---
title: "What is OT Security? Operational Technology Explained"
description: "What OT security is, the asset classes it protects, why availability ranks above confidentiality, and how NIST SP 800-82, ISA/IEC 62443 and NCSC guidance map…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/what-is-ot-security#webpage",
      "url": "https://fire-vault.com/learn/what-is-ot-security",
      "name": "What is OT Security? Operational Technology Explained",
      "description": "What OT security is, the asset classes it protects, why availability ranks above confidentiality, and how NIST SP 800-82, ISA/IEC 62443 and NCSC guidance map…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/what-is-ot-security#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/what-is-ot-security#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "https://fire-vault.com/"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "What is OT Security?",
          "item": "https://fire-vault.com/learn/what-is-ot-security"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "What is OT Security? Operational Technology Explained",
      "description": "What OT security is, the asset classes it protects, why availability ranks above confidentiality, and how NIST SP 800-82, ISA/IEC 62443 and NCSC guidance map…",
      "image": "https://fire-vault.com/images/og/og-base-learn.jpg",
      "author": {
        "@type": "Organization",
        "name": "Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png"
        }
      },
      "datePublished": "2025-11-04",
      "dateModified": "2026-08-27",
      "mainEntityOfPage": "https://fire-vault.com/learn/what-is-ot-security"
    },
    {
      "@context": "https://schema.org",
      "@type": "TechArticle",
      "@id": "https://fire-vault.com/learn/what-is-ot-security#article",
      "headline": "What is OT Security?",
      "description": "What OT security is, the asset classes it protects, why availability ranks above confidentiality, and how NIST SP 800-82, ISA/IEC 62443 and NCSC guidance map onto it.",
      "about": [
        {
          "@type": "Thing",
          "name": "Operational technology security"
        },
        {
          "@type": "Thing",
          "name": "OT/ICS asset classes"
        },
        {
          "@type": "Thing",
          "name": "NIST SP 800-82"
        },
        {
          "@type": "Thing",
          "name": "ISA/IEC 62443"
        }
      ],
      "keywords": "what is OT security, OT security, operational technology security, OT cyber security, ICS security, SCADA security, OT/ICS, safety instrumented systems, NIST SP 800-82, ISA/IEC 62443",
      "articleSection": "OT and ICS security",
      "inLanguage": "en-GB",
      "isAccessibleForFree": true,
      "wordCount": 2300,
      "image": [
        "https://fire-vault.com/assets/explainer-what-is-ot-security-DYMZS1W1.jpg"
      ],
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "url": "https://fire-vault.com/about",
        "jobTitle": "Director and Co-Founder, Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "url": "https://fire-vault.com"
      },
      "datePublished": "2025-11-04",
      "dateModified": "2026-08-27",
      "url": "https://fire-vault.com/learn/what-is-ot-security",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/what-is-ot-security"
      },
      "citation": [
        {
          "@type": "CreativeWork",
          "name": "NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security",
          "url": "https://csrc.nist.gov/pubs/sp/800/82/r3/final"
        },
        {
          "@type": "CreativeWork",
          "name": "ISA/IEC 62443 series",
          "url": "https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards"
        },
        {
          "@type": "CreativeWork",
          "name": "NCSC, Operational Technology guidance collection",
          "url": "https://www.ncsc.gov.uk/collection/operational-technology"
        },
        {
          "@type": "CreativeWork",
          "name": "NCSC, Cyber Assessment Framework (CAF)",
          "url": "https://www.ncsc.gov.uk/collection/caf"
        },
        {
          "@type": "CreativeWork",
          "name": "NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events",
          "url": "https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is OT security in plain English?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "OT security is the practice of protecting the hardware and software that monitors and controls physical processes on plants, sites and utilities. It differs from IT security in that its top priority is keeping the process available and safe, not keeping data confidential."
          }
        },
        {
          "@type": "Question",
          "name": "What does OT stand for in cyber security?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "OT stands for operational technology. It refers to the industrial control systems and connected devices that monitor and control physical processes, as distinct from the enterprise IT estate that handles email, documents and business applications."
          }
        },
        {
          "@type": "Question",
          "name": "What is the difference between OT security and ICS security?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Industrial control systems (ICS) are a subset of operational technology. ICS security specifically covers controllers such as PLCs, RTUs, DCS and SCADA. OT security is the broader discipline that also covers historians, engineering workstations, safety systems and the networks connecting them."
          }
        },
        {
          "@type": "Question",
          "name": "Why does OT security prioritise availability over confidentiality?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Because in OT environments, loss of availability can mean loss of control over a physical process, which can create a safety event. NIST SP 800-82 and ISA/IEC 62443 both describe this as an inversion of the IT priority ranking, where confidentiality usually comes first."
          }
        },
        {
          "@type": "Question",
          "name": "Can OT systems be patched the same way as IT systems?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Rarely on the same schedule. Patching an OT system usually requires a planned maintenance window, vendor validation and, in some cases, a partial or full process shutdown. Many OT assets run for fifteen to thirty years and cannot be patched without risking the safety case for the process."
          }
        },
        {
          "@type": "Question",
          "name": "What standards govern OT security?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The main references are NIST SP 800-82 Revision 3 in the United States, the ISA/IEC 62443 series internationally, and NCSC operational technology guidance in the United Kingdom. In UK critical national infrastructure, outcomes are commonly assessed against the NCSC Cyber Assessment Framework rather than pursued as a certification."
          }
        },
        {
          "@type": "Question",
          "name": "What is a safety instrumented system?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A safety instrumented system (SIS) is a set of sensors, logic solvers and final control elements designed to bring a process to a safe state if a defined hazardous condition occurs, independent of the basic process control system. Protecting SIS integrity is a distinct priority within OT security."
          }
        },
        {
          "@type": "Question",
          "name": "What is OT gold data?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "OT gold data is the verified, known good set of configurations, firmware, programs and recovery assets needed to rebuild a control system after a fault, misconfiguration or cyber incident. Its availability, separate from the live network, is central to OT recovery planning."
          }
        },
        {
          "@type": "Question",
          "name": "Is a historian part of OT?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. A historian is a database that records time-series process data from an OT environment for trending, reporting and analysis. It is typically located at Level 3 of a Purdue-style architecture and is a common target for both operational monitoring and attackers seeking a foothold."
          }
        },
        {
          "@type": "Question",
          "name": "Do all industrial sites need the same OT security controls?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Controls should be proportionate to the safety and business consequences of failure at that site, the assets in scope and the applicable regulatory regime. A water treatment works and a discrete manufacturing line will reasonably apply different controls even under the same standard."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Knowledge Vault](/learn/knowledge)

