RealVNC logomark

RealVNC Viewer

Productivity

icon close circle

OT Cybersecurity Best Practices: Strategic Risk Priorities

Contents

A maintenance connection reaches the wrong controller, a production process pauses, and the pressure spreads beyond the control room. Operators need to keep the process stable as engineering, IT, and facility leaders determine what changed and who owns the next decision.

OT cybersecurity best practices are the governance, technical, and operating controls that keep industrial systems available, accurate, and predictable. They start with accountable asset records, validated network boundaries, and identity-governed remote maintenance, then use risk-based patch exceptions and review cycles to protect production without introducing unsafe changes to live processes.

This work differs from conventional IT security since operational technology (OT) controls physical processes. Programmable logic controllers (PLCs), human-machine interfaces (HMIs), and supervisory control and data acquisition (SCADA) systems may govern pressure, chemical dosing, turbine speed, or safety alarms. A routine update or access restriction so needs engineering validation against process dependencies before it reaches a live environment.

This guide sets out a practical baseline for industrial security leaders. It explains how to map assets and dependencies, reduce unnecessary external paths, segment networks by function and consequence, govern remote access by named identity and role, and treat patch exceptions as documented risk decisions. It shows how IEC 62443, the NIST Cybersecurity Framework (NIST CSF), NERC CIP, and NIS2 inform investment priorities, reviews, and accountable recovery planning.

What makes OT cybersecurity best practices urgent now?

A production interruption quickly becomes a leadership problem when engineering, IT, and facility teams must decide which systems stay online and which controls are safe to apply. OT cybersecurity best practices are the governance, technical, and operational controls that protect the availability, integrity, and safe operation of industrial systems. They matter since connected operations, aging equipment, and ransomware exposure can turn a cyber event into a production, safety, or service-continuity incident.

The priority order changes the decision. Enterprise IT commonly starts with confidentiality. Operational technology puts availability first, followed by integrity: a controller must behave predictably as the process remains running. The FBI Internet Crime Report 2023 recorded 1,193 ransomware complaints from U.S. critical-infrastructure organizations in 2023. That figure reinforces why industrial resilience needs executive ownership before an incident forces hurried trade-offs.

Safety consequences: A change to a PLC, sensor, or human-machine interface (HMI) can affect a physical process, not merely a data record.

Production dependency: Plant operations often rely on systems that cannot be paused without engineering review.

Legacy exposure: Older equipment may lack modern authentication, encryption, or practical patch paths.

External connectivity: Remote maintenance, supplier links, and enterprise integration create paths that need accountable governance.

Legacy Security Assumption Modern OT Reality Leadership Implication
The production network is isolated Support and data flows often cross network boundaries Validate every external path and its owner
A patch resolves the issue A patch may interrupt a safety-sensitive process Treat patching as an engineering risk decision
Asset lists change slowly Controllers and connections change through maintenance work Maintain accountable, current asset records
Perimeter controls are enough Valid credentials may enable ordinary-looking access Review identity, permissions, and session evidence

Manufacturing featured in 2,305 incidents in Verizon’s 2024 dataset, including 849 with confirmed data disclosure (Verizon 2024 DBIR Executive Summary, 2024). The practical outcome is evident: leadership must govern industrial security as part of operational resilience, with engineering authority built into every material decision.

Which OT risk model guides investment decisions?

An OT risk model should rank work by physical-process criticality, exposure pathways, control feasibility, and recovery readiness. IEC 62443 provides an industrial-control lifecycle framework, NIST Cybersecurity Framework (NIST CSF) organizes enterprise risk management, and NERC CIP sets obligations for applicable North American bulk electric system entities. The value comes from using one shared model for funding, exceptions, and recovery decisions.

Frameworks answer different questions. IEC 62443 helps teams define lifecycle requirements across industrial automation and control systems. NIST CSF gives leaders a common structure for Identify, Protect, Detect, Respond, and Recover. NERC CIP and the EU’s NIS2 Directive introduce sector and regional obligations that legal, compliance, and operational leaders must map to their own scope.

Think of risk prioritization like setting fire protections by the consequence of a room failing, rather than by the age of every electrical component in the building. A small controller governing chemical dosing may deserve earlier funding than a newer workstation with limited process consequence. This keeps device counts and published severity scores from substituting for engineering judgment.

