OT Security Across 12 Industries

12 Industries, One Framework. OT security principles are universal, but every industry has its own threats, assets and standards. Choose your sector for an industry-specific cybersecurity overview.

Industry-specific OT defense

Choose Your Sector

Each industry faces unique challenges. Defending ICS and SCADA systems requires a sector-specific framework that takes regulatory environment, typical assets and threat models into account.

Common framework

What Is the Same in Every Sector

The threat picture and regulatory environment differ across the twelve sectors, but the methodology is shared. The IEC 62443 zone-and-conduit model works everywhere; only the classification and priorities change.

01

Passive asset inventory

The first step in every sector. An inventory built from traffic mirroring does not disturb the process and shows what actually communicates with what.

02

Risk assessment from the process

We start not from the device but from what happens if that process stops or is manipulated. This determines how much protection each zone needs.

03

Zones and conduits

Dividing the network into groups with equivalent requirements, defining precisely what traffic may pass. The industrial DMZ is the most important boundary everywhere.

04

Sector specifics

This is where the work diverges: safety systems, regulatory expectations and typical protocols differ by sector.

Sectors

Where We Have Field Experience

Differences

What Changes by Sector

The methodology is shared, but every sector differs in three respects, and these determine where the project's emphasis falls.

SectorTypical protocolWhat differs most
ManufacturingPROFINET, EtherNet/IP, S7commMany vendors, mixed estates
Power and energyIEC 61850, DNP3Substation automation, real-time requirements
Oil and gasModbus, DNP3, OPCDistributed sites, remote supervision
Chemical and pharmaceuticalPROFIBUS, ModbusValidated systems, revalidation burden
Water and wastewaterModbus, DNP3Unattended sites, narrow bandwidth
HealthcareHL7, DICOM, BACnetMedical devices, patient safety
TransportIEC 61375, proprietary protocolsPassenger safety, distributed infrastructure
Building automationBACnet, KNX, ModbusThe most frequently overlooked area
Frequently asked

Sector Approach: Common Questions

Why does our sector matter?

For three reasons. One: protocols differ, and an OT-aware device is only worth something if it understands what runs on the network. Two: process safety risk differs; the consequence of a faulty intervention in a chemical plant is not comparable with a packaging line. Three: regulatory expectations and downtime windows differ. The methodology, however, stays the same.

Our sector is not on the list. Is that a blocker?

No. The twelve sectors are where we have concrete field experience, but the IEC 62443 methodology applies to any industrial environment. In such cases the first phase of assessment runs longer because learning the process and protocols takes more time. We flag this during scope alignment, not afterwards.

Does it apply to building automation?

Yes, and this is the most frequently overlooked area. Smart building control systems (BACnet, KNX) are technically OT systems, often connected directly to the office network with default passwords. The HVAC and access control systems of an office block or shopping centre can be as much an entry point as a production line.

How much do quotes differ by sector?

Device count and number of sites drive it, not the sector. A distributed water utility with ten sites requires different assessment effort from a single-site factory, even at similar device counts. This is why assessment comes first: at its end we provide a phased proposal for the rest.

Found your industry?
See the OT services too.

8 OT-specific services from risk assessment to incident response: all aligned with standards (IEC 62443, NIST CSF, ISO 27019).