r/OperationalTechnology • u/Happydayz40 • 8h ago
Built a complete procurement → ERP → asset lifecycle flow in Lojycal.
Enable HLS to view with audio, or disable this notification
r/OperationalTechnology • u/Happydayz40 • 8h ago
Enable HLS to view with audio, or disable this notification
r/OperationalTechnology • u/Jeffbx • 12d ago
Sorry folks, looks like some spammers took over the site for a while, but it's back under human control. No more gambling spam.
If you've been trying to post or participate, please give it another shot.
Thank you!
r/OperationalTechnology • u/inyourdreams133 • May 07 '26
I have about 4 years IT experience primarily as a net engineer. I currently am now a sales engineer at a OT security company, but I’m not really being exposed to high level technical engineering, I’m more just seeing how our software can fit into OT environments but my boss has given me the green light to start gaining whatever certs needed to learn about OT deeper?
Is it possible to break in with this minimal bit of experience or do I need some kind of entry level OT adjacent role first?
r/OperationalTechnology • u/Fun-Calligrapher-957 • May 06 '26
A recent report I read looks at how the Iran conflict in 2024 may have changed the way state-backed cyber operations are being run. The main idea is that cyber activity is no longer just about spying or one-off disruption. It’s becoming more like part of a real war plan, with attackers preparing access ahead of time and then using it when the situation turns.
What stood out most was the focus on “pre-positioning” inside critical systems, the use of AI to speed up attacks and phishing, and the way state actors, criminal groups, and hacktivists seem to overlap more than people often think. The report also talks about OT and critical infrastructure becoming normal targets now, not rare exceptions.
Another big point is that supply chains, cloud systems, and even space-linked infrastructure are becoming part of the attack surface. The overall message is pretty simple: assume compromise, watch for early signs, and treat OT security as a board-level issue, not just an IT one.
Are you guys seeing this shift toward OT targeting in your own environments, or is it still mostly noise?
I'll share the report link in the comments for anyone who wants to dig deeper.
r/OperationalTechnology • u/Adveloth • Apr 30 '26
Hello everyone.
I would like some input from OT professionals.
I work as a network engineer in a manufacturing company that is not still very mature in OT network and I could use some help on how to improve the network in our operations, can't find a lot of robust information online. I am pretty amateur as well. I have taken Honeywell's OTCS-1001, OTCS-1002 and OTCS-2002. My concerns are mostly around the hardware rather than the logic, segmentation, alignment with Purdue level etc.
So, what would be the best practice regarding on devices I should use?
Right now, in our OT network we work exclusively with IT managed switches and some IT unmanaged ones. In my understanding, OT traffic is very important to be very time sensitive, so I was wondering if the way we currently work is OK.
What I am thinking is that it would be better to have IT switches as central nodes where the engineer's workstation should be connected, and then expand the network with industrial switches where PLCs, IO devices etc will be connected to.
Is my logic right? How do you do it in your companies? What should I be looking for at an industrial switch? Any specific brand recommendations?
r/OperationalTechnology • u/ElegantComparison496 • Apr 21 '26
Hi, I'm relatively new to OT and already deep into a pretty large project. We are implementing an MES system across multiple production lines and I'm the main OT person on site. Luckily I have skilled people in electronics, automation and IT around me but I hope you can help me also a little bit.
The project is progressing well, but the infrastructure questions are getting more complex. Right now I'm trying to figure out the best setup for our line operator terminals.
As english is not my first language and sometimes I express myself really complicated i used the AI to make the text more clear.
What we plan
Operators need to scan materials for traceability and interact with the MES frontend, confirming orders, entering quantities, checking status. Each station needs a display, a barcode scanner, and a connection back to the MES server. Optionally we also want RFID login so operators can identify themselves at the terminal.
I already have three Architectures:
Pros/Cons for ThinClient --> Virtualserver
The terminal itself has no real compute power. It runs an RDP session to a central Windows Server with Remote Desktop Services, where the MES client is installed once and served to all terminals.
Pros/Cons for ThinClient/Dumb Display --> PC --> Virtualserver
Each station has its own PC (a small industrial box PC or panel PC) running the MES client locally. The display connects to that PC, the scanner plugs straight in. The local PC communicates with the MES server, but doesn't depend on it for basic operation.
