The air gap is a memory: securing operational technology in the connected plant
Energy operators digitized their industrial estates for efficiency and inherited an attack surface their security programs were never scoped for. The fix starts with visibility, not firewalls.
Every operational-technology security conversation still begins with someone invoking the air gap — the comforting idea that the control systems running turbines, substations, and pipelines are physically separated from the networks attackers can reach. In the estates we assess, the air gap is a memory. Remote-maintenance links for vendors, historians feeding cloud analytics, engineering laptops that commute between corporate and control networks, cellular modems installed during a project and never decommissioned: the connections exist because the business wanted the data. The exposure came with it.
Why IT playbooks fail in the plant
The instinct of every security organization confronting OT is to extend its IT playbook downward, and the plant rejects it like a transplanted organ. You cannot patch a controller mid-run when the process it controls cannot stop. Scanning fragile legacy devices can crash them. Endpoint agents have no host to live on. And the priority order inverts: in IT, confidentiality leads; in OT, availability and safety outrank everything, because failure modes are physical.
Effective OT security therefore looks different. Passive network monitoring instead of active scanning. Segmentation designed around process zones and conduits rather than org charts. Compensating controls — strict access brokering, protocol-aware detection, hardened jump paths — where patching is impossible. And change windows negotiated with operations, not imposed on them.
Detection is the highest-leverage investment
Most industrial intrusions are not zero-day wizardry against controllers; they are ordinary IT compromises — phished credentials, exposed remote access — that dwell, pivot, and eventually touch the OT boundary. That dwell time is the defender’s gift. An operator with real visibility into its control networks — who talks to what, which commands are normal, what an engineering workstation should never do — can catch the traversal long before it becomes a process event.
Yet detection is precisely where OT programs are thinnest. Budgets go to segmentation projects that take years, while the network’s actual behavior goes unwatched. The unglamorous move — instrument first, then segment with the knowledge you gain — delivers protection years earlier, and the traffic map you build becomes the segmentation design.
Regulation is catching up to the risk
From NERC CIP’s maturing enforcement in North America to NIS2’s supply-chain and incident-reporting duties in Europe, critical-infrastructure operators face a reporting and evidence regime converging on the financial sector’s. The practical consequence: “we didn’t have visibility into that network” is transitioning from an explanation to an admission.
What to do about it
Start with an honest inventory of every path between your corporate estate and your control systems — including the vendor connections your contracts allow and your diagrams omit. Put passive monitoring on the critical zones this quarter, not after the segmentation program lands. And run one exercise a year in which the incident begins in IT and the question is how long it takes anyone to notice it reaching for the plant. The answer will set your priorities better than any framework document.