  • Process criticality: What physical outcome follows if this asset behaves unexpectedly?
  • Exposure pathways: Which network, supplier, or remote-support route reaches it?
  • Control feasibility: Which safeguards work without disrupting the process?
  • Recovery readiness: How quickly can the team restore safe, predictable operation?
Risk Dimension Executive Question Evidence Source Decision Supported Common Misread
Process criticality What process consequence follows a failure? Process maps and safety reviews Funding priority Counting every device equally
Exposure pathways How could a connection reach this zone? Network flows and support records Segmentation scope Assuming an air gap exists
Control feasibility Which control is safe to operate here? Vendor guidance and engineering tests Exception treatment Applying IT controls unchanged
Recovery readiness What restores the process after disruption? Recovery plans and drills Resilience investment Treating backups as a full recovery plan

How do safety and process criticality change risk?

Criticality measures the consequence of impaired process control, not the purchase value of the device. PLCs can govern valve operation, turbine speed, chemical dosing, pipeline pressure, and safety alarms; a risk review must trace each asset to the process and safety relationships it serves. Availability, integrity, and confidentiality form the relevant order when predictable operation protects people and production.

Where do exposure and control feasibility intersect?

A vulnerable controller with limited connectivity and documented compensating controls may need a different treatment from a newer engineering workstation reachable through an external route. NIST SP 800-82 Rev. 3 recommends functional zones and a demilitarized zone (DMZ) between enterprise and OT operations-management tiers. That architecture gives teams room to reduce connectivity while preserving validated industrial communications.

The connectivity problem is not theoretical. SANS 2024 State of ICS/OT Cybersecurity found that 22% of surveyed organizations had ICS or OT assets dual-homed with IT networks or located directly on the enterprise network. A defensible investment plan documents those paths, assigns risk owners, and records why each exception remains acceptable.

How should leaders sequence the OT security baseline?

Leaders should sequence an OT security baseline by understanding assets and process dependencies, reducing unnecessary connectivity, governing access, and managing controls that cannot safely be deployed. This is a decision order, not a universal timetable. Each stage establishes evidence needed for the next one, so teams avoid changing production systems before they understand the operational consequence.

Asset visibility comes first: unknown connections make every later decision weaker. The NIST NCCoE zero-trust architecture draft demonstrates discovery and identification of identifiers, endpoint assets, and data flows. For an industrial program, the inventory must connect each device to a named owner, communication path, and process dependency.

  1. Map assets and process dependencies – Create an authoritative inventory from passive traffic and engineering records. Assign an inventory owner, and confirm that PLCs, HMIs, sensors, workstations, and communication paths have accountable owners. A spreadsheet alone does not provide continuous visibility.
  2. Remove internet exposure and review external paths – Review firewall, internet service provider, and remote-support records. Each external connection needs a documented business justification and monitoring plan; an assumed air gap is not evidence.
  3. Segment by function and consequence – Use Purdue-level and data-flow mapping to set zone boundaries and DMZ placement. Engineering teams must validate rules before they limit process-critical communications.
  4. Apply identity-based remote access – Map maintenance roles to least privilege, meaning each person receives only the permissions needed for a defined task. Every remote session needs a named identity and reviewable oversight.
  5. Manage patch exceptions as risk decisions – Use vendor guidance, maintenance windows, and process consequences to decide whether to patch, mitigate, monitor, or accept the risk. Every exception needs compensating controls and a review date.
Baseline Control Leadership Decision Common Error Evidence of Completion
Asset inventory Name the record owner Treating records as static Assets and dependencies are assigned
External-path review Approve each connection Assuming isolation Approved paths are documented and monitored
Network segmentation Set zone boundaries Blocking validated traffic Rules separate enterprise and control zones
Remote-access governance Approve role permissions Using shared vendor accounts Sessions map to named identities
Patch exception process Accept, mitigate, or patch Using an IT cadence unchanged Exceptions have controls and review dates

Internet reachability deserves early attention. Censys’ 2024 State of the Internet Report observed more than 145,000 publicly reachable ICS services across 175 countries. Removing unnecessary routes before expanding monitoring gives leaders a smaller, more governable set of access decisions.

When should OT cybersecurity best practices be reviewed?

Industrial risk governance requires scheduled review plus reassessment when the operating environment changes. A calendar review keeps owners accountable. Event-driven review tests whether prior assumptions still match current connectivity, suppliers, process design, and recovery capacity. The cadence must reflect process criticality and regulatory scope rather than a fixed interval copied from enterprise IT.

