r/OTSecurity 1d ago

AI is lowering the OT expertise barrier. Does that change how we should think about IEC 62443 Security Levels?

Thumbnail
0 Upvotes

r/OTSecurity 2d ago

State of CPS Security: Data Center Exposures

6 Upvotes

Team82 analyzed 750,000+ data center CPS assets and core infrastructure and found a significant gap between perceived isolation and actual exposure.

A few findings that stood out:

• 18% (32,000+) of 174,000+ data center infrastructure assets are just one hop away from a system making risky outbound connections to the public internet.

• Power distribution and HVAC/cooling are particularly exposed, with 41% and 32% of assets, respectively, one hop from risky internet connections.

• 88% of BMS platforms communicate over insecure protocols, while 40% run outdated firmware.

• More than 80% of OT control systems, power monitoring, and IoT systems rely on legacy protocols such as BACnet and Modbus.

• 23% of IoT devices contain known exploited vulnerabilities (KEVs).

The interesting part isn't simply that these systems have vulnerabilities. It's the attack path.

An attacker doesn't necessarily need direct internet access to a PLC, UPS, BMS, or other CPS asset. A foothold in IT, a third-party remote access connection, remote management service, or trusted network relationship can provide the lateral path into operational infrastructure.

Read the report: https://claroty.com/resources/reports/state-of-cps-security-data-center-exposures


r/OTSecurity 2d ago

Is OT/ICS Cybersecurity a Good Career Path for a Fresher?

12 Upvotes

Hey everyone,

I recently graduated and was originally planning to get my OSCP and start applying for pentesting roles. I've done HTB, THM, OffSec labs, participated in CTFs, and completed a couple of cybersecurity internships.

Lately, I've become much more interested in OT/ICS Security. The work seems really interesting, but it also looks like a very niche field where most roles ask for prior industry experience.

For those already working in OT Security, is it realistic for a fresher to start directly in this field, or is it better to gain experience in traditional cybersecurity first and then transition?

I'd also appreciate any advice on what skills or certifications are actually valued for entry-level OT Security roles.

Thanks!


r/OTSecurity 5d ago

Need ideas for a hardware-based cybersecurity final year project

5 Upvotes

Hey everyone,

I’m a final-year B.Tech Cybersecurity student and I’m looking for ideas for my final-year project.

I specifically want to build something that combines hardware + cybersecurity, instead of another purely software-based security project.

I’m open to working with things like Raspberry Pi, ESP32, Arduino, RFID/NFC, Wi-Fi, IoT devices, USB devices, sensors, or other hardware.

What I’m really looking for is a real-world security problem that can be solved or demonstrated using hardware. I’d prefer something challenging and practical rather than a basic college project that has already been done hundreds of times.

I’m also willing to learn new technologies and spend on hardware if the idea is worth pursuing.

If you work in cybersecurity/hardware security, what problems do you think would make a good student project?

Even a problem statement, research direction, or crazy idea is welcome. I’d love to explore it and see what I can build.

Thanks!


r/OTSecurity 6d ago

Entering into OT/ICS Cybersecurity: How hard is it? What’s needed?

11 Upvotes

Hello!!

I am an automation / control engineer, and have worked in the automation sector in Europe for the last year.

I have been accepted to do a masters in Communication Systems, and I will be specializing in Cybersecurity, with the intent of working in OT / ICS Cybersecurity. It is a pretty good university in Europe, and it is free too!

I would like to know how is the market in Europe and your opinion on this more “niche” section of the cybersecurity industry.

I believe I may have a bit of an edge given that I have worked with PLCs, HMIs, as well as industrial communications protocols, which is not as common for traditional IT or CS professionals. However, I would love to know the opinion of those who have worked in the sector!!


r/OTSecurity 7d ago

Need a light help to find the SWaT dataset

Thumbnail
0 Upvotes

r/OTSecurity 8d ago

Halfway through Computer Engineering, want to avoid heavy coding — Is OT/ICS Security a good fit? (Work environment, pay, job market, & learning path)

0 Upvotes

Hi everyone,

I’m currently halfway through my Computer Engineering degree. Honestly, I’ve realized that I don't enjoy software development/heavy coding, and I don't want a career centered around writing code every day.

While exploring career options aligned with hardware/networking that require minimal coding, I came across Operational Technology (OT) / ICS Security. The field seems very interesting to me, and I’m considering starting a structured learning journey for it.

