OT Cybersecurity
Glossary
Your reference for OT and industrial cyber risk — from field devices and industrial protocols to cyber risk quantification, insurance frameworks, and regulatory standards. From AEL to Zero Trust.
73 terms
Annual Expected Loss
The average financial loss an organization can expect to incur from OT cyber incidents over a one-year period, calculated using probability and impact modeling.
Attack Surface
The total set of entry points and vulnerabilities in an OT environment that a threat actor could exploit to gain unauthorized access or cause disruption.
CVSS
Common Vulnerability Scoring System — a standardized framework for rating the severity of security vulnerabilities in IT and OT systems on a scale of 0 to 10.
Air Gap
A physical or logical network separation between OT systems and external networks. Air gaps were once the primary OT security strategy but have been systematically eroded by remote access requirements and IT/OT convergence.
CIA Triad
The foundational IT security model organized around Confidentiality, Integrity, and Availability. In OT environments the priority order is inverted: Availability comes first because a control system outage can have immediate physical and safety consequences.
DCS
Distributed Control System — a control architecture where controllers are distributed across the plant. DCS platforms are common in continuous process industries such as chemicals, oil and gas, and power generation.
DNP3
Distributed Network Protocol 3 — an industrial communication protocol used in electric utilities and water systems. DNP3 was designed for reliability in harsh environments but was not built for adversarial network conditions.
HMI
Human Machine Interface — the operator dashboard through which personnel monitor and interact with industrial control systems. HMIs display real-time process data and are a frequent target for adversaries seeking to manipulate operator perception of the process state.
ICS
Industrial Control Systems — the collective term for hardware and software used to control industrial processes, including SCADA, DCS, PLCs, and RTUs. ICS environments were designed for reliability and availability, not cybersecurity, which creates the structural vulnerabilities that OT security programs must address.
IT/OT Convergence
The deliberate or gradual connecting of industrial OT networks to corporate IT infrastructure and the internet. Convergence eliminates the isolation assumption that once served as OT's primary security control, creating IT-to-OT attack paths that now dominate the industrial threat landscape.
Legacy Systems
Industrial control system components designed before security was a consideration and that cannot be updated using standard IT practices. OT environments routinely operate PLCs and DCS components with 15–30 year lifecycles running firmware that may no longer receive security patches.
Modbus
An industrial communication protocol developed in 1979 with no authentication mechanism — designed for closed serial networks under the assumption of physical isolation. Any device that can reach a Modbus-enabled controller over the network can issue commands to it without credentials.
Operational Technology
Hardware and software that monitors and controls physical processes, devices, and infrastructure in industrial environments. Unlike IT systems, OT prioritizes availability and safety over confidentiality — a fundamental difference that makes standard IT security controls inapplicable without significant adaptation.
Passive Network Monitoring
A visibility approach that collects OT security intelligence by observing network traffic without sending active probe packets to industrial devices. Passive monitoring is the standard approach in OT because active scanning can cause PLC lockups, device reboots, and process disruptions.
PLC
Programmable Logic Controller — a ruggedized industrial computer used to automate electromechanical processes such as valve control and motor operation. PLCs are high-value targets because modifying their ladder logic can directly alter the physical process they control.
Purdue Model
A hierarchical reference architecture that organizes industrial assets into distinct levels from field devices (Level 0–1) through control systems (Level 2) to supervisory and business systems (Levels 3–4). The Purdue Model provides the structural basis for designing segmentation and security controls in OT environments.
RTU
Remote Terminal Unit — a field device that monitors and controls remote assets such as pipeline valves and substations, transmitting data back to a central SCADA system. RTUs are common in geographically distributed infrastructure and a frequent target in critical infrastructure attacks.
SCADA
Supervisory Control and Data Acquisition — a system architecture used to remotely monitor and control industrial processes across geographically distributed assets. SCADA systems aggregate data from field devices and are among the most frequently targeted systems in critical infrastructure attacks.
Anomaly Detection
The identification of patterns or behaviors that deviate from established baselines in an OT environment. Anomaly detection is a core defensive capability in industrial networks where signature-based detection fails against novel or customized attack tools.
