Operational technology · Industrial control systems
Defensive knowledge for protecting cyber-physical environments
A practical field guide for understanding, architecting, monitoring, hunting, hardening and defending OT, ICS, SCADA and cyber-physical environments.
Command centre
Find anything by protocol or component
One box across the whole atlas, narrowed the way an OT engineer thinks: the protocol on the wire and the device it terminates on.
Type a term, or narrow by a protocol on your wire and the component it runs on — results span protocols, components, vendors, industries, incidents, hunt playbooks, ATT&CK techniques and hardening guides.
Start here
Where are you today?
Jump straight to the part of the atlas that matches your job right now.
I'm new to OT
Start with fundamentals, terminology and how industrial environments fit together.
I need to know my estate
Component and protocol encyclopedias with Purdue placement and monitoring advice.
I'm designing a network
Zones, conduits, the Purdue model, segmentation and safe remote access.
I'm hunting threats
OT-specific hunt playbooks built on baselines, protocol behaviour and ATT&CK for ICS.
I'm responding right now
Safety-first first-24-hours guidance with operations at the table.
I'm building a programme
Maturity assessment, OT risk prioritisation and a programme builder.
Operating model
The OT security lifecycle
Discover, understand, baseline, architect, harden, monitor, hunt, respond, recover, improve — each stage links to practical guidance.
01
Discover
Know what you have — assets, connections and dependencies.
02
Understand
Learn what each system does and what talks to what.
03
Baseline
Capture what normal looks like before hunting for abnormal.
04
Architect
Design zones, conduits and a defensible boundary.
05
Segment
Separate IT and OT and restrict east/west traffic.
06
Harden
Reduce attack surface on hosts, controllers and access paths.
07
Monitor
Build visibility safely, favouring passive collection.
08
Hunt
Run structured hypotheses against your data.
09
Prioritize
Rank vulnerabilities by OT consequence, not CVSS alone.
10
Remediate
Patch, mitigate, isolate, monitor or formally accept.
11
Validate
Prove the control works and the process is unaffected.
12
Respond
Safety-aware incident response with operations at the table.
13
Recover
Restore from validated backups and verify process integrity.
14
Improve
Feed lessons back into architecture and detection.
Context
Why OT security is not IT security
Defensive guidance must account for performance, reliability and safety constraints.
| Area | IT | OT |
|---|---|---|
| Primary priority | Confidentiality, then integrity and availability | Safety and availability, then integrity; confidentiality usually last |
| Availability | Planned downtime is normal | Downtime may be measured in lost production or public service |
| Safety | Rarely a direct factor | Physical harm is a credible consequence |
| Patching | Frequent, often automated | Vendor-validated, scheduled into maintenance windows |
| Lifecycle | 3–5 years | 10–30 years; unsupported systems are common |
| Protocols | Standard, generally authenticated and encrypted | Industrial protocols, frequently unauthenticated by design |
| Operating systems | Current, centrally managed | Mixed, including embedded and end-of-life systems |
| Change windows | Weekly or on demand | Tied to outages and turnarounds |
| Consequences | Data loss, financial and reputational | Physical, environmental, safety and community impact |
| Monitoring | Agents and active scanning | Passive collection preferred; active probing can disrupt |
| Incident response | Isolate and rebuild quickly | Coordinate with operations; safety and process stability come first |
Learning paths
Structured routes through the atlas
Foundational
OT Fundamentals
Understand what OT is, how the terminology fits together, and how an industrial environment is put together.
Intermediate
OT Security Analyst
Interpret OT telemetry, triage alerts with process context, and know when to escalate.
Advanced
OT Threat Hunter
Run structured, protocol-aware hunts against OT data sources.
Advanced
OT Network Architect
Design zones, conduits, a DMZ and remote access that engineering will actually accept.
Intermediate
Controls Engineer → Security
Map familiar process knowledge onto security concepts and controls.
Intermediate
Security Engineer → OT
Unlearn the IT reflexes that are unsafe in OT and apply the right controls instead.
Expert
OT Security Leader
Build, prioritise and measure an OT security programme.
Standard
IEC 62443 implementation guide
Security levels, foundational requirements, zones and conduits, and a staged compliance path for asset owners.