The implementation of the European NIS2 directive and the convergence of IT/OT environments require critical infrastructure operators to transition to standardized security architectures. Directly applying traditional IT security methods to the industrial segment often leads to operational disruptions, which is unacceptable for manufacturing.
Security priorities in operational technology
According to the NIST SP 800-82 guidelines, the top priority in operational technology (OT) is availability and process continuity, unlike IT, where confidentiality dominates. Active network scanning or traffic blocking by standard IT firewalls can overload controllers and cause emergency equipment shutdowns. The standard recommends passive monitoring and architectural solutions that do not interfere with signal transmission.
Legacy equipment protection and segmentation
Industrial controllers operate for decades, and their regular updating is often impossible due to continuous production requirements. In such cases, compensating controls are applied: deep segment isolation, virtual patching at the network gateway level, and strict access control.
The ISA/IEC 62443 standard requires strict network segmentation to isolate critical control systems from the corporate IT network. For secure integration, the OPC UA protocol is used to normalize data from legacy sensors and transmit it to analytical systems without granting direct access to lower network levels.
IIoT management and NIS2 compliance
Scaling IIoT requires formalized device lifecycle management from edge to cloud. Pre-filtering data at the edge level reduces latency and data leakage risks. To implement such architectures, solutions from Softengi and the domestic platform UnityBase are utilized, which supports deployment in isolated OT segments with built-in access control.
Compliance with the NIS2 directive requires not only technical standards but also organizational steps: asset auditing, process formalization, and AI risk management using the NIST AI RMF 1.0 methodology through the Govern, Map, Measure, and Manage functions.
What it means for companies
Applying standard IT security tools to industrial networks risks causing severe operational disruptions, controller overloads, and emergency equipment shutdowns. For critical infrastructure operators, failing to transition to standardized OT security architectures means facing compliance penalties under the NIS2 directive and leaving legacy systems vulnerable to cyber threats.
What to do next
- Prioritize availability: Use passive monitoring and architectural solutions instead of active scanning to avoid disrupting signal transmission.
- Segment networks: Isolate critical control systems from corporate networks using the ISA/IEC 62443 standard and apply virtual patching at the gateway level.
- Secure data integration: Use the OPC UA protocol to normalize data from legacy sensors and transmit it without granting direct access to lower network levels.
- Deploy specialized solutions: Utilize platforms like Softengi and UnityBase to support secure deployment in isolated OT segments.
- Take organizational steps: Conduct asset auditing, formalize security processes, and manage AI risks using the NIST AI RMF 1.0 methodology.
Prepared by a Software Ukraine member. Original publication.