ICS Cybersecurity for C&I Operators
Your control systems were not built for the internet. They are on it now. Here is how to see what is exposed, reduce it in the right order, and govern it as an ongoing risk.
Who this is for
- ■Plant managers and facility managers running networked OT
- ■Operations executives at manufacturers, hospitals, data centers, and utilities
- ■C-suite leaders responsible for ICS environments and uptime
- ■Anyone whose electric bill is five, six, or seven figures and whose energy systems are networked
Do you have visibility into what OT is exposed, a sequence to reduce that exposure, and governance that treats this as ongoing risk?
IT security prioritizes confidentiality. OT security must prioritize availability and physical safety. That is a different risk hierarchy, and it is the reason your IT team's standard toolset is the wrong starting point for your plant.
| IT security | Confidentiality of data | Data loss or disclosure |
| OT security | Availability and physical safety | Process disruption, harm to operators or public |
31%of this guide, read. The rest of it is below.
- 02 The mechanism The air gap collapsed, and five structural vulnerabilities took its place
OT networks that were previously isolated from the internet are now connected to it. Every sensor, meter, SCADA terminal, and building management system that gets an IP address becomes a potential attack vector. Physical isolation as a security control no longer holds.
Permanent conditions, not a checklistThe five structural vulnerabilities
OneIT/OT convergence expands the attack surface
The same connectivity that gives you supply chain visibility gives attackers more entry points.TwoLegacy systems lack encryption and authentication
Built decades ago, never designed for connectivity, and cannot be locked down like a modern endpoint.ThreeInsufficient access controls
Especially for third-party vendors and OEM contractors with remote access to your ICS.FourVulnerability management lags
No tolerance for downtime, rare maintenance windows, patches do not get applied on a standard cycle.FiveAdvanced attackers exploit the hesitancy
They understand you cannot patch quickly and they plan around it. 203 What it does to you HMIs, BMS, and pre-positioned adversariesTwo asset classes get underestimated: human-machine interfaces and building management systems. Claroty's Team82 analyzed a large sample of OT assets that included HMIs and the exposure numbers are not comfortable.
HMI exposure in the Team82 sample125,000assetsOT assets in the sample13%of HMIs insecurely connected to the internet36%of HMIs with a publicly exploited vulnerabilityA meaningful share of HMIs are reachable from the internet, and more than a third carry a vulnerability that has already been used in the wild.Building management systems control HVAC, elevators, coolant, and life-safety functions in hospitals, data centers, and manufacturing facilities. They rarely get treated with the same rigor as SCADA. That is a mistake. Recategorize BMS as critical infrastructure and you will make different choices about who can reach it and how.
- 03 What it does to you HMIs, BMS, and pre-positioned adversaries
Two asset classes get underestimated: human-machine interfaces and building management systems. Claroty's Team82 analyzed a large sample of OT assets that included HMIs and the exposure numbers are not comfortable.
HMI exposure in the Team82 sample125,000assetsOT assets in the sample13%of HMIs insecurely connected to the internet36%of HMIs with a publicly exploited vulnerabilityA meaningful share of HMIs are reachable from the internet, and more than a third carry a vulnerability that has already been used in the wild.Building management systems control HVAC, elevators, coolant, and life-safety functions in hospitals, data centers, and manufacturing facilities. They rarely get treated with the same rigor as SCADA. That is a mistake. Recategorize BMS as critical infrastructure and you will make different choices about who can reach it and how.
304 The trap Chasing every CVE, and treating this as a project you finishTwo traps burn ICS security budgets. The first is trying to patch every vulnerability. Most C&I operators cannot, and the ones who try exhaust their team before they touch the highest-risk exposures. The second is treating cybersecurity as a capital project with an end date. It is not.
The myth The reality We will patch our way to a secure OT environment. Maintenance windows are rare. Compensating controls are the durable line item, not a temporary bridge. Our IT security stack covers the plant. Generic tools do not interpret industrial protocols and produce blind spots or alert fatigue. An annual audit is enough. The threat environment, your connected assets, and known vulnerabilities all change continuously. Security posture is a living condition. No attack means we are safe. Pre-positioning is real. Quiet does not mean clean. Cybersecurity is a project we complete. Cybersecurity risk cannot be eliminated. It is managed through informed decision-making, like any other enterprise risk. - 04 The trap Chasing every CVE, and treating this as a project you finish
Two traps burn ICS security budgets. The first is trying to patch every vulnerability. Most C&I operators cannot, and the ones who try exhaust their team before they touch the highest-risk exposures. The second is treating cybersecurity as a capital project with an end date. It is not.
