Manufacturers need to protect the systems that keep physical processes running. Operational technology includes production equipment, industrial controls, and building systems, with constraints that differ from ordinary office IT.
NIST SP 800-82 Revision 3 provides OT security guidance that accounts for performance, reliability, and safety. Use those constraints to shape the work with plant operations, equipment vendors, and qualified OT specialists.
Understand the connections
Production monitoring, maintenance, inventory integration, and vendor support may connect OT with business networks or remote users. List the connections and the work each supports. A useful boundary needs to allow required operations while limiting unnecessary access.
Do not assume an environment is isolated because it was designed that way years ago. Confirm current communication paths and remote-access arrangements with the people who operate the plant.
Plan around safety and availability
Patching or isolating a device may interrupt a physical process. Older systems may also have limited vendor support or strict change requirements. Review the consequences of a change before applying an IT procedure to production equipment.
Discovery tools need the same care. Active scanning can affect some OT devices; passive monitoring also needs appropriate installation and interpretation. Select and test the approach with OT owners and the equipment vendor rather than assuming any tool is disruption-free.
A practical sequence
1. Build an agreed inventory. Combine asset records, diagrams, vendor information, and appropriately validated discovery methods. Identify the equipment owner, support status, and dependencies.
2. Review IT/OT boundaries. Segmentation and controlled pathways, potentially including a DMZ, can limit unwanted access. Prioritize them against your actual risks; they are not automatically the highest-impact action in every plant. Verify that access rules enforce the intended separation.
3. Control remote access. Limit vendor access to the equipment and time needed. Review authentication, approval, logging, and termination of sessions, with a safe support path for urgent maintenance.
4. Plan changes with operations. Define maintenance windows, test procedures, rollback steps, and interim protections for systems that cannot be updated immediately.
5. Rehearse an OT incident. Include plant operations, safety staff, IT, and the relevant specialists. Agree on who can isolate equipment and how the team evaluates the physical consequences.
Check contractual scope
CMMC does not apply to every manufacturer or every OT device. The CMMC program rules address defense-contractor protection of FCI and CUI. Determine the applicable contract requirements and system scope with the responsible compliance and technical teams.
Start with one documented production dependency and the people responsible for it. A useful plan connects security changes with safe operations, clear ownership, and a tested response.
Get the next issue in your inbox
Harborcoat Threat Watch sends concise cybersecurity analysis for business and IT leaders when there is something worth your time.