24/7 Emergency Response: 1-800-868-8189
OPERATIONAL TECHNOLOGY SECURITY

OT and ICS Vulnerability Management

Industrial control systems, PLCs, RTUs, and SCADA infrastructure cannot be managed with the patch-and-scan cycles that IT security teams rely on. The program applies passive asset discovery, OT-corrected risk prioritization, and layered compensating controls to identify and reduce the vulnerabilities that pose genuine operational risk, while protecting the availability and safety of production systems throughout the engagement.

OT Vulnerability Management Lifecycle: asset inventory through patch validation for operational technology environments
  • Passive DPI Asset Discovery
  • OT-Corrected CVSS Scoring
  • CISA ICS Advisory Tracking
  • Risk-Based Prioritization
  • Compensating Controls Design
  • NERC CIP-007 and CIP-010
  • IEC 62443 Zone/Conduit Model
  • TSA Pipeline Compliance
  • NIST SP 800-82 Rev 3
  • Continuous Passive Monitoring
  • MITRE ATT&CK for ICS
  • Expert Witness Support
Operational technology vulnerability management dashboard showing asset inventory and risk scores

The OT Vulnerability Management Challenge

Applying IT vulnerability management practices to operational technology environments produces outcomes that range from ineffective to dangerous. The differences between IT and OT are not superficial; they are structural, and they require a fundamentally different methodology from asset discovery through remediation.

The most visible gap is in vulnerability data quality. According to Dragos research, 25% of ICS-CERT and NVD advisories contain incorrect CVSS scores for OT-relevant vulnerabilities. A vulnerability that scores 9.8 in an IT context may be unexploitable in an OT environment due to network isolation, compensating controls, or the specific firmware version deployed. Conversely, a moderate-severity advisory may be catastrophic if it affects a safety instrumented system or a controller managing a high-pressure process. Acting on raw CVSS scores without OT operational context causes security teams to misallocate resources: treating theoretical high-severity findings as emergencies while missing genuine risks that received lower generic scores.

The remediation picture is equally challenging. In 2025, 45% of ICS-CERT advisories recommended hardware replacement rather than a software patch. Roughly 26% of advisories had no vendor patch or mitigation available at all. The asset lifecycle in OT environments runs 15 to 25 years, compared to 3 to 5 years for typical IT infrastructure. Patching a live PLC controlling a continuous industrial process carries operational risk that IT teams never encounter: a failed patch push to a Windows server causes a service restart; a failed firmware update to a PLC managing a chemical reactor can cause a process upset, equipment damage, or a personnel safety incident.

The result is that only a narrow slice of OT vulnerabilities qualify for immediate remediation action. Dragos analysis of 2025 ICS-relevant vulnerability data found that just 2% required immediate action and approximately 2 to 6% of the total OT vulnerability population posed genuine, actionable operational risk when evaluated with full operational context. The remaining 94 to 98% should be monitored, addressed within planned maintenance windows, or managed through compensating controls rather than treated as emergencies. The capability to correctly identify that 2 to 6% is the core value of a mature OT vulnerability management program.

GDF's OT Vulnerability Management Program

GDF's program is structured in four interconnected phases: asset discovery, vulnerability identification and correlation, risk-based prioritization, and compensating control design. Each phase is designed around the operational constraints of production OT environments.

Asset Discovery: The Foundation

Vulnerability management is only as complete as the asset inventory it covers. OT environments present unique discovery challenges: assets may run proprietary protocols not visible to generic network discovery tools, dormant devices may not communicate during observation windows, and engineering workstations may bridge IT and OT networks in ways that standard asset management systems do not capture.

GDF uses a layered discovery approach that NIST SP 800-82 Rev 3 and leading OT security platforms endorse:

  • Passive deep packet inspection (DPI): Network TAPs or mirror ports collect all ICS network traffic for analysis across 600 or more ICS protocols including Modbus, DNP3, OPC UA, EtherNet/IP, PROFINET, BACnet, IEC 61850, and ICCP. No probe packets are generated. Assets are identified from their communications, with make, model, firmware version, and configuration details extracted from protocol traffic where available. This is the primary discovery method and the only one safe to run continuously on live OT networks.
  • OT-safe active collection: Scheduled, deliberate, read-only queries executed during planned maintenance windows and validated by vendors for specific device types fill gaps that passive monitoring cannot reach, particularly dormant devices that do not communicate during observation periods. These queries are explicitly not IT active scanning and are planned in coordination with operations staff.
  • Engineering workstation integration: Configuration data from engineering tools connected to PLCs, RTUs, and HMIs is extracted without generating additional network traffic, providing firmware versions, hardware configurations, and logic revision histories that protocol traffic alone may not reveal.
  • CMDB and historian ingestion: Existing asset data from process historians, computerized maintenance management systems (CMMS), and configuration management databases is ingested to supplement and cross-validate the discovery picture, reducing the initial discovery burden and building on data the operations team has already assembled.