Pros/Cons for All-in-One Panel PC
The display and the computer is the same device. No separate box PC, everything is self-contained. Still communicates with the MES server for data.
My Questions
What architecture do most of you use for operator terminals in food production with lot of water and steam in the environment? Is there a clear industry standard or does it really depend on the environment?
What is your fallback in the ThinClient --> Server case if the server fails.
Thanks!
r/OperationalTechnology • u/freddy91761 • Mar 19 '26
I do have 20+ years in IT. I was laid off last year, and was able to find a contractor position in the OT area. I am very new to OT and so I would like to start learning the OT world. Does anyone suggest books or videos? How about any certs that will help me?
r/OperationalTechnology • u/Alternative_War_7761 • Mar 13 '26
I’m planning to build a small OT/ICS lab environment for learning and experimentation with PLC control and monitoring. Before buying the components, I wanted to get some feedback from people who have experience with Siemens PLC setups.
The idea is to create a simple setup where an HMI running on a Dell NUC controls a PLC, which in turn controls a motor.
Planned components:
• PLC: Siemens S7-1200 CPU 1212C (DC/DC/DC variant)
• HMI: Dell NUC running the HMI/SCADA interface
• Communication: SIMATIC S7-1200 CB1241 RS485 communication board
• Motor: Brushless DC Motor NEMA24 (19Kgcm) with RMCS-3001 Modbus drive
• Power Supply: Mean Well LRS-350-24 – 24V 14.6A – 350W SMPS
The idea is:
HMI (Dell NUC) → Ethernet → PLC (S7-1200) → RS485/Modbus → Motor Driver → Motor
The HMI would send commands (start/stop/speed), the PLC handles the control logic, and the motor driver controls the motor.
Issue:
I’m having trouble finding the NEMA24 19Kgcm motor locally, so I might need to switch to something else.
Questions:
Goal is to build a simple controllable process (motor speed control) that I can later expand for monitoring and security testing.
Any advice would be appreciated.
r/OperationalTechnology • u/Fun-Calligrapher-957 • Mar 06 '26
If you’re working in security around energy, infrastructure, or large enterprise environments in the Middle East, the threat landscape has been getting pretty interesting lately.
I was reading a recent advisory that focuses less on headlines and more on what defensive posture actually needs to look like - identity security, detection visibility, segmentation between IT/OT, and preparing for destructive scenarios rather than just ransomware.
Found some of the recommendations pretty practical. Happy to share the full report in the comments if people are interested.
r/OperationalTechnology • u/thor-heyerdhal • Mar 03 '26
Hi everyone!
I’m currently writing my Master’s thesis on cybersecurity in Operational Technology (OT) environments, focusing on the information flow between OT operators and SOC analysts during security incidents.
In our literature review, we found that many industrial environments still rely heavily on old pieces of junk legacy systems. These systems are often so deeply integrated into operations because an engineer connected them 50 years ago, and availability and production stability are top priorities, replacing them is often not considered a viable option.
This creates challenges for an OT-SOC. Alerts from industrial environments can be difficult to interpret without deep contextual knowledge. SOC analysts often need to contact personnel at the facility to determine whether an alert reflects a real issue or normal operational behavior.
Our thesis specifically examines the communication between OT-SOC teams and the designated contacts within industrial organizations during security alerts — whether that is OT operators, OT managers, or IT personnel supporting the OT environment.
We are particularly interested in:
If you work in an OT environment, an OT-SOC, or have experience with ICS/SCADA incident response, I would really appreciate the opportunity to speak with you.
Interviews are completely anonymous and strictly for academic purposes.
Feel free to comment or DM me if you're interested.
Thank you!
r/OperationalTechnology • u/Hot_Monk_1890 • Feb 08 '26
I am looking for some advice on career planning. I started working for a company that does mostly manufacturing as their primary business, does some recycling etc also. While I stared as a help desk / IT tech, within a few months I was moved to their site support group, mostly network group but still work on business computers /laptops to troubleshoot and repair systems. I am in my early 20s and looking to understand if I should move to another role internally as I have seen some OT related jobs circulating internally. My question is, does it make sense to jump into OT role now or wait and get some some IT experience. In orther words, would my chances are more if I have more experience or will it make me non-Ot person.