Crown Jewels
The critical assets, systems, or processes in an OT environment whose compromise would have the greatest operational and financial impact. Crown jewels analysis is the first step in any OT risk quantification exercise.
Firewall
A network security device that monitors and controls traffic based on predefined rules. In OT environments, firewalls must understand industrial protocols — standard IT firewalls miss OT-specific attack patterns.
Incident Response
The structured process for detecting, containing, eradicating, and recovering from a cyber incident. OT incident response differs from IT because containment actions must be evaluated against operational safety risks — isolating a compromised PLC can cause process disruption or hazardous conditions.
Network Segmentation
The division of a network into isolated zones to limit lateral movement and contain the blast radius of a compromise. In OT environments, segmentation between IT and OT networks is a primary control against cross-domain attack paths.
Residual Risk
The level of cyber risk that remains after security controls have been applied. Residual risk reflects the gap between current security posture and the organization's defined risk appetite, and is the primary basis for cyber insurance placement decisions.
Risk Appetite
The level of cyber risk an organization is willing to accept in pursuit of its operational and business objectives. Defining risk appetite is a prerequisite for OT risk quantification because it establishes the threshold against which residual risk is measured.
Safety Instrumented System
A dedicated control system designed to bring a process to a safe state when predetermined conditions are exceeded. SIS are the last automated line of defense before physical harm in industrial processes — their compromise, as demonstrated by TRITON, represents the highest severity category of OT cyber attack.
Threat Intelligence
Structured, actionable information about adversary TTPs, campaigns, and tools relevant to an organization's threat environment. In OT risk quantification, threat intelligence is the outside-in data component that connects the risk model to real-world threat actors targeting industrial sectors.
Vulnerability Management
The continuous process of identifying, assessing, prioritizing, and remediating security weaknesses across OT assets. OT vulnerability management cannot follow IT patch cadences — it must balance security risk against operational availability and the physical risk of updating live industrial systems.
Zero Trust
A security model that requires continuous verification of every user, device, and connection regardless of network location. Implementing Zero Trust in OT requires careful adaptation because many legacy industrial protocols have no native authentication capabilities.
Annual Expected Loss
The probability-weighted financial loss an organization can expect to incur from OT cyber incidents over a 12-month period. AEL is the single number most useful for board governance and budget planning because it is comparable year over year and across business units.
Asset Inventory
A complete, up-to-date record of all hardware and software components in an OT environment, including PLCs, DCS, RTUs, HMIs and their firmware versions. Accurate asset inventory is the foundation of every credible OT security program and risk quantification model.
Bottom-Up Aggregation
A portfolio risk approach that builds the organizational risk picture by first modeling risk at each individual facility, then aggregating upward. It preserves facility-specific accuracy and reveals which sites drive the most financial exposure across a multi-site portfolio.
Cyber Insurance
Insurance coverage designed to transfer financial losses from cyber incidents. In OT environments, placement increasingly requires quantified risk submissions — AEL, VaR, and documented control posture — because qualitative descriptions do not give underwriters enough information to price industrial cyber exposure accurately.
FAIR Framework
Factor Analysis of Information Risk — a quantitative model that breaks cyber risk into measurable components including threat event frequency, vulnerability probability, and loss magnitude. FAIR provides a structured methodology for translating OT cyber scenarios into probability-weighted financial impact estimates.
Inside-Out Data
Telemetry collected from within the industrial environment itself — device inventories, vulnerability scan results, network architecture, and security control posture. Inside-out data is what makes an OT risk quantification model facility-specific rather than generic.
Loss Exceedance Curve
A probability distribution showing the likelihood of exceeding any given financial loss threshold from OT cyber incidents. It is the primary tool for sizing insurance towers and evaluating risk transfer alternatives at every confidence level simultaneously.
OT Cyber Risk Quantification
The practice of translating the security posture of an industrial control system environment into financial terms — specifically, the probability and magnitude of loss that a cyber incident could cause. OT CRQ converts security investment decisions into ROI calculations defensible to boards, CFOs, and insurance underwriters.
Outside-In Data
Threat intelligence and external data that shapes an OT risk profile — adversary TTPs, sector-specific incident statistics, vulnerability disclosures for deployed vendors, and firmographic factors. Combined with inside-out data, it allows the risk model to reflect the current threat environment accurately.
