Why conventional antivirus and EDR fail on the plant floor, and the principles OT-specific endpoint protection is built on, illustrated with txOne Networks tooling.
When an organisation first tries to extend its IT security tooling onto the plant floor, it usually hits the same wall: the endpoint agent either cannot be installed, or can be installed but operations will not allow it. This is not obstruction, it is justified caution.
This article covers the handful of fundamental differences that make industrial environments require a distinct class of tooling, and what that looks like in practice.
The operating systems are old. A significant share of plant HMIs and engineering workstations run Windows 7, or even XP. Not through neglect, but because the control software running on them is only certified for that version, and the equipment vendor does not support anything newer. Modern EDR agents either will not run on these, or are not supported.
Resources are scarce. An industrial panel PC often has 2 GB of memory. A continuously scanning agent consumes the headroom the control application needs, and latency here is not a comfort issue.
There is no internet connectivity. A properly segmented OT network has no egress. A model built on daily signature updates therefore does not work.
A false positive means downtime. If an EDR quarantines a file by mistake in an IT environment, someone is annoyed. If the same happens to a component of a control application, production stops.
Vendor approval is missing. Many equipment vendors explicitly prohibit installing third-party software, on pain of voiding warranty or certification.
Tools designed for this purpose follow different logic.
The core question in IT protection is: is this file malicious? Answering it requires a continuously updated knowledge base.
In OT protection it is: is this file on the list of what is permitted to run? The software set on a production HMI is unchanged for months, often years. If you record the list of approved applications, everything else is blocked by default, regardless of whether the malware is known. This approach also defends against zero-day attacks and requires no daily updates.
This is called application lockdown or trust-list based protection. The txOne Stellar product family, for example, is built on this principle and handles modern and legacy systems separately.
Some systems will accept nothing. Portable inspection is the answer: a USB device the engineer connects, which runs the scan and then moves to the next machine. No installation, no running process, no resource footprint.
This also solves the supplier device problem: a visiting technician's laptop or USB stick is scanned before entry. Removable media remains one of the most common infection routes onto isolated networks, that has not changed since Stuxnet. The txOne Portable Inspector addresses exactly this use case.
If a vulnerable device cannot be updated, protection has to sit in front of it. An industrial IPS deployed inline recognises traffic targeting a specific vulnerability and blocks it, while the device itself remains untouched.
This is virtual patching: it does not fix the flaw, but prevents its exploitation. In industrial environments this is often the only realistic answer to a CVE for which no vendor fix will appear for years. The txOne EdgeIPS and EdgeFire appliances provide this layer, with deep inspection of industrial protocols (Modbus, S7comm, EtherNet/IP, DNP3).
A general-purpose firewall sees Modbus traffic as a single TCP port. An OT-aware device also sees the function code: it can distinguish a read operation from a write, and normal operation from a program download.
This enables rules such as "from this segment PLCs may only be read; writes are permitted only from the engineering workstation, within a change window". That granularity is something an IT firewall cannot provide.
Endpoint protection is not a programme on its own. The useful order:
Endpoint protection is therefore step four, not step one. Deploying agents before the inventory and segmentation are in place typically means a great deal of work for little risk reduction.
Start in monitoring mode. An allow-list cannot be assembled theoretically. The system first runs in learning mode, collects what actually runs on the machine, and only after review do you switch to enforcement.
Consult the equipment vendor. Many manufacturers now support or explicitly recommend OT-specific protection tools. Settle the warranty question in advance.
Test on spare hardware. If an identically configured spare HMI exists, validate the deployment there before touching a live machine.
Account for change management. When the equipment vendor updates the control software, the allow-list must be updated too. Make this part of the process rather than an after-the-fact surprise.
Exploit the compliance overlap. NIS2 measure area five (vulnerability handling) and area nine (asset inventory, access control) can both be served by these tools, deployment documentation therefore does double duty.
OT endpoint protection is not a cut-down version of the IT solution; it rests on different design principles: allow-listing instead of block-listing, offline operation instead of cloud dependency, virtual patching instead of updating, and protocol awareness instead of port filtering.
As a txOne Networks partner, ARLITECH deploys these tools in industrial environments, but deployment always begins with inventory and segmentation, because a tool is only worth something once you know what you are protecting and from what.
If this is on your agenda, our OT asset hardening service covers this area, and the full portfolio is on the OT services page.
OT Asset Hardening (OT-specific service. Targeted hardening of PLCs, HMIs, RTUs and gateways) from factory…
8 OT cybersecurity services: risk and vulnerability assessment, regulatory compliance, hardening, asset…
Why the IT security toolkit does not work on the plant floor, and how to build an OT security programme…
Our specialists are happy to discuss what this means in your organisation's environment.