Section 7
Section 7
Section 6
Section 5 ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS
OT Threat Landscape & Threat Modeling Controls)
Cyber threats targeting OT: threat actors & malware You will learn:
origins 1. ICS Incident Response: Plan Why timely detection,
Understand the typical OT threat landscape across the response, and containment are essential in OT
Purdue model layers. environments.
Threat modeling in OT: Mapping assets, vulnerabilities, 2. Defensible ICS Network Architecture: Building segmented,
and potential attack paths. risk-aware architectures to protect critical operations.
3. ICS Network Visibility & Monitoring: Leveraging passive
monitoring tools for asset inventory, anomaly detection,
and continuous oversight.
4. ICS Secure Remote Access: How to enable secure, least-
privilege remote connectivity for vendors and operators.
5. Risk-Based ICS Vulnerability Management: Prioritizing
vulnerabilities, applying compensating controls, and
managing patching challenges in OT.
Simone's CyberSecurity
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
SANS
#2 Defensible OT/ICS Network Architecture
SANS
#3 OT/ICS Network Visbility & Monitoring
SANS
#4 OT/ICS Secure Remote Access
SANS
#5 Risk-Based OT/ICS Vulnerability Management
Simone's CyberSecurity 67
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
Simone's CyberSecurity 68
SANS IT Incident Response vs OT Incident Response
#1 Same attack, very different consequences
Action: Isolate Infected Device (Laptop, Server, Desktop.. etc.) Action: Isolate Infected Device (PLC, HMI..etc)
Impact: Business ontinues with minor disruption Impact: Production halt, Equipment risk, Safety Hzard
Simone's CyberSecurity 69
16
ICS Incident Response: The Challenge of Timely Detection & Response
SANS Why SANS ranks Incident Response as the #1 ICS/OT Critical Security Control
#1
Responsiveness to threats:
depends on the security
operation team’s ability to
immediately inspect an alarm
Simone's CyberSecurity 71
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
Simone's CyberSecurity 72
Maturity Levels of Defensible Network Architecture
Progression of Segmentation (Mapped to Purdue Model & ISA/IEC 62443 Zones/Conduits)
Level 3
Level 0: Flat, no segmentation
Level 2
Level 1: Basic Zone separation
Level 1
Level 2: Firewalls between IT/OT
Simone's CyberSecurity 73
Level 0: Flat IT/OT combined (No Segmentation)
Equivalent to ignoring Purdue zones — enterprise and control systems in one flat domain.
Scenario:
Demonstrates the current state of many industrial networks where IT and OT systems coexist in a flat, unsegmented environment. There is no separation between
enterprise and control assets.
Risks:
• No segmentation boundary between IT and OT
• Single broadcast domain increases exposure
• High lateral movement risk across systems
• Attackers gaining access to IT can easily pivot to OT
• Lack of network zoning complicates monitoring and containment
Enterprise
Server
Public
OT data
Server
historian
PLC
Internet
Workstation
HMI
Simone's CyberSecurity 74
Level 1: Segmented IT/OT (Basic Segmentation)
Scenario:
Represents organizations that have begun their segmentation journey by separating IT and OT into two distinct zones. However, there is no dedicated OT DMZ for secure data
exchange, and the OT side lacks micro-segmentation — meaning environments like R&D labs, test benches, or engineering workstations are still grouped into a single flat OT
zone.
Risks:
• Single security boundary between IT and OT (single firewall).
• Limited visibility and control across zones.
• Potential for lateral movement if the IT zone is compromised.
• No additional buffer zone for secure data exchange.
Enterprise
Server
Public
OT data
Server
historian
PLC
Internet
Workstation
HMI
Simone's CyberSecurity 75
Level 2: IT/OT Segmentation with Dedicated OT DMZ
Scenario:
Shows more mature segmentation where a dedicated OT DMZ exists between IT and OT, improving monitoring and control of data flows. While this architecture is
stronger, the OT network itself remains broadly zoned. There is still significant scope to introduce additional micro-segmentation of OT environments (e.g., separating
production, R&D, and test benches) to further reduce lateral movement risks..
Risks:
• If DMZ firewall rules are weak, attackers may pivot from IT to OT.
• OT DMZ often hosts data historians or jump servers, making it a high-value target.
• Misconfigured DMZ components can lead to data leakage or indirect access to OT assets.
