01Introduction
Operational technology runs the physical world: power grids, water treatment, factories and building systems. When it's attacked the outcome can be physical damage or safety risk, not only a data breach.
02What is OT security?
Operational technology (OT) security is the protection of hardware and software that monitors and controls physical processes, including industrial control systems (ICS), SCADA, programmable logic controllers (PLCs) and the networks that connect them.
Standards such as ISA/IEC 62443 and NIST SP 800-82 guide it. The IT-facing systems around OT, such as historians, remote access portals and vendor web apps, are ordinary application security and cloud security problems.
03How OT security works
OT security favors availability and safety over rapid change.
- 1.
Inventory passively
Map assets and protocols without scanning that could disrupt fragile devices.
- 2.
Segment
Separate OT from IT networks using zones and conduits, following the Purdue model.
- 3.
Control access
Lock down remote access and vendor connections, in line with zero trust.
- 4.
Monitor
Watch industrial protocols for anomalous commands and feed alerts to the SOC.
04Threats and risks
OT has a distinct risk profile.
Unpatchable legacy
Controllers that run for decades and can't take updates. See patch management.
IT-to-OT pivot
Ransomware that enters through corporate IT and spreads into plant networks.
Insecure remote access
Vendor portals and VPNs exposed to the internet.
Insecure-by-design protocols
Industrial protocols with no authentication.
05How Parameter helps
Parameter secures the IT-facing systems that are the usual entry point into OT.
Web and API testing
The pentesting agents test remote access portals, dashboards and vendor APIs.
Cloud connections
Cloud Security maps cloud accounts that bridge into operational networks.
External exposure
External attack surface management finds internet-reachable interfaces.