Explainer OT and ICS security 

# What is OT Security?

Operational technology security in plain English: the asset classes it covers, why availability ranks above confidentiality, and how the leading standards frame it.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 November 2025 15 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security&text=What%20is%20OT%20Security%3F%0A%0AOperational%20technology%20security%20in%20plain%20English%3A%20the%20asset%20classes%20it%20covers%2C%20why%20availability%20ranks%20above%20confidentiality%2C%20and%20how%20the%20leading%20standards%20frame%20it.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security)[](mailto:?subject=What%20is%20OT%20Security%3F&body=Operational%20technology%20security%20in%20plain%20English%3A%20the%20asset%20classes%20it%20covers%2C%20why%20availability%20ranks%20above%20confidentiality%2C%20and%20how%20the%20leading%20standards%20frame%20it.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security)

![OT security in practice: an industrial control room with SCADA process schematics and operator consoles](/assets/explainer-what-is-ot-security-DYMZS1W1.jpg)

Operational technology security protects the systems that monitor and control physical processes, not just the data they generate.

Written by

Mark Fermor, Co-Founder, Firevault

Technical review

Firevault architecture team

First published

4 November 2025

Last reviewed

27 August 2026

Review cycle

At least annually, or following material changes to NIST, NCSC or ISO guidance.

How we built this explainer:  Firevault reviewed NIST SP 800-82 Revision 3, the ISA/IEC 62443 series and NCSC UK operational technology guidance, then set out the asset classes, priority ranking and standards landscape that most commonly cause confusion for teams new to OT security.