Vulnerability Identification and Correlation

With an accurate asset inventory in place, GDF correlates discovered assets against the relevant OT vulnerability intelligence sources. This correlation requires specialist knowledge: CISA ICS advisories are written for specific product versions and firmware revisions, and a generic match to a product name without confirming the specific firmware version deployed produces significant false positives and false negatives.

GDF's vulnerability identification process draws from the following sources:

  • CISA ICS Advisories: The primary US government source for ICS-specific vulnerability disclosures. CISA published 508 ICS advisories in 2025, a 20.6% year-over-year increase across all sources, totaling 2,207 unique advisories. GDF tracks these advisories with version-specific matching rather than product-name-only correlation.
  • NIST National Vulnerability Database (NVD) with OT-corrected CVSS: NVD contains ICS CVEs but lacks OT operational context. GDF analysts apply OT-corrected scoring that accounts for network location, exploit complexity in an industrial environment, compensating controls, and operational impact, producing risk scores that reflect the actual threat level in the specific OT environment being assessed.
  • Vendor PSIRT advisories: Product Security Incident Response Teams at Schneider Electric, Rockwell Automation, Siemens, ABB, and other major OT vendors increasingly publish advisories that precede or supplement CISA disclosures. GDF monitors these channels for clients in relevant sectors.
  • CISA Known Exploited Vulnerabilities (KEV) catalog: Only 1.32% of High and Critical OT CVEs appear in the KEV catalog, but those that do represent confirmed exploitation in the wild and must be treated as immediate-priority findings regardless of network location or compensating controls.
  • MITRE ATT&CK for ICS: The ICS-specific adversary technique framework maps identified vulnerabilities to actual threat actor techniques, enabling GDF to assess whether a given vulnerability is part of a documented attack pattern used by threat groups active in the client's sector.

Risk-Based Prioritization

After identification and OT-corrected scoring, GDF applies a structured prioritization framework that evaluates each vulnerability in the context of the specific OT environment. This framework focuses security resources on the 2 to 6% of vulnerabilities that pose genuine operational risk, rather than generating remediation lists that operations teams cannot execute on their maintenance schedules.

The prioritization framework evaluates each vulnerability across the following dimensions:

  • Purdue Model location: A vulnerability in a Level 1 PLC controlling a physical process is evaluated differently from the same vulnerability in a Level 3 operations management server. Proximity to physical process control elevates priority.
  • Network exposure: Internet-facing assets and assets accessible from IT networks without compensating controls are elevated. Deeply segmented assets with no realistic exploit path are deprioritized accordingly.
  • Exploit availability: Public proof-of-concept code, KEV catalog inclusion, and documented exploitation by tracked threat groups all elevate priority. Theoretical vulnerabilities with no known exploit are categorized differently from those with confirmed exploitation in the wild.
  • Operational criticality: Safety-critical systems, systems managing high-consequence physical processes, and systems with no available failover receive higher priority than auxiliary monitoring or reporting systems.
  • Safety system proximity: Vulnerabilities in assets that communicate with or could affect safety instrumented systems (SIS) receive special scrutiny regardless of their apparent network isolation.
  • Compensating controls in place: Existing network segmentation, protocol whitelisting, monitoring coverage, and access restrictions are factored into the effective risk rating, which may reduce the priority of a high-severity vulnerability already mitigated by effective controls.

The output is a tiered finding set with three priority levels: immediate action required, address within the next planned maintenance window, and monitor without immediate remediation. This structure gives operations and security teams an actionable plan that fits OT operational realities rather than generating uniform urgency across hundreds of findings that cannot all be addressed simultaneously.

Compensating Controls When Patching Is Not Feasible

For vulnerabilities that cannot be patched within an acceptable timeframe, whether due to vendor patch availability, operational scheduling constraints, or the asset's 20-year lifecycle, GDF designs layered compensating controls that reduce risk to acceptable levels while preserving production operations. Compensating controls are documented with sufficient rigor to satisfy regulatory auditors under NERC CIP, TSA pipeline directives, and IEC 62443 requirements.

