For decades, the industrial control system (ICS) security playbook has relied on a single, flawed metric: network visibility via passive packet capture. Plant managers and OT engineers are often told that if they deploy SPAN ports or TAPs and feed traffic into an SIEM, they are “monitoring” their environment. This approach works reasonably well in IT for detecting brute-force login attempts or known malware signatures. But in the world of Operational Technology (OT), where Modbus registers shift by one bit and DNP3 commands are infrequent but critical, relying solely on port mirroring is like trying to hear a whisper in a hurricane while wearing noise-canceling headphones.
The reality of modern OT security is that lateral movement rarely looks like an IT intrusion. Attackers do not need to exfiltrate terabytes of data; they only need to alter a setpoint, trip a breaker, or disrupt a sequence to cause physical damage. To detect these subtle, malicious maneuvers, we must move beyond the illusion of visibility and embrace protocol-aware behavioral analysis.
The Illusion of Passive Visibility
Most legacy OT networks are designed for availability, not observability. When engineers deploy passive monitoring tools, they assume that capturing packets equals understanding traffic. This is a dangerous misconception. Port mirroring captures bytes; it does not capture context. Without an accurate asset inventory and protocol-specific parsing, a captured packet of OPC UA traffic is just encrypted noise to most legacy SIEMs.
Consider the complexity of modern manufacturing floors. A single PLC might communicate via Ethernet/IP for configuration, Modbus TCP for real-time control, and PROFINET for diagnostics. A port mirror collects all these streams into a bucket, but without deep packet inspection (DPI) tailored to industrial protocols, the data is useless for detecting lateral movement. An attacker moving from an engineering workstation to a safety controller might generate traffic that looks like normal maintenance activity to a generic firewall, yet represents a critical security breach.
Why Asset Inventory Is Your First Line of Defense
You cannot detect what you do not know exists. This is the foundational truth of OT cybersecurity that many organizations struggle to accept. In our assessments, we consistently find that incomplete asset inventories are the root cause of failed security monitoring strategies. If you do not know which Siemens S7-1500 PLCs are controlling your water treatment process, you cannot define a baseline for “normal” behavior for those devices.
Red Trident’s engagement findings highlight a stark reality in this domain. In our assessments we’ve run across multiple industrial sites, we identified that every assessment had recurring issues involving incomplete asset inventories, missing or non-OT-specific security policies, undefined security roles/responsibilities, lack of adopted security frameworks, insufficient OT-specific awareness/training, and continuous monitoring not tied to business/security objectives.
This is not a minor administrative gap; it is a critical blind spot. Without a verified asset list that includes firmware versions, patch levels, and communication relationships, any attempt to detect lateral movement is guessing. You might be monitoring the wrong ports or ignoring legitimate traffic from an undocumented device because it doesn’t match your flawed baseline.
Defining Normal: The Behavioral Baseline
Lateral movement in OT is often characterized by deviations from established behavioral baselines rather than known attack signatures. For example, a Rockwell Automation ControlLogix PLC might typically communicate with an HMI every 100 milliseconds. If that same PLC suddenly begins sending large volumes of data to an unknown IP address on port 445 (SMB), it is likely compromised or misconfigured. However, detecting this requires more than just seeing the packet; it requires understanding the protocol semantics.
We must establish baselines for:
- Command frequency: How often are read/write commands issued?
- Protocol usage: Is Modbus TCP used where PROFINET is expected?
- Source-destination pairs: Is this engineering workstation allowed to talk to this safety PLC?
- Data payload size: Is the register write within expected value ranges?
When lateral movement occurs, these baselines are violated. An attacker might attempt to escalate privileges by sending a Modbus Write Multiple Registers command to a device that only accepts Read Holding Registers. A protocol-aware analyzer will flag this as an anomaly, whereas a port mirror would simply record the bytes.
