What Is OT Security?

Operational technology (OT) security protects the systems, networks, and access used to monitor or control physical processes. That includes industrial control systems (ICS), SCADA, programmable logic controllers (PLCs), engineering workstations, building controls, field devices, and the infrastructure connecting them.

What does OT security cover?

OT cybersecurity extends beyond individual industrial devices. It includes the systems around them, the paths into the environment, the communications between assets, and the evidence available when something goes wrong.

01

Assets

Controllers, servers, workstations, sensors, gateways, field devices, and supporting systems.

02

Networks

Communication inside OT and between operational systems, IT, remote sites, vendors, and external services.

03

Access

Engineering access, remote administration, credentials, third parties, and paths between IT and OT.

04

Security operations

Monitoring, detection, investigation, threat hunting, incident response, recovery, and validation.

How is OT security different from IT security?

Many cybersecurity controls apply to both. OT changes the operating constraints around those controls.

IT securityProtect computing and data.
  • Endpoint agents are commonly available.
  • Patching and restarts are routine.
  • Isolation is often a viable response.
  • Host telemetry is usually a major evidence source.
OT securityProtect cyber systems and the physical process.
  • Some assets cannot support conventional agents.
  • Maintenance may depend on operational windows.
  • Isolation can affect production or service delivery.
  • Network evidence can carry more weight when host telemetry is limited.

OT security is not a separate form of cybersecurity. It applies cybersecurity controls where performance, reliability, safety, equipment lifespan, and operational continuity can change how those controls are deployed.

What does an OT security platform do?

There is no single definition of an OT security platform. Products can focus on different jobs, so the useful question is what the platform actually does, what telemetry it needs, and how it fits with controls already deployed.

Asset visibility

Identify systems and understand what is present.

Network visibility

Observe how systems communicate and where traffic crosses boundaries.

Threat detection

Surface known malicious activity, suspicious behavior, or changes that warrant investigation.

Investigation

Connect a detection to the evidence needed to determine what happened.

Threat hunting

Search available telemetry for activity existing detections may not have surfaced.

Incident analysis

Establish sequence, scope, affected systems, and the evidence supporting the conclusion.

AtlasCyber

Use CrunchSense, existing tools, or PCAP, NetFlow, and Zeek to support detection, investigation, threat hunting, forensics, campaign analysis, and reporting. Operators retain control of consequential actions.

Explore AtlasCyber

How does OT network security work?

OT network security controls and monitors communication between operational systems and the networks around them. Network visibility becomes especially useful where endpoint telemetry is limited.

Access paths
Enterprise IT
Remote access
Vendor access
Passive view
OT network
Engineering
HMI
PLC
Field devices
TrafficProtocolsSessionsTimingEvidence
What is communicating?

Which systems, protocols, and segments are involved?

What changed?

Did a new host appear or established behavior move somewhere unexpected?

What crossed into OT?

Did remote access, a vendor path, or shared infrastructure cross the boundary?

What evidence remains?

Can investigators return to the traffic that produced the signal?

Passive monitoring can provide network visibility without actively probing the operational systems being observed. Coverage still depends on architecture, collection points, protocols, and retention.

Explore Network Detection & Response

What happens after an OT security alert?

Detection identifies something worth examining. It does not automatically establish whether the activity was malicious, how far it went, or what the operator should do next.

01Detection

Something in the available telemetry needs attention.

02Evidence

Find what supports, contradicts, or changes the initial signal.

03Scope

Determine which systems and surrounding activity are actually involved.

04Verdict

State what the evidence supports and what still remains unknown.

A severity score is not the same thing as an investigated verdict.

Explore Alert Investigation

Where does threat hunting fit into OT security?

Not every intrusion produces a useful alert. Threat hunting starts with a question and searches the available evidence for activity existing detections may not have surfaced.

Unexpected zone trafficUnusual remote accessKnown indicatorsRelated techniques
Explore Threat Hunting

How are OT security incidents investigated?

Once an event becomes an incident, the question expands from whether something happened to how far it went.

01How did the activity begin?
02Where did it move?
03Did anything cross between IT and OT?
04Which systems were actually affected?
05What does the available evidence support?
Explore Host & Network Forensics

What should an OT security program prioritize?

There is no universal OT security checklist. These five questions expose common gaps without assuming every environment uses the same architecture or tooling.

01What is connected?

Know the assets, network paths, remote connections, and dependencies in scope.

02Who can reach it?

Account for operators, administrators, vendors, engineering access, and IT/OT paths.

03What can you see?

Know which network, endpoint, firewall, identity, log, and other telemetry is available.

04Who investigates?

Monitoring creates value only when someone can determine what the signal means.

05What evidence survives?

Retention determines what can still be reconstructed when an incident is investigated later.

OT security questions, answered.

What does OT mean in cybersecurity?

Operational technology refers to programmable systems and devices that interact with the physical environment or manage devices that do. OT cybersecurity focuses on protecting those systems, their communications, and the operations they support.

What is the difference between OT, ICS, and SCADA?

OT is the broader category of technology used to monitor or control physical processes. Industrial control systems are a subset of OT used for industrial control. SCADA is one type of control system used to supervise and manage distributed processes.

How is OT security different from IT security?

IT and OT use many of the same cybersecurity principles. OT environments can add constraints around availability, safety, equipment lifespan, maintenance, active scanning, and the ability to deploy endpoint security.

What is an OT security platform?

An OT security platform is software used to support one or more operational technology cybersecurity functions such as asset visibility, OT network monitoring, threat detection, vulnerability management, investigation, threat hunting, or incident response. Capabilities vary by platform.

Can OT networks be monitored passively?

Yes. Passive network monitoring observes traffic without actively probing the devices being monitored. What it can see depends on network placement, traffic collection, protocols, encryption, and the telemetry available.

Primary guidance.

The definitions and operational distinctions on this page are grounded in primary government guidance for securing operational technology.

NISTSP 800-82 Rev. 3, Guide to Operational Technology (OT) SecurityOpen source ↗
CISAPrinciples of Operational Technology CybersecurityOpen source ↗

See what your OT network evidence can tell you.

Bring the traffic or telemetry you already have. See how CrunchAtlas carries suspicious network activity into an investigated case.

Visibility and conclusions depend on network architecture, available telemetry, collection points, retention, integrations, protocol support, and approved scope. Consequential actions remain operator controlled.