OT Endpoint Security vs. IT Tools

Why conventional antivirus and EDR fail on the plant floor, and the principles OT-specific endpoint protection is built on, illustrated with txOne Networks tooling.

When an organisation first tries to extend its IT security tooling onto the plant floor, it usually hits the same wall: the endpoint agent either cannot be installed, or can be installed but operations will not allow it. This is not obstruction, it is justified caution.

This article covers the handful of fundamental differences that make industrial environments require a distinct class of tooling, and what that looks like in practice.

Why conventional endpoint protection fails

The operating systems are old. A significant share of plant HMIs and engineering workstations run Windows 7, or even XP. Not through neglect, but because the control software running on them is only certified for that version, and the equipment vendor does not support anything newer. Modern EDR agents either will not run on these, or are not supported.

Resources are scarce. An industrial panel PC often has 2 GB of memory. A continuously scanning agent consumes the headroom the control application needs, and latency here is not a comfort issue.

There is no internet connectivity. A properly segmented OT network has no egress. A model built on daily signature updates therefore does not work.

A false positive means downtime. If an EDR quarantines a file by mistake in an IT environment, someone is annoyed. If the same happens to a component of a control application, production stops.

Vendor approval is missing. Many equipment vendors explicitly prohibit installing third-party software, on pain of voiding warranty or certification.

The principles of OT endpoint protection

Tools designed for this purpose follow different logic.

Allow-listing instead of block-listing

The core question in IT protection is: is this file malicious? Answering it requires a continuously updated knowledge base.

In OT protection it is: is this file on the list of what is permitted to run? The software set on a production HMI is unchanged for months, often years. If you record the list of approved applications, everything else is blocked by default, regardless of whether the malware is known. This approach also defends against zero-day attacks and requires no daily updates.

This is called application lockdown or trust-list based protection. The txOne Stellar product family, for example, is built on this principle and handles modern and legacy systems separately.

Agentless scanning for machines that cannot take an agent

Some systems will accept nothing. Portable inspection is the answer: a USB device the engineer connects, which runs the scan and then moves to the next machine. No installation, no running process, no resource footprint.

This also solves the supplier device problem: a visiting technician's laptop or USB stick is scanned before entry. Removable media remains one of the most common infection routes onto isolated networks, that has not changed since Stuxnet. The txOne Portable Inspector addresses exactly this use case.

Virtual patching at the network layer

If a vulnerable device cannot be updated, protection has to sit in front of it. An industrial IPS deployed inline recognises traffic targeting a specific vulnerability and blocks it, while the device itself remains untouched.

This is virtual patching: it does not fix the flaw, but prevents its exploitation. In industrial environments this is often the only realistic answer to a CVE for which no vendor fix will appear for years. The txOne EdgeIPS and EdgeFire appliances provide this layer, with deep inspection of industrial protocols (Modbus, S7comm, EtherNet/IP, DNP3).

Understanding industrial protocols

A general-purpose firewall sees Modbus traffic as a single TCP port. An OT-aware device also sees the function code: it can distinguish a read operation from a write, and normal operation from a program download.

This enables rules such as "from this segment PLCs may only be read; writes are permitted only from the engineering workstation, within a change window". That granularity is something an IT firewall cannot provide.

How it fits the bigger picture

Endpoint protection is not a programme on its own. The useful order:

  1. Asset inventory, via passive discovery. Without it you do not know where to deploy what. We covered this in detail in our ICS/SCADA article.
  2. Segmentation, industrial DMZ, zone boundaries. This delivers the largest risk reduction.
  3. Network protection at zone boundaries, with virtual patching for devices that cannot be updated.
  4. Endpoint protection where it can be installed; portable inspection where it cannot.
  5. Monitoring, watching for deviations from the baseline.

Endpoint protection is therefore step four, not step one. Deploying agents before the inventory and segmentation are in place typically means a great deal of work for little risk reduction.

Deployment considerations

Start in monitoring mode. An allow-list cannot be assembled theoretically. The system first runs in learning mode, collects what actually runs on the machine, and only after review do you switch to enforcement.

Consult the equipment vendor. Many manufacturers now support or explicitly recommend OT-specific protection tools. Settle the warranty question in advance.

Test on spare hardware. If an identically configured spare HMI exists, validate the deployment there before touching a live machine.

Account for change management. When the equipment vendor updates the control software, the allow-list must be updated too. Make this part of the process rather than an after-the-fact surprise.

Exploit the compliance overlap. NIS2 measure area five (vulnerability handling) and area nine (asset inventory, access control) can both be served by these tools, deployment documentation therefore does double duty.

The tool does not replace the process. Allow-list based protection is worth something only if there is a maintenance regime behind it: who approves new entries, how often alerts are reviewed, and what happens when something is blocked on a night shift.

In summary

OT endpoint protection is not a cut-down version of the IT solution; it rests on different design principles: allow-listing instead of block-listing, offline operation instead of cloud dependency, virtual patching instead of updating, and protocol awareness instead of port filtering.

As a txOne Networks partner, ARLITECH deploys these tools in industrial environments, but deployment always begins with inventory and segmentation, because a tool is only worth something once you know what you are protecting and from what.

If this is on your agenda, our OT asset hardening service covers this area, and the full portfolio is on the OT services page.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.