Cybersecurity (OT)

« Back to Glossary Index

Theme: Protect physical function throughout the lifecycle

Quick definition

Cybersecurity (OT) is the management of cyber risk and protection of systems that monitor or control physical processes. It limits unauthorised access, manipulation and disruption while respecting process performance, reliability and safety throughout design, operation, maintenance and recovery.

In context: priorities follow consequence

OT is not distinguished from IT by a universal rule that availability always ranks first. A protective shutdown can matter more than continued production; environmental protection, equipment and data integrity may govern other decisions. Risk assessment starts with the consequence of an incorrect or missing function.

A concrete production scenario

A blending line suffers a compromised operator account. Controls should limit which recipes and setpoints it can change, alert on abnormal activity and preserve local safety logic. Recovery includes a verified configuration and controlled return to production, not merely restarting a server.

Layers of protection

A resilient architecture combines asset knowledge, zones and communication boundaries, least privilege, practical allowlisting, secure remote access, logging and monitoring. Encrypted transport protects a path, but it does not solve identity governance, vulnerable endpoints or incorrect control logic.

Opportunities

Consequence-led security can improve system visibility, change control, diagnosis and recovery at the same time. Explicit owners and test cases make requirements usable in procurement and operations. Passive monitoring can provide visibility without immediately disturbing sensitive equipment.

Limitations and trade-offs

Scanning, patching and authentication changes can affect time-critical or legacy equipment and need testing. A difficult control does not make the risk disappear; compensating measures and planned modernisation may be necessary. Centralisation can simplify support while increasing the reach of a failure.

HubMind’s view

Trace each security requirement to a physical consequence and an accountable owner. IT and OT specialists can then select proportionate controls without reducing security to a product list. Require evidence through configuration, logs, exercises and tested restoration.

A practical next step

Select one critical function and describe normal operation, dangerous commands, dependencies and safe state. Map users and data flows, inspect segmentation and privileges, then run a tabletop test covering intrusion, communications loss and recovery with operations, IT and the relevant supplier.

Related concepts

OT, Network Segmentation, IEC 62443, Secure Connect.

Sources and further reading

Scope and freshness

General OT security guidance under final NIST SP 800-82 Rev. 3, September 2023. This page does not prescribe sector-specific controls or legal compliance. Reviewed 31 August 2026.

« Back to Glossary Index
Contact us