ICS/OT Security

OT Risk Assessment: Scoring What Kills Uptime

By October 3, 2026No Comments

When I walk into a plant and ask the operations team to define “critical,” the silence is usually deafening. In many industrial environments, criticality is treated as a static attribute assigned by an engineer who left five years ago or derived from a spreadsheet that hasn’t been touched since the last capital project.

For plant managers, OT engineers, and CISOs, this disconnect between technical risk and operational reality is where budgets disappear and outages begin. Traditional IT risk models rely on data confidentiality as the primary driver of severity. That approach is fundamentally broken in Operational Technology (OT). In ICS and SCADA environments, a vulnerability that leaks no data but halts production is infinitely more dangerous than one that exposes sensitive IP.

We need to stop scoring OT risk based on CVSS scores alone and start scoring it based on what actually kills uptime. Here is how we approach OT risk assessment at Red Trident, grounded in the reality of control rooms and the specific findings we see when we roll up our sleeves.

The Myth of the “Critical” Asset List

Before we can score risk, we must know what we are protecting. Yet, the most common failure mode we encounter is not a sophisticated exploit; it is simply not knowing what exists on the network.

In our internal assessments and walkdowns, we consistently find that asset inventories are either non-existent or so outdated they are actively misleading. We have seen engineering teams rely on vendor documentation from 2015 to claim a “secure” environment, only to find that five years of brownfield modifications have introduced dozens of unmanaged devices.

This is why we emphasize continuous monitoring over periodic audits. As recent research from Nozomi Networks Labs highlights, real-time ICS network visualization and automated asset inventory are the only ways to proactively identify hidden vulnerabilities. In one specific engagement, we found that an operational technology exposure had spread beyond the traditional control room into distributed assets outside of centralized monitoring. This expansion of the attack surface is a growing trend flagged by the OT-ISAC, yet many operators still rely on static, manual audits that miss these shifts entirely.

If you cannot see it, you cannot secure it. If you cannot secure it, you cannot score its risk accurately. We start every engagement by establishing a “single source of truth” for asset data, correlating device behavior with asset records to detect anomalies early and reduce manual audit gaps.

Configuration Decay: The Silent Killer

Once we know what assets exist, we look at their posture. In IT, configuration drift is a nuisance. In OT, it is often the precursor to a catastrophic failure. We have seen environments where security controls were configured correctly during commissioning but decayed over time due to routine maintenance, vendor access, and patching cycles.

A recent Red Trident engagement revealed a stark example of this decay. In assessments run on two endpoints from the same industrial organization, we found that at least seven high-value Windows audit subcategories were explicitly set to No Auditing. These categories included Process Creation, Process Termination, Credential Validation, Kerberos Service Ticket Operations, Kerberos Authentication Service, Detailed File Share, and Removable Storage.

Why does this matter for uptime? When a malicious actor compromises an engineering workstation or a historian server, they rely on stealth. By disabling these audit policies, the organization has blinded itself to the very indicators of compromise (IOCs) that would allow an incident response team to detect lateral movement. In one case, we noted that the audit policy left major gaps in process, credential, Kerberos, file-share, and removable-media visibility.

Without visibility into these events, a ransomware attack can encrypt historian databases or manipulate PLC logic before anyone realizes anything is wrong. The risk score for such a configuration is not just “high” because of the vulnerability; it is critical because the detection capability required to prevent an outage has been voluntarily disabled.

Scoring Based on Operational Impact

So, how do we translate these findings into a risk score that resonates with plant leadership? We move away from abstract CVSS vectors and toward a framework that weighs operational impact. At Red Trident, we assess risk based on three pillars: Availability, Safety, and Integrity.

1. Availability

This is the primary concern for most operators. Does this vulnerability allow an attacker to stop production? In our assessments, we look for single points of failure in communication protocols like Modbus or DNP3. For example, if a legacy RTU communicates over unencrypted TCP/IP and lacks authentication, the risk score is elevated not because data is stolen, but because any actor on the network can send commands to trip a breaker or stop a pump.

2. Safety

Can this vulnerability lead to physical harm? This is particularly relevant in sectors like water and wastewater, where the recent attacks on Minnesota utilities have revealed major OT security gaps. In these environments, legacy equipment often remains unpatched and exposed. We score risk highly for any finding that could allow an attacker to manipulate sensor readings or override safety interlocks, regardless of whether it impacts immediate production.

3. Integrity

In manufacturing, product quality is paramount. If a vulnerability allows an attacker to subtly alter setpoints on a chemical process, the resulting batch might be ruined, leading to massive financial loss and waste. We treat integrity failures as high-severity events because they are often difficult to detect without specialized monitoring tools.

The Problem with Scanner-First Assessments

Many organizations attempt to score their OT risk using standard IT vulnerability scanners. This approach is flawed for several reasons:

  • Protocol Misinterpretation: Scanners often fail to understand proprietary industrial protocols, leading to false positives that waste engineering time or, worse, false negatives where critical vulnerabilities are missed.
  • Operational Disruption: Aggressive scanning can overwhelm legacy devices, causing crashes or resets. In a live control room, this is unacceptable.
  • Lack of Context: A scanner sees an open port; it doesn’t see that the port is used by a safety system that cannot be patched.

Instead of starting with a scanner, we recommend starting with a deep-dive into asset inventory and network segmentation. As noted in our backlog of ideas, OT monitoring starts with asset inventory. Without knowing what you have, you cannot know what is vulnerable.

Making Findings Actionable

Once we have scored the risk based on operational impact, the next challenge is prioritization. In one engagement, we identified dozens of high-severity findings across a sprawling manufacturing facility. The natural reaction from leadership was to panic and attempt to fix everything at once.

We advised against this. Instead, we helped them prioritize based on a simple matrix: Severity x Likelihood of Exploitation x Ease of Remediation. We focused first on findings that were both high-severity (impacting uptime) and had known exploitation paths available in the wild. For example, vulnerabilities in widely used HMI software or remote access gateways.

We also emphasized the importance of compensating controls. In many cases, patching is not an option due to vendor certification requirements. Here, we scored risk lower if strong network segmentation was in place, effectively isolating the vulnerable asset from the rest of the network. This nuanced approach allows operators to make defensible decisions about what to fix now and what to monitor closely.

The Path Forward

OT risk assessment is not a one-time exercise. It is a continuous process that must evolve alongside your operational technology landscape. As OT exposure spreads beyond control rooms into distributed assets, as seen in the energy sector, the attack surface grows daily.

We recommend that operators:

  1. Establish a dynamic asset inventory: Use passive monitoring to keep track of all devices in real-time.
  2. Score risk based on operations: Work with OT engineers to define criticality based on uptime, safety, and integrity.
  3. Implement targeted monitoring: Focus on the seven high-value audit categories we found missing: process creation, termination, credential validation, and Kerberos operations.
  4. Test your response: Conduct tabletop exercises that simulate OT-specific scenarios, not just IT data breaches.

By aligning your risk assessment with the realities of industrial operations, you can move from a posture of fear to one of confident management. You will be able to speak the same language as your plant managers and C-suite leaders, demonstrating how cybersecurity directly supports your operational goals.

Ready to Score Your OT Risk Correctly?

If you are tired of generic CVSS scores that don’t reflect your operational reality, let’s talk. Red Trident specializes in OT/ICS cybersecurity assessments that focus on what matters most: keeping your plants running safely and efficiently.

Schedule a free OT security assessment consultation today. We will help you identify the gaps that actually threaten your uptime and build a roadmap to close them.

author avatar
Emmett Moore