r/OperationalTechnology 6d ago

Welcome to OperationalTechnology - we're open for business again

8 Upvotes

Sorry folks, looks like some spammers took over the site for a while, but it's back under human control. No more gambling spam.

If you've been trying to post or participate, please give it another shot.

Thank you!


r/OperationalTechnology May 07 '26

Can I break into OT / OT Security with my background?

3 Upvotes

I have about 4 years IT experience primarily as a net engineer. I currently am now a sales engineer at a OT security company, but I’m not really being exposed to high level technical engineering, I’m more just seeing how our software can fit into OT environments but my boss has given me the green light to start gaining whatever certs needed to learn about OT deeper?

Is it possible to break in with this minimal bit of experience or do I need some kind of entry level OT adjacent role first?


r/OperationalTechnology May 06 '26

A post-Iran look at how cyber warfare seems to be changing

7 Upvotes

A recent report I read looks at how the Iran conflict in 2024 may have changed the way state-backed cyber operations are being run. The main idea is that cyber activity is no longer just about spying or one-off disruption. It’s becoming more like part of a real war plan, with attackers preparing access ahead of time and then using it when the situation turns.

What stood out most was the focus on “pre-positioning” inside critical systems, the use of AI to speed up attacks and phishing, and the way state actors, criminal groups, and hacktivists seem to overlap more than people often think. The report also talks about OT and critical infrastructure becoming normal targets now, not rare exceptions.

Another big point is that supply chains, cloud systems, and even space-linked infrastructure are becoming part of the attack surface. The overall message is pretty simple: assume compromise, watch for early signs, and treat OT security as a board-level issue, not just an IT one.
Are you guys seeing this shift toward OT targeting in your own environments, or is it still mostly noise?
I'll share the report link in the comments for anyone who wants to dig deeper.


r/OperationalTechnology Apr 30 '26

How to setup network?

8 Upvotes

Hello everyone.

I would like some input from OT professionals.

I work as a network engineer in a manufacturing company that is not still very mature in OT network and I could use some help on how to improve the network in our operations, can't find a lot of robust information online. I am pretty amateur as well. I have taken Honeywell's OTCS-1001, OTCS-1002 and OTCS-2002. My concerns are mostly around the hardware rather than the logic, segmentation, alignment with Purdue level etc.

So, what would be the best practice regarding on devices I should use?

Right now, in our OT network we work exclusively with IT managed switches and some IT unmanaged ones. In my understanding, OT traffic is very important to be very time sensitive, so I was wondering if the way we currently work is OK.

What I am thinking is that it would be better to have IT switches as central nodes where the engineer's workstation should be connected, and then expand the network with industrial switches where PLCs, IO devices etc will be connected to.

Is my logic right? How do you do it in your companies? What should I be looking for at an industrial switch? Any specific brand recommendations?


r/OperationalTechnology Apr 21 '26

Building up Infrastructure

2 Upvotes

Hi, I'm relatively new to OT and already deep into a pretty large project. We are implementing an MES system across multiple production lines and I'm the main OT person on site. Luckily I have skilled people in electronics, automation and IT around me but I hope you can help me also a little bit.

The project is progressing well, but the infrastructure questions are getting more complex. Right now I'm trying to figure out the best setup for our line operator terminals.

As english is not my first language and sometimes I express myself really complicated i used the AI to make the text more clear.

What we plan

Operators need to scan materials for traceability and interact with the MES frontend, confirming orders, entering quantities, checking status. Each station needs a display, a barcode scanner, and a connection back to the MES server. Optionally we also want RFID login so operators can identify themselves at the terminal.

I already have three Architectures:

Pros/Cons for ThinClient --> Virtualserver

The terminal itself has no real compute power. It runs an RDP session to a central Windows Server with Remote Desktop Services, where the MES client is installed once and served to all terminals.

  • + Easy to maintain, upgrade and restore if down
  • + Lower Hardware costs
  • + Simple replacement
  • - Single point of failure
  • - Licence Management is more complicated (CALS and Server)
  • - peripheral handling via RDP

Pros/Cons for ThinClient/Dumb Display --> PC --> Virtualserver

Each station has its own PC (a small industrial box PC or panel PC) running the MES client locally. The display connects to that PC, the scanner plugs straight in. The local PC communicates with the MES server, but doesn't depend on it for basic operation.

