OT and ICS security
By the end of this module you will be able to:
- State how operational technology inverts the IT security priority order, and why the inversion is correct rather than careless
- Place assets on the Purdue model and draw zones and the conduits allowed to cross between them
- Use IEC 62443 security levels and its role split correctly in a supplier conversation
- Explain the GB energy regulatory position under the NIS Regulations 2018 and the Ofgem-adapted assessment
- Challenge the air-gap claim professionally, with the design grammar that replaces it
Colonial Pipeline, from the other side of the IT/OT boundary
In module 5 the Colonial Pipeline incident of May 2021 taught an IT entry lesson: a dormant virtual private network account with no second factor let the DarkSide group into the corporate network. This module revisits the same case from the other side of the boundary, because the part that mattered to the public was not the intrusion. It was the decision to shut the pipeline down.
The ransomware struck the business and billing systems, not the control system that moves the fuel. Colonial still halted operations for roughly five days. It could not bill accurately while its systems were encrypted, and, more tellingly, it could not be certain the two worlds were cleanly separated, so it could not rule out an effect on the pipeline itself. When you cannot prove the boundary held, you assume it did not.
That is the theme of this module. In operational technology the question is never only "was data stolen". It is "can the physical process still be trusted", and the honest answer depends entirely on how the two worlds are joined.
If the ransomware only reached the billing systems, why did the fuel stop flowing?
1. Where software meets physics
is the hardware and software that monitors and controls physical processes: the pumps, valves, turbines, breakers and production lines that make electricity, move water, refine fuel and build things. It runs on devices most office workers never see. A reads a sensor and drives an actuator on a fixed cycle measured in milliseconds. A system gathers those readings across a plant or a region so an operator can watch and command the process from one screen.
The reason IT instincts mislead in this world is that the worst outcome changes. In a bank, the nightmare is a data breach: confidentiality lost. On a pipeline or a substation, the nightmare is a burst main, a fire, a blackout or an injured worker: safety and availability lost. So the familiar order of confidentiality, integrity and availability turns over. Availability and safety come first, then integrity of the control signal, and confidentiality last. An engineer who locks a control network so tightly that an operator cannot reach an alarm has not made the plant safer; they have created a new way for it to fail.
This inversion is not the only difference. IT assets are replaced every three to five years and patched within days of a fix. OT assets run for ten to twenty years, are patched only inside scheduled outage windows agreed months ahead, and often cannot be rebooted on demand because rebooting means stopping production. The free, government-backed reference for all of this is NIST SP 800-82r3, the Guide to Operational Technology Security, published in September 2023. It is the document to hand a colleague who still thinks OT is just IT in a hard hat.
2. The Purdue model and its modern erosion
The is the shared map of an industrial network. It arranges systems into levels by how close they sit to the physical process. Level 0 is the process itself: sensors and actuators. Level 1 is basic control: the PLCs and safety controllers that act on those sensors. Level 2 is supervisory control: the human-machine interfaces and alarm servers an operator works from. Level 3 is site operations: the SCADA servers, historians and engineering workstations that run the plant day to day. Levels 4 and 5 are the business and enterprise systems, the ordinary IT of scheduling, email and the wider corporation.
Read from the bottom, the model is a statement about blast radius. The closer a system sits to Level 0, the more directly a fault there becomes a physical event, so the more carefully traffic reaching it must be controlled. The whole point of the layering is that nothing at Level 5 should be able to speak straight to a Level 1 controller.
The honest problem is that the clean levels blur in practice. A modern plant streams telemetry to a cloud analytics service. Vendors expect remote access to maintain the equipment they sold. Industrial internet-of-things sensors arrive with their own network stacks. Each of these is a good operational reason to punch a hole between the levels, and each hole is a path an attacker can walk. This is why the popular claim that industrial systems are safe because they are air-gapped is, for most real plants, no longer true. The gap rarely survives contact with the demands of running the business.
Common misconception
“Operational technology is safe because it is air-gapped from the internet and from the corporate network.”
A true, maintained air gap is rare in modern operations. Plants are connected for telemetry, cloud analytics, remote vendor maintenance and industrial internet-of-things devices, and every one of those is a route between the enterprise and the process. The air gap is usually a story people tell about a network that has quietly grown dozens of crossings. IEC 62443 zones and conduits exist precisely because the gap does not hold: instead of pretending no path exists, you name every path, justify it, and control what may cross it.
The move a mature operator makes is to stop arguing about whether a gap exists and start governing the crossings that undeniably do. That is the subject of the next section, and it is the design idea the figure below sets out: the levels held inside two zones, split by a controlled boundary, with each crossing named.
3. Zones, conduits and IEC 62443
The international standard for securing industrial automation is the series. Its central design idea is deceptively plain. Group assets that share the same security needs into a , and allow those zones to communicate only through a conduit: a defined, controlled channel that is the sole permitted crossing. An industrial demilitarised zone sits between the enterprise zone and the control zone, so that a patch server or a data broker can do its job without the two sides ever talking directly. Draw the zones, draw the conduits, and any connection you have not drawn is by definition one that should not exist. That is the test the knowledge check below asks you to apply.
62443 measures how strong a zone needs to be with a , graded SL1 to SL4. SL1 resists casual or accidental misuse; SL4 resists a well-resourced attacker who is specifically targeting that system with deep knowledge of it. You set a target level per zone based on what a failure there would cost, then choose controls that meet it, rather than buying one expensive control and hoping it helps everywhere. Underneath the levels sit the standard's seven foundational requirements, which name the capabilities every design has to address: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability.
