Why OT Security Keeps Missing The Real Risk

Recent attacks targeting U.S. water and wastewater facilities have put operational technology (OT) security back in the spotlight.

For many organizations, the immediate concern is preventing unauthorized access to industrial control systems and internet-connected devices.

But during the most recent episode of Ready.Set.Midmarket!, OT security experts Joe Weiss, managing partner at Applied Control Solutions, and Mike Carr, field CTO at Xona, argued that the industry’s biggest challenge runs deeper than exposed controllers or insecure remote access.

According to Weiss, OT security efforts often focus on protecting networks, but can overlook the physical systems that drive operations.

“The real damage doesn’t come from network,” Weiss said, “It occurs from equipment.”

Weiss, who helped establish the control system cybersecurity program for the electric utility industry and contributed to the ISA/IEC 62443 cybersecurity standards, said there remains a persistent disconnect between network security teams and engineers responsible for operational systems.

That divide, he argues, stems from fundamentally different priorities. Security professionals are trained to limit access and reduce risk. Engineers are trained to maximize reliability, availability, and safety.

“The engineers are trying to do exactly the opposite,” Weiss said. “That’s the culture problem that’s pervasive everywhere.”

Carr said many OT environments were never designed with modern cybersecurity requirements in mind. Rather, industrial systems were built to keep operations running, often long before these organizations had to factor in internet connectivity, identity management, or secure remote access.

“The job needs to get done,” Carr said. “If the only way the person in the field knows how to reach that PLC is to poke a hole in a firewall, that’s what they’ve been doing,”

As attackers shift focus toward critical infrastructure, Carr believes organizations must embrace a zero-trust mindset while still respecting the operational realities of industrial environments.

However, both experts cautioned that better network security alone will not eliminate OT risk.

Weiss argued that OT security efforts often focus on securing networks and data traffic while overlooking the sensors, actuators, pumps and valves that control physical processes.

“If you can’t trust what you measure, it doesn’t really matter what you do from there,” he said.

For midmarket teams operating industrial systems, both experts agreed that technology alone if not enough. Improving OT security requires greater collaboration between cybersecurity professionals, network teams, engineers, and technology vendors.

When asked what organizations should be able to demonstrate to prove their OT security programs are effective, Carr pointed to visibility and accountability.

“If I don’t see who’s doing what, when, if I don’t have auditability, if I can’t separate identity from authorization and access, it’s not good enough,” he said.

Weiss said that an effective IT security program should prove “the system is reliable and safe," he said. “And I use the word ‘system,’ not network,” he added.

He cautioned that boards and executive teams often discuss cyber risk in terms of networks and security controls while paying less attention to the operational equipment that actually delivers water, powers facilities, or drives production.

“Networks are just support,” Weiss said. “The biggest thing they have are pumps and valves and relays and transformers and turbines.”

Watch the full conversation to hear Weiss and Carr discuss the disconnect between cybersecurity and engineering teams, the challenges facing critical infrastructure operators, and actionable advice organizations can take to strengthen OT security.

The full episode can be watched on YouTube and heard on Spotify and Apple Podcasts.

https://www.youtube.com/embed/SPMDKJVDjQ8?si=4FkMwimv4kk1c8H0

Previous RSM! episodes are here.

https://player.simplecast.com/4c907eab-87fc-4e8d-a325-a444bb9f6cf8?dark=fal