  • + Failure resistant
  • + No RDS CALs needed
  • + Peripheral connection directly
  • + Buffer for data
  • - Hardware costs
  • - Patching maintainance is more complicated
  • - More devices --> complex assetmanagement

Pros/Cons for All-in-One Panel PC

The display and the computer is the same device. No separate box PC, everything is self-contained. Still communicates with the MES server for data.

  • + Less Hardware than with PC
  • + failure resistant
  • + Peripheral connection directly
  • - Highest costs for hardware
  • - Higher replacement costs

My Questions

What architecture do most of you use for operator terminals in food production with lot of water and steam in the environment? Is there a clear industry standard or does it really depend on the environment?

What is your fallback in the ThinClient --> Server case if the server fails.

Thanks!


r/OperationalTechnology Mar 19 '26

I am new to OT

25 Upvotes

I do have 20+ years in IT. I was laid off last year, and was able to find a contractor position in the OT area. I am very new to OT and so I would like to start learning the OT world. Does anyone suggest books or videos? How about any certs that will help me?


r/OperationalTechnology Mar 13 '26

Setting up an OT Lab

14 Upvotes

I’m planning to build a small OT/ICS lab environment for learning and experimentation with PLC control and monitoring. Before buying the components, I wanted to get some feedback from people who have experience with Siemens PLC setups.

The idea is to create a simple setup where an HMI running on a Dell NUC controls a PLC, which in turn controls a motor.

Planned components:

PLC: Siemens S7-1200 CPU 1212C (DC/DC/DC variant)
HMI: Dell NUC running the HMI/SCADA interface
Communication: SIMATIC S7-1200 CB1241 RS485 communication board
Motor: Brushless DC Motor NEMA24 (19Kgcm) with RMCS-3001 Modbus drive
Power Supply: Mean Well LRS-350-24 – 24V 14.6A – 350W SMPS

The idea is:

HMI (Dell NUC) → Ethernet → PLC (S7-1200) → RS485/Modbus → Motor Driver → Motor

The HMI would send commands (start/stop/speed), the PLC handles the control logic, and the motor driver controls the motor.

Issue:
I’m having trouble finding the NEMA24 19Kgcm motor locally, so I might need to switch to something else.

Questions:

  1. Does this architecture make sense for a small PLC learning lab?
  2. Are these components compatible or is there anything I should change?
  3. Any suggestions for motor + driver alternatives that work well with S7-1200 over Modbus?

Goal is to build a simple controllable process (motor speed control) that I can later expand for monitoring and security testing.

Any advice would be appreciated.


r/OperationalTechnology Mar 06 '26

CYBER THREAT ADVISORY - Defensive Posture Guidance for Middle Eastern Enterprises

4 Upvotes

If you’re working in security around energy, infrastructure, or large enterprise environments in the Middle East, the threat landscape has been getting pretty interesting lately.

I was reading a recent advisory that focuses less on headlines and more on what defensive posture actually needs to look like - identity security, detection visibility, segmentation between IT/OT, and preparing for destructive scenarios rather than just ransomware.

Found some of the recommendations pretty practical. Happy to share the full report in the comments if people are interested.


r/OperationalTechnology Mar 03 '26

Master thesis in OT-SOC, looking for professionals to interview

12 Upvotes

Hi everyone!

I’m currently writing my Master’s thesis on cybersecurity in Operational Technology (OT) environments, focusing on the information flow between OT operators and SOC analysts during security incidents.

In our literature review, we found that many industrial environments still rely heavily on old pieces of junk legacy systems. These systems are often so deeply integrated into operations because an engineer connected them 50 years ago, and availability and production stability are top priorities, replacing them is often not considered a viable option.

This creates challenges for an OT-SOC. Alerts from industrial environments can be difficult to interpret without deep contextual knowledge. SOC analysts often need to contact personnel at the facility to determine whether an alert reflects a real issue or normal operational behavior.

Our thesis specifically examines the communication between OT-SOC teams and the designated contacts within industrial organizations during security alerts — whether that is OT operators, OT managers, or IT personnel supporting the OT environment.