62443 also does something most security standards skip: it splits responsibility between three named roles, and each has its own parts of the standard. The asset owner runs the plant and owns the risk. The system integrator designs and builds the secured system from components. The product supplier makes the PLC or the software to a secure development standard. The 62443-2-1 part, which sets out the security programme an asset owner must run, was reissued in 2024, so a supplier who quotes the older edition is telling you how current they are. For the attacker's view of this world, the ATT&CK for ICS knowledge base catalogues the specific techniques seen against control systems, from manipulating a controller to inhibiting a safety function, which lets a defender check their zones against real tradecraft rather than against imagination.
4. GB energy, regulated
In Great Britain this is not only good practice; for energy it is law. Under the Network and Information Systems Regulations 2018, an energy company that meets the thresholds is an and must take appropriate security measures and report significant incidents. For the GB energy sector the competent authority that enforces this is Ofgem, working with the Department for Energy Security and Net Zero. Ofgem does not assess operators against a tick-box checklist. It uses a profile adapted from the National Cyber Security Centre's Cyber Assessment Framework, with the weighting shifted towards the operational-technology outcomes that matter most when the asset in question is a substation rather than a spreadsheet.
The stakes are rising because the sector is adding digital surface every quarter. The National Energy System Operator took over Great Britain's system operation in October 2024. The Review of Electricity Market Arrangements concluded in July 2025, with its delivery plan running from April 2026. The move to market-wide half-hourly settlement is migrating towards its May 2027 milestone. Each of these programmes connects more devices, more data flows and more parties to systems that used to be closed. A regulator that once worried about a handful of control rooms now has to reason about a grid of smart meters, distributed generation and market platforms, all of which widen the ground an attacker can stand on.
5. The IT/OT boundary in practice
Turning the zone diagram into a real boundary rests on a small number of concrete mechanisms. A jump host, sitting in the demilitarised zone, is the single monitored machine through which any human administrator must pass to reach the control side, so that remote access is a controlled event rather than a standing door. A protocol break terminates the enterprise-side connection and starts a fresh one into the control zone, so no packet flows end to end and a payload cannot simply ride through. Where data need only move in one direction, out of the plant to a historian or a dashboard, a enforces that physically: it can send but is built so nothing can come back the other way. Together these are ordinary applied to a boundary that carries physical consequences.
The harder problem is often not technical but organisational: who owns patching a fifteen-year-old PLC that the maker no longer supports and that cannot be taken offline without stopping production. The IT team says it is not their device; the engineering team says security is not their trade; the vendor says the contract ended years ago. Nobody is wrong, and so nobody acts. Naming that owner, and giving them the outage windows and the compensating controls to act within, is as much a part of OT security as any gateway. This is also where a posture meets its limits: you cannot simply demand that a decades-old controller authenticate every request when it was never built to, so you protect it by controlling everything that can reach it. The practical work of this module is exactly that, and the workspace tool for it lets you place your own assets on the levels and defend the conduits you draw.
A plant network has these five assets: a corporate email server, a SCADA historian, a pressure sensor on a pipe, a human-machine interface an operator watches, and a PLC that closes a valve. Reading the Purdue model from Level 0 upward, which ordering places them correctly by proximity to the physical process?
You have drawn an enterprise zone, an industrial demilitarised zone and a control zone, with conduits into and out of the DMZ. An engineer proposes one more connection to save time. Which proposed conduit most clearly must not exist?
Try it in the workspace
A studio tool turns this module into something you can build and export.
Core distinctions
- In operational technology the priority order inverts: availability and safety come first, then integrity, then confidentiality, because the worst outcome is physical harm, not disclosure. OT assets also run for ten to twenty years and are patched only in scheduled windows.
- The Purdue model orders systems by proximity to the physical process, from Level 0 sensors to Level 5 enterprise IT. Nothing at the top should be able to speak directly to a controller at the bottom.
- The air gap is mostly a myth in modern plants connected for telemetry, cloud analytics and remote maintenance. IEC 62443 replaces it with zones and conduits: name every crossing, justify it, and treat any undrawn connection as one that should not exist.
- IEC 62443 grades zone strength with security levels SL1 to SL4, rests on seven foundational requirements, and splits duty between asset owner, system integrator and product supplier. Its 2024 62443-2-1 edition is the current programme reference; NIST SP 800-82r3 is the free companion guide.
- GB energy operators are operators of essential services under the NIS Regulations 2018, assessed by Ofgem against a Cyber Assessment Framework profile weighted towards OT. NESO, the market review outcome and half-hourly settlement are all adding digital surface, which raises the stakes each year.
Standards and sources cited in this module
ISA/IEC 62443 series of standards (ISA)
The international standard for industrial automation security: zones and conduits, security levels SL1 to SL4, the seven foundational requirements and the asset-owner, integrator and supplier roles.
NIST SP 800-82r3: Guide to Operational Technology (OT) Security
The free, government-backed reference on OT security, including why OT risk priorities differ from IT and how to secure control systems.
NIS Regulations 2018 implementation in the GB energy sector (GOV.UK)
How the operator-of-essential-services duties apply to energy in Great Britain and who enforces them.
Ofgem cyber security (energy regulation)
The competent authority's own account of how it assesses GB energy operators against an adapted Cyber Assessment Framework.
MITRE ATT&CK updates (ATT&CK for ICS)
The current adversary technique catalogue for industrial control systems, for checking zone designs against observed tradecraft.