Building Incident Response Readiness for Manufacturing OT Environments
Why IT incident response plans fail on the plant floor, and how to build a specialized OT IR playbook focused on safety, containment, and production continuity.


Many organizations operate under the assumption that their industrial environments are secure simply because they are highly specialized, use proprietary protocols, or are perceived to be isolated from the corporate IT network.
However, when our engineers at VajraSec conduct an OT Security Health Check—a comprehensive, passive assessment of an industrial control system (ICS) environment—the reality we uncover often starkly contradicts these assumptions.
An OT Security Health Check isn't about pointing fingers; it’s about establishing a factual baseline of risk. By illuminating the dark corners of the industrial network, plant managers and security teams can make informed decisions to protect safety and production uptime.
Here is a look at what we actually find when we look under the hood of typical manufacturing and industrial environments.
The most persistent myth in industrial cybersecurity is the "air gap"—the belief that the OT network is physically disconnected from the IT network and the internet.
In almost every assessment, we find undocumented connections bridging this gap. We frequently discover:
As discussed in our previous insights, flat networks are incredibly common. We regularly see assessments where Level 1 (PLCs), Level 2 (HMIs and SCADA), and Level 3 (Site Operations) assets all reside on a single, massive broadcast domain (e.g., a massive /16 subnet).
In these environments, there are no internal firewalls or access control lists (ACLs) to prevent a compromised engineering workstation from talking directly to a safety instrumented system (SIS) controller. This architecture offers zero resistance to lateral movement by ransomware or targeted attacks.
"You cannot protect what you cannot see." When we ask organizations for their OT asset inventory prior to an assessment, we are typically handed an outdated Excel spreadsheet.
When we deploy passive network discovery tools, we routinely find 30% to 50% more devices on the network than the organization knew existed. These "ghost assets" often include forgotten legacy PLCs, undocumented network switches, and rogue wireless access points installed by operators for convenience. These unmanaged assets are prime targets for exploitation because they are unmonitored and unpatched.
Industrial protocols like Modbus TCP, DNP3, and Ethernet/IP were designed for reliability, not security. They transmit commands in clear text without authentication. While this is a known architectural limitation, it highlights the need for strict network segmentation.
More alarmingly, we frequently find critical infrastructure devices—including PLCs, industrial network switches, and protective relays—still operating with factory default credentials (e.g., admin/admin). Attackers routinely scan for these default passwords. If an attacker gains access to the network, compromising these devices requires zero technical sophistication.
Third-party vendor access is a critical necessity, but it is often poorly managed. Health checks frequently reveal:
OT environments are characterized by long lifecycles and a resistance to downtime. It is standard practice to find PLCs running firmware that is five to ten years out of date, containing dozens of known vulnerabilities (CVEs).
Furthermore, the Windows-based systems used for HMIs and engineering workstations are often severely outdated. We routinely find Windows 7, Windows XP, and even Windows NT running critical supervisory systems. Because these operating systems are end-of-life, they no longer receive security patches, leaving them perpetually vulnerable to exploits like EternalBlue (used in the WannaCry attacks).
When asked how they would respond to a cyber incident on the plant floor, many organizations point to the corporate IT incident response plan.
An IT response plan focuses on isolating systems to protect data confidentiality. Applying this to OT can cause massive physical damage or safety incidents. Most organizations lack an OT-specific IR plan that dictates how to safely degrade operations, when to initiate manual control overrides, and how to preserve forensic evidence in volatile legacy systems without disrupting production.
Discovering these vulnerabilities during an assessment can be sobering, but it is a highly positive exercise. Attackers automate the discovery of these exact same flaws. Finding them first allows you to remediate them on your own terms.
The goal of a health check is not to fix everything immediately—that is impossible in a complex OT environment. The goal is to prioritize risk. By understanding that a critical production line is sitting on a flat network with default passwords, you know exactly where to apply your first set of compensating controls, such as implementing a localized firewall and updating credential management policies.
Why IT incident response plans fail on the plant floor, and how to build a specialized OT IR playbook focused on safety, containment, and production continuity.
Vendor remote access is a necessity, but it's often the weakest link in OT security. Learn how to secure external access without hindering maintenance.
Discover the hidden risks of flat industrial networks, how they facilitate lateral movement for attackers, and practical steps to begin segmenting your OT environment.