The OT CISO Series: Chapter Four Securing Legacy OT Systems: Strategies for Extended Lifecycles

Legacy Isn't a Problem ... It's Reality

When we talk about OT cybersecurity, the conversation often jumps to Zero Trust, AI, and edge computing. But for most asset owners, the elephant in the control room is much older—and far less glamorous. We're talking about legacy systems. Those DCS nodes from 1995. The PLCs are still running ladder logic that no one dares to touch. The Windows XP HMI is still holding on for dear life.

This chapter presents a leadership-level examination of one of the most persistent—and misunderstood challenges in OT security: securing legacy systems that were not designed with cybersecurity in mind.

The Legacy Landscape in OT Environments

Legacy systems in OT aren't a niche challenge. They're the norm. During assessments and fieldwork, I've seen everything from Pnumatic controls to TDC 3000s to unpatched Windows NT machines running critical processes. The primary reason they're still operational? Because they still work. And replacing them often means expensive investment, expensive downtime, lost tribal knowledge, and complex system migrations.

However, as we extend the lifecycles of these systems, we must also address the growing cybersecurity risks that accompany this decision.

Why Securing Legacy Systems Is Uniquely Difficult

Unlike modern IT systems, legacy OT components often:

  • Lack of vendor support or patch availability
  • Use proprietary protocols with little to no documentation
  • Can't be taken offline for updates without disrupting operations
  • They were never designed to be connected to enterprise or cloud networks

In some cases, security controls themselves can be the risk. I've seen firewalls cause communication faults in serial-based systems, and antivirus software crash legacy HMIs. The result? Many asset owners simply choose to leave them alone, which works, until it doesn't.

The Leadership Dilemma: Risk vs. Reality

Here's the uncomfortable truth: sometimes, you can't secure a system in the traditional sense. So leadership must shift the mindset from "How do we secure it?" to "How do we secure around it?

That means:

  • Network segmentation to isolate high-risk devices
  • Monitoring and anomaly detection to spot unusual behavior
  • Strong access controls and remote access governance
  • Documenting system dependencies and failure impacts

It's less about installing the latest patch and more about creating compensating controls that protect the process, not just the asset.

Aging Systems, Aging Workforce

Another hidden vulnerability? The people who know how these systems work are retiring. Often, there is no documentation. No drawings. Just experience—and once that walks out the door, it’s gone.

A proactive OT CISO program doesn’t just focus on the tech—it invests in capturing institutional knowledge, training cross-functional teams, and building transition plans for critical expertise.

From Risk Acceptance to Informed Decision-Making

Too many organizations live in a state of silent risk acceptance. Not out of recklessness, but because no one has quantified the cost of legacy risk in operational terms. OT leaders must work with finance, operations, and cybersecurity teams to:

  • Prioritize legacy system risk based on business impact
  • Align mitigation strategies with operational realities
  • Plan for phased modernization without operational shocks

Closing Thoughts: Honor the Past, Secure the Future

We can't build a modern OT security program without addressing the legacy foundation it rests on. The key is not to fear legacy, but to understand it, plan around it, and respect its role in the continuity of operations.

Because in OT, legacy isn't just a system—it's an asset. And like any asset, it deserves to be protected wisely.

Previous
Previous

The Human Element: Building an Effective OT Security Culture

Next
Next

The OT CISO Series: Chapter Three Who Owns What?