Explanations: How to secure OT for cyber-resiliency

ARC Leadership Forum, 2026 included discussions about securing OT for cyber-resiliency. Impacts of industrial cybersecurity breaches are increasing, affecting productivity, outages, brand degradation, lost business and intellectual property.

Industrial cybersecurity advice insights

  • Reasons operational technology (OT) personnel need to change cybersecurity approaches were among topics in a Fortinet presentation at the 2026 ARC Leadership Forum by ARC Advisory Group.
  • Prepare for probable and potentially costly cybersecurity breaches with a risk-based framework; are lives at risk?
  • Article covers four cybersecurity operations; four cybersecurity standard sections; and three benefits of an OT risk-control cybersecurity architecture along with cybersecurity zones and conduits and mapping.

Operational technology (OT) cybersecurity issues include the added layers needed for modern production systems and increased complexity to controls, according to Erik Anderson, OT specialist, systems engineering, Fortinet (Figure 1), at the 2026 ARC Leadership Forum by ARC Advisory Group, Feb. 9-12, Orlando, Florida. Theme of the 30th Annual ARC Industry Leadership Forum event was “How AI Is Driving the Future of Industrial Operations and Supply Chain.”

Reasons OT needs to change its cybersecurity approaches

Anderson said OT needs to reduce risk and increase resiliency. Most controls lack security by design. Air gapping (the physical separation of systems from outside connections) as a means of protection is going away, and the attack surface of increasingly connected automation and control systems are expanding. Remote access requirements need a zero-trust approach. Digital transformation turning analog into digital. Asset owners increasingly rely on original equipment manufacturers (OEMs) and system integrators to help, Anderson said.

Figure 2: Millions of dollars of losses accrue from a 48-hour production-line shutdown after cybersecurity attack to operational technology systems, as this ransomware attack example shows, in a Fortinet presentation at the 2026 ARC Leadership Forum by ARC Advisory Group. Courtesy: Mark T. Hoske, Control Engineering

Probable cybersecurity breaches: Get ready with risk-based framework

In a recent survey of OT chief information security officers (CISOs), Anderson said 6 of 10 reported at least three breaches in the past year. Impacts of industrial cybersecurity breaches are increasing, affecting productivity, outages, brand degradation, lost business and intellectual property (IP). Assigning a dollar value to threats and consequences (Figure 2) helps to get appropriate resources to improve cybersecurity, Anderson said. Applying a risk-based framework can be done by looking at

risk = probability x impact 

or

risk = threat x vulnerability x impact.

Figure 3: Here’s how legacy technologies can result in damage to a programmable logic controller (PLC), explained in a Fortinet presentation at the 2026 ARC Leadership Forum by ARC Advisory Group. Courtesy: Mark T. Hoske, Control Engineering

A recent pipeline cybersecurity breach resulted from using a legacy protocol that created outside access to a programmable logic controller (PLC). The breach allowed a hacker to read a tag value, subscribe to the tag, change a setpoint, update logic and stop the PLC’s central processing unit (CPU), he explained (Figure 3).

Figure 4: A continuous risk reduction model includes network architecture, asset visibility, access controls and endpoint and system hardening, as explained in a Fortinet presentation at the 2026 ARC Leadership Forum by ARC Advisory Group. Courtesy: Mark T. Hoske, Control Engineering

A continuous risk reduction model can include industrial network architecture, assets visibility, access controls, endpoint and system hardening (Figure 4).

Is a cybersecurity breach going to cost lives?

Carlos-Raul Sanchez, senior director operational technology solution engineer specialists at Fortinet (Figure 1), said it’s helpful to know who owns risk in the organization, because it varies. In some facilities a cybersecurity breach could result in loss of life. Interconnectedness and processing power increases speed, and, often, it’s helpful for things to go more slowly. “Faster” creates more challenges because we must remediate the problem in real time, Sanchez said. When a breach happens, not knowing assets and how they touch operations creates delay, greater risks and other challenges.

Separating IT from OT is a common strategy, but segmentation must be conducive to operations without slowing down the process.

“Where are we on the journey?” Sanchez asked. “As we move forward to segmentation, everything has to be done at speed.”

Figure 5: Operational technology cybersecurity needs to reduce the attack surface, decrease consequences and cut recovery time, not just detect threats, according to a Fortinet presentation at the 2026 ARC Leadership Forum by ARC Advisory Group. Fortinet helps enforce, discover, detect and manage. Courtesy: Mark T. Hoske, Control Engineering

Four cybersecurity operations; four cybersecurity standard sections

Four basic operations for cybersecurity in a continuous risk reduction model are to allow, deny, monitor and quarantine. Standards help inform industrial cybersecurity efforts. ISA/IEC-62443 industrial cybersecurity of components and systems has sections with (1) general information such as concepts and models, (2) policies and procedures, (3) system and (4) component/product.

Today’s threats require a more active approach to mitigating threats. Preparation makes recovery easier when a breach happens. Micro-segmentation helps in two ways: passive monitoring and active query of advice. Older PLCs can be turned into a paperweight with the wrong treatment. Multi-factor authentication helps with the use of a defined model. Virtual patching addresses vulnerability of legacy devices without taking them out of operation by shrouding devices with proper protection.

Three benefits of OT risk-control cybersecurity architecture

Benefits of creating a layered OT risk-control cybersecurity architecture include:

1. Reduce surface reduction

2. Consequence reduction

3. Recovery time reduction.

The cybersecurity system needs to confirm that a device is who it says it is. When it’s a headless device, another approach is needed to recognize the device and let it operate. Micro-segmentation is needed from layer 1 to layer 7 in the OT infrastructure (Figure 5).

Cybersecurity zones and conduits, mapping

Zones are groupings of industrial control devices based on function, risk and trust level. Conduits are secure pathways controlling the flow of data from one zone to another. Maturing cybersecurity efforts in IT and OT require a pragmatic approach to cybersecurity from basic to advance at five levels: secure, defend, contain, monitor and manage. The plant manager ultimately is responsible, not just the CISO.

Those with cybersecurity insurance may be disappointed when filing a claim; some type of audit needed for any insurance claim, with records.

Layered cybersecurity controls

Layered protection includes data in motion and data at rest, network segmentation, an OT application-layer policy and OT vulnerability protection, Anderson and Sanchez said. No one is getting slower, only faster.

Mark T. Hoske is editor-in-chief, Control Engineering, WTWH Media, [email protected].

Keywords

OT cyber-resilience, industrial cybersecurity framework, cybersecurity tips

Consider this

Cybersecurity breaches may result from already embedded threats. Are you ready?

You also might like

See other cybersecurity help from Control Engineering.

https://www.controleng.com/industrial-cyber-security

https://www.arcweb.com/events/arc-industry-leadership-forum-orlando

Written by

Mark T. Hoske

Mark Hoske has been Control Engineering editor/content manager since 1994 and in a leadership role since 1999, covering all major areas: control systems, networking and information systems, control equipment and energy, and system integration, everything that comprises or facilitates the control loop. He has been writing about technology since 1987, writing professionally since 1982, and has a Bachelor of Science in Journalism degree from UW-Madison.