Defense in Depth in OT: The Architecture of Resilience
From Shadows to Structure
In the previous edition, “Shadows in the Machine,” we explored how unseen actions within trusted networks can cripple entire plants. Now we turn from the incident room to the drawing board — from reaction to design.
Because resilience isn't built by accident, it's engineered by architecture.
“You can’t protect what isn’t visible — and you can’t make it visible without design.”
Why Defense in Depth Matters in OT
OT environments couple deterministic control systems with increasingly connected layers. When an intrusion reaches this domain, consequences are physical. Defense in Depth (DiD) in OT therefore serves a dual purpose: sustaining availability while constraining propagation.
The recurring weakness observed in assessments is sequence. Controls are often deployed before risk is understood. Security that precedes architecture becomes noise.
Engineering Principles of DiD
Applied together, these principles turn control measures into a coherent architecture.
Seven Domains of Protection
- Policy and Awareness — Governance, defined roles, and exercised response plans.
- Network and Perimeter Design — Zoning, segmentation, and monitored conduits.
- Identity and Access Management — Role mapping, least privilege, multi-factor control.
- Detection and Response — Event correlation, anomaly baselining, and coordinated actions.
- Infrastructure and Endpoint Integrity — Hardening, configuration management, and patch governance.
- Application Security — Validation, version control, and secure configuration.
- Data Protection — Integrity checking, controlled backup, and verified restoration.
Each domain should degrade safely—never catastrophically—under partial failure.
Implementation Realities
Field experience exposes persistent constraints:
- Legacy platforms that cannot host modern controls.
- Overlapping tools without systemic integration.
- Security mechanisms that obstruct operations and invite bypass.
- Firmware and patch dependencies outside the operator’s authority.
- Shortage of multidisciplinary personnel bridging control and cyber domains.
Governance and verification compensate where technology cannot.
Quantifying Depth
Defense is measurable. Typical indicators include:
Metrics transform assurance from belief to evidence.
Closing Observation
Security in OT is not achieved through accumulation but through alignment. Defense in Depth is an architectural discipline—a balance of visibility, control, and verification.
Defense in Depth isn’t protection by addition; it’s protection by design.