GeoBusinessIQGeoBusinessIQ

Industrial cybersecurity: why plant control systems cannot be defended the way office systems are

What this answers

How do we protect control systems we cannot patch, cannot reboot freely and are not allowed to modify?

Security practice built for offices assumes you can patch on a schedule, reboot at will and retire an unsupported machine. A plant assumes none of those. Controllers stay in service for decades, engineering workstations run whatever the machine builder validated, and a reboot in the wrong minute ruins a batch or trips a furnace. Protecting operational technology therefore means accepting constraints that would be intolerable on a corporate network, then compensating for them somewhere else.

Written for: controls engineers, plant managers, information security leads.

Availability comes first, and that inverts the usual priorities

Office security ranks confidentiality highest and treats a short outage as an inconvenience. On a plant the ranking reverses: an unexpected stop can spoil a batch, damage equipment, release material or expose people to risk during the unplanned restart. That inversion explains most of the friction. A patch requiring a reboot cannot be applied when it is released; it waits for a shutdown window that may be a long way off. An endpoint agent scanning aggressively can delay a control loop. Security measures must also never interfere with a safety function, which is designed and validated separately and is not itself a security control.

Assets that outlive the company that supplied them

Control equipment is bought as plant rather than as computing, and is expected to last as long as the machine around it. The result is a population of controllers, drives and operator stations whose suppliers stopped issuing fixes long ago, alongside engineering workstations on operating systems that no longer receive updates because the programming software will not run on anything newer. For much of it no patch exists and none is coming. The response is compensating control: isolate the asset, restrict what can reach it, monitor what does, and handle replacement as an obsolescence programme rather than an incident waiting to happen.

Supported configurations limit what you are permitted to change

A great deal of plant equipment arrives under a support arrangement specifying the configuration exactly, sometimes down to which software may be installed and which services must keep running. Changing it can end support, disturb a validated state in regulated production, or break the machine in ways the local team cannot diagnose. Security teams used to deploying agents everywhere find this genuinely constraining and occasionally refuse to believe it. The workable route is to raise the requirement with the machine builder, obtain the supported position in writing, and design controls around any machine on which nothing may be installed.

The paths in are rarely the ones on the network diagram

Diagrams show the connections that were designed. The ones that matter are those that accumulated: an engineer's laptop that also reaches the corporate network and a customer site, removable media carrying programs between machines, a remote support link an integrator asked for during commissioning and nobody revoked, a cellular modem inside a machine the supplier uses for diagnostics. An accurate asset and connection inventory is therefore the opening piece of work rather than a later refinement, because nothing can be segmented or monitored until it has been found. Expect the inventory itself to expose the largest gaps.

Detection, response and restoring a controller nobody has ever restored

Detection on a plant leans on passive observation rather than installed agents, because watching traffic disturbs nothing. What happens next matters more. Response plans written for information systems assume a machine can be isolated, whereas isolating a controller mid-process may be the more damaging act, so the plan needs production and engineering judgement inside it, with named decision-makers and a defined authority to stop. Recovery depends on something most sites lack: current, tested backups of controller programs, drive parameters and operator station configurations, plus somebody who has actually performed a restore. The standards series IEC 62443 covers security for industrial automation and control systems.

Frequently asked questions

Can we just install antivirus on the machine computers?
Sometimes, and frequently not. Many machine builders specify exactly what may run on their computers, and adding an agent can end support or, in regulated production, disturb a qualified state. Where scanning is permitted it may need exclusions and careful scheduling so it does not interfere with a control loop. Ask the builder for a written position, and where the answer is no, compensate around the machine using network restriction, controlled media handling and monitoring of what the equipment communicates with.
Is an air gap enough on its own?
Genuine air gaps are rare and rarely stay genuine. Somebody has to load a program, take a backup, pull a report or let a supplier connect for diagnostics, and each of those creates a path. Removable media crosses isolation routinely and laptops cross it daily. Treat isolation as one control among several rather than a finished answer, and verify it periodically by examining what the equipment actually connects to instead of what the drawing claims it connects to.
Should plant security be owned by information technology or by engineering?
Neither alone works. Engineering understands the process, the consequences of stopping it and the support constraints on each machine. Security understands threat, controls and monitoring. The arrangement that functions puts accountability with a named person on the operations side, with security supplying standards, tooling and expertise, plus a joint decision route for anything touching a running process. What fails is a policy written centrally and applied to plant equipment without anybody checking whether it can be met.

Data limitations

  • Plant, process, utility and equipment material is business intelligence, not engineering design. Layout, structural, electrical, mechanical, pressure, ventilation and fire-safety decisions require a qualified engineer working to the codes in force at the site.
  • Manufacturing figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no factory costs, production volumes, yields, cycle times, tooling prices or capacity data and does not estimate them — every result reflects only the figures you enter.

Explore the graph

Sources

  • Cybersecurity and Infrastructure Security Agency CISA (accessed )
    Covers: Guidance and advisories on industrial control system and operational technology security.
    Does not cover: Vendor product assessments, or the security posture of any specific installation.
    Why it matters: Cited on industrial cybersecurity pages as the public authority for control-system security practice.
    Review cadence: annual
  • National Institute of Standards and Technology NIST (accessed )
    Covers: Measurement science, manufacturing technology research, cybersecurity frameworks, and industrial standards support.
    Does not cover: Certification of products, endorsement of vendors, or costs for any specific implementation.
    Why it matters: A United States federal research institute whose public material covers measurement, manufacturing technology and control-system security.
    Review cadence: annual
  • International Electrotechnical Commission IEC (accessed )
    Covers: International standards for electrical, electronic and related technologies, including industrial automation and machinery safety.
    Does not cover: Standard text, conformity decisions, or product approval.
    Why it matters: Cited for the origin of electrotechnical and automation standards referenced on automation and machinery pages.
    Review cadence: annual

Educational and operational information only — not legal, engineering, safety, customs, tax, or financial advice. Requirements vary by jurisdiction, product, process, and contract; confirm with the relevant authority or a qualified professional before acting.

Last updated: