Operational Technology (OT)

The Hardware & Software
That Controls the Physical World

Operational technology is the technology behind every power grid, water treatment plant, oil pipeline, and manufacturing line. It monitors and controls physical processes at industrial scale — and it is increasingly at the centre of the cybersecurity conversation.

Industrial Control Systems SCADA & DCS Critical Infrastructure Safety-Critical Systems Real-Time Control OT Cybersecurity

What is Operational Technology?

Operational technology (OT) refers to hardware and software that detects or causes change through the direct monitoring and control of industrial equipment, assets, processes, and events. Unlike IT — which manages data and business information — OT directly interacts with the physical world. It keeps the lights on, the water flowing, and industrial processes running safely and efficiently.

🏭

Definition

Hardware and software that directly monitors and controls physical industrial processes — distinct from IT, which manages data and business information systems.

🌐

Scope

Found across every sector that operates physical infrastructure: energy, water, manufacturing, oil & gas, mining, transport, and building automation.

⚙️

Key Systems

Encompasses SCADA, DCS, PLCs, RTUs, HMIs, and data historians — each performing a specific role within the industrial monitoring and control hierarchy.

🔌

Industrial Protocols

Communicates via dedicated industrial protocols such as Modbus, DNP3, IEC 61850, PROFINET, and EtherNet/IP — many designed before cybersecurity was a consideration.

🛡️

Safety Priority

Availability and safety take precedence over confidentiality. A system downtime can mean physical harm, environmental damage, or loss of critical services to entire communities.

🔗

IT/OT Convergence

Increasing connectivity between OT and enterprise IT networks creates new operational efficiencies — and new security risks that require careful, structured management.


Where is Operational Technology Used?

Operational technology underpins nearly every sector of the modern economy that involves physical processes. Australia's critical infrastructure — as defined under the SOCI Act — relies on OT across eleven industry sectors.

⚡

Energy & Utilities

Power generation, transmission, and distribution networks. SCADA systems manage grid stability, fault detection, and load balancing across thousands of kilometres of infrastructure.

💧

Water & Wastewater

Treatment plants, pumping stations, and distribution networks. PLCs and SCADA automate chemical dosing, pressure management, reservoir levels, and water quality monitoring.

🏗️

Manufacturing

Production lines, robotic assembly, quality control, and logistics. DCS and PLC systems coordinate complex multi-stage processes across automotive, food, pharmaceutical, and chemical manufacturing.

🛢️

Oil & Gas

Upstream exploration, midstream pipelines, and downstream refining. SCADA monitors flow rates, pressures, and valve states across remote and often hazardous environments where personnel access is limited.

🚂

Transport & Logistics

Railway signalling, traffic management systems, port automation, and airport infrastructure. OT ensures the safe, coordinated movement of passengers and freight at scale.

⛏️

Mining & Resources

Conveyor systems, ore processing plants, tailings management, and mine ventilation. OT automation reduces personnel exposure to hazardous environments and improves throughput consistency.


IT vs OT at a Glance

IT/OT means information technology and operational technology. The two share some technology foundations but differ fundamentally in purpose, security priorities and operational requirements — IT protects confidentiality first, OT protects safety and availability first. Understanding the difference between IT and OT is essential before applying IT security thinking to an OT environment.

Information Technology (IT)

Manages data, communications, and business processes. Prioritises confidentiality first (CIA triad). Typical system lifecycle of 3–5 years with regular patching. Designed to be connected and accessible.

Operational Technology (OT)

Controls physical industrial processes. Prioritises availability and safety first (AIC). System lifecycles of 15–25+ years. Patching is rare, tightly managed, and requires vendor qualification before deployment.

Converged IT/OT

Business demand drives OT systems to connect with enterprise IT and cloud platforms. Convergence enables efficiency and remote visibility but eliminates the isolation that historically protected OT environments.

IT vs OT: read the full comparison →


OT Security in Australia

Australia has established a comprehensive regulatory framework for the security of critical infrastructure systems — the majority of which rely on operational technology. Australian OT operators face binding legislative obligations, not just best-practice guidance.

Security of Critical Infrastructure (SOCI) Act 2018 (as amended)

The SOCI Act is Australia's primary critical infrastructure legislation. It covers 11 sectors and requires operators to implement Critical Infrastructure Risk Management Programs (CIRMPs), report significant cyber incidents within 12 hours of awareness, and maintain board-level accountability for cybersecurity posture. Civil penalties for non-compliance can reach AUD 11 million for corporations. The Act specifically acknowledges the unique vulnerabilities of OT environments and interconnected industrial networks.

Australian Energy Sector Cybersecurity Framework (AESCSF)

The AESCSF is a sector-specific cybersecurity framework developed by AEMO and the energy sector for electricity and gas operators. Built on NIST CSF and supplemented with OT-specific guidance, it provides a risk-tiered maturity model. The AESCSF references IEC 62443 as the preferred technical standard for OT security controls and is directly linked to SOCI Act compliance obligations for energy sector participants.

ACSC Industrial Control Systems Security Guidance

The Australian Cyber Security Centre (ACSC) publishes dedicated guidance for Industrial Control Systems security, supplementing the broader Essential Eight framework with OT-specific recommendations. The ACSC also issues sector-specific threat advisories and operates ReportCyber for 24/7 incident reporting. The ACSC recommends IEC 62443 as the foundational technical standard for Australian OT security programs.

Explore OT cybersecurity in depth →


Operational Technology: Frequently Asked Questions

Direct answers to the questions most often asked about operational technology, OT systems and OT security.

What is operational technology (OT)?

Operational technology (OT) is hardware and software that detects or causes change through the direct monitoring and control of industrial equipment, assets, processes, and events. Unlike information technology (IT), which processes business data, OT directly interacts with the physical world — controlling pumps, valves, motors, generators, and entire industrial processes. OT encompasses Industrial Control Systems (ICS), SCADA systems, Distributed Control Systems (DCS), Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), and Human-Machine Interfaces (HMIs).

What is the difference between OT and IT?

The key differences between operational technology (OT) and information technology (IT) are: (1) Purpose — IT manages data and business processes; OT controls physical industrial processes. (2) Security priorities — IT prioritises confidentiality first (CIA triad); OT prioritises availability and safety first (AIC). (3) System lifecycles — IT systems are refreshed every 3–5 years; OT assets routinely operate for 15–25+ years. (4) Patching — IT follows regular patch cycles; OT patches must be vendor-qualified and applied during planned maintenance windows. (5) Network design — IT is internet-connected by default; OT was traditionally air-gapped. (6) Failure impact — IT failures cause data loss; OT failures can cause physical harm, environmental damage, or disruption to critical public services.

What are Industrial Control Systems (ICS)?

Industrial Control Systems (ICS) is the broad term for the family of systems used to monitor and control industrial processes. ICS is a major segment within operational technology and encompasses SCADA (Supervisory Control and Data Acquisition), DCS (Distributed Control Systems), PLC-based systems, Safety Instrumented Systems (SIS), and building automation systems. ICS is used across critical infrastructure sectors including energy, water, manufacturing, oil and gas, transport, and mining.

What is SCADA?

SCADA (Supervisory Control and Data Acquisition) is a system architecture that provides centralised monitoring and control of industrial processes spread across large geographic areas. SCADA systems gather real-time data from remote field devices — PLCs, RTUs, and sensors — and transmit it to a central control system where operators can monitor status, receive alarms, and issue commands. SCADA is widely used in electric utilities, water and wastewater systems, oil and gas pipelines, and transport infrastructure.

What is a PLC?

A Programmable Logic Controller (PLC) is a ruggedised industrial computer designed to execute control logic in real time. PLCs read sensor inputs (temperature, pressure, flow, position), execute programmed logic, and actuate outputs (open/close valves, start/stop motors, trigger alarms). PLCs are highly reliable, designed for harsh industrial environments, and are the primary building block of manufacturing automation, process control, and discrete control applications.

What industries use operational technology?

Operational technology is used across every industry sector that operates physical infrastructure: energy generation, transmission, and distribution; water and wastewater treatment and distribution; oil and gas exploration, pipeline transport, and refining; manufacturing (automotive, food and beverage, pharmaceuticals, chemicals); mining and resources; transport and logistics (railways, ports, traffic management); and building automation (HVAC, access control, fire systems in large facilities).

What is OT cybersecurity?

OT cybersecurity refers to the practices, technologies, and frameworks used to protect operational technology systems from cyber threats. It differs from IT security in that OT environments prioritise availability and safety, cannot tolerate unplanned downtime, run legacy systems that cannot be quickly patched, and use industrial protocols (Modbus, DNP3, IEC 61850) that lack built-in security. Key OT cybersecurity frameworks include IEC 62443, NIST SP 800-82, and in Australia, the SOCI Act requirements and the AESCSF.

What is the SOCI Act and how does it relate to OT?

The Security of Critical Infrastructure (SOCI) Act 2018 is Australian legislation that establishes cybersecurity obligations for operators of critical infrastructure, including those using OT systems. The SOCI Act has been amended multiple times, most recently by the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024. It covers 11 sectors including energy, water, communications, and transport, and requires operators to implement Critical Infrastructure Risk Management Programs (CIRMPs), report significant cyber incidents within 12 hours, and maintain board-level accountability for cybersecurity. Non-compliance can attract civil penalties of up to AUD 11 million for corporations.

What is IT/OT convergence?

IT/OT convergence refers to the increasing integration of information technology and operational technology networks and systems. Business demands for real-time operational data, remote monitoring, and efficiency gains are driving OT systems to connect to enterprise IT networks and the internet. While convergence creates significant operational benefits, it also eliminates the traditional isolation that protected OT environments, exposing them to the full range of cyber threats faced by IT systems — but in environments where a successful attack can have physical and safety consequences.

What protocols are used in OT environments?

Common OT communication protocols include: Modbus (developed 1979, widely used in PLCs, no native security), DNP3 / IEEE 1815 (used in electric utilities and water systems), IEC 61850 (substation communication standard), PROFINET (Ethernet-based, common in European manufacturing), EtherNet/IP (common in North American manufacturing, used with Allen-Bradley PLCs), OPC UA / IEC 62541 (modern, secure IT/OT integration standard), and IEC 60870-5 (telecontrol in power systems). Most legacy OT protocols were designed before cybersecurity was a consideration and lack authentication or encryption.

What is the Purdue Model in OT?

The Purdue Model (also called the Purdue Enterprise Reference Architecture or PERA) is a hierarchical model that organises industrial control system components into levels — from physical field devices at Level 0, through PLCs and RTUs at Level 1, SCADA and HMIs at Level 2, manufacturing operations at Level 3, an industrial DMZ at Level 3.5, and enterprise IT at Levels 4–5. The model is used to define network segmentation boundaries and guide the implementation of security zones and conduits as described in IEC 62443-3-2.

Why is OT security harder than IT security?

OT security is harder than IT security for several reasons: (1) Legacy systems — OT assets operate for 15–25+ years, often running unsupported operating systems that cannot be patched. (2) Availability constraints — OT systems cannot be taken offline for patching or security updates without operational impact. (3) Safety sensitivity — security testing and active scanning can disrupt or damage OT systems. (4) Proprietary protocols — many OT protocols lack authentication or encryption and are poorly understood by IT security tools. (5) Skills shortage — OT security requires deep knowledge of both industrial processes and cybersecurity, a rare combination. (6) Physical consequences — a successful OT breach can cause physical harm, not just data loss.

Need OT security expertise for your organisation or infrastructure project? Get in touch ↗