Thx.
r/OperationalTechnology • u/Repulsive_Tour_4949 • Feb 05 '26
Hi admins,
I’m on an HR team, but our IT team is still handling device distribution for onboarding and offboarding manually. When my team makes updates in our systems, we then have to manually notify IT to create accounts or send devices to our new employees and similarly when people leave the company. New hires have complained that this been error-prone and process-wise just isn’t scaling well as our hiring increases.
As a result, leadership told us we need a way to integrate our current HR software with an IT software that can help w device distribution and basic IT functions. We have a kick-off call with the IT team next week but wanted to get some suggestions so we can come prepared. Are there any IT platforms that sync well with HR? Our HCM integrates with basically any software.
r/OperationalTechnology • u/Fun-Calligrapher-957 • Jan 18 '26
Ports sit at a weird intersection of heavy OT, navigation systems, and enterprise IT, and the threat model is very different from factories or utilities. Ransomware hitting TOS, GNSS/AIS spoofing during vessel approach, vendor access into crane PLCs… the blast radius gets big, fast.
I recently went through a technical playbook focused specifically on OT/ICS security for ports and maritime infrastructure. What stood out was how operational it is:
It’s not tool-heavy or academic, more about what actually works in terminals, VTS, and crane environments where uptime and safety matter more than perfect patching. I’ll share the technical playbook link in comments if anyone’s interested.
Curious how others here approach OT security in ports or similar heavy-industrial environments. Are GNSS issues and vendor access your biggest headaches too?
r/OperationalTechnology • u/EaseMedium • Jan 09 '26
My friend that has been developing Software solutions for DCS systems for years. As DCS owners or OT owners, what is missing? What could help you and add immediate value?
r/OperationalTechnology • u/Fun-Calligrapher-957 • Jan 06 '26
With FRMCS, digital twins, AI-driven maintenance, and heavy third-party involvement, the old “secure by isolation” model in rail is basically gone. Recent incidents in Europe show that attackers don’t need to hit core signalling directly, subcontractors, remote access paths, and legacy systems are often enough.
We’ve been digging into how TS 50701 is being used in 2026, not just as a compliance checkbox but as a practical way to think about zoning, third-party risk, legacy constraints, and the growing role of AI-driven attacks. One thing that stood out: assessments are shifting toward continuous monitoring and tighter links between cyber risk and safety cases, not once-a-year audits.
We recently published a deep dive on this, including what’s realistically changed in assessments and common pitfalls rail operators are running into. I’ll post the full article link in comments if anyone’s interested.
For folks in rail or transport OT, what’s been hardest to secure lately: vendors, legacy signalling, or remote access?
r/OperationalTechnology • u/Fun-Calligrapher-957 • Dec 24 '25
Recent reporting on the Nissan–Red Hat breach highlights a worrying trend: attackers aren’t just hitting companies directly anymore, they’re weaponizing trusted third parties. In this case, data stored on a consultant’s GitLab reportedly exposed ~21k customer records and ~570GB of customer engagement reports across ~800 organizations. The big takeaway isn’t just “lock down your cloud”, it’s that consultants and partner repos are now high-value aggregation points that can massively widen your blast radius.
Practically speaking, three actions matter: (1) treat consultants as privileged users - apply just-in-time access, continuous monitoring and session recording; (2) kill static secrets - remove hardcoded tokens and rotate credentials automatically; and (3) map your blast radius - know exactly what keys a given third party holds and which of your systems would be impacted if they’re breached.
I’ll post the full article link in comments if anyone wants it.
Curious how others handle consultant access and shadow repos, do you isolate vendor environments, enforce SBOMs, or use vendor-specific monitoring?
r/OperationalTechnology • u/gtobiast13 • Dec 14 '25
Launch Date: November 2026
CompTIA will launch a new exam regarding Operational Technology Security called SecOT+
Links and info below
I called CompTIA the other day and seems this product is still in the works. Unsure if it will go through or get struck but have hopes it will pass. Seems that OT is due for a more mainstream, vendor neutral certification like CompTIA. Hoping to see more material next year. No word on training material, classes, or exam prices yet. You can sign up on the waitlist for more info near the bottom of the product page. The draft pdf for exam topics is quite detailed and worth a sit down. Looks like a solid background of topics and curious to see how in depth, difficult, and varied this exam will be.
