12 Industries, One Framework. OT security principles are universal, but every industry has its own threats, assets and standards. Choose your sector for an industry-specific cybersecurity overview.
Each industry faces unique challenges. Defending ICS and SCADA systems requires a sector-specific framework that takes regulatory environment, typical assets and threat models into account.
Paint shops, stamping lines, robotics
Reactors, chemical processes, safety systems
Packaging, refrigeration, production lines
Infusion pumps, imaging, patient care
PLCs, MES, industrial IoT, supply chain
Ship ICS, port networks, shore-side PLCs
Mining equipment, autonomous fleet, transport
Pipeline SCADA, wells, refineries
GMP processes, cold chains, validation
Power plants, substations, energy distribution
Rail, signaling, intelligent traffic
Water treatment, pump stations, utility SCADA
The threat picture and regulatory environment differ across the twelve sectors, but the methodology is shared. The IEC 62443 zone-and-conduit model works everywhere; only the classification and priorities change.
The first step in every sector. An inventory built from traffic mirroring does not disturb the process and shows what actually communicates with what.
We start not from the device but from what happens if that process stops or is manipulated. This determines how much protection each zone needs.
Dividing the network into groups with equivalent requirements, defining precisely what traffic may pass. The industrial DMZ is the most important boundary everywhere.
This is where the work diverges: safety systems, regulatory expectations and typical protocols differ by sector.
The methodology is shared, but every sector differs in three respects, and these determine where the project's emphasis falls.
| Sector | Typical protocol | What differs most |
|---|---|---|
| Manufacturing | PROFINET, EtherNet/IP, S7comm | Many vendors, mixed estates |
| Power and energy | IEC 61850, DNP3 | Substation automation, real-time requirements |
| Oil and gas | Modbus, DNP3, OPC | Distributed sites, remote supervision |
| Chemical and pharmaceutical | PROFIBUS, Modbus | Validated systems, revalidation burden |
| Water and wastewater | Modbus, DNP3 | Unattended sites, narrow bandwidth |
| Healthcare | HL7, DICOM, BACnet | Medical devices, patient safety |
| Transport | IEC 61375, proprietary protocols | Passenger safety, distributed infrastructure |
| Building automation | BACnet, KNX, Modbus | The most frequently overlooked area |
For three reasons. One: protocols differ, and an OT-aware device is only worth something if it understands what runs on the network. Two: process safety risk differs; the consequence of a faulty intervention in a chemical plant is not comparable with a packaging line. Three: regulatory expectations and downtime windows differ. The methodology, however, stays the same.
No. The twelve sectors are where we have concrete field experience, but the IEC 62443 methodology applies to any industrial environment. In such cases the first phase of assessment runs longer because learning the process and protocols takes more time. We flag this during scope alignment, not afterwards.
Yes, and this is the most frequently overlooked area. Smart building control systems (BACnet, KNX) are technically OT systems, often connected directly to the office network with default passwords. The HVAC and access control systems of an office block or shopping centre can be as much an entry point as a production line.
Device count and number of sites drive it, not the sector. A distributed water utility with ten sites requires different assessment effort from a single-site factory, even at similar device counts. This is why assessment comes first: at its end we provide a phased proposal for the rest.