Seven practical tips to improve industrial cybersecurity 

Conventional information technology network security technologies are not enough to secure an industrial control system. Operational technology environments require resilient standards, technologies, organizations, and practices.

Industrial cybersecurity insights 

  • Examine best practices for safeguarding a control system from modern cybersecurity threats. 
  • Understand key considerations for planning a network segmentation approach and choosing an industry standard. 
  • Review the importance of maintaining cybersecurity throughout the life cycle of the control system. 

Industrial cybersecurity is no longer a theoretical concern reserved for information technology (IT) departments. As industrial control systems (ICSs) become more connected—supporting remote access, enterprise visibility, and advanced analytics—the attack surface within operational technology (OT) environments continues to grow.

Many organizations recognize the risk but struggle with implementation. Control systems are expected to run continuously, tolerate little latency, and support maintenance staff who are focused first on safety and uptime. Security measures that disrupt operations often face resistance, even when the risk is well understood.

Effective industrial cybersecurity does not have to be overly complex or disruptive. A practical, risk-based approach, aligned with industry standards and operational realities, can significantly reduce exposure while maintaining system performance.

The seven tips that follow reflect common lessons learned from assessing, designing, and supporting ICS networks across critical infrastructure and manufacturing environments.

Figure 1: Cybersecurity assessment flowchart shows steps involved in the process. Source: CDM Smith

1. Start with a comprehensive assessment

Every cybersecurity program should begin with an honest assessment of the current environment. Without understanding how the system is built, operates, and is maintained, it is difficult to prioritize risk or justify investment.

A comprehensive assessment is often conducted by a third-party familiar with industrial best practices, but organizations with mature internal capabilities may perform this work in-house. Regardless of who leads the effort, the assessment should clearly define:

  • Organizational goals and operational constraints 
  • The current state of the control system and supporting network 
  • The desired future state based on risk tolerance 
  • A realistic capital improvement plan with scopes, schedules, and budgets for improvement projects. 

In many cases, this effort can be combined with a formal cybersecurity risk assessment. A formal risk assessment allows your organization to quantify cyber threats, prioritize spending, and make highly targeted, actionable decisions.

Successful assessments look beyond hardware and software. They evaluate the standards, technologies, organization, and practices supporting the control system. This broader view often reveals that process gaps and unclear ownership pose risks equal to those of technical shortcomings (Figure 1).

Figure 2: Purdue Reference Model is useful to understand how cybersecurity segmentation might be applied. Source: CDM Smith 

2. Select a cybersecurity standard that fits operational technology

Not all cybersecurity frameworks (CSFs) translate well into industrial environments. Selecting the right standard early helps align design decisions, policies, and long-term governance.

The ISA/IEC 62443 series is the most widely adopted ICS-specific standard. It provides a risk-based structure tailored for industrial automation and control systems, allowing organizations to apply security controls proportional to system criticality and risk.

Many facilities also use the Purdue Enterprise Reference Model to structure network design. The Purdue Model separates the OT environment (Levels 0 through 3) from enterprise IT systems (Levels 4 through 5), typically using a demilitarized zone (Level 3.5). This separation remains a foundational best practice for reducing the spread of cyber incidents (Figure 2).

The National Institute of Standards and Technology (NIST) CSF is increasingly used to align IT and OT security efforts, especially when paired with ISA/IEC 62443. Its six core functions—Govern, Identify, Protect, Detect, Respond, and Recover—map well to industrial environments when adapted to OT constraints.

Before adopting any standard, organizations should understand the operational impact. For example, physical separation of IT and OT networks may be cost-prohibitive compared to virtual segmentation for geographically dispersed IT/OT systems that share WAN infrastructure. Moreover, controls that work well in an IT environment may introduce unacceptable latency or complexity in control systems if applied without modification.

3. Segment operational technology networks without compromising performance

Network segmentation is one of the most effective tools for limiting cyber risk in industrial environments, but it must be implemented carefully.

Firewalls or data diodes should be considered to isolate the control system network from enterprise or other external networks. In systems requiring high availability, firewall redundancy should be evaluated to avoid introducing single points of failure.

Beyond perimeter defenses, physical or virtual segmentation can significantly reduce risk by limiting lateral movement and the spread of incidents. Segmenting networks by process area or criticality ensures that a problem in one segment does not cascade across the facility.

Excessive routing between networks can introduce latency and jitter that affect deterministic protocols. The goal is intentional segmentation—not maximum segmentation—that aligns with system architecture and operational requirements.

