The exposure of OT to the internet via IoT devices.

  • Increases efficiency, visibility, integration
  • Exposes more vulnerabilities

Originally, most OT systems were Flat Network

Contrast

IT

  • More focused on CIA Triad
  • Impact is data loss or downtime
  • CVE exploitable age is average 250 days

OT

  • More focused on Availability and safety
  • Impact is physical harm and downtime
  • CVE exploitable age usually 6-10 years
  • Legacy systems