The myth The reality We will patch our way to a secure OT environment. Maintenance windows are rare. Compensating controls are the durable line item, not a temporary bridge. Our IT security stack covers the plant. Generic tools do not interpret industrial protocols and produce blind spots or alert fatigue. An annual audit is enough. The threat environment, your connected assets, and known vulnerabilities all change continuously. Security posture is a living condition. No attack means we are safe. Pre-positioning is real. Quiet does not mean clean. Cybersecurity is a project we complete. Cybersecurity risk cannot be eliminated. It is managed through informed decision-making, like any other enterprise risk. 405 Your leverage The sequence, the frameworks, and what to askThere is a defensible order of operations. It starts with seeing your assets and ends with locking down remote access. Skipping steps produces spend without protection.
The ICS security implementation sequenceYou cannot protect what you cannot see, and you cannot detect what your tools cannot interpret. The order matters. - 1 Establish a complete asset inventory, including devices installed by vendors or contractors. You cannot protect what you cannot see.
- 2 Move to exposure management. Prioritize by exploitability, insecure connectivity, poor access controls, and operational consequence, not by CVE count.
- 3 Segment the OT network to limit lateral movement, and separate corporate IT from operational technology.
- 4 Deploy purpose-built ICS threat detection that interprets industrial protocols. Generic monitoring will create blind spots.
- 5 Apply zero trust to remote access, especially for vendor sessions. Never trust, always verify.
GovernanceTwo frameworks to know by name
Risk Management ProcessDOE with NIST and NERC
Grounds cybersecurity risk inside enterprise risk management. Cybersecurity risk cannot be eliminated. It is managed through informed decision-making.CRISPCybersecurity Risk Information Sharing Program
Public-private partnership co-funded by DOE and industry, managed by the Electricity Information Sharing and Analysis Center. Facilitates bi-directional sharing of classified and unclassified threat information.CRISP participant coverageCRISP participants cover the majority of continental U.S. electricity subsector customers. Your DOE-aligned peers are already working from this. - 05 Your leverage The sequence, the frameworks, and what to ask
There is a defensible order of operations. It starts with seeing your assets and ends with locking down remote access. Skipping steps produces spend without protection.
The ICS security implementation sequenceYou cannot protect what you cannot see, and you cannot detect what your tools cannot interpret. The order matters. - 1 Establish a complete asset inventory, including devices installed by vendors or contractors. You cannot protect what you cannot see.
- 2 Move to exposure management. Prioritize by exploitability, insecure connectivity, poor access controls, and operational consequence, not by CVE count.
- 3 Segment the OT network to limit lateral movement, and separate corporate IT from operational technology.
- 4 Deploy purpose-built ICS threat detection that interprets industrial protocols. Generic monitoring will create blind spots.
- 5 Apply zero trust to remote access, especially for vendor sessions. Never trust, always verify.
GovernanceTwo frameworks to know by name
Risk Management ProcessDOE with NIST and NERC
Grounds cybersecurity risk inside enterprise risk management. Cybersecurity risk cannot be eliminated. It is managed through informed decision-making.CRISPCybersecurity Risk Information Sharing Program
Public-private partnership co-funded by DOE and industry, managed by the Electricity Information Sharing and Analysis Center. Facilitates bi-directional sharing of classified and unclassified threat information.CRISP participant coverageCRISP participants cover the majority of continental U.S. electricity subsector customers. Your DOE-aligned peers are already working from this. 5Decision matrixWhen to spend on ICS security now, and when to hold
✓ Move now- You cannot produce a complete inventory of connected OT assets in your facility.
- Your HMIs or building management systems are reachable from the internet and you do not know which are exploitable.
- Vendors and OEM contractors have remote access to your control systems without session monitoring or termination controls.
- Your monitoring stack was built for IT endpoints and does not interpret industrial protocols.
- You are treating cybersecurity as an annual audit line, not a continuous discipline.
✗ Sequence and hold- You are being sold a purpose-built detection tool before you have completed asset inventory.
- A vendor proposal centers on patching every CVE rather than exposure prioritization.
- The pitch is a one-time project with a defined end date and no ongoing operating model.
- The tool cannot demonstrate that it understands the ICS protocols on your network.
