OT Cybersecurity

    Securing the systems that run physical processes

    Operational technology security is not IT security applied to a factory. The protocols are different, most of them are unauthenticated, the equipment has a service life measured in decades, and stopping a process to apply a patch has a cost that stopping a web server does not. This is the pillar page for how Spharaka approaches it, and the entry point to the detail underneath.

    Why operational technology needs its own approach

    In an enterprise network the ordering of priorities is confidentiality, then integrity, then availability. In an industrial network that ordering inverts. A process that stops has an immediate physical consequence, and in some plants a safety consequence, so availability comes first and every security control is judged by whether it can be applied without interrupting production.

    The second difference is the protocol layer. Industrial networks run hundreds of specialised protocols, most designed before authentication was a consideration, and conventional security tooling cannot interpret them. It sees a TCP session on port 502 rather than a write to a register that controls a burner. That gap produces both blind spots and false positives on entirely legitimate traffic.

    The third is lifespan. A controller commissioned in 2009 may be supported until 2035 and cannot be patched on a monthly cycle, if at all. Unpatchable devices are the normal case rather than the exception, which shifts the work from remediation towards segmentation, monitoring and compensating controls that can be evidenced to an auditor.

    How Spharaka Signal™ sees an industrial network

    Signal is an AI-native OT and ICS platform. Collection is passive by default: sensors observe mirrored traffic from a SPAN port, a network tap or ERSPAN, and never inject traffic into a safety controller. Each sensor runs its collection modules independently.

    • Deep packet inspection across 276+ industrial and IT protocol decoders
    • Intrusion detection using Suricata-derived rules tuned for ICS protocols
    • Passive asset fingerprinting from TCP stack behaviour, JA3 and JA3S, MAC OUI and protocol banners
    • Session and flow accounting
    • Syslog, Windows Event Log and SNMP collection from firewalls, switches and workstations
    • DNS and TLS observation
    • Optional active OT polling, opt-in and explicitly scoped

    Protocols decoded

    Discrete and process control

    • Modbus TCP and RTU
    • Siemens S7comm
    • EtherNet/IP and CIP
    • Profinet
    • CIP Safety

    Utility and substation

    • DNP3
    • IEC 60870-5-104
    • IEC 61850 MMS and GOOSE

    Supervisory and integration

    • OPC UA
    • BACnet
    • HART-IP

    276+ protocol decoders ship with the sensor. Those above are the ones named explicitly in the platform reference.

    Standards and continuous evidence

    Compliance in an industrial estate is usually assembled by hand shortly before an audit. Signal treats it as continuous evidence instead, mapping data it already collects, asset inventory completeness, configuration baselines, patch posture, segmentation conformance, access records and change history, onto specific controls.

    IEC 62443-3-3

    System security requirements, SR 1 through SR 7.

    NERC CIP

    CIP-002 through CIP-014, for bulk electric system operators.

    NIST SP 800-82r3

    The current guide to operational technology security.

    AWWA G430

    Security practices for water and wastewater utilities.

    Read more about zones, conduits and security levels under IEC 62443.

    OT cybersecurity questions

    The questions that come up most often when an industrial estate is being secured for the first time.

    What is OT cybersecurity?

    Operational technology cybersecurity protects the systems that monitor and control physical processes: programmable logic controllers, remote terminal units, intelligent electronic devices, human-machine interfaces and the industrial networks connecting them. It differs from IT security because the primary objective is availability and safety rather than confidentiality, and because a control system cannot usually be patched, scanned or rebooted on the schedule IT security assumes.

    How is OT security different from IT security?

    Three differences dominate. Availability outranks confidentiality, because stopping a process has an immediate physical and financial consequence. The protocols are different and mostly unauthenticated, so IT tooling cannot interpret them. And the equipment has a service life measured in decades, which means unpatchable devices are normal rather than exceptional and have to be defended by compensating controls instead.

    Can OT security tools scan industrial networks safely?

    Active scanning has caused outages on production control systems, which is why Spharaka Signal is passive by default. It observes mirrored traffic from a SPAN port or network tap and never injects traffic into a safety controller. Active OT polling is available but opt-in and explicitly scoped.

    What is the Purdue model and does it still apply?

    The Purdue model describes the layers of an industrial network, from field instrumentation at Level 0 up to enterprise systems at Level 4 or 5, with a demilitarised zone between the industrial and enterprise domains. It remains the common vocabulary for describing segmentation, and IEC 62443 zones and conduits build on it, though cloud connectivity and remote vendor access have made strict layer separation harder to maintain in practice.

    Which standards apply to industrial cybersecurity?

    IEC 62443 is the cross-sector standard, with 62443-3-3 defining system security requirements. NERC CIP applies to bulk electric system operators in North America. NIST SP 800-82r3 is the current guide to operational technology security. AWWA G430 covers water and wastewater utilities. Spharaka Signal reports continuous evidence against all four.

    Where does Spharaka Signal fit alongside Sphere?

    Signal is the OT and ICS extension of Spharaka Sphere. It collects and analyses industrial telemetry passively, and its findings correlate with IT telemetry inside Sphere so a single security operations team sees one picture across both domains rather than running two disconnected consoles.

    See Spharaka Signal™ on your own network

    Passive collection means an evaluation can run against production traffic without a change window.