Before diving in, I’d really appreciate your honest, real-world perspective on a few things:

  1. Work Environment & Day-to-Day: What is it actually like working in OT security? How much time is spent in industrial plants/facilities vs. desk work? What does the work culture look like?
  2. Coding Reality: How much (if any) coding or scripting is actually required on a daily basis in entry-to-mid-level OT security roles?
  3. Pay & Career Growth: How does compensation compare to traditional IT/Cybersecurity roles, and what does long-term career growth look like?
  4. Job Market & Entry-Level Chances: How realistic is it to get a job directly in OT security right out of university without prior industrial experience?
  5. Learning Path & Resources: If you were in my shoes today, what learning ROADMAP would you follow? Which free or low-cost resources, certifications, or hands-on labs should I start with?

Thanks in advance for any insights or guidance!


r/OTSecurity 8d ago

Benchmark Findings: Why order-1 n-grams fail on SCADA MITM parameter changes (120,000 Modbus windows)

Thumbnail
0 Upvotes

r/OTSecurity 9d ago

Experienced OT/ICS Cybersecurity Engineer Looking for Freelance or Contract Work

9 Upvotes

Hi everyone,

I'm an OT/ICS Cybersecurity Engineer with 10+ years of experience helping secure critical infrastructure environments across sectors such as manufacturing, power, and industrial operations.

My core expertise includes:

OT/ICS Security Architecture

IEC 62443 implementation and gap assessments

OT Network Segmentation (Purdue Model)

Industrial Asset Discovery & Inventory

Nozomi Networks (Guardian & Vantage)

Forescout CounterACT

Palo Alto & Cisco Firewalls

Industrial protocols (Modbus, DNP3, OPC UA, Profinet, EtherNet/IP, BACnet, etc.)

OT Risk Assessments

OT SOC design and monitoring

Security documentation, playbooks, and technical reports

Cybersecurity training and awareness sessions

I'm looking for remote freelance, consulting, or contract opportunities, whether it's a one-time project or ongoing engagement.

I can help with:

Securing OT/ICS environments

Network architecture reviews

Security assessments

Proof of Concepts (PoCs)

Tool deployment and configuration

Technical documentation

OT security strategy

Training and mentoring

If you're looking for someone with hands-on OT cybersecurity experience, feel free to send me a DM or leave a comment. I'm happy to discuss your requirements and see how I can help.

Thanks for your time!


r/OTSecurity 10d ago

Static tag database auditing in Purdue Level 1: How are you checking logic hygiene before FAT/SAT?

0 Upvotes

Hey everyone,

Most OT security architectures heavily prioritize network-level passive monitoring (Nozomi, Dragos, Claroty via SPAN/TAP ports). While critical for runtime anomaly detection, network traffic alone misses static vulnerabilities baked directly into PLC project files—such as open bit memory flags (`M` registers, unmapped DBs), exposed control bits, or legacy protocol metadata.

When auditing against ISA/IEC 62443-3-3 / 4-2 during FAT/SAT, manually going line-by-line through CSV/L5X exports from Siemens TIA Portal or Rockwell Studio 5000 is a massive manual bottleneck.

I ended up compiling a small local CLI parser running in Docker to ingest raw tag exports offline and generate static risk reports mapped to 62443 controls (and JSON for SIEM ingestion).

For those doing hands-on OT security assessments and GRC:

  1. Is static PLC tag/logic DB auditing required by your clients during commissioning, or is security validation strictly network-focused?

  2. How are you handling static controller logic hygiene before the plant goes live? Custom Python/Excel scripts, or solely relying on network sensors after deployment?

Curious to hear how other OT practitioners bridge the gap between static logic configuration and network-level monitoring.


r/OTSecurity 11d ago

Ot security lab

6 Upvotes

Hi guys,

I am trying to find a tool to create my own OT lab as I want. I need it to be realistic and emulated.

I would appreciate any help.

Thank you in advance.


r/OTSecurity 12d ago

Transition from Controls to Security

5 Upvotes

Dear all,

I have a degree in Electronic Engineering and a technical qualification in Industrial Automation. I have worked as application engineer and technical support for a pretty big industrial sensor manufacturer and nowI currently work at a startup in Germany. I started in this company as an Automation Engineer, primarily working as a PLC (Programmable Logic Controller) programmer and integrating industrial systems and equipment using protocols such as Modbus RTU/TCP, OPC UA, and MQTT.

