WAJD Learning

Operational technology security · Level 4 to 6. Control and automation engineers, plant managers, IT and security staff who have inherited a plant

Operational technology security: protecting plant without stopping it

Why office security advice breaks a plant, and what a real OT incident asks of you at three in the morning.

  • 2modules
  • 4.5CPD hours
  • 240guided minutes
  • Freemodule 1

Start module 1 Create a free account to save progress

About this course

Operational technology is the equipment that runs physical processes: the controllers, drives, sensors and control room systems behind a generator, a water treatment works, a production line or a body shop. It has been connected to ordinary networks for two decades and secured like ordinary networks for rather less time than that.

This course teaches why the office playbook does not transfer. It covers the inverted priorities that put safety and availability above confidentiality; the asset realities that make prompt patching impossible; the reference model for segmenting a plant and what the industrial demilitarised zone is actually for; why safety instrumented systems stay independent; and remote access, which is how most of the carefully drawn boundaries are quietly bypassed.

The second module is the incident itself. Building an asset inventory when nobody has one, monitoring passively because active scanning can stop a controller, responding when pulling the plug is not available, deciding who has the authority to halt production, and recovering a controller that has never once been restored from backup. It closes on the United Kingdom regulatory position for operators of essential services.

What you will be able to do

  • Explain why operational technology inverts the usual security priorities
  • State why prompt patching and active scanning are unsafe on many plant assets
  • Describe a layered reference model and the purpose of the industrial demilitarised zone
  • Explain why safety instrumented systems remain independent of the control system
  • Assess remote access routes and the risk they carry into a plant
  • Build an asset inventory using methods that will not disturb the process
  • Run an incident response where isolation and shutdown are not free actions
  • Identify who holds the authority to stop production and why that must be agreed beforehand
  • State the United Kingdom duties on operators of essential services

Modules

  1. 1 Why operational technology is not information technology 120 min study · 5 min script · 5 question knowledge check
  2. 2 Detecting and responding without stopping the plant 120 min study · 6 min script · 5 question knowledge check

Assessment and certificate

Knowledge check after each module and a final assessment at 80 per cent, with unlimited attempts.

A free digital certificate showing 4.5 CPD hours with a verification code. It evidences knowledge. It is not a competence to work on live plant, and no website can grant that: work on a running process is authorised by the duty holder for that site.

Questions

Why can we not just patch the plant like we patch the offices?

Three reasons, and only one of them is cultural. Many controllers cannot be patched without stopping the process they are running, and the process may run for months at a time. Applying a patch outside the vendor's validated list can void support on a machine worth more than the plant's annual security budget. And a large proportion of installed equipment is beyond vendor support entirely, so no patch exists at any price. The answer is compensating controls rather than pretending the patch will happen.

Is it true that scanning can break a controller?

Yes, and it still surprises people. Older controllers have very small network stacks that were built to talk to a handful of known peers on a quiet network. A routine scan can exhaust them and cause a fault, and a faulted controller is a stopped process. This is why passive monitoring, which reads the traffic already on the wire, is the default technique on plant networks.

Who decides to stop production during an incident?

That has to be settled in writing before the incident, not argued during one. A security team that can isolate a network segment can stop a furnace without knowing it. A plant manager who refuses to stop may be protecting a process that genuinely cannot be interrupted safely. Both positions are reasonable, which is exactly why the decision right, and the safety advice it must follow, belongs in the plan.

Does any of this apply to a small manufacturer?

The regulatory duties apply to operators of essential services and to relevant digital service providers, so most small manufacturers fall outside them. The engineering does not care about that. A small plant with one unsegmented network, a vendor with permanent remote access and no controller backups carries the same technical exposure as a large one, with fewer people to recover it.