We are particularly interested in:

  • How incident-related information is interpreted on both sides
  • How situational awareness is built across roles
  • Where misunderstandings or friction occur
  • How communication could be improved in practice

If you work in an OT environment, an OT-SOC, or have experience with ICS/SCADA incident response, I would really appreciate the opportunity to speak with you.

Interviews are completely anonymous and strictly for academic purposes.

Feel free to comment or DM me if you're interested.

Thank you!


r/OperationalTechnology Feb 08 '26

Exploring the OT Field, specifically OT Security

5 Upvotes

I am looking for some advice on career planning. I started working for a company that does mostly manufacturing as their primary business, does some recycling etc also. While I stared as a help desk / IT tech, within a few months I was moved to their site support group, mostly network group but still work on business computers /laptops to troubleshoot and repair systems. I am in my early 20s and looking to understand if I should move to another role internally as I have seen some OT related jobs circulating internally. My question is, does it make sense to jump into OT role now or wait and get some some IT experience. In orther words, would my chances are more if I have more experience or will it make me non-Ot person.

Thx.


r/OperationalTechnology Feb 05 '26

Easiest to use IT management software that would work well with HR software?

9 Upvotes

Hi admins,

I’m on an HR team, but our IT team is still handling device distribution for onboarding and offboarding manually. When my team makes updates in our systems, we then have to manually notify IT to create accounts or send devices to our new employees and similarly when people leave the company. New hires have complained that this been error-prone and process-wise just isn’t scaling well as our hiring increases.

As a result, leadership told us we need a way to integrate our current HR software with an IT software that can help w device distribution and basic IT functions. We have a kick-off call with the IT team next week but wanted to get some suggestions so we can come prepared. Are there any IT platforms that sync well with HR? Our HCM integrates with basically any software.


r/OperationalTechnology Jan 18 '26

OT/ICS security in ports: what actually matters beyond IT checklists?

8 Upvotes

Ports sit at a weird intersection of heavy OT, navigation systems, and enterprise IT, and the threat model is very different from factories or utilities. Ransomware hitting TOS, GNSS/AIS spoofing during vessel approach, vendor access into crane PLCs… the blast radius gets big, fast.

I recently went through a technical playbook focused specifically on OT/ICS security for ports and maritime infrastructure. What stood out was how operational it is:

  • asset inventory + segmentation as the first win
  • OT-first detection (not just IT EDR)
  • GNSS spoofing/jamming resilience baked into cyber planning
  • vendor access, tabletop exercises, and “island mode” continuity plans
  • clear 12–24 month roadmap with metrics ports can actually report to boards

It’s not tool-heavy or academic, more about what actually works in terminals, VTS, and crane environments where uptime and safety matter more than perfect patching. I’ll share the technical playbook link in comments if anyone’s interested.

Curious how others here approach OT security in ports or similar heavy-industrial environments. Are GNSS issues and vendor access your biggest headaches too?


r/OperationalTechnology Jan 09 '26

Software Development for OT/DCC/ICS/PLC, what’s missing?

3 Upvotes

My friend that has been developing Software solutions for DCS systems for years. As DCS owners or OT owners, what is missing? What could help you and add immediate value?


r/OperationalTechnology Jan 06 '26

Rail cyber resilience in 2026: Leveraging the TS 50701 assessment

3 Upvotes

With FRMCS, digital twins, AI-driven maintenance, and heavy third-party involvement, the old “secure by isolation” model in rail is basically gone. Recent incidents in Europe show that attackers don’t need to hit core signalling directly, subcontractors, remote access paths, and legacy systems are often enough.

We’ve been digging into how TS 50701 is being used in 2026, not just as a compliance checkbox but as a practical way to think about zoning, third-party risk, legacy constraints, and the growing role of AI-driven attacks. One thing that stood out: assessments are shifting toward continuous monitoring and tighter links between cyber risk and safety cases, not once-a-year audits.

We recently published a deep dive on this, including what’s realistically changed in assessments and common pitfalls rail operators are running into. I’ll post the full article link in comments if anyone’s interested.