• Segmentation improves security, but micro-segmentation is still missing.
Enterprise
Server
Public
OT data
Server
historian
PLC
Internet
Workstation
HMI
Simone's CyberSecurity 76
General Shopfloor Layout
77
Level 3 Segmentation: Two Scenarios (Logical and Zone based segmentation)
Simone's CyberSecurity 78
Level 3: Scenario 1 (Firewall Zone Based Segmentation)
Purdue-aligned Architecture with OT Micro-Segmentation
Scenario:
Represents a more mature network security model with IT, OT, and OT DMZ all clearly separated, combined with micro-segmentation within the OT side. Critical sub-zones such
as R&D, test benches, production cells, and engineering stations are isolated, reducing lateral movement and supporting defense-in-depth..
Risks:
Complexity of firewall policies may lead to misconfigurations.
Rule sprawl and inconsistent updates can weaken security posture.
Higher operational overhead for maintaining multiple firewalls and policies.
Potential performance bottlenecks if firewall capacity is not sized correctly.
Legacy OT devices may still lack proper endpoint security.
Enterprise
Server
Public
OT data
Server
historian
PLC
Internet
Workstation
HMI
Simone's CyberSecurity 79
Level 3: Mature Segmentation with OT Micro-Segmentation via Firewall Zone segmentation
IT DMZ IT network OT DMZ OT network
SCADA
Enterprise
Server
Public
OT data
Server
historian Process / Production
PLC
Line 1
Internet
Workstation
HMI
HMI
HMI
80
Level 3: Scenario 2 (Logical VLAN based Segmentation)
Purdue-aligned Architecture with OT Micro-Segmentation
Scenario:
Represents a more mature network security model with IT, OT, and OT DMZ all clearly separated, combined with micro-segmentation within the OT side. Critical sub-VLANs such
as R&D, test benches, production cells, and engineering stations are isolated, reducing lateral movement and supporting defense-in-depth..
Risks:
VLAN hopping attacks: Misconfigured switches may allow attackers to move between VLANs.
Shared infrastructure risks: VLANs are logical, not physical; they still run on the same switch fabric, so compromise at Layer 2 can bypass isolation.
Management complexity: Large numbers of VLANs can become hard to manage, leading to inconsistent policies.
Lack of true enforcement: VLAN segmentation depends heavily on correct ACLs and switch configuration — a misstep can collapse segmentation.
Insider or misconfigured port issues: If an access port is incorrectly assigned, a device could end up in the wrong VLAN.
Enterprise
Server
Public
OT data
Server
historian
PLC
Internet
Workstation
HMI
Simone's CyberSecurity 81
Level 3: Mature Segmentation with OT Micro-Segmentation via Logical Segmentation (VLANs)
IT DMZ IT network OT DMZ OT network
Enterprise
Server
Public
OT data
Server
historian Process / Production
PLC
Line 1
Internet
Workstation
HMI
HMI
HMI
82
From Maturity Levels to Real Architectures
From Maturity Levels to Purdue-aligned Architecture
Level 3
Level 2
Level 1
Level 0
Concept to
Blueprint
Simone's CyberSecurity 83
Level 3: Scenario 1: OT Micro-Segmentation via Firewall Zone segmentation
Level 2
Local HMI Local HMI
Supervisory
Level 1
Control
Level 0
Process
Simone's CyberSecurity
Level 3: Scenario 2: OT Micro-Segmentation via Logical Segmentation (VLANs)
Level 2
Local HMI Local HMI
Supervisory
Level 1
Control
Level 0
Process
Simone's CyberSecurity
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
Simone's CyberSecurity 86
Active Directory in IT & OT: Why a Shared AD Weaknes Segmentation
Single AD = Expanded Attack Surface Accross IT and OT
The IT AD standard
Active Directory is the central identity management for most IT
environments. It's built for convenience and broad connectivity.
IT AD OT using
OT's unique constraints
IT AD
OT networks prioritize safety, reliability, and uptime. They often
include legacy systems incompatible with modern security practices.
OT
Initial AD Group Policy disruption $70M
Access Compromise Push Impact
Simone's CyberSecurity 88
Separate OT Active Directory – Enforcing True Segmentation
Isolating IT and OT Identities to Reduce Risk
IT AD Seperate
OT AD
A dedicated OT AD forest – no ports shared with IT AD.