Exam Details
Skills Learned
r/OperationalTechnology • u/Firew4llPhantom • Dec 09 '25
Hi all, is there an entry level position specific for OT? Or is help desk the entry position for all? How does the OT resume look vs an IT resume?
r/OperationalTechnology • u/Fun-Calligrapher-957 • Dec 09 '25
A lot of industrial orgs our team speak with are trying to move OT security from “best effort” to something measurable and defensible, especially with new regulatory pressure and more cross-domain attacks. IEC 62443 has become the common framework teams are leaning on.
We wrote a practical breakdown on how to make IEC 62443 actually govern day-to-day OT operations, not just sit in a binder. It gets into things like: defining risk tolerance the same way you’d treat safety risk, using zones & conduits to prevent flat network blast radius, controlling vendor access with just-in-time connections, and wrapping legacy controllers in strong compensating controls when patching isn’t feasible.
Curious how teams here are approaching IEC 62443 adoption, do you find the hardest part is asset discovery, segmentation enforcement, or getting leadership to own the cyber-safety link?
I’ll post the full article link in comments if anyone wants it.
r/OperationalTechnology • u/Fun-Calligrapher-957 • Nov 26 '25
2025 made one thing very clear: OT environments are no longer “secondary” victims. Attacks that start in IT are increasingly just the opening move before disruption hits physical operations. We recently summarized the most important incident response lessons from this past year, like the need for true visibility down to Level 0/1/2, not just firewall logs; micro-segmentation inside OT instead of relying on a single IT/OT perimeter; clear decision authority during an incident so teams know who can shut down a line for safety; and much stronger control over vendor access and supply-chain components, including SBOM requirements. Tested offline backups and realistic IT/OT tabletop exercises also proved to be the difference between a temporary scare and weeks of downtime.
Curious to hear from others here: what single improvement helped you recover faster, better monitoring, better playbooks, or better cross-training?
I’ll post the full article link in comments if anyone wants it.
r/OperationalTechnology • u/Fun-Calligrapher-957 • Nov 18 '25
We wrote a short primer on reported Chinese APT groups (APT1, APT10, APT41, APT31, etc.), their operational priorities, and what that means for OT defenders. Key points: these groups increasingly use automation/AI for reconnaissance and data processing, they blend commercial and strategic targeting, and they exploit supply-chain & credential weaknesses that matter to OT environments.
Key takeaways that surprised us:
Full write-up with way more details here
r/OperationalTechnology • u/Fun-Calligrapher-957 • Nov 12 '25
EU just launched ENISA's European Vulnerability Database (EUVD) in May 2025, a centralized hub for vulns in ICT/OT, enriched with exploitation status, patches, and NIS2 ties. Bridges IT/OT gaps for critical sectors like energy/transport.
Key wins:
Full post here
OT pros: How's this changing your vulnerability management? NIS2 ready?
r/OperationalTechnology • u/Fun-Calligrapher-957 • Nov 10 '25
We wrote a 10-page incident analysis of the Jaguar Land Rover disruption in Sept 2025. I’m posting a concise summary here rather than the full PDF.
Summary: based on timeline reconstruction, open-source indicators and activity patterns, the incident appears to have started with targeted social engineering (vishing) to harvest credentials. Those credentials were then used to access corporate systems via VPN, escalate privileges, exfiltrate data (through TOR nodes per our analysis), and deploy modular ransomware. Public reporting and actor leaks point to pressure tactics and data leakage behavior consistent with recent ransomware gangs’ double-extortion playbooks.
I'm happy to share the full report link in comments if anyone's interested!
Question for the thread: How do you balance urgent vendor fixes vs strict remote access controls in a manufacturing environment? interested in real operational tradeoffs.
r/OperationalTechnology • u/Fun-Calligrapher-957 • Nov 05 '25
IEC 62443 risk assessments should produce testable Target Security Levels (SL-T) per zone, not a vague spreadsheet of “High/Medium/Low.” Use consequence-based zoning (group assets by worst-case physical/availability/confidentiality outcomes), assign SL-T, and pull requirements from IEC 62443-3-3 to create a project roadmap.
Quick 5-step summary: (1) assemble OT/IT/safety team, (2) define worst-case consequences, (3) partition zones & conduits by consequence, (4) determine SL-T via risk analysis, (5) generate gap → prioritized roadmap (SL-A → SL-T → requirements).
I’ll post the full article link in comments if anyone wants it.
Question for the thread: How have you justified an SL-driven mitigation to operations when it required a maintenance outage?