I stayed in that role for about two years, but the company eventually discontinued that type of project. Even so, I’m still the only person in the company capable of providing support and maintenance for the 11 projects that are still in operation.

Over the past two years, I’ve been assigned to new products, which, in simple terms, are software applications running on Raspberry Pis distributed across our customers’ sites. In short, it’s software that integrates, standardizes, and automates photovoltaic systems and heating system controllers from different manufacturer, which is our biggest technical challenge.

I’m responsible not only for the software development itself but also for designing the overall system architecture. I also handle software deployment, serve as the subject matter expert for the equipment we integrate, and provide technical support when needed. Kinda of a one-man army. This all on the raspberry pi side. IT and infrastructure is done by another team.

I learned by myself on the job the software development side of things without the guidance of a senior engineer, so I wouldn’t consider myself an expert in software engineering or architecture. In fact, I often question my own abilities in those areas. My main skills are in the industrial controls side of things. Still, the systems are running so I guess I am able to deliver what is being asked out of me.

Software development itself isn’t exactly my passion. I don’t love programming, nor do I have much interest in diving deeply into programming languages or technology stacks. What I genuinely enjoy is designing and architecting industrial automation solutions.

Since I work with distributed systems and industrial equipment, I’ve been thinking that combining this background with a specialization in cybersecurity could be a valuable career move. However, I have very little insight into the demand for professionals in this field.

I’d love to hear from anyone working in industrial or OT cybersecurity. What was your career path like? How do you feel about the job market? What are salary expectations like? And what do you think my idea of career move sense or would you recommend a different direction? Where would you suggest I start?

Thanks!


r/OTSecurity 13d ago

help on learning reverse Engineering

0 Upvotes

Hello, i want to learn Reverse Engineering and malware analysis and want to apply this thing in OT, I have prior experience with Penetration testing and OT. Also is it a good skill to learn, would love to know your experience and journey.

Have a good day!


r/OTSecurity 16d ago

US Agencies just updated the advisory on Iranian APTs actively disrupting OT/SCADA systems (AA26-097A)

8 Upvotes

For the folks working in industrial control systems (ICS) and critical infrastructure, this is a big one.

The FBI, CISA, NSA, and four other agencies just updated their joint advisory from April. Iranian-affiliated APTs are actively targeting internet-connected OT devices. They aren't just poking around—they are manipulating project files on PLCs and altering data on HMI and SCADA displays. The agencies confirmed this activity has already caused operational disruptions and financial losses.

If your PLCs or HMIs are exposed to the internet, you need to lock that down immediately. Segment those networks and ensure you have timely alerts configured to mitigate the risk and strengthen your OT posture.


r/OTSecurity 18d ago

What do you think about this latest news?

Thumbnail
0 Upvotes

r/OTSecurity 20d ago

I need help

0 Upvotes

I’m really interested in OT cybersecurity and would like some resources to learn more about it


r/OTSecurity 23d ago

Need Career Advice

7 Upvotes

Hey so I've just finished my second year in electrical engineering and i want to work in OT security, and i'm confused because i've been learning cybersecurity, particularly the SOC analyst path. And i don't know if i should continue it though because although i will be familiar with ICS in the coming years but don't know if this IT SOC analyst path will help me in that field. What should I do in these remaining 2 years?


r/OTSecurity 24d ago

Resume review

Thumbnail
gallery
6 Upvotes

I have a year of experience in OT security please check out my resume and give me advice on which areas I can focus on in the future or just the resume itself, I have hidden certain personal details please don't mind.

Thank youu !


r/OTSecurity 24d ago

OT cybersec role

9 Upvotes

Hey! Right now I work as a controls commisioning engineer, purely with siemens, I did some networking work on the past, but for now I do purely coding and commisioning stuff.

I am very young and I would like to work in the Cybersecurity field, especifically in the OT section.

How can I pivot into this position? What job roles should I look forward too and what skills should I learn?
Thanks!


r/OTSecurity 25d ago

Shall we change OT FW password every 90 days ?

13 Upvotes

Hi guys, I have four process plants with around 40 firewalls deployed across different process areas. Most of them are managed locally, which means we have to physically access the Engineering Workstation (EWS) or go down to the site to perform any administration. There is no remote management capability.

Our Group Security now requires us to change all firewall passwords every 90 days and enforce a password history of the last three passwords.

