Then build on this regularly with at least monthly interventions to create the Desire in the workforce to engage and to take ownership in their areas. Build Knowledge by training them in new OT policies and the remediation work that is underway. This should then be continually progressed such that the workforce attains the Ability to work in this new world and regular Reinforcement is covered. For the full benefit of OT security coverage such a change project must be implemented.

Policy
Likely the existing IT policies will be insufficient to use unchanged for OT. Also, it is useful to create specific policies on OT usage, removable media, third party management and then to train the workforce in these policies so everyone knows how to work in the new world of OT security.

Physical
Often OT controls cannot be directly provided, but a layered ‘defence in depth’ approach is needed. This starts with the physical aspects of access to the site, to the production line and to the machine.

Supply chain
Older equipment may not have a ready supply of spares. Global supply chains mean that the cheapest equipment may come from countries that are not aligned to our security needs. Attention to procurement and to the routes that equipment can take to enter our sites is key to avoid vulnerabilities coming in through the front door.

Checklist: Key remediation actions

If you were to get going on proactive remediation and get the swiftest protections in place, while the lumbering assurance project progresses, what would you do?

Build a configuration management database (CMDB) of your OT assets. This allows asset management, change control, vulnerability control and ensures you are on top of your estate.

Apply least privilege account access – password protecting your devices and removing shared access as far as possible, removing the manufacturer default password that is in place in many systems and the printed password that often sits on screens.

Implement an OT anti-malware capability using a tool that can scan across more ancient versions of Windows and scan every system.

Build or implement a sheep dip solution – a simple locked down standalone computer running a virus checker and allowing a range of removable media to be inserted. The OT policy should state that all media are checked in transit from office to factory floor and again in reverse.

Build an effective third-party management process and ensure that site staff implement it – control externals and the computers and media that they bring on site to avoid malware coming from that source.

Review for internet connectivity, both connected systems, in which case firewalls or patching may be needed, and unknowns such as hidden modems inside cabinets. Also control external connections for maintenance purposes.

Implement backups at program, configuration and PC-image levels and test for recovery.

Run a tabletop exercise simulating an OT incident with cross-functional participation, including all levels of governance, and their alternates.

What to avoid

Some controls are hard or impossible to implement today. Protective monitoring in a mixed age, multi supplier estate is an example. Also, device to device authentication. In IT security, patching is key, but in OT updating firmware and operating system levels may lead to the OT system becoming inoperable, or one machine failing to communicate with the next. With availability as the most important attribute in OT, nobody wishes to bring down a previously working production process. In OT all systems are production systems. There is no test environment to trial changes before committing to production. So instead of updating firmware, find other compensating controls.

Do not pin all remediation measures on the strategic corporate projects. They will come along, but in the meantime take the tactical actions detailed here to afford immediate protections at a low implementation cost. Overall, follow the risk thread.

More on: Project One
United Kingdom
Company profile
Project One is a United Kingdom partner of Consultancy.org
Partnership information »
Partnership information

Consultancy.org works with three partnership levels: Local, Regional and Global.

Project One is a Local partner of Consultancy.org in and United Kingdom.

Upgrade or more information? Get in touch with our team for details.