VajraSec Technologies
Securing
0%
Article

What an OT Security Health Check Actually Finds

VajraSec Technologies5 min read
What an OT Security Health Check Actually Finds

Many organizations operate under the assumption that their industrial environments are secure simply because they are highly specialized, use proprietary protocols, or are perceived to be isolated from the corporate IT network.

However, when our engineers at VajraSec conduct an OT Security Health Check—a comprehensive, passive assessment of an industrial control system (ICS) environment—the reality we uncover often starkly contradicts these assumptions.

An OT Security Health Check isn't about pointing fingers; it’s about establishing a factual baseline of risk. By illuminating the dark corners of the industrial network, plant managers and security teams can make informed decisions to protect safety and production uptime.

Here is a look at what we actually find when we look under the hood of typical manufacturing and industrial environments.

1. The Myth of the Air Gap

The most persistent myth in industrial cybersecurity is the "air gap"—the belief that the OT network is physically disconnected from the IT network and the internet.

In almost every assessment, we find undocumented connections bridging this gap. We frequently discover:

  • Dual-homed workstations: PCs on the plant floor with one network interface card (NIC) connected to the OT network and a second NIC connected to the corporate IT network, bypassing firewalls entirely.
  • Rogue LTE/5G Modems: Maintenance engineers or vendors installing unauthorized cellular modems on machinery to facilitate easy remote troubleshooting, creating a direct, unmonitored backdoor from the internet to the control systems.
  • Unsecured IT/OT Conduits: Legacy integrations where historical process data is pushed to IT databases using insecure, bi-directional trust relationships.

2. Pervasive Flat Networks

As discussed in our previous insights, flat networks are incredibly common. We regularly see assessments where Level 1 (PLCs), Level 2 (HMIs and SCADA), and Level 3 (Site Operations) assets all reside on a single, massive broadcast domain (e.g., a massive /16 subnet).

In these environments, there are no internal firewalls or access control lists (ACLs) to prevent a compromised engineering workstation from talking directly to a safety instrumented system (SIS) controller. This architecture offers zero resistance to lateral movement by ransomware or targeted attacks.

3. The Asset Inventory Black Hole

"You cannot protect what you cannot see." When we ask organizations for their OT asset inventory prior to an assessment, we are typically handed an outdated Excel spreadsheet.

When we deploy passive network discovery tools, we routinely find 30% to 50% more devices on the network than the organization knew existed. These "ghost assets" often include forgotten legacy PLCs, undocumented network switches, and rogue wireless access points installed by operators for convenience. These unmanaged assets are prime targets for exploitation because they are unmonitored and unpatched.

4. Clear-Text Protocols and Default Credentials

Industrial protocols like Modbus TCP, DNP3, and Ethernet/IP were designed for reliability, not security. They transmit commands in clear text without authentication. While this is a known architectural limitation, it highlights the need for strict network segmentation.

More alarmingly, we frequently find critical infrastructure devices—including PLCs, industrial network switches, and protective relays—still operating with factory default credentials (e.g., admin/admin). Attackers routinely scan for these default passwords. If an attacker gains access to the network, compromising these devices requires zero technical sophistication.

5. Unmonitored and "Always-On" Vendor Access

Third-party vendor access is a critical necessity, but it is often poorly managed. Health checks frequently reveal:

  • Permanent VPN tunnels back to vendor corporate networks that remain active 24/7.
  • Use of unauthorized remote desktop tools like TeamViewer or AnyDesk installed directly on HMIs.
  • Shared, generic accounts used by multiple vendor technicians, making accountability and auditing impossible.

6. The Patching Reality (and Windows XP)

OT environments are characterized by long lifecycles and a resistance to downtime. It is standard practice to find PLCs running firmware that is five to ten years out of date, containing dozens of known vulnerabilities (CVEs).

Furthermore, the Windows-based systems used for HMIs and engineering workstations are often severely outdated. We routinely find Windows 7, Windows XP, and even Windows NT running critical supervisory systems. Because these operating systems are end-of-life, they no longer receive security patches, leaving them perpetually vulnerable to exploits like EternalBlue (used in the WannaCry attacks).

7. Lack of OT-Specific Incident Response Plans

When asked how they would respond to a cyber incident on the plant floor, many organizations point to the corporate IT incident response plan.

An IT response plan focuses on isolating systems to protect data confidentiality. Applying this to OT can cause massive physical damage or safety incidents. Most organizations lack an OT-specific IR plan that dictates how to safely degrade operations, when to initiate manual control overrides, and how to preserve forensic evidence in volatile legacy systems without disrupting production.

Why Finding This Matters

Discovering these vulnerabilities during an assessment can be sobering, but it is a highly positive exercise. Attackers automate the discovery of these exact same flaws. Finding them first allows you to remediate them on your own terms.

The goal of a health check is not to fix everything immediately—that is impossible in a complex OT environment. The goal is to prioritize risk. By understanding that a critical production line is sitting on a flat network with default passwords, you know exactly where to apply your first set of compensating controls, such as implementing a localized firewall and updating credential management policies.

BOOK OT SECURITY ASSESSMENT •