There is a specific kind of frustration that only an OT engineer or plant manager understands. It happens when the cybersecurity team hands over a risk assessment report with a bright red “Critical” score on a non-critical asset, while a legacy PLC controlling a vital pump reads “Medium.” The operational reality is inverted: the critical IT asset has no process impact if it fails, while the medium-risk OT asset brings the entire line to a halt.
This disconnect is why so many OT risk assessments fail to drive action. Operators are trained to ignore noise. When every vulnerability looks like an emergency, nothing is urgent. To fix this, we have to stop applying IT-centric scoring models to operational technology and start scoring based on what actually matters in the plant: safety, environment, production continuity, and asset integrity.
Why IT Scoring Models Fail in OT
The standard CVE (Common Vulnerability and Exposures) scoring system is built on a foundation of Confidentiality, Integrity, and Availability (CIA), with a heavy bias toward data protection. In the Information Technology world, if a database is encrypted or stolen, that is a catastrophic failure of confidentiality.
In Operational Technology, confidentiality is rarely the primary concern. The attacker already knows what Modbus registers hold; they do not need to steal the IP address to disrupt operations. Instead, OT security prioritizes Availability and Integrity. A vulnerability that allows an attacker to modify a setpoint on a Honeywell Experion system or inject false data into a Siemens S7 controller via OPC UA is dangerous not because it leaks data, but because it can cause physical damage or unsafe operating conditions.
When we apply a CVSS (Common Vulnerability Scoring System) score directly to an ICS asset without context, we are measuring the theoretical exploitability of a protocol flaw, not the operational risk. For example, a default password on a Rockwell Allen-Bradley PanelView terminal might have a high CVSS score for “Privilege Escalation” in an IT context. In an OT context, if that terminal is air-gapped from any write-capable network and requires physical access to interact with the HMI, the operational risk is negligible despite the technical severity.
Red Trident’s core philosophy is simple: Assessment should identify risk without creating operational risk. This means our assessments focus on passive discovery and controlled testing to understand the actual attack paths rather than just listing flaws. We look at how a vulnerability interacts with the physical process, not just the code.
Defining Operational Impact Categories
To score findings that operations will act on, we must translate technical vulnerabilities into business outcomes. This requires a multi-dimensional scoring model that weighs the following factors:
- Safety and Environmental (EHS) Impact: Does the vulnerability allow for unsafe actuation of valves, motors, or heaters? Can it lead to over-pressurization, uncontrolled release, or fire? This is the highest tier of risk. If a finding can cause harm to people or the environment, it is immediately “Critical,” regardless of exploit complexity.
- Production Continuity: What is the impact on throughput if this asset is compromised? A vulnerability in a single gateway switch might have low confidentiality impact but high availability impact because it segments the entire cell. Conversely, a vulnerability in a redundant server cluster might have near-zero production impact due to failover capabilities.
- Asset Integrity: Can the flaw cause permanent hardware damage? In OT, unlike IT, we cannot simply “re-image” a controller or replace an industrial PC without significant downtime and safety checks. A vulnerability that allows firmware corruption is far more severe than one that just crashes the application.
- Regulatory and Compliance Exposure: With rising regulatory scrutiny, such as the SEC rules on cybersecurity risk management, compliance failures are becoming a financial risk. However, in OT, we must distinguish between administrative gaps and technical vulnerabilities that expose the firm to enforcement actions.
The Reality of Asset Inventories and Policy Gaps
Before we can accurately score any finding, we must have a clear view of what we are protecting. One of the most persistent challenges we encounter is the lack of accurate asset data. In our internal engagement records, we have noted recurring issues involving incomplete asset inventories, missing or non-OT-specific security policies, undefined security roles/responsibilities, and a lack of adopted security standards/frameworks.
These are not just administrative headaches; they are blind spots that prevent accurate risk scoring. If you do not know that a specific Schneider Electric PLC is running an unpatched firmware version on a critical loop, you cannot score its vulnerability. You cannot prioritize it for patching during the next outage window.
Furthermore, operational challenges often arise from generic IT policies applied blindly to OT environments. We have documented instances where strict multi-factor authentication (MFA) requirements or generic/shared-account prohibitions created operational friction without improving security. For example, requiring MFA on a legacy HMI that only supports basic HTTP can render the system unusable for operators who are already struggling with complex interfaces. This leads to workarounds, such as writing passwords on sticky notes, which is a far greater risk than the vulnerability itself.
Additionally, many organizations lack clear guidance on configuration management and hardening. We have seen assessments where hardening requirements existed without an approval path, or where network-design/architecture approval requirements were absent. This creates a state of “shadow OT” where engineers make changes to meet production needs without cybersecurity oversight, introducing un-scored risks.
Contextualizing Threats: The Distributed Attack Surface
The challenge of accurate risk scoring is being compounded by the expanding attack surface. Recent intelligence from the OT-ISAC highlights an emerging trend where operational technology exposure in the energy sector is spreading beyond traditional control rooms to distributed assets. This shift suggests a need for broader security measures beyond centralized monitoring.
Similarly, recent attacks on water utilities have revealed major OT security gaps, emphasizing that legacy equipment in treatment facilities remains unpatched and exposed to cyber threats due to inadequate network segmentation. These incidents underscore the importance of aligning OT security with regulatory requirements, such as SEC rule readiness for OT/IoT, to avoid financial penalties.
When assessing risk for distributed assets, we must consider the physical location and connectivity. A vulnerability in a remote telemetry unit (RTU) connected via cellular network has a different risk profile than one on the local control network. The former is exposed to the public internet, increasing the likelihood of automated scanning and exploitation, while the latter requires insider threat or lateral movement from an IT system.
Turning Findings into Actionable Roadmaps
The goal of any OT risk assessment is not a report that sits on a shelf. It is a roadmap that guides capital expenditure and maintenance schedules. To make findings actionable, we must prioritize them based on the operational impact model described above.
This involves a trade-off between technical remediation and operational feasibility. For example, patching a PLC might require a full plant shutdown. If the risk is “Medium,” it may not justify the millions of dollars in lost production. Instead, compensating controls such as network segmentation, intrusion detection systems (IDS) tuned for Modbus or DNP3 protocols, and strict change management processes may be more effective.
We recommend the following steps to bridge the gap between IT security and OT operations:
- Map Assets to Processes: Connect your asset inventory directly to business processes. Know which assets are critical for safety, which for production, and which for support.
- Assess Attack Paths, Not Just Flaws: Determine how an attacker can reach the asset. Is it via a vendor connection? A wireless network? A compromised IT workstation? The risk is in the path, not just the node.
- Engage Operations Early: Include OT engineers in the assessment process. They understand the nuances of legacy systems and production constraints that external auditors might miss.
- Develop Compensating Controls: When patching is not an option, implement network segmentation, whitelisting, and monitoring to mitigate the risk.
- Create a Phased Roadmap: Prioritize remediation based on operational impact and business cycles. Align security projects with planned outages and maintenance windows.
By shifting the focus from technical severity to operational impact, we can create risk assessments that resonate with plant managers and CISOs alike. This approach ensures that security investments are directed toward the risks that truly matter: those that threaten our people, our environment, and our ability to produce.
Next Steps for Your OT Security Program
If your organization is struggling to align cybersecurity findings with operational priorities, or if you need a clearer view of your OT assets and risks, we can help. Red Trident specializes in OT/ICS cybersecurity assessments that bridge the gap between technical vulnerabilities and business impact.
We offer a free consultation to discuss how our assessment methodologies can provide you with actionable insights and a realistic roadmap for securing your industrial operations. Contact us today to schedule a conversation about your specific challenges.