**On this page**[What is OT security?](#definition)[The OT asset classes](#asset-classes)[Why availability outranks confidentiality](#priority-inversion)[OT security and the safety case](#safety-cases)[Patching and maintenance windows](#patching)[Protocol realities on the plant floor](#protocols)[The standards landscape](#standards)[OT gold data and recovery assets](#gold-data)[Practical decision criteria](#decision-criteria)[Limits and failure modes](#limits)[How Firevault applies these principles](#firevault)[Sources and further reading](#sources)

On this page

1.  [What is OT security?](#definition)
2.  [The OT asset classes](#asset-classes)
3.  [Why availability outranks confidentiality](#priority-inversion)
4.  [OT security and the safety case](#safety-cases)
5.  [Patching and maintenance windows](#patching)
6.  [Protocol realities on the plant floor](#protocols)
7.  [The standards landscape](#standards)
8.  [OT gold data and recovery assets](#gold-data)
9.  [Practical decision criteria](#decision-criteria)
10.  [Limits and failure modes](#limits)
11.  [How Firevault applies these principles](#firevault)
12.  [Sources and further reading](#sources)

Operational technology (OT) security is the discipline of protecting the systems that monitor and control physical processes, from a single packaging line to a national electricity grid. It sits alongside IT security as part of an organisation's wider cyber security programme, but it starts from a different set of priorities, a different asset base and a different tolerance for downtime.

This explainer sets out what counts as OT, why the priority ranking is inverted compared with IT security, how safety cases and maintenance windows shape what can and cannot be changed, and how the standards landscape, from NIST to ISA/IEC 62443 to NCSC guidance, maps onto day to day OT security decisions.

## What is OT security?

Operational technology is the hardware and software that detects or causes a change in physical processes through direct monitoring or control of physical devices such as valves, pumps, motors and sensors. OT security is the set of practices, controls and architecture decisions that protect that technology from failure, misuse and attack.

[NIST SP 800-82 Revision 3](https://csrc.nist.gov/pubs/sp/800/82/r3/final) defines OT broadly enough to include industrial control systems, building automation, physical access control systems and other cyber-physical systems. In practice, most organisations use "OT security" and "ICS security" fairly interchangeably, with ICS treated as the industrial subset of the wider OT category.

## The OT asset classes

A useful OT security programme starts with a precise inventory of what is actually on the estate. The following asset classes recur across almost every OT and ICS environment.

PLC

Programmable logic controller. Executes the control logic that runs a machine or process step.

RTU

Remote terminal unit. Gathers field data and relays it to supervisory systems, common in distributed sites such as pipelines.

DCS

Distributed control system. Coordinates control across a large, continuous process, typically within one site.

SCADA

Supervisory control and data acquisition. Provides centralised monitoring and control across geographically dispersed assets.

HMI

Human-machine interface. The screen and controls an operator uses to view and act on the process.

Historian

A database that records time-series process data for trending, reporting and forensic analysis.

Engineering workstation

The computer used to program, configure and update controllers and supervisory systems.

Safety instrumented system (SIS)

An independent layer of sensors, logic and final elements that brings the process to a safe state on a defined hazardous condition.

These asset classes typically sit at different levels of a Purdue-style reference architecture, from physical process at the bottom to enterprise IT at the top. For a full treatment of how those levels relate to each other and to network segmentation, see the [Purdue Model explainer](/news/the-purdue-model-everything-you-need-to-know).

## Why availability outranks confidentiality

IT security commonly follows the confidentiality, integrity, availability (CIA) ranking, in that order. Losing confidentiality of a document is usually a serious but contained problem. OT security inverts that ranking to availability, integrity, then confidentiality, because losing availability of a control system can mean losing control of a physical process, which can create a safety event, not just a business one.

IT security

Confidentiality first

-   Confidentiality
-   Integrity
-   Availability

Losing access to a system is disruptive but rarely a safety event.

OT security

Availability first

-   Availability
-   Integrity
-   Confidentiality

Loss of control over a process can create an immediate safety consequence.

IT and OT rank the same three properties in opposite order, and that inversion drives most downstream design decisions.

## OT security and the safety case

Many OT environments, particularly those covered by process safety regulation, operate under a documented safety case: an analysis that shows the risks of a process have been reduced to a tolerable level. Security controls that change timing, add network hops or introduce new failure modes must be assessed against that safety case before they are deployed.

This is why a control that is routine in IT, such as an endpoint agent that quarantines a host on suspicious activity, can be inappropriate in OT. An automatic isolation action taken against a controller mid-process could itself cause the unsafe condition the safety case was designed to prevent.

Practical implication:  Any OT security control with an automated response action needs sign-off from whoever owns the safety case for that process, not only from the security team.

## Patching and maintenance windows

OT assets are commonly in service for fifteen to thirty years, running firmware and operating systems that were current when they were installed. Patching typically requires vendor validation, a planned outage or maintenance window, and in some cases physical presence on site. Continuous, automatic patching of the kind common in IT is rarely available in OT.

Step 1

Vendor releases or validates a patch

Confirms compatibility with the specific control system version in use.

Step 2

Safety and engineering review

Assesses whether the change affects the process safety case or timing behaviour.

Step 3

Maintenance window scheduled

Often planned months in advance, sometimes tied to a full plant shutdown.

Step 4

Backout plan and gold data confirmed

A known good configuration is verified and available before the change is made.

Step 5

Patch applied and process re-validated

Operators confirm normal process behaviour before returning to full production.

A typical OT patch cycle runs through several checkpoints an IT patch cycle does not need.

## Protocol realities on the plant floor

OT networks run deterministic industrial protocols, such as Modbus, DNP3, PROFINET and EtherNet/IP, that were designed for reliability and real-time performance rather than authentication or encryption. Many of these protocols have limited or no built-in security, which is why network-level controls, rather than protocol-level fixes, carry much of the security burden in OT.

Introducing a control that adds latency, such as inline deep packet inspection, can itself become a safety issue if it interferes with the timing a process depends on. This is one reason OT monitoring is more often built around passive network taps than inline appliances.

## The standards landscape

A small number of references dominate OT security practice internationally. None of them replace the others; most organisations map their controls against several at once, depending on sector and geography.

Reference

Origin

Primary use

NIST SP 800-82 Rev. 3

United States

Guide to OT security architecture, asset classes and controls.

ISA/IEC 62443 series

International

Security levels, zones and conduits for industrial automation and control systems.

NCSC OT guidance

United Kingdom

Practical guidance on OT architecture, secure connectivity and asset visibility.

NCSC Cyber Assessment Framework (CAF)

United Kingdom

Outcome-based framework, mapped against an organisation's OT environment rather than pursued as a pass or fail certification.

The main OT security references and what each one is used for.

A common misunderstanding is treating the CAF as something an organisation can be "certified" against in the way a management system can be certified to an ISO standard. The [NCSC CAF](https://www.ncsc.gov.uk/collection/caf) is explicitly outcome-based: an organisation and its regulator assess how well existing arrangements achieve the stated outcomes, rather than checking off a fixed list of technical requirements.

## OT gold data and recovery assets

Because prevention cannot be guaranteed to succeed, OT security programmes increasingly treat recovery as a first order requirement rather than a fallback. OT gold data is the verified set of configurations, firmware images, PLC logic and engineering documentation needed to rebuild a control system after a fault, misconfiguration or cyber incident.

LOGIC

Controller programs and logic

PLC and DCS programs, including the last known good version.

CONFIG

Device and network configuration

Firewall rules, switch configurations, HMI and historian settings.

FIRMWARE

Firmware and OS images

Verified firmware for controllers, RTUs and engineering workstations.

DOCS

Engineering and safety documentation

As-built drawings, safety case references and change records.

A layered view of what OT gold data typically includes, from controller logic through to full system images.

[NIST SP 1800-11](https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events) sets out the general principle behind this: recovery depends on having a verified, trustworthy copy of the data and configuration needed to rebuild, separate from the systems that may themselves be compromised.

## Practical decision criteria

When assessing an OT security control, the following questions are a useful starting point before any technical detail is decided.

