OT vs IT Patching: The Protection Gap

3 73 166
calendar_today agoschedule2 min read

Why You Can't Patch a PLC on Tuesday

Every IT security professional who moves into OT eventually has the same conversation. They walk into a plant, run a scan, find a controller two years behind on firmware, and say the obvious thing: just patch it.

The engineer says no. And the IT person walks away thinking the plant doesn't take security seriously.

That read is wrong — and understanding why is the first real step into OT security.

Availability is the priority, not confidentiality

Enterprise IT is built around protecting data. Confidentiality sits at the top, which is why patching quickly is a virtue: a brief service interruption costs far less than a breach.

OT inverts that. These systems aren't storing information — they're running a furnace, a turbine, a water pump serving a municipality. The primary security objective is that the process keeps running safely and predictably. Everything else is negotiated against that.

A reboot is not a restart

When an OT patch requires a reboot, you aren't restarting a server. You're stopping production.

For a continuous process, that can mean hours of ramp-down and ramp-up. For some plants, the only acceptable window is a scheduled turnaround that happens once or twice a year. There are also vendor validation constraints — patching outside an approved firmware baseline can void support or invalidate a safety certification.

None of that is resistance to security. It's physics and economics.

Compensate first, then patch

The productive move is to stop framing patching as the goal and start framing risk reduction as the goal. Between now and the next maintenance window, you have real options:

  • Segment it. Zones and conduits, per IEC 62443, so an unpatched controller isn't reachable from anywhere that matters.
  • Monitor it. Passive detection on the segment gives you visibility into whether the vulnerability is being probed.
  • Restrict access. Lock down the engineering workstation and remote access paths that would be needed to exploit it.

Then patch when the window opens — with the change fully planned rather than forced.

Why this matters beyond patching

This one conversation is a proxy for the entire IT/OT relationship. Show up demanding compliance and you get treated as an obstacle. Show up understanding the operational constraint and offering protection that works inside it, and you get invited into planning conversations.

That's the actual goal. Not the patch — the seat at the table.


OT Basics is a short-form series on industrial cybersecurity fundamentals. One idea, sixty seconds, no fluff. Episode 2 covers the Purdue Model.

Part 1 of 1 in OT Basics
🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Comparison: Universal Import vs. Plaid/Yodlee

Pocket Portfolio - Mar 12

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14

IT vs OT: Understanding the Key Differences in Modern Industrial Environments

Muhammad Ali Khan - Dec 15, 2025

MCP Is the USB-C of AI. So Why Are You Plugging Everything In?

Ken W. Algerverified - Jun 10

The Privacy Gap: Why sending financial ledgers to OpenAI is broken

Pocket Portfolio - Feb 23
chevron_left
5.8k Points242 Badges
81Posts
55Comments
17Connections
Muhammad Ali Khan is an OT Cybersecurity Specialist dedicated to protecting ICS and critical infrast... Show more

Related Jobs

Commenters (This Week)

1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!