Back to OT Cybersecurity

    OT Cybersecurity

    Critical Infrastructure Security

    Critical infrastructure is the category where a control system failure stops being a business problem. Water treatment, transport signalling, public utilities and municipal services all share a property that changes the security calculation: the consequence of failure is physical, immediate and visible to the public, and the organisations running them are frequently the least resourced to defend them.

    Critical Infrastructure
    Water
    Transport

    The resourcing asymmetry

    Critical infrastructure operators are often public bodies or regulated utilities with constrained budgets, small technical teams and equipment that has been in service for decades because replacing it requires capital approval on a political timescale.

    The adversaries are not correspondingly constrained. This asymmetry, high consequence against low resourcing, is the defining feature of the sector and it has a practical implication: controls that require continuous specialist attention will not be sustained. What survives is what runs continuously without a dedicated operator watching it.

    That is an argument for passive monitoring and automated evidence over tooling that assumes a staffed security operations centre. A small water utility does not have one and is not going to acquire one.

    A control that needs a specialist watching it will not survive in an organisation that cannot hire one. In this sector, sustainable beats sophisticated.

    Water and wastewater

    Water treatment has become the most frequently discussed critical infrastructure target, partly because several incidents involved unsophisticated access to internet-reachable control interfaces rather than advanced technique.

    The estate is typically dispersed across treatment works, pumping stations and reservoirs, connected by telemetry and often managed remotely by a small team or an outsourced provider. Remote access is therefore both essential and the primary exposure, which makes reconstructing and monitoring those sessions the highest-value single control.

    AWWA G430 sets out security practices for the sector, and Signal reports continuous evidence against it alongside IEC 62443-3-3, NERC CIP and NIST SP 800-82r3.

    Transport and signalling

    Rail signalling, traffic management and port operations share the safety-critical character of industrial control with an additional constraint: the systems are frequently accessible from public space, and the safety case governing them is a regulatory artefact that any change must be assessed against.

    That makes change slow and deliberate by design, which is appropriate for safety and awkward for security. It reinforces the same conclusion as elsewhere in the sector: monitoring and segmentation carry the load, because they can be introduced without reopening a safety case, whereas modifying the signalling system itself cannot.

    Legacy equipment as the normal case

    Public infrastructure runs equipment that has outlived several vendors. Controllers commissioned in the 1990s remain in service because they work, replacement requires capital approval, and the process they run cannot be interrupted for a rebuild.

    There is no realistic path to patching that population. What is realistic is knowing precisely what it consists of, limiting what can reach it, watching what it does, and recording compensating controls so a decision not to replace a device is documented as a considered risk acceptance rather than an oversight.

    Signal scores each asset on defended posture rather than raw severity, subtracting for compensating controls, which is what makes a legacy estate assessable rather than uniformly red.

    Public consequence changes incident response

    In a manufacturing incident the affected parties are the operator, its customers and its insurer. In critical infrastructure they include the public, the regulator, and frequently the press before either of the other two.

    That reshapes what an incident response process needs. The evidence chain has to withstand external scrutiny, not just internal review. The timeline has to be reconstructible without the people who were on shift. And the question asked afterwards is not only what happened but what was known beforehand and what was done about it.

    This is why continuous evidence matters more here than the compliance framing suggests. It is not principally about passing an audit; it is about being able to answer credibly when the question is asked in public.

    A realistic starting point

    For an operator with limited resources, the sequence that delivers the most defensibility for the least ongoing effort is consistent.

    • Establish what is on the network, passively and continuously, so the inventory maintains itself.
    • Identify and monitor every remote access path, including the undocumented ones, since this is where incidents in this sector have generally started.
    • Confirm what actually crosses between the operational network and everything else, rather than trusting the design.
    • Record compensating controls against the assets that cannot be replaced, with an approver and a review date.
    • Let compliance evidence accumulate from operations rather than reconstructing it before each audit.

    Frequently asked questions

    What counts as critical infrastructure?

    Sectors where a failure has consequences for public safety or essential services: water and wastewater, energy, transport, healthcare, and public utilities. The defining characteristic for security purposes is that failure is physical and publicly visible rather than commercial and private.

    Why are water utilities targeted so often?

    Less because they are strategically valuable than because they are frequently reachable. Several publicised incidents involved unsophisticated access to internet-exposed control interfaces at small operators with minimal security staffing. The dispersed estate and reliance on remote management widen the exposure.

    What is AWWA G430?

    A standard setting out security practices for water and wastewater utilities, covering the organisational and operational side of protecting treatment and distribution. Signal reports continuous evidence against it alongside IEC 62443-3-3, NERC CIP and NIST SP 800-82r3.

    How do you secure equipment that cannot be replaced?

    By changing what the score measures. Know exactly what the equipment is, limit what can reach it, monitor what it does, and record compensating controls against it. Signal subtracts compensating controls from the risk score, so a legacy device behind strong segmentation is not ranked alongside an equivalent device sitting exposed.

    We have no security operations centre. Is this still viable?

    Yes, and that constraint should drive the tool choice. Passive collection needs no operator, the inventory maintains itself, and compliance evidence accumulates from operations. What matters is choosing controls that run without continuous specialist attention, because those are the ones that will still be running in two years.

    Why does incident evidence matter more in this sector?

    Because the audience is external. A critical infrastructure incident is reviewed by a regulator and often reported publicly, so the timeline has to be reconstructible without the staff who were on shift, and the question asked afterwards includes what was known beforehand and what was done about it.