Operational technology security has to protect availability, safety and engineering outcomes. That changes how organisations discover assets, monitor networks and introduce controls.

Singapore's OT Cybersecurity Masterplan 2024 promotes Secure-by-Deployment across the OT lifecycle. It was developed with more than 60 organisations and addresses people, process and technology. The direction matters beyond critical information infrastructure because building systems, manufacturing environments and other cyber-physical operations share many of the same constraints.

Establish a trustworthy asset view

Many OT programmes begin with incomplete inventories, undocumented connections and uncertain ownership. Passive network monitoring can identify communicating assets, protocols and relationships without actively probing sensitive systems. Validate the resulting view with engineering teams and maintain it through change.

Understand normal operations before tuning detection

OT behaviour is strongly shaped by process cycles, maintenance windows and vendor activity. Baseline normal communications, then review unexpected devices, new paths, protocol changes and abnormal commands in context. Detection should help operators understand risk without flooding them with signals that do not support a decision.

Prioritise exposure by operational consequence

A vulnerability score is only one input. Consider whether an asset is reachable, whether an exploit path exists, what process it supports, whether compensating controls are present and what a failed change could affect. This gives engineering and security teams a remediation sequence they can safely execute.

Control remote and privileged access

Vendor maintenance and engineering access need named identities, approved windows, least privilege and complete session records. Remove persistent access where it is unnecessary and define how access is revoked during an incident.

Carry assurance through design, testing and handover

Security requirements should appear in the design, implementation records, test procedures, exception register and final operating documentation. Independent assurance helps confirm that the delivered environment matches the approved architecture and that residual risks have accountable owners.

Protect operations without disrupting them

Combine passive visibility, engineering context, controlled access and independent verification. Introduce active testing only when it is authorised and safe for the environment.

Sources and further reading