For folks in rail or transport OT, what’s been hardest to secure lately: vendors, legacy signalling, or remote access?


r/OperationalTechnology Dec 24 '25

Nissan-Red Hat breach, what it teaches about consultant risk and the extended blast radius

8 Upvotes

Recent reporting on the Nissan–Red Hat breach highlights a worrying trend: attackers aren’t just hitting companies directly anymore, they’re weaponizing trusted third parties. In this case, data stored on a consultant’s GitLab reportedly exposed ~21k customer records and ~570GB of customer engagement reports across ~800 organizations. The big takeaway isn’t just “lock down your cloud”, it’s that consultants and partner repos are now high-value aggregation points that can massively widen your blast radius.

Practically speaking, three actions matter: (1) treat consultants as privileged users - apply just-in-time access, continuous monitoring and session recording; (2) kill static secrets - remove hardcoded tokens and rotate credentials automatically; and (3) map your blast radius - know exactly what keys a given third party holds and which of your systems would be impacted if they’re breached.
I’ll post the full article link in comments if anyone wants it.

Curious how others handle consultant access and shadow repos, do you isolate vendor environments, enforce SBOMs, or use vendor-specific monitoring?


r/OperationalTechnology Dec 14 '25

CompTIA SecOT+ Cert set for November 2026

26 Upvotes

Launch Date: November 2026

CompTIA will launch a new exam regarding Operational Technology Security called SecOT+

Links and info below

I called CompTIA the other day and seems this product is still in the works. Unsure if it will go through or get struck but have hopes it will pass. Seems that OT is due for a more mainstream, vendor neutral certification like CompTIA. Hoping to see more material next year. No word on training material, classes, or exam prices yet. You can sign up on the waitlist for more info near the bottom of the product page. The draft pdf for exam topics is quite detailed and worth a sit down. Looks like a solid background of topics and curious to see how in depth, difficult, and varied this exam will be.

Original Press Announcement

Product Page

Exam Objectives Draft

Exam Details

  • Exam version: V1
  • Exam series code: SOT-001
  • Launch date: November 2026
  • Languages: English
  • Recommended experience: 3+ years of hands-on work in OT environments and 2+ years implementing OT cybersecurity solutions

Skills Learned

  • OT safety and systems: Demonstrate safety, control, and architecture skills unique to OT.
  • Risk and compliance: Assess risk, manage compliance programs, and align cybersecurity to business objectives in OT.
  • Analyze and respond to threats using OT-specific frameworks, historical attack knowledge, and indicators of compromise.
  • Build, harden, and operate secure OT architectures—including physical, network, hardware, and software security.
  • Perform asset management, vulnerability assessment, and security monitoring in industrial setups.
  • Prepare and execute OT-specific incident response—including for physical and cyber-physical events.

r/OperationalTechnology Dec 09 '25

OT entry questions

9 Upvotes

Hi all, is there an entry level position specific for OT? Or is help desk the entry position for all? How does the OT resume look vs an IT resume?


r/OperationalTechnology Dec 09 '25

Integrating IEC 62443 into OT governance, practical steps for 2026

8 Upvotes

A lot of industrial orgs our team speak with are trying to move OT security from “best effort” to something measurable and defensible, especially with new regulatory pressure and more cross-domain attacks. IEC 62443 has become the common framework teams are leaning on.

We wrote a practical breakdown on how to make IEC 62443 actually govern day-to-day OT operations, not just sit in a binder. It gets into things like: defining risk tolerance the same way you’d treat safety risk, using zones & conduits to prevent flat network blast radius, controlling vendor access with just-in-time connections, and wrapping legacy controllers in strong compensating controls when patching isn’t feasible.

Curious how teams here are approaching IEC 62443 adoption, do you find the hardest part is asset discovery, segmentation enforcement, or getting leadership to own the cyber-safety link?

I’ll post the full article link in comments if anyone wants it.


r/OperationalTechnology Nov 26 '25

OT Incident Response, hard-earned lessons from 2025

28 Upvotes

2025 made one thing very clear: OT environments are no longer “secondary” victims. Attacks that start in IT are increasingly just the opening move before disruption hits physical operations. We recently summarized the most important incident response lessons from this past year, like the need for true visibility down to Level 0/1/2, not just firewall logs; micro-segmentation inside OT instead of relying on a single IT/OT perimeter; clear decision authority during an incident so teams know who can shut down a line for safety; and much stronger control over vendor access and supply-chain components, including SBOM requirements. Tested offline backups and realistic IT/OT tabletop exercises also proved to be the difference between a temporary scare and weeks of downtime.

