OT Security – Complete Guide
1) What is OT and how it differs from IT
OT = systems/devices (PLCs, RTUs, DCS, SCADA, HMIs, sensors/actuators) that control physical
processes. Key differences: Availability & safety > confidentiality; longer lifecycle (10–20+ years);
physical safety impact; limited resources.
2) Typical OT Architecture & Components
Field devices, PLCs/RTUs, SCADA/DCS, HMIs, historians, engineering networks, IT-OT interface
(DMZ), Purdue Model layers.
3) Common Industrial Protocols
Modbus (no auth, cleartext), DNP3 (secure variant exists), OPC/OPC UA, IEC 61850, vendor
protocols. Risks: lack of encryption, auth.
4) Threats & Real Attacks
Examples: TRITON/TRISIS (safety systems), Stuxnet, Industroyer. Use MITRE ATT&CK; ICS to
map adversary behaviors.
5) Standards & Frameworks
IEC 62443, NIST SP 800-82, MITRE ATT&CK; ICS, CISA ICS advisories.
6) Core Defensive Controls
Inventory, segmentation, hardening, secure remote access, patch mgmt, monitoring/IDS, privileged
access control, backups, incident response.
7) Vendor Security Questions
Ask about firmware signing, patch/update policy, secure configuration guides, vulnerability
disclosure, IEC 62443 compliance.
8) Hands-on Lab Ideas
OpenPLC + Modbus, Conpot honeypot, passive asset discovery with Wireshark, simulate
segmentation, practice patch mgmt.
9) Interview Questions & Answers
Q: OT vs IT? A: Safety/availability > confidentiality; lifecycle differences. Q: IEC 62443? A:
Standard for IACS security lifecycle, zones, conduits, security levels. Q: Remote vendor access? A:
Jump hosts, MFA, session recording, DMZ. Q: Patching? A: Test in lab, apply in maintenance
windows, virtual patching. Q: Incident response? A: Safety first, isolate zone, vendor coordination,
recovery.
10) Certifications & Resources
Certs: GICSP, SANS ICS, ISA/IEC 62443 training. Must-read: NIST SP 800-82, IEC 62443, MITRE
ATT&CK; ICS, CISA ICS advisories. Blogs: Dragos, Nozomi, Claroty.