Underwriting
The process by which insurers assess risk and determine coverage terms and premiums. In OT cyber insurance, underwriters increasingly require quantified risk submissions — AEL, VaR, and documented security posture — because narrative questionnaires do not provide enough information to price industrial cyber exposure.
Value at Risk
The maximum financial loss at a given confidence level — typically 95th or 99th percentile — from OT cyber incidents over a defined time horizon. VaR captures tail risk that Annual Expected Loss averages over; it is what insurance markets price against and what boards need to evaluate insurance program adequacy.
Asset Owner
In IEC 62443 terminology, the organization accountable for operating and maintaining an IACS environment. Asset owners are responsible for defining security requirements, selecting target security levels, and ensuring that service providers and product suppliers meet those requirements.
Defense in Depth
A layered security strategy that implements multiple overlapping controls so that the failure of any single control does not result in full system compromise. IEC 62443 mandates a defense-in-depth approach for all IACS environments.
IACS
Industrial Automation and Control Systems — the IEC 62443 term for the combination of hardware, software, personnel, and procedures used to control industrial processes. IACS security encompasses everything from field devices up to enterprise integration layers.
IEC 62443
The international series of standards defining cybersecurity requirements for Industrial Automation and Control Systems. The only internationally recognized security standard built specifically for OT environments, addressing asset owners, service providers, and product suppliers with role-specific requirements.
NERC CIP
North American Electric Reliability Corporation Critical Infrastructure Protection — mandatory cybersecurity standards for bulk electric system operators in North America. Unlike IEC 62443, NERC CIP compliance is enforceable with financial penalties.
NIS2
The EU Network and Information Systems Directive 2 — the primary cybersecurity regulatory framework for critical infrastructure operators in Europe. IEC 62443 alignment is widely recognized as a structured approach to demonstrating NIS2 compliance.
NIST CSF
The NIST Cybersecurity Framework — a governance overlay organizing security activities into six functions: Govern, Identify, Protect, Detect, Respond, Recover. NIST CSF and IEC 62443 are complementary: CSF provides program structure while IEC 62443 provides OT-specific technical
Patch Management
The process of applying vendor-released security updates to software and firmware. In OT environments, patch management cannot follow IT timelines because updating a running PLC or DCS may require a full production shutdown — a planned event measured in weeks or months, not days.
Product Supplier
In IEC 62443 terminology, any organization that manufactures hardware or software used in an IACS. Product suppliers are accountable for meeting the Secure Development Lifecycle requirements in IEC 62443-4-1 and the component-level security requirements in 62443-4-2.
Security Level
An IEC 62443 classification defining the required protection level for an IACS zone or component against intentional cyber attack. Security Levels range from SL 1 (protection against opportunistic threats) to SL 4 (protection against state-sponsored attacks), determining what countermeasures must be implemented.
System Integrator
An organization that designs, installs, and commissions IACS systems on behalf of asset owners. Under IEC 62443, system integrators must meet the security program requirements of Part 2-4 and are responsible for ensuring delivered systems achieve the security levels specified by the asset owner.
Zone and Conduit Model
The IEC 62443 architectural approach to OT network segmentation, grouping assets into security zones based on criticality and routing inter-zone communication through conduits with defined security properties. It drives the technical implementation of network segmentation controls.
Data Historian
An industrial database server that collects and serves time-series process data from OT systems to IT business systems. Historians are a critical pivot point in cross-domain attacks because they communicate with both OT and IT networks simultaneously.
Engineering Workstation
A computer used to configure, program, and maintain PLCs, DCS, and other industrial control devices. Engineering workstations are a critical pivot point in cross-domain attacks because they run standard enterprise operating systems while having direct write access to OT field devices.
Exfiltration
The unauthorized transfer of data out of an organization's environment. Exfiltration is what triggers regulatory breach notification obligations and produces the direct data-related losses in the primary cyber loss model.
Impair Process Control
An ATT&CK for ICS tactic covering techniques that manipulate, disable, or damage control system functions — the stage where a cyber attack translates into direct physical operational impact. Techniques include modifying setpoints and altering control logic on PLCs.
