Back to BlogManufacturing

OT Cybersecurity: Secure the Connections Around Old Machines

September 16, 20264 min read
Industrial control panel with pushbuttons and a display

OT cybersecurity gets harder when a reliable old machine gains a new path to the outside world. The controller may have run for twenty years without trouble, but now a vendor logs in remotely, production data feeds an office dashboard, and a maintenance laptop moves between networks. Each connection solves a business problem. Each one also needs an owner and a boundary.

That does not make the machine harmless. Older controllers may lack modern authentication, supported patches, useful logs, or encryption. Replacing every working machine is rarely practical, though, and a new controller connected through an unmanaged remote-access path can inherit the same exposure on day one.

The practical job is to understand the machine, the connection, and the consequence together. For manufacturers in Pueblo, Fountain, and Colorado Springs, that is a much more useful starting point than treating age alone as the risk score.

What counts as an OT connection?

Operational technology, or OT, includes systems that monitor or change physical processes. NIST's Guide to Operational Technology Security covers programmable logic controllers, industrial control systems, building automation, physical access control, and other systems that interact with the physical environment.

A connection is not just the Ethernet cable plugged into a controller. It can be a route between the office and production networks, a vendor VPN, a cellular modem, a remote desktop tool, a historian that talks to both sides, a shared account, or a laptop used for programming and email. USB media and temporary maintenance connections belong on the map too.

Some of those paths are necessary. Remote support can shorten a stoppage, and production data can help a shop schedule maintenance before a failure. The goal is to allow the business function without leaving a broad, permanent route into the line.

Start OT cybersecurity with an honest asset map

You cannot set a useful firewall rule for a system nobody remembers. CISA's 2025 OT asset inventory guidance recommends identifying assets, classifying them by function and criticality, and documenting their communication paths and dependencies.

For a small plant, the first version can be simple. Record the device, its process owner, physical location, network address, software or firmware version, normal communication partners, remote-access method, and what happens if it becomes unavailable. Include the engineering workstation, historian, firewalls, switches, and vendor-managed equipment. The overlooked support system is often as important as the controller itself.

Do this with the plant manager and the people who maintain the equipment. Aggressive discovery or scanning can disrupt fragile OT, so the method and timing should be agreed with operations before anyone starts probing devices.

A legacy controller can be both useful and risky. The safe design assumes that and controls every path leading to it.

Use segmentation to improve OT cybersecurity

A flat network lets an office compromise become a production problem. Proper segmentation creates defined zones for systems with similar security and operational needs, then permits only the necessary traffic between them. CISA's current primary OT mitigations specifically call for separating IT and OT networks and using a demilitarized zone, or DMZ, to pass required data.

That means the accounting workstation should not have a direct route to a PLC. A reporting system may read selected data from a historian in the DMZ, while control traffic remains inside the OT zone. Firewall rules should name the source, destination, protocol, and business reason. "Allow any" is easy during commissioning and painful years later when nobody remembers why it exists.

Segmentation supports a broader cybersecurity program, but it also helps with ordinary mistakes. A bad update or misconfigured laptop has less room to spread when the boundaries match the process.

Remote vendor access should expire

The vendor who tunes a press brake may need remote access. That does not require a shared account that stays enabled all year. Give each person a named identity, require phishing-resistant multifactor authentication where the solution supports it, limit access to the asset and service needed, and turn the access off when the window closes.

CISA's mitigation guidance also recommends removing OT assets from the public internet, using secure private connectivity or a VPN when remote access is essential, applying least privilege, and disabling dormant accounts. Put vendor sessions through a controlled jump point and retain logs. If the remote method cannot produce a reliable record of who connected and when, that limitation belongs in the risk decision.

Emergency access needs a procedure too. Decide who can approve it, how credentials are recovered after hours, and how the plant returns to its normal locked state. Otherwise the emergency exception quietly becomes the everyday configuration.

Protect the old machine without pretending it is modern

Once the paths are controlled, address the device itself. Apply vendor-supported updates during an approved maintenance window. Remove unused services. Back up controller programs and configuration files. Restrict engineering tools to managed workstations. Monitor the network traffic that crosses OT boundaries, and investigate changes from the known baseline.

When a device cannot support a needed control, document the compensating protection around it. A dedicated zone, narrowly filtered conduit, monitored jump host, and tested spare or recovery procedure may reduce risk while the machine remains in service. None of those steps makes unsupported equipment immortal. They make the tradeoff visible and manageable.

And test recovery with operations in the room. Can the team restore the controller logic? Can it run safely if the office network is unavailable? Who calls the machine vendor? Where is the offline copy of the configuration? OT security has to protect safety and availability as well as data.

Make one controlled improvement at a time

A good first engagement does not begin with ripping out the floor. It begins with the real diagram, the remote-access list, and one agreed boundary to tighten. A manufacturing-focused review should involve operations, IT, safety, and the machine integrator when their knowledge is needed.

GTZ Integrations can help a Southern Colorado manufacturer document connections, separate business and production traffic, and build a practical access plan around the equipment already in place. Where ongoing monitoring and maintenance are needed, that work can also fit into a broader managed IT plan.

If you cannot say which systems can reach a controller today, start there. The first useful result is a map everyone trusts and a short list of connections that deserve attention.

Free Consultation

Questions About Your IT?

Book a free assessment with Efrain. No sales pitch, no obligation.

Get Your Free Assessment
Call (719) 203-7752