External warning belongs in that routine. CISA’s 2024 Year in Review states that the agency conducted 2,131 Pre-Ransomware Notifications during 2024, bringing its total to 3,368 since March 2023. Early-warning coordination gives security leaders a reason to check whether known exposure paths, emergency contacts, and access records remain current before a local event occurs.

A newly connected condition-monitoring system illustrates the difference between a technical task and governance review. The team must update the asset inventory, reassess the network zone, review supplier access, and test the incident playbook. Running a vulnerability scan alone does not answer whether the new connection changes process consequence or recovery ownership.

  1. A material architecture change – Review a new Industrial Internet of Things (IIoT) deployment, plant expansion, integration, or remote-access path.
  2. A safety, production, or cyber event – Test whether assumptions, communications plans, and recovery evidence remain valid.
  3. A newly identified vulnerability or exposure – Reassess exploitability, process consequence, and available compensating controls.
  4. A supplier or maintenance-contract change – Revalidate third-party access, support obligations, and software or firmware dependencies.
  5. A formal governance cycle – Review risk acceptance, funded backlog, control effectiveness, and incident-drill lessons with executive sponsors.

Vulnerability-management guidance from ENISA calls for regular vulnerability scanning, policy-based updates, and a policy that identifies and tracks vulnerabilities. In an OT setting, that policy must state who decides when a patch is unsafe, which compensating control applies, and when the exception returns for review.

Executive sponsors should ask drills for evidence, not reassurance: who made the shutdown decision, which communications path failed, what access records were available, and whether the recovery plan restored the process as designed. Those answers turn a review cycle into an operating discipline.

Where do common OT control failures create risk?

Most recurring OT control failures begin with unclear ownership rather than an absent security product. An undocumented maintenance route, an inventory without an accountable owner, or a shared supplier account can persist without a team owning the decision to close, govern, or accept it. Leaders need to make those decisions visible before a routine support activity becomes an investigation.

  • Assumed isolation: Undocumented remote paths, dual-homed assets, and maintenance connections weaken an assumed air gap.
  • Unowned inventory: No accountable source of truth exists for devices, firmware, protocols, or network dependencies.
  • Shared or persistent access: Supplier convenience overrides attributable, time-bounded access governance.
  • Compliance-only patching: Published severity scores replace context about safety, exploitability, connectivity, and process consequence.
Control Failure Operational Consequence Executive Corrective Decision
Assumed isolation A connection bypasses intended network boundaries Require documented path validation
Unowned inventory Teams cannot assess a change completely Assign asset and dependency ownership
Shared access Session accountability is lost Require named, time-bounded access
Context-free patching A maintenance action disrupts a process Approve risk-based exception treatment

The consequences of public connectivity are documented. CISA’s AA23-335A advisory reported that CyberAv3ngers compromised at least 75 Unitronics PLC devices between November 2023 and January 2024, including at least 34 in the U.S. Water and Wastewater Systems Sector. The lesson is not that every device needs identical treatment; it is that leaders must know which devices are reachable and who owns remediation.

The joint FBI, CISA, EPA, and MS-ISAC advisory directs operators to remove HMIs and PLCs from the public internet and to use a firewall or virtual private network (VPN), strong passwords, and multifactor authentication where remote access remains necessary. An air gap remains a useful defense layer, but it does not remove the need to validate supplier connections, remote support, and hidden overlaps.

How RealVNC Closes the OT Cybersecurity Gap

Maintenance and remediation often require remote access across IT, engineering, maintenance, and external-service boundaries. Shared credentials, standing permissions, and incomplete session evidence weaken the access-control baseline established through inventory and segmentation. The joint FBI, CISA, EPA, and MS-ISAC advisory supports removing HMIs and PLCs from public internet exposure and apply strong authentication where remote connectivity remains necessary.

RealVNC Connect supports a controlled remote-support workflow around those decisions. Multi-factor authentication (MFA) and single sign-on (SSO) with Microsoft Entra ID or Okta tie access to workforce identity and centralized authentication policy. Role-based access controls (RBAC) and granular action-based permissions separate the right to connect from the actions permitted during a session, including keyboard, mouse, and file-transfer use. Session monitoring, recording, and detailed audit logs give authorized teams reviewable evidence for maintenance oversight and incident investigation. Code Connect uses single-use, time-bound 9-digit session codes for third-party support, avoiding a standing access path for an unmanaged device.