The Hidden Cost of Poor Visibility in Healthcare and Critical Infrastructure
The stakes of poor visibility are highest in sectors like healthcare and critical infrastructure, where OT environments are increasingly interconnected with IT networks. Recent research from Forescout Vedere Labs highlights a critical gap in healthcare security where visibility into OT/ICS environments is not effectively translated into actionable risk reduction strategies. The lack of integration between IT and OT security frameworks creates vulnerabilities that can be exploited by attackers seeking to disrupt patient care or operational continuity.
This is not just a theoretical concern. As AI-driven threats and supply chain attacks evolve, the attack surface for OT systems expands rapidly. A 51% surge in vulnerabilities affecting IoT and OT infrastructure, as reported by Forescout, underscores the urgency of adopting proactive detection methods. Passive monitoring alone cannot keep pace with this threat landscape. We need active understanding of how protocols interact and where lateral movement opportunities exist.
Case Study: The Danger of Default Routes in OT
To illustrate the importance of granular configuration analysis, consider a specific finding from one of our recent engagements. On one workstation assessed for an OT remote-operation environment, Red Trident observed two simultaneously active network interfaces on separate networks, with a default gateway on each interface, while the Windows Internet Connection Sharing service was also running.
This configuration created a direct, unintended path between the corporate IT network and the OT control network. To an observer relying only on high-level flow data, this might look like a complex routing scenario. But to a security analyst looking for lateral movement vectors, this is a smoking gun. The combination of active default routes and Internet Connection Sharing effectively bypassed any segmentation controls intended to protect the OT environment. This single host became a bridge for potential attackers, allowing them to move laterally from the corporate side directly into the control layer without triggering standard perimeter alerts.
This finding, documented in our internal assessment records (Findings 2.14 and 2.15), serves as a powerful reminder that lateral movement often exploits configuration errors rather than sophisticated exploits. By analyzing network interfaces and routing tables at the endpoint level, we can identify these bridges before they are exploited.
From Gap Analysis to Actionable Roadmaps
Identifying these gaps is only half the battle. The challenge for plant managers and CISOs is translating these technical findings into an actionable roadmap. Too often, gap analyses result in long lists of recommendations that overwhelm OT teams who are already stretched thin by operational demands.
Effective OT security requires prioritizing findings based on business impact and operational risk. For example, resolving the asset inventory issue mentioned earlier is a foundational step. Without it, no other control can be effectively deployed. Once visibility is established, organizations should focus on:
- Implementing protocol-aware monitoring: Deploy tools that understand Modbus, DNP3, and OPC UA semantics.
- Enforcing strict segmentation: Use industrial firewalls to enforce allow-lists between zones and conduits.
- Establishing behavioral baselines: Continuously monitor for deviations from normal operational patterns.
- Integrating IT/OT security teams: Ensure that OT engineers understand security implications and IT security teams understand operational constraints.
This approach aligns with frameworks like IEC 62443 and NIST SP 800-82, which emphasize defense-in-depth and continuous monitoring tailored to the unique needs of ICS. It also addresses the “missing layer” in healthcare security identified by Forescout Vedere Labs: the integration of visibility into actionable risk reduction.
Conclusion: Embrace Protocol-Aware Security
Detecting lateral movement in OT requires a fundamental shift from passive packet capture to active, protocol-aware analysis. It demands a rigorous understanding of industrial protocols, accurate asset inventories, and behavioral baselines tailored to each specific environment. The findings from our engagements, including the critical issue of incomplete asset inventories across every assessment, highlight that foundational visibility is non-negotiable.
As threats evolve, driven by AI and sophisticated supply chain attacks, passive monitoring will no longer suffice. You must understand not just what traffic is flowing, but what it means. Only then can you distinguish between normal operational noise and malicious lateral movement.
Take Control of Your OT Security Posture
If you are struggling to define clear baselines or need an independent assessment of your OT environment’s visibility, Red Trident offers specialized support. We help industrial operators move beyond generic monitoring to actionable, protocol-aware security. Contact us today for a free OT security assessment consultation to identify your blind spots and build a resilient defense strategy.