Inhibit Response Function
An ATT&CK for ICS tactic covering techniques that prevent safety systems and operators from detecting or responding to an ongoing attack. By suppressing alarms or disabling protective relays, adversaries extend the damage window and prevent automatic mitigation.
Initial Access
The ATT&CK tactic covering the techniques an adversary uses to gain their first foothold in the target environment. In industrial attack chains, initial access almost always occurs through the IT network before moving toward OT.
Lateral Movement
The techniques adversaries use to progressively move through a network after gaining initial access. In OT attack chains, lateral movement from corporate IT through historian servers and engineering workstations into the OT network is the standard path in documented industrial incidents.
MITRE ATT&CK for ICS
A publicly available knowledge base of adversary tactics and techniques observed in attacks against industrial control systems. Organized into 12 tactic categories, it documents what attackers actually do in OT environments and serves as the primary vocabulary for structured OT threat modeling
OPC-UA
Open Platform Communications Unified Architecture — a modern industrial communication protocol designed for interoperability between vendor systems. OPC-UA acts as a pivot point in cross-domain attacks because it bridges OT field devices and enterprise IT systems using standard network protocols.
Pivot Point
A component that translates data between different protocol formats or technology domains, enabling an adversary to cross from one network to another. In industrial environments, pivot points include historians, engineering workstations, and protocol gateways — frequently under-enumerated in OT security assessments.
Ransomware
Malware that encrypts an organization's systems or data and demands payment for decryption. In OT contexts, ransomware can achieve significant operational impact without ever touching the ICS network — the Colonial Pipeline and Norsk Hydro incidents both demonstrated this clearly.
Spearphishing
A targeted phishing attack directed at specific individuals using personalized information to increase credibility. Spearphishing is one of the most consistently documented initial access techniques in industrial cyber incidents and the entry point in the Norsk Hydro attack scenario.
Stuxnet
A sophisticated piece of malware discovered in 2010 that destroyed uranium enrichment centrifuges at Natanz, Iran. Stuxnet was the first publicly documented cyberweapon to cause physical destruction, establishing the template for subsequent ICS-targeted malware.
Supply Chain Attack
An attack that compromises a less-secure element of an organization's supply chain — vendors, integrators, or software providers — to gain access to the primary target. Supply chain attacks are particularly effective in OT environments where third-party remote access for maintenance is widespread.
Threat Actor
An individual or group responsible for a cyber incident or attack. In OT security, threat actors range from nation-state groups conducting long-dwell reconnaissance against critical infrastructure to ransomware operators targeting operational disruption as financial leverage.
TRITON
Malware discovered in 2017 designed to attack Schneider Electric Triconex Safety Instrumented Systems — the last automated defense before physical disaster in industrial processes. TRITON represents the most serious category of OT malware because its objective was to disable safety systems entirely.
Tail Risk
The risk of rare but severe outcomes that fall beyond the typical range of expected losses — the right tail of the loss distribution. In OT environments, tail risk is driven by scenarios involving physical destruction, cascading infrastructure failures, or multi-facility correlated attacks.
Penetration Testing
A controlled, authorized simulation of an adversary attack to identify exploitable vulnerabilities before a real attacker does. OT penetration testing requires specialized methodology because standard IT techniques can crash industrial devices — passive reconnaissance and careful scoping are prerequisites.
Critical Infrastructure Protection
The policies, standards, and technical controls applied to safeguard industrial systems that underpin essential services — energy, water, transportation, and manufacturing. Critical infrastructure protection programs are increasingly required to demonstrate quantified cyber risk exposure to regulators and government agencies.
Cyber Risk Governance
The organizational structures, policies, and accountability frameworks through which executive leadership and boards oversee cyber risk in OT environments. Effective cyber risk governance requires financial risk metrics — AEL, VaR, and scenario-based exposure — rather than technical status reports that boards cannot act on.
Industrial Cyber Insurance
Insurance coverage specifically designed for the financial losses arising from cyber attacks on operational technology environments — including production downtime, equipment damage, regulatory penalties, and business interruption. Industrial cyber insurance placement requires quantified OT-specific risk submissions that reflect physical consequence scenarios, not generic IT loss estimates.
No terms found.