Chris Butera, Acting Executive Assistant Director for Cybersecurity at CISA, said in DTS Solution commentary: “CISA has observed threat actors like Volt Typhoon targeting OT systems to compromise, escalate, and maintain access within operational environments. Zero Trust architecture is critical to preventing cyber incidents that could cause operators to lose visibility or control of essential systems.”

These controls support attributable access to support systems and evidence for access-governance review. They complement network segmentation, accountable inventories, and engineering safety validation; they do not replace them. That boundary keeps remote support aligned with operational resilience instead of creating another unmanaged route into the control environment.

Final Words

OT cybersecurity best practices work when leaders treat each control as a decision about safe, predictable operations. Start with an accountable view of assets and process dependencies, then reduce unnecessary external paths, set validated network zones, and govern every maintenance connection by identity and role. When patching is unsafe, document the exception, apply compensating controls, and bring it back for review. Scheduled governance and event-driven reassessment keep those decisions aligned with changing suppliers, connectivity, and production conditions.

This discipline gives engineering, IT, and facility leaders the evidence to act together when a session, vulnerability, or operational change demands attention. RealVNC Connect supports that access-governance layer with multi-factor authentication, role-based access controls, and session monitoring, recording, and detailed audit logs, and Code Connect gives third parties time-bound access without permanent credentials. Those controls complement segmentation, inventory ownership, and safety validation; they do not replace them. Leave the workflow unmanaged, and routine remote support becomes a blind spot when you need attributable evidence most. Book a 30-minute demo to see how controlled remote access can fit your industrial security governance model.

FAQs

Framework selection and remote-access governance depend on the industrial process, regulatory scope, and safety consequence involved.

What are OT cybersecurity best practices for leaders?

A strong OT cybersecurity best practices program protects safe, continuous operations through risk-based governance. Leaders should identify process-critical assets, document network paths, separate environments by function, govern human and supplier access, manage patch exceptions, and test incident response. NIST Cybersecurity Framework (NIST CSF) provides a useful structure through Identify, Protect, Detect, Respond, and Recover.

How do IEC 62443 and NERC CIP differ?

IEC 62443 addresses security requirements for industrial automation and control systems across their lifecycle. NERC CIP applies to in-scope entities and systems supporting the North American bulk electric system. An organization may map shared controls across both, but legal and compliance teams must confirm which obligations apply to its operations.

What is the NIST standard for OT security?

NIST SP 800-82 Rev. 3 is the primary NIST guidance for operational technology security. It explains how to adapt security practices to systems that monitor or control physical processes, including the use of functional zones and a demilitarized zone (DMZ) between enterprise and OT operations-management tiers. It is guidance, not a certification.

How often should industrial cyber risk be reviewed?

Industrial cyber risk needs a scheduled governance review plus reassessment after material changes. New connectivity, supplier changes, process redesign, newly identified vulnerabilities, safety events, and changes to production systems should trigger a fresh review. The team must examine access, dependencies, recovery evidence, and compensating controls rather than relying on a vulnerability scan alone.

How does OT security differ from IT cybersecurity?

OT security prioritizes safe and predictable physical operations, and enterprise IT security often gives greater weight to data confidentiality. A change to a programmable logic controller (PLC), human-machine interface (HMI), or supervisory control and data acquisition (SCADA) system may affect production or safety. Security decisions require engineering validation alongside IT risk analysis.

How does RealVNC support controlled OT access?

RealVNC Connect supports controlled remote access through multi-factor authentication (MFA), single sign-on (SSO), role-based access controls (RBAC), session monitoring, and detailed audit logs. Code Connect provides time-bound third-party sessions through single-use 9-digit codes. These controls provide attributable access evidence alongside network segmentation, asset governance, and engineering controls; they don't replace them.

Learn more on this topic

This release is one of those "something for everyone" ones. There's a redesigned home screen that makes finding and connecting...
A data and analytics strategy turns conflicting reports into trusted decisions - but when governance slows access to sensitive insight,...
A hybrid cloud strategy can stall services, blur accountability, and inflate costs. See the governance model that keeps workloads controlled...

Try RealVNC® Connect today for free

No credit card required for 14 days of free, secure and fast access to your devices. Upgrade or cancel anytime