1.  Safety impact.  Could this control, or its failure mode, affect the process safety case?
2.  Timing sensitivity.  Does the control add latency or jitter that the process cannot tolerate?
3.  Vendor support.  Is the change validated by the equipment vendor for this specific system version?
4.  Maintenance window.  Can the change be deployed only during a planned outage, and if so, when is the next one?
5.  Recovery position.  If the change goes wrong, is a verified gold copy available to restore from?

## Limits and failure modes

OT security has real limits that are worth stating plainly. Legacy assets sometimes cannot be patched at all within their remaining service life. Passive monitoring can detect anomalies but cannot always block them without risking the process. Segmentation reduces exposure but does not eliminate the risk of insider error, supply chain compromise or a vendor's remote access credentials being misused.

Because of these limits, most mature OT security programmes accept that some level of compromise is possible and focus proportionate effort on detection, containment and, critically, on being able to recover quickly from a known good state.

## How Firevault applies these principles

Firevault's role in an OT security programme is narrow and specific: it protects the OT gold data and recovery assets described above with a physically disconnected copy, so that a verified restore point exists independently of the network that a ransomware attack or destructive event may have compromised. Offline Secure Storage® holds configurations, firmware and engineering documentation in a state that cannot be reached, altered or encrypted over a network connection. Firevault Control governs when a connection to that storage is permitted, so that the data path is closed by default and opened only for a defined recovery or verification operation, consistent with the Disconnect to Protect® principle. This sits alongside, not instead of, the safety, segmentation and monitoring controls described in this explainer.

Key takeaway 

## OT security starts from a different question than IT security

IT security asks how to keep information confidential. OT security asks how to keep a physical process running safely, which means availability and integrity come first. That single inversion explains most of the practical differences in patching, network design, tooling and recovery planning between the two disciplines.

A credible OT security programme treats the asset inventory, the standards mapping and the recovery architecture as equally important. Without a verified, offline copy of OT gold data, detection and prevention controls are not enough on their own to guarantee a safe and rapid return to production.

Questions 

## Frequently Asked Questions

Straight answers on how Offline Secure Storage® behaves in practice.

### What is OT security in plain English?

### What does OT stand for in cyber security?

### What is the difference between OT security and ICS security?

### Why does OT security prioritise availability over confidentiality?

### Can OT systems be patched the same way as IT systems?

### What standards govern OT security?

### What is a safety instrumented system?

### What is OT gold data?

### Is a historian part of OT?

### Do all industrial sites need the same OT security controls?

## Sources and further reading

-   [NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final)
    
    The primary US reference for OT/ICS asset classes, threats, network architecture and security controls.
    
-   [ISA/IEC 62443 series](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards)
    
    International standards for industrial automation and control systems security, including security levels, zones and conduits.
    
-   [NCSC, Operational Technology guidance collection](https://www.ncsc.gov.uk/collection/operational-technology)
    
    UK guidance on OT architecture, secure connectivity and asset visibility.
    
-   [NCSC, Cyber Assessment Framework (CAF)](https://www.ncsc.gov.uk/collection/caf)
    
    Outcome-based framework commonly mapped against OT and essential-services environments rather than used as a pass or fail certification.
    
-   [NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events](https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events)
    
    Practice guide on recovery architecture, applicable to OT gold data and configuration backups.
    

Related Firevault guides

[OT vs IT security: the real differences that matter](/learn/ot-vs-it-security) [The Purdue Model: everything you need to know](/news/the-purdue-model-everything-you-need-to-know) [Physical air gap for ransomware protection](/learn/physical-air-gap-ransomware-protection) [OT network segmentation explained](/learn/ot-network-segmentation)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this explainer 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security&text=What%20is%20OT%20Security%3F%0A%0AOperational%20technology%20security%20in%20plain%20English%3A%20the%20asset%20classes%20it%20covers%2C%20why%20availability%20ranks%20above%20confidentiality%2C%20and%20how%20the%20leading%20standards%20frame%20it.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security)[](mailto:?subject=What%20is%20OT%20Security%3F&body=Operational%20technology%20security%20in%20plain%20English%3A%20the%20asset%20classes%20it%20covers%2C%20why%20availability%20ranks%20above%20confidentiality%2C%20and%20how%20the%20leading%20standards%20frame%20it.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fwhat-is-ot-security)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)