Figure 3: Process-based network segmentation structure is shown. Source: CDM Smith 

Designing a network with intentional segmentation requires expertise in both network design and OT device application programming. OT networks designed exclusively by personnel with IT networking experience often fail to account for traffic patterns. For example, if the person assigning your IP addresses does not understand that your equipment drives do not frequently communicate with each other, placing these drives on a separate network from the programmable logic controllers that monitor and control them can lead to excessive routing that degrades network performance (Figure 3).

4. Enforce strong, role-based user authentication

User access remains a frequent entry point for cybersecurity incidents. Weak credentials, shared accounts, and insufficient access controls are still common in control system environments.

User authentication requirements should complement physical access control measures, such as video surveillance, door locks with badge readers, and network switch port security. Authentication requirements for users accessing the system from a secured control room should be different from users accessing the system remotely.

Any form of remote access should require multi-factor authentication and encrypted communications. Remote access solutions should be tightly controlled, monitored, and disabled when not actively needed.

Each control system user should have unique credentials with access limited to their job function. Privileged access should be granted sparingly, reviewed regularly, and logged.

In most control system environments, authentication should be designed to work locally to ensure system availability, rather than rely on external services. Therefore, many facilities implement local authentication services so users can still access systems when external connections are unavailable. Authentication controls must support reliability, not undermine it.

Figure 4: An example architecture for operational technology network monitoring may differ from how information technology applies cybersecurity. Source: CDM Smith 

5. Monitor operational technology networks continuously

Preventive controls alone are not sufficient. Industrial cybersecurity requires visibility into what is happening on the network in real time. 

Passive network monitoring sensors can establish baselines of normal traffic and detect anomalies without disrupting operations. Because industrial communication patterns are often predictable, deviations can be strong indicators of equipment failure or malicious activity.

When combined with log aggregation and Security Information and Event Management (SIEM) platforms, monitoring tools enable faster detection and response. Even basic alerting can help reduce the time to detect issues and may limit the impact of incidents. However, monitoring should be thoughtfully designed to support operations, avoiding excessive or unnecessary alerting that can overwhelm staff (Figure 4).

6. Address staffing, training gaps for cybersecurity

People are one of the most overlooked and exploited elements of industrial cybersecurity.

Organizations should evaluate whether they have sufficient OT cybersecurity expertise available and consider dedicated cybersecurity roles, cross-training existing staff, or leveraging trusted third-party support.

Equally important is awareness training for control system users. Engineers, operators, and technicians are frequent targets of phishing and social engineering because they often have elevated access.

A formal cybersecurity awareness program helps staff recognize threats and respond appropriately. Training materials from government agencies and reputable third-party providers can accelerate development and improve consistency.

The objective is not to turn operators into security experts, but to equip them to recognize and deal with cyber risks as part of their day-to-day responsibilities.

7. Establish cross-functional cybersecurity governance

Cybersecurity is not a one-time project. Threats, technologies, and operational requirements evolve continuously, and security programs must evolve with them.

A formal governance committee provides structure and accountability. This group should include representatives from IT, network security, operations, engineering, and maintenance.

Typical responsibilities include:

  • Maintaining written policies and procedures 
  • Conducting periodic risk and cybersecurity assessments 
  • Reviewing and approving new technologies used to reduce risk 
  • Reviewing intelligence on new cyber threats. 

Effective governance ensures cybersecurity decisions are technically sound, operationally feasible, and aligned with organizational priorities. 

Building practical cyber-resilience

Industrial cybersecurity is ultimately about resilience—protecting systems in a way that supports safety, reliability, and operational continuity. While standards and technologies are important, success depends on applying them pragmatically within real world constraints.

Organizations that start with assessment, apply risk-based standards, segment networks thoughtfully, manage access, monitor continuously, invest in people, and govern consistently are far better positioned to manage today’s evolving threat landscape.

Cyber risks will continue to evolve, and a structured, operationally focused cybersecurity program positions OT systems to adapt over time.

Disclaimer: This article includes graphics generated by CDM Smith with the assistance of artificial intelligence. These visuals were created to complement the content and enhance reader understanding.

Geno Triana, CDM Smith, Dallas, Texas, is a senior automation engineer at CDM Smith. Edited by Mark T. Hoske, editor-in-chief, Control Engineering, WTWH Media, [email protected]. 

Keywords 

Industrial cybersecurity, cybersecurity assessment 

Consider this 

How’s the industrial cybersecurity at your location, and what can you do to help? 

You also might like

https://www.controleng.com/industrial-cyber-security

https://www.controleng.com/nist-releases-version-2-0-of-landmark-cybersecurity-framework/

Written by

Geno Triana, CDM Smith

Geno Triana, CDM Smith, Dallas, Texas, is a senior automation engineer at CDM Smith, supporting the planning, design, and assessment of industrial control systems for critical infrastructure clients. His work focuses on integrating automation, networking, and cybersecurity in operationally resilient operational technology environments.