OT Cybersecurity
Securing the systems that run physical processes
Operational technology security is not IT security applied to a factory. The protocols are different, most of them are unauthenticated, the equipment has a service life measured in decades, and stopping a process to apply a patch has a cost that stopping a web server does not. This is the pillar page for how Spharaka approaches it, and the entry point to the detail underneath.
Why operational technology needs its own approach
In an enterprise network the ordering of priorities is confidentiality, then integrity, then availability. In an industrial network that ordering inverts. A process that stops has an immediate physical consequence, and in some plants a safety consequence, so availability comes first and every security control is judged by whether it can be applied without interrupting production.
The second difference is the protocol layer. Industrial networks run hundreds of specialised protocols, most designed before authentication was a consideration, and conventional security tooling cannot interpret them. It sees a TCP session on port 502 rather than a write to a register that controls a burner. That gap produces both blind spots and false positives on entirely legitimate traffic.
The third is lifespan. A controller commissioned in 2009 may be supported until 2035 and cannot be patched on a monthly cycle, if at all. Unpatchable devices are the normal case rather than the exception, which shifts the work from remediation towards segmentation, monitoring and compensating controls that can be evidenced to an auditor.
Explore OT cybersecurity
Each page below covers one part of the subject in depth.
Category
ICS Security
The control layer: PLCs, RTUs, IEDs and the protocols that command them, including safety-instrumented systems.
SCADA Security
The supervisory layer: HMIs, historians, engineering workstations and wide-area telemetry links.
Industrial Cybersecurity
The programme view: governance, IT and OT convergence, ownership, and how an industrial security function is actually run.
Capability
OT Asset Discovery
Building a device-of-record for an estate nobody has fully documented, without probing a safety controller.
OT Threat Detection
Three detection engines over one event store: signature, query-language rules and behavioural models.
Passive OT Monitoring
Why passive collection is the default in industrial networks, and what it can and cannot see.
Sector
Manufacturing OT Security
Discrete and process manufacturing: Profinet, EtherNet/IP, CIP Safety, and cell-to-cell segmentation.
Energy and Utilities OT Security
Substations and generation: IEC 61850, DNP3, IEC 60870-5-104, and NERC CIP evidence.
Critical Infrastructure Security
Water, transport and public infrastructure, where the consequence of failure is physical and public.
How Spharaka Signal™ sees an industrial network
Signal is an AI-native OT and ICS platform. Collection is passive by default: sensors observe mirrored traffic from a SPAN port, a network tap or ERSPAN, and never inject traffic into a safety controller. Each sensor runs its collection modules independently.
- Deep packet inspection across 276+ industrial and IT protocol decoders
- Intrusion detection using Suricata-derived rules tuned for ICS protocols
- Passive asset fingerprinting from TCP stack behaviour, JA3 and JA3S, MAC OUI and protocol banners
- Session and flow accounting
- Syslog, Windows Event Log and SNMP collection from firewalls, switches and workstations
- DNS and TLS observation
- Optional active OT polling, opt-in and explicitly scoped
Protocols decoded
Discrete and process control
- Modbus TCP and RTU
- Siemens S7comm
- EtherNet/IP and CIP
- Profinet
- CIP Safety
Utility and substation
- DNP3
- IEC 60870-5-104
- IEC 61850 MMS and GOOSE
Supervisory and integration
- OPC UA
- BACnet
- HART-IP
276+ protocol decoders ship with the sensor. Those above are the ones named explicitly in the platform reference.
Standards and continuous evidence
Compliance in an industrial estate is usually assembled by hand shortly before an audit. Signal treats it as continuous evidence instead, mapping data it already collects, asset inventory completeness, configuration baselines, patch posture, segmentation conformance, access records and change history, onto specific controls.
IEC 62443-3-3
System security requirements, SR 1 through SR 7.
NERC CIP
CIP-002 through CIP-014, for bulk electric system operators.
NIST SP 800-82r3
The current guide to operational technology security.
AWWA G430
Security practices for water and wastewater utilities.
Read more about zones, conduits and security levels under IEC 62443.
OT cybersecurity questions
The questions that come up most often when an industrial estate is being secured for the first time.
What is OT cybersecurity?
Operational technology cybersecurity protects the systems that monitor and control physical processes: programmable logic controllers, remote terminal units, intelligent electronic devices, human-machine interfaces and the industrial networks connecting them. It differs from IT security because the primary objective is availability and safety rather than confidentiality, and because a control system cannot usually be patched, scanned or rebooted on the schedule IT security assumes.
How is OT security different from IT security?
Three differences dominate. Availability outranks confidentiality, because stopping a process has an immediate physical and financial consequence. The protocols are different and mostly unauthenticated, so IT tooling cannot interpret them. And the equipment has a service life measured in decades, which means unpatchable devices are normal rather than exceptional and have to be defended by compensating controls instead.
Can OT security tools scan industrial networks safely?
Active scanning has caused outages on production control systems, which is why Spharaka Signal is passive by default. It observes mirrored traffic from a SPAN port or network tap and never injects traffic into a safety controller. Active OT polling is available but opt-in and explicitly scoped.
What is the Purdue model and does it still apply?
The Purdue model describes the layers of an industrial network, from field instrumentation at Level 0 up to enterprise systems at Level 4 or 5, with a demilitarised zone between the industrial and enterprise domains. It remains the common vocabulary for describing segmentation, and IEC 62443 zones and conduits build on it, though cloud connectivity and remote vendor access have made strict layer separation harder to maintain in practice.
Which standards apply to industrial cybersecurity?
IEC 62443 is the cross-sector standard, with 62443-3-3 defining system security requirements. NERC CIP applies to bulk electric system operators in North America. NIST SP 800-82r3 is the current guide to operational technology security. AWWA G430 covers water and wastewater utilities. Spharaka Signal reports continuous evidence against all four.
Where does Spharaka Signal fit alongside Sphere?
Signal is the OT and ICS extension of Spharaka Sphere. It collects and analyses industrial telemetry passively, and its findings correlate with IT telemetry inside Sphere so a single security operations team sees one picture across both domains rather than running two disconnected consoles.
See Spharaka Signal™ on your own network
Passive collection means an evaluation can run against production traffic without a change window.