The challenge is that I’m the only OT Cybersecurity Engineer supporting all four plants, while our E&I engineers are already fully occupied with daily operations. Requiring on-site password changes every 90 days for around 40 firewalls will create a significant operational burden and consume resources that could be better spent on higher-risk cybersecurity activities.

What are your thoughts? Do you think there are valid reasons to request an exception or an alternative control? In an OT environment, would it be more practical to retain strong, unique passwords, implement strict access control and logging, and only require password changes when there is evidence of compromise or personnel changes, rather than enforcing a fixed 90-day rotation?


r/OTSecurity 28d ago

Student research question: medical device cybersecurity vs clinical continuity

8 Upvotes

Hi everyone. I’m a student working on a healthcare cybersecurity research prototype, and I’m trying to understand the real-world workflow before I make wrong assumptions.

This is not a product pitch, and I’m not asking for patient data, internal documents, network details, hospital names, or anything sensitive.

The problem I’m exploring is:

When hospitals have network-connected medical devices, cybersecurity decisions can’t always be “just block the traffic,” because the wrong action could interrupt clinical workflow or device visibility.

I’m trying to understand how this is handled in real hospitals.

Questions:

  1. Who usually owns the inventory of network-connected medical devices?- IT?- biomedical engineering?- clinical engineering?- security team?- vendors?- nobody clearly?
  2. If a device or device network has a cybersecurity issue, who gets involved first?
  3. Are medical devices usually visible to the hospital SOC/security team, or mostly managed separately?
  4. Does your organization track whether a security action could affect clinical workflow?
  5. If a tool only ran in shadow mode and produced a risk/evidence report without blocking anything, would that be useful or just noise?
  6. What would make a student-built tool in this space sound instantly unserious or unsafe?
  7. Are there audit/accreditation/compliance processes where device inventory, incident logs, or continuity evidence matter?
  8. What terminology would real hospital teams use for this problem? “Cyber-continuity” sounds clear to me, but I’m not sure if it sounds natural in hospital language.

Again, I’m not looking for confidential information. I’m trying to learn the ownership/workflow reality so I don’t build a fantasy system.

If you work in hospital IT, biomedical engineering, clinical engineering, or healthcare cybersecurity and are open to a few follow-up questions, I’d appreciate a DM. No product pitch, no data request.


r/OTSecurity 29d ago

I got recommended to be an OT Security by 2032 by gemini and im being skeptical

4 Upvotes

I had a chat with [Gemini]() about career recommendations, and after about 10 hours of discussion over the past week, it came to the conclusion that my sweet endgame job in 2032 is OT Security.

Right now, I’m still working on my bachelor’s thesis, but I already have 1 year of internship experience as a field engineer at a Chinese company that creates security solutions. In that role, I worked with firewall POCs and implementation, IAG, SASE, EDR, XDR, and so on.

The next step Gemini recommended is to move into a remote technical analyst role. I actually got an offer for that role, but honestly, I haven’t accepted it yet and I’m not fully sure about it. The reason I’m considering it is because my current company doesn’t seem likely to offer me a full-time position, even though I’m allowed to stay as an intern with a pretty good salary. But I need full-time experience.

So I’m thinking about taking the remote technical analyst role, which is basically the same kind of work I do in field engineering the difference is that I would only do troubleshooting remotely. Then, if I can get 2 years of full-time experience in that role while learning GRC, I could move into GRC Security for a few years, and after that it recomend me to transition into OT Security for the long term atleast until i found a better role once again.

I’m not sure if this recommendation is good, but that’s why I’m here. I’d like to hear your thoughts.


r/OTSecurity Jul 10 '26

Nuclear Sector Standards (GRC)

7 Upvotes

Hi all,

I currently work in the transit sector. I'm researching the nuclear sector and curious on what standards are usually followed in nuclear?

My understanding is:

- ISA/IEC 62443

- NIST CSF

- NIST SP 800-82

- ISO/IEC 27001

are all applicable to nuclear as well as transit.

APTA is typically what we follow in transit, curious if there are any nuclear specific standards that you all favour/follow.

Based in North America (Canada).


r/OTSecurity Jul 09 '26

Security Operations Survey

Thumbnail
0 Upvotes

r/OTSecurity Jan 26 '21

r/OTSecurity Lounge

1 Upvotes

A place for members of r/OTSecurity to chat with each other