Operational technology security has a constraint IT security never faces: the plant cannot stop. You do not reboot a steel furnace to patch it. Every assessment method, every architectural change, every test has to respect a system that is running, hot, and revenue-critical. This playbook distils our GCC engagements into four moves.
Move 1: Assess passively, against a standard
Start with an IEC 62443 / ISA-99 aligned risk assessment across management, operational and network controls — using passive configuration review only. Benchmark against best practice without touching running ICS. Cover all ten operational control domains, from change management to patch management, and leave with three artefacts: a risk register, a risk analysis report and a risk controls document. If an assessor proposes active scanning of your PLCs, end the meeting.
Move 2: Plan for the bad day
Business continuity in OT means knowing, before the incident, which systems matter most and how fast they must return. An ISO 22301/22317-aligned business impact analysis across SCADA, DCS, PLC and Level 2/3 systems establishes RTO and RPO with criticality tiering based on safety, production, financial and cascade impact. Then test on a gradient: tabletop exercises first, controlled functional failover tests later, cross-plant communication drills when the muscle memory exists.
Move 3: Segment along the Purdue Model
Flat networks are how ransomware reaches the plant floor. Purdue Model (ISA-95) aligned OT/IT segmentation — with zones and conduits designed per IEC 62443-3-2/3-3 — is the structural fix. In practice this means firewall placement for both north-south and east-west traffic, deliberate VLAN and subnet strategy, and evaluation of industrial redundancy protocols (MRP, HSR, PRP, RSTP). Legacy migration needs rollback procedures and maintenance-window alignment — cutover runbooks are not optional paperwork.
Move 4: See everything, then hand over the keys
Visibility comes from IDS design using SPAN, RSPAN and ERSPAN placement for maximum monitoring coverage, validated with vendor-agnostic on-site PoCs before you sign a BoQ. The engagement is not finished at go-live: as-built documentation, deployment validation, and knowledge-transfer workshops — architecture rationale, firewall rule management, IDS alert triage, day-2 operations — decide whether the security posture survives its first staff rotation.
Good OT security is measured in decades of uneventful operation.
Critical infrastructure operators in the GCC face regulatory scrutiny that is only intensifying. The operators who fare best treat OT security not as a compliance checkbox, but as an engineering discipline with the same rigour as safety.