Simone's CyberSecurity 89
The segmented AD for OT architecture
Secure OT Identity: The Dedicated Forest Model
Dedicated OT AD forest
Create a completely separate Active Directory forest for OT
infrastructure. This ensures that a compromise of the IT forest
IT AD (Levels 4-5)
does not automatically grant access to OT assets.
Simone's CyberSecurity 90
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
Simone's CyberSecurity 91
16
OT/ICS Network Visibility & Monitoring
Develop capability for monitoring ICS environments
Temperature
Temperature Embedded PC
Embedded PC Sensor Gateway
Sensor Gateway
Industrial Workstation
Industrial Workstation
Remote I/O
Remote I/O
Simone's CyberSecurity
16
Building Visibility: Data Sources & Collection
From passive scanning to integerations: enabling full OT visibility
Connectors
Passive scanning Active Scanning integreating with
collection Collection several IT/OT tools
Simone's CyberSecurity
16
Turning Visibility into Action
Leveraging OT visbility tools for classification, segmentation and risk reductions
Enterprise
Network
HMI IoT Controller Controller
Industrial Printer
Management:
ERP
Building Automation CNC System
Reporting Server Device
Remote Access Planning:
Gateway MES
Level 2
Small
Electrical Drive
Power Meter Supervisory:
Building Automation Computer
HMI / ENG / SCADA /
3 1
4 2
Controller
Historian
Temperature
Embedded PC Level 1
Sensor Gateway
Industrial Workstation Automation: PLC
/ RTU
Remote I/O Ethernet
Level 0 connectivity
Process: Field
Network Attached Storage
Temperature Sensor Devices
Hardwired
Safety Instrumented System Instrumnetation
Simone's CyberSecurity
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
Simone's CyberSecurity 95
Introduction to OT/ICS Secure Remote Access
Why Remote Access is Critical (and Dangerous) for OT
The "Why"
Remote access allows for significant cost savings and
improved efficiency for maintenance, monitoring, and
troubleshooting of industrial systems. Internet
The "Danger"
Unlike IT breaches that cause data loss, a compromised
OT remote access session can lead to physical damage,
safety hazards, and major operational disruption. OT network
Key takeaway
We must transition from ad-hoc, insecure remote access
to a purpose-built OT secure remote access solution that
integrates MFA, monitoring, and least privilege. Case Study: A Secure OT Remote Access Workflow
A maintenance engineer needs to update a PLC at a remote pump station.
Simone's CyberSecurity
96
The OT/ICS Remote Access Threat Landscape
Common Attack Vectors & Risks
Insecure
Protocols
Key Controls for Secure OT/ICS Remote Access
Session Recording & Monitoring: Log and record all remote Secure OT
sessions for forensic visibility. Remote
Access
Multi-Factor Time-Bound
Time-Bound Access: Approve access only for the required Authentication Access
duration and revoke it automatically after. (MFA)
Vendor
Forensic Access &
Logging Device Posture
Governance
Check
Simone's CyberSecurity
98
Implementing a OT/ICS Secure Remote Access Solution
OT DMZ
Connection via Secure Gateway – Access routed through jump
server in OT DMZ.
OT network
99
OT/ICS Security Fundamentals (Aligned to SANS 5 Critical OT/ICS Controls)
Simone's CyberSecurity
Breaking the Sisyphean Loop with a Risk-Based Approach
All vulnerabilities are not created equal and a savvy security team must prioritize its efforts.
Identify your "Crown Jewels." Understand context and exposure Analyze real-world threat intelligence Prioritize and Mitigate based on
risk.
Simone's CyberSecurity
Breaking the Sisyphean Loop with a Risk-Based Vulnerability Management Cycle
Identify, Assess, Prioritize, Mitigate, Monitor
Identify
Identify critical OT assets & processes
Monitor & Review
Continously monitor & update
Assess
Analyze vulnerabilities & threats
Mitigate
Apply controls & response plans
Priortize
Rank risks by likelihood & impact
Simone's CyberSecurity
End of Section 6
Section 6 Summary – Key Takeaways
#1
Incident Section 7
Response Plan
#3
5 Network Visibility
& monitoring
#2 SANS
Defensible Network Critical OT/ICS
Architecture Controls
#4
Secure Remote
Access
#5
Governance & Processess (Who
Risk-Based Vulnerability
Ensures OT Security Happens?)
Management
Simone's CyberSecurity