Securing Critical Infrastructure: SCADA, ICS, and the IT/OT Convergence Challenge
Published by the 0g0 research team
The water treatment plant that supplies drinking water to 400,000 residents. The electrical substation that powers hospitals and emergency services. The natural gas pipeline that heats homes across a region. These systems — and thousands more like them — are increasingly connected to digital control systems that can be accessed, monitored, and in some cases manipulated remotely. They are also increasingly targeted by nation-state actors, criminal organisations, and hacktivists with capabilities that far exceed what their operators anticipated when those digital connections were established.
Industrial Control System (ICS) and Supervisory Control and Data Acquisition (SCADA) security represents one of the most technically complex and operationally constrained domains in cybersecurity. Getting it wrong has consequences that go far beyond data loss.
The IT/OT Convergence Problem
For most of their history, industrial control systems operated in isolation. A SCADA system controlling a water treatment plant had no connection to the internet, to corporate networks, or to any external system. Security was achieved through physical isolation — air gaps that prevented any external access.
Over the past two decades, economic pressure and operational efficiency have driven a systematic erosion of these air gaps. Remote monitoring capabilities allow operators to oversee multiple facilities without travelling to each. Centralised management platforms enable enterprise-wide visibility of distributed infrastructure. Predictive maintenance systems connect operational technology directly to vendor networks for diagnostics.
Each of these connections — individually justified on operational or economic grounds — has collectively created a threat surface that did not exist a generation ago. The IT network and the OT (operational technology) network, once completely separate, are now increasingly interconnected. And the security frameworks, tools, and practices that have evolved to protect IT systems often cannot be applied to OT environments without modification — or at all.
Why OT Security Is Different
The security controls that are standard practice in IT environments frequently cannot be implemented in OT contexts:
Patching: Critical infrastructure systems often cannot be taken offline for patching because they run continuously to maintain essential services. A water treatment plant cannot have its control systems rebooted during peak demand. An electrical distribution system cannot have patches applied during high-load periods. Many ICS components have vendor support arrangements that void warranties if software is modified without vendor involvement — which may mean waiting months for approved patches.
Authentication: Multi-factor authentication — a standard requirement in IT security — is often impractical for operational technology environments where operators need rapid access during emergencies. A power grid operator responding to an equipment fault cannot be slowed by a multi-step authentication process.
Monitoring agents: Endpoint detection agents of the type deployed on Windows workstations in corporate environments often cannot be installed on embedded ICS controllers, PLCs (Programmable Logic Controllers), or RTUs (Remote Terminal Units) because the underlying operating systems do not support them or the performance impact is unacceptable.
Availability prioritisation: In IT environments, security controls may accept brief service disruptions as a trade-off for security. In OT environments, availability is paramount — the security control that might briefly interrupt a water treatment process, an electrical distribution system, or a gas pipeline is simply unacceptable.
The Threat Landscape for Critical Infrastructure
The threat to critical infrastructure is real, documented, and escalating. Several incidents illustrate the operational stakes:
The 2021 Oldsmar, Florida water treatment attack saw an attacker remotely increase sodium hydroxide levels in a water treatment plant to 111 times normal levels, a change that could have seriously harmed the local water supply. An alert operator noticed the change and reversed it manually, preventing a public health crisis.
The 2022 attack on Ukrainian energy infrastructure — part of a broader Russian cyber-physical campaign against civilian infrastructure — demonstrated the integration of cyberattack and physical kinetic operations to maximise infrastructure disruption.
Volt Typhoon — a Chinese state-sponsored threat actor specifically focused on US critical infrastructure — has been documented by CISA and FBI as pre-positioning in US critical infrastructure systems, not for immediate disruption but to develop the capability to disrupt essential services in the event of geopolitical conflict.
Effective OT Security Without Disrupting Operations
The security framework for critical infrastructure must be designed around the operational constraints of OT environments rather than imposing IT security models that cannot be applied. Effective approaches include:
Network segmentation and the Purdue model: Organising networks in distinct zones — from the enterprise IT network through demilitarised zones to the OT control network to the physical field devices — with tightly controlled connections between zones. This does not eliminate the connections that operational efficiency requires, but it controls and monitors them.
Passive monitoring: Unlike IT security monitoring that may use active scanning, OT security monitoring is typically passive — capturing and analysing network traffic without injecting any packets that could interfere with control communications. Passive monitoring can identify anomalous communications between ICS components without any impact on operational systems.
Asset inventory: Many utilities have limited visibility into the full population of OT devices on their networks. Establishing and maintaining a comprehensive OT asset inventory is a prerequisite for meaningful security — you cannot protect what you cannot see.
Anomaly detection for OT protocols: ICS communications use specialised protocols (Modbus, DNP3, IEC 61850, PROFINET) that differ entirely from IT network protocols. Effective OT security monitoring understands these protocols and can detect anomalous commands — for instance, a Modbus command to increase a pump speed beyond its operational design parameters.
Vendor access control: Remote vendor access is one of the most significant security risks in critical infrastructure. Vendor connections must be limited to specific maintenance windows, monitored in real time, and terminated when not in active use.
Regulatory Frameworks: NERC CIP and Beyond
For electric utilities, the NERC Critical Infrastructure Protection (CIP) standards provide a mandatory security framework. CIP requirements cover asset identification, security management controls, personnel training, electronic security perimeters, physical security of critical assets, systems security management, and incident reporting.
Water and wastewater systems are covered by EPA's Baseline Cybersecurity Technical Reference Architecture and the America's Water Infrastructure Act of 2018, which requires risk and resilience assessments and emergency response plans.
Pipeline operators fall under TSA's Pipeline Cybersecurity Guidelines, which were substantially strengthened following the Colonial Pipeline ransomware attack of 2021.
0g0 Aegis and Critical Infrastructure Security
Our team includes industrial control system security specialists with experience in electric, water, gas, and transportation infrastructure environments. We provide OT/IT convergence security assessments, passive OT network monitoring implementation, NERC CIP compliance support, and incident response planning specific to critical infrastructure operational requirements. We understand that protecting infrastructure means protecting the communities that depend on it.
Need a product briefing?
Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.
Request a BriefingFree Assessment Tools
Test your own security posture with our free tools — no account required.
Explore free toolsProtect your organisation
Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.
Request a Briefing