THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Joe Mariscal, Director of Cybersecurity and Compliance, RyersonJoe, Director of Cybersecurity and Compliance, has over 22 years of information security experience, with 15 years focused directly on cybersecurity. He specializes in managing Cyber resilience and multilayered defensive platforms. He holds an MBA, a Masters in Cybersecurity, and certifications in CISSP and CISM.
Recognizing Joe Mariscal’s deep expertise in cybersecurity and compliance, this article explores the critical challenges of securing legacy Operational Technology (OT) in manufacturing and offers strategic approaches to mitigate risks, ensuring operational resilience in an evolving threat landscape.
Securing OT and IIOT Systems for a Resilient Future
The world runs on machines, often referred to as Operating Technology (OT). These include Programmable Logic Controllers (PLC’s), Human Machine Interfaces (HMI), Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) systems and Computer Numerical Control (CNC) systems. These machines support power plants, water systems, goods manufacturing and food development, just to name a few. They are ubiquitous and it is no surprise threat actors have begun targeting them, causing significant supply chain impacts and forcing companies to react.
Managing and securing OT and IIOT devices is a resource-intensive but essential part of risk mitigation
As IT systems have become more secure, threat actors have figured out they only have to interrupt the supply chain to have a major effect on an organization. Threat actors have turned to easier targets with often better outcomes due to the criticality and difficulty in restoring OT. These systems are hard to patch, usually end-of-life, unsupported and often cost-prohibitive to upgrade.
A simple query on Shodan shows organizations frequently expose these systems to the open internet, increasing malicious opportunity. Disabling an OT device can result in anything from minor outages to severe equipment damage and production loss, or a devastating injury or loss of human life. Also entering the market is Industrial Internet of Things (IIoT), those little boxes that measure criteria like temperature, humidity and vibration or controls fire systems, security panels and the like. These devices are often rarely patched and difficult to harden.
Worsening the situation, many run on outdated operating systems like Windows XP or Windows 7, and occasionally even Windows 98 and NT 4 are seen in production. These systems often cannot run agents such as Endpoint Protection & Response (EDR), as either EDR is no longer supported or agents can introduce unpredictability into the system.
And if that was not enough, most of the devices need some sort of legitimate remote support. Vendors offer a wide array of remote support capabilities. Many of these devices require support services that use local VPN routers or employ remote management tools like TeamViewer, which may not have a strong patch and update cycle.
The threat actors know OT is a prime target, as Robert Lemos from Dark Reading notes, "Because of the criticality of remaining operational, industrial companies and utilities are far more likely to pay, attracting even more threat groups and a focus on OT systems."
With all these concerns, it can be hard to know where to start to secure OT and IIoT and mitigate risks in the organization. Understanding the critical data in your network, often called crown jewels and how this critical data integrates with the rest of the company allows you to rank your Operating Technology and Industrial Internet of Things appropriately, especially with limited budgets and teams.
What are some of the best practice ways to protect these systems.
• Crown Jewels – Knowing what your critical data is and how it connects to the OT environment.
• Know what you have – Use Cyber Asset Management tools designed for OT.
• Segment and firewall – Use separate physical stacks or logical VLANs categorized by vendor or device class to segment and protect from the internet.
• Change default passwords – Adding a security layer and barrier to compromise is crucial.
• VPN with Multi-Factor Authentication – Secure connections and strong authentication limit access to OT devices.
• Logging – Always log and monitor traffic to know your baseline, alerting for Indicators of Compromise.
• Control the remote access tools – Use strong authentication and logging for remote access tools.
• Use a Mirrored server – Employ a mirrored file or jump servers with appropriate controls on OT segments.
• Patch when possible – Patch OT devices when feasible.
• Penetration testing – Use pen testing tools and companies specializing in OT devices.
Implement least privilege principles by limiting access to only the essential ports, protocols, and IP addresses required for operations. Any deviations from these controls should be promptly investigated.
Managing and securing Operational Technology and Industrial Internet of Things devices can be a resource-intensive, multiyear project. However, it is essential to invest in and prioritize these efforts as they play a critical role in your overall risk mitigation strategy. Properly addressing the unique security requirements of OT and IIoT environments helps to protect your infrastructure, maintain operational continuity and prevent potential vulnerabilities from being exploited. Ensurung the necessary resources to managing and securing these technologies is a vital component of a comprehensive risk management approach.