What I am unlearning about operational technology
Where the interest came from
I came across Michael Holcomb’s OT, ICS, and SCADA videos on YouTube — he leads ICS/OT cybersecurity at Fluor and publishes at @utilsec — and kept watching for longer than idle curiosity accounts for. That was the itch. The actual starting point came later, when Dow offered me a place on the SANS study program for GIAC’s Global Industrial Cyber Security Professional certification. I am working through the material now and drafting my index, with the exam planned for November 2026.
Anyone who has sat a GIAC exam will know what “drafting my index” means, and that it is most of the work.
It is worth saying plainly what that does and does not make me. It makes me a student of this field. It does not make me a practitioner in it. My career has been spent on the enterprise IT side, and everything below is a beginner’s correction to a beginner’s assumptions — not a description of how anyone’s plant actually runs.
Why it is not a detour
Alerts related to manufacturing sites reach me now and then. I can work them with the instincts the enterprise side gave me, and mostly that is enough, but “mostly” has been sitting badly with me for a while. What I want is a real understanding of the on-the-ground reality behind those alerts, and enough shared vocabulary to talk to the people who live with it every day. The failure I am trying to avoid is the familiar one where a security person and an operations person use the same words and quietly mean different things.
Some of that has to happen away from a desk. I toured a plastics manufacturing facility to see first-hand how operational technology controls an industrial process, and how communications are handled in a working environment rather than in a reference diagram. I do not have a tidy lesson to report from it. What it did was make the coursework concrete, which turns out to be worth an afternoon.
What I have had to unlearn
None of the following will be news to anyone who works in OT. It is in the opening chapter of any primer. I am writing it down because it is the shape of my own correction, and I would rather record that while I can still see what I had wrong.
Equipment lifecycles. In enterprise IT, a machine still in place after a decade is something I would raise. In an industrial environment, long lifecycles are ordinary — the equipment is expected to outlast several generations of the office hardware I am used to reasoning about.
Patching cadence. My reflexes are built on a monthly rhythm: Microsoft ships on Patch Tuesday, and the fleet follows within a defined window. That assumes you can restart the thing. Production generally cannot stop every month to accommodate it, so patching waits for planned downtime. The question I was trained to ask — why is this not patched yet — turns out to be the wrong opening question, and learning what the better one is has been most of the value of the study so far.
What a computer looks like. My mental image of an endpoint is a laptop or a server with an agent reporting to a console I can query. The device controlling the production of plastics is more likely to be a purpose-built controller mounted in a secure enclosure. That is a small fact with a long tail: almost everything I know about visibility, inventory, and containment assumes a kind of device that may not be the one that matters here.
What surprised me
How common these systems are.
I had filed industrial control systems as a heavy-industry specialty — refineries, power generation, the sites that appear in the case studies. They are that. They are also controlling flow rates through pipes and the temperature of the office I am sitting in. Once the shape of these systems is pointed out to you, they stop being a category you visit and start being infrastructure you are standing in the middle of most of the time.
The part I keep returning to is that the less visible ones deserve the same security attention as the systems that get written about. I do not yet know enough to say what that should look like in practice. That is roughly what the next year is for.