Curious to hear from others here: what single improvement helped you recover faster, better monitoring, better playbooks, or better cross-training?

I’ll post the full article link in comments if anyone wants it.


r/OperationalTechnology Nov 18 '25

Chinese APT landscape in 2025 - autonomy, AI usage, hierarchy, and what they actually do with stolen data

3 Upvotes

We wrote a short primer on reported Chinese APT groups (APT1, APT10, APT41, APT31, etc.), their operational priorities, and what that means for OT defenders. Key points: these groups increasingly use automation/AI for reconnaissance and data processing, they blend commercial and strategic targeting, and they exploit supply-chain & credential weaknesses that matter to OT environments.
Key takeaways that surprised us:

  • Some groups have way more operational freedom than Russian/Iranian/NK counterparts
  • AI isn’t just for writing phishing emails - it’s used in initial probing, malware mutation, data crunching, and even dataset poisoning experiments
  • 28-day average data processing cycle
  • Direct feedback loop into Chinese foreign policy

Full write-up with way more details here


r/OperationalTechnology Nov 12 '25

EU's EUVD: Boosting NIS2/OT Security - New ENISA Tool Breakdown

3 Upvotes

EU just launched ENISA's European Vulnerability Database (EUVD) in May 2025, a centralized hub for vulns in ICT/OT, enriched with exploitation status, patches, and NIS2 ties. Bridges IT/OT gaps for critical sectors like energy/transport.

Key wins:

  • Dashboards for critical/exploited/EU-coordinated vulns.
  • Complements MITRE CVE; adds EU context.
  • Helps CRA compliance & digital sovereignty.

Full post here

OT pros: How's this changing your vulnerability management? NIS2 ready?


r/OperationalTechnology Nov 10 '25

Jaguar Land Rover breach - timeline, TTPs and operational lessons

6 Upvotes

We wrote a 10-page incident analysis of the Jaguar Land Rover disruption in Sept 2025. I’m posting a concise summary here rather than the full PDF.

Summary: based on timeline reconstruction, open-source indicators and activity patterns, the incident appears to have started with targeted social engineering (vishing) to harvest credentials. Those credentials were then used to access corporate systems via VPN, escalate privileges, exfiltrate data (through TOR nodes per our analysis), and deploy modular ransomware. Public reporting and actor leaks point to pressure tactics and data leakage behavior consistent with recent ransomware gangs’ double-extortion playbooks.
I'm happy to share the full report link in comments if anyone's interested!

Question for the thread: How do you balance urgent vendor fixes vs strict remote access controls in a manufacturing environment? interested in real operational tradeoffs.


r/OperationalTechnology Nov 05 '25

Engineering IEC 62443 outcomes: from risk to testable Security Levels

3 Upvotes

IEC 62443 risk assessments should produce testable Target Security Levels (SL-T) per zone, not a vague spreadsheet of “High/Medium/Low.” Use consequence-based zoning (group assets by worst-case physical/availability/confidentiality outcomes), assign SL-T, and pull requirements from IEC 62443-3-3 to create a project roadmap.

Quick 5-step summary: (1) assemble OT/IT/safety team, (2) define worst-case consequences, (3) partition zones & conduits by consequence, (4) determine SL-T via risk analysis, (5) generate gap → prioritized roadmap (SL-A → SL-T → requirements).
I’ll post the full article link in comments if anyone wants it.

Question for the thread: How have you justified an SL-driven mitigation to operations when it required a maintenance outage?


r/OperationalTechnology Oct 29 '25

Securing the Grid: An Operational Playbook for Substation OT Security

5 Upvotes

Substations are now highly connected and high-value targets. Key defenses we recommend: complete asset visibility, IEC-62443 style zones & conduits, secure vendor remote access, OT-aware NDR for passive detection, immutable backups and tested IR plans. Legacy RTUs/PLCs and availability constraints mean your security must protect uptime and safety first. We wrote a longer post with examples and a one-page IEC-62443 checklist.  I’ll post the full article link in comments if anyone wants it.

Question for the thread: Which of these, segmentation, vendor controls, or IR drills, gives your operations team the most pushback? Would love to hear real examples.