- The proposal skips segmentation and jumps straight to advanced threat hunting.
- Decision matrix
When to spend on ICS security now, and when to hold
✓ Move now- You cannot produce a complete inventory of connected OT assets in your facility.
- Your HMIs or building management systems are reachable from the internet and you do not know which are exploitable.
- Vendors and OEM contractors have remote access to your control systems without session monitoring or termination controls.
- Your monitoring stack was built for IT endpoints and does not interpret industrial protocols.
- You are treating cybersecurity as an annual audit line, not a continuous discipline.
✗ Sequence and hold- You are being sold a purpose-built detection tool before you have completed asset inventory.
- A vendor proposal centers on patching every CVE rather than exposure prioritization.
- The pitch is a one-time project with a defined end date and no ongoing operating model.
- The tool cannot demonstrate that it understands the ICS protocols on your network.
- The proposal skips segmentation and jumps straight to advanced threat hunting.
Questions for your morning huddle- Can we produce a complete inventory of every connected OT asset, including devices installed by vendors or contractors?
- Of our HMIs and building management systems, do we know which are internet-facing and which carry unpatched, publicly known vulnerabilities?
- When a vendor or OEM contractor accesses our control systems remotely, what authentication, session monitoring, and termination controls are in place?
- Are our security tools capable of interpreting ICS-specific protocols, or are we running a generic monitoring setup that will produce blind spots?
The one thing to rememberCybersecurity risk for your OT environment cannot be eliminated. It is managed through informed decision-making, in a defined sequence, on a continuous basis.
This week, commission a complete inventory of connected OT assets, including anything installed by vendors or contractors, and flag every HMI and building management system that is reachable from the internet.
6The Energy Decision BlueprintKnow if the numbers actually pencil out before you sign anything.
A written second opinion on the project in front of you, whether that is a rate change, new equipment, or a renewable installation.
- 01A short call, to figure out quickly whether we can actually be helpful. If we can't, we'll say so on the spot.
- 02We pull the data, your bills, your rate structure, vendor proposals, project specs.
- 03You get the verdict in writing: whether the payback will materialize, and the opportunities or risks nobody has raised.
Get a Blueprint at blueprint.tac-nrg.com Free for Indiana-based operations spending five figures or more a month on electricity. No obligation. You keep the write-up either way. - The one thing to remember
Cybersecurity risk for your OT environment cannot be eliminated. It is managed through informed decision-making, in a defined sequence, on a continuous basis.
This week, commission a complete inventory of connected OT assets, including anything installed by vendors or contractors, and flag every HMI and building management system that is reachable from the internet.
The Energy Decision BlueprintKnow if the numbers actually pencil out before you sign anything.
A written second opinion on the project in front of you, whether that is a rate change, new equipment, or a renewable installation.
- 01A short call, to figure out quickly whether we can actually be helpful. If we can't, we'll say so on the spot.
- 02We pull the data, your bills, your rate structure, vendor proposals, project specs.
- 03You get the verdict in writing: whether the payback will materialize, and the opportunities or risks nobody has raised.
Get a Blueprint at blueprint.tac-nrg.com Free for Indiana-based operations spending five figures or more a month on electricity. No obligation. You keep the write-up either way. 7Glossary- OT
- Operational technology. The systems that run the physical process: SCADA, HMIs, PLCs, building management systems, energy controls.
- ICS
- Industrial control systems. The broader category of hardware and software that monitors and controls industrial processes.
- HMI
- Human-machine interface. The screen and controls an operator uses to see and act on a process. A common attack surface when internet-exposed.
- BMS
- Building management system. Controls HVAC, elevators, coolant, and life-safety functions. Critical infrastructure in hospitals, data centers, and plants, whether labeled that way or not.
- IT/OT convergence
- The connection of previously isolated operational networks to IT networks and the internet. Delivers visibility and integration, and expands the attack surface.
- Exposure management
- Prioritizing remediation by exploitability, insecure connectivity, access controls, and operational consequence, rather than by raw CVE count.
- Zero trust
- A security approach summarized as never trust, always verify. Assumes an attacker is already inside the network when granting access.
- Pre-positioning
- An adversary embedding capabilities in a network for later activation. A quiet network is not necessarily a safe network.
- CRISP
- Cybersecurity Risk Information Sharing Program. Public-private partnership co-funded by DOE and industry and managed by the Electricity Information Sharing and Analysis Center for bi-directional threat information sharing.