  • Network segmentation and strict ACLs: Restrict ICS protocol traffic to only documented and necessary communication paths; block unauthorized lateral movement from IT networks to OT segments
  • Virtual patching: Deploy IDS and IPS rules that detect and block the specific exploit patterns associated with a known vulnerability without modifying the affected device
  • Protocol whitelisting: Allow only specific, approved Modbus function codes, DNP3 commands, EtherNet/IP services, and other industrial protocol operations; block programming writes and configuration commands outside maintenance windows
  • Application-aware firewalls: Deep packet inspection at OT network boundaries with ICS-protocol awareness, blocking malformed or unauthorized command types
  • Microsegmentation: Isolate critical process cells and safety zones within the OT network, limiting the blast radius if an adjacent system is compromised
  • Read-only access models: Restrict engineering workstation and HMI connections to read-only modes except during documented, monitored maintenance sessions with session recording
  • Enhanced monitoring: Increase detection sensitivity and alerting thresholds around known-vulnerable assets; prioritize behavioral anomalies on those assets for immediate analyst review
  • Physical controls: Cabinet locks, USB port blockers, and physical access logging for assets where network-layer controls cannot be applied

Continuous Monitoring and Threat Intelligence

Point-in-time vulnerability assessments provide a snapshot of the risk picture at a given moment. The OT threat environment changes continuously: CISA publishes new ICS advisories, threat groups develop new capabilities, and infrastructure changes create new exposure. GDF's continuous monitoring capability extends vulnerability management from a periodic assessment into an ongoing program.

Passive network monitoring using specialized OT security platforms including Dragos Platform, Claroty, Nozomi Networks, and Wireshark captures ICS network traffic for behavioral analysis, new asset identification, and anomaly detection without introducing any active probe traffic. New assets that appear on the network are identified and assessed for vulnerability exposure. Changes in communication patterns that may indicate pre-attack reconnaissance or lateral movement are surfaced for analyst review. Protocol anomalies that match documented exploitation techniques are flagged against the MITRE ATT&CK for ICS technique library.

The 2025 threat environment provides clear justification for continuous monitoring in OT environments. Dragos tracked 119 ransomware groups targeting industrial entities in 2025, up from 80 in 2024, with ransomware incidents increasing 64% year-over-year. Critically, 96% of OT security incidents originate from IT-level compromises: attackers establish access on corporate IT networks and move laterally through inadequately segmented connections to reach control systems. Continuous monitoring at the IT/OT boundary is the primary detection mechanism for this attack pattern.

State-sponsored threat actors present a distinct and growing concern. The threat group VOLTZITE, associated with China's Volt Typhoon campaign, targeted electric utilities and telecommunications operators, exfiltrating GIS data, OT network diagrams, and operational instructions that enable precise targeting of physical infrastructure. The FBI has characterized these operations as preparation for destructive attacks in major crisis or conflict scenarios, not simply espionage. GDF's threat intelligence integration tracks adversary groups active in clients' sectors and maps their documented techniques to the specific vulnerabilities and exposure points identified in the client's OT environment.

CISA's Known Exploited Vulnerabilities catalog serves as a continuous feed of confirmed, actively exploited vulnerabilities that require priority attention. GDF monitors KEV additions on a continuous basis and notifies clients when a KEV-catalogued vulnerability matches their asset inventory, regardless of the periodic assessment schedule.

Regulatory Compliance Documentation

OT vulnerability management findings have direct implications for regulatory compliance across multiple mandatory frameworks. Vulnerability management at GDF is structured to satisfy the evidence requirements of applicable regulatory programs, making compliance documentation a direct output of the security work rather than a separate administrative exercise.

NERC CIP

For bulk electric system operators, NERC CIP-007 mandates patch management processes including tracking of security patches for BES Cyber Systems, documenting the applicability of each patch, and either applying patches within defined timeframes or documenting compensating measures for patches that cannot be applied. NERC CIP-010 requires vulnerability assessments for high and medium impact BES Cyber Systems on an annual basis. GDF's vulnerability management findings map directly to these requirements, producing CIP-007 patch tracking documentation and CIP-010 assessment evidence that satisfies FERC and NERC auditor expectations.

TSA Pipeline Security Directives

TSA SD Pipeline-2021-02F (effective May 2025 through May 2026, renewal expected) requires pipeline operators to maintain a patch management process with a risk methodology that prioritizes CISA KEV patches, submit annual Cybersecurity Assessment Plans to TSA for approval, and assess 30% of Critical Infrastructure Protection elements annually with 100% coverage every three years. The directive also explicitly requires zero trust implementation for OT network access control. GDF's vulnerability management program generates the documentation required to satisfy these requirements, including risk methodology documentation, compensating control records, and assessment coverage tracking.

EPA Water Utility Requirements

Community water systems serving more than 3,300 people must complete Risk and Resilience Assessments (RRA) under America's Water Infrastructure Act that include cybersecurity assessments of electronic and automated systems. AWIA recertification deadlines vary by system size: systems serving 50,000 to 99,999 residents faced a December 2025 recertification deadline; systems serving 3,301 to 49,999 residents face a June 2026 deadline. GDF's OT vulnerability assessments produce the technical findings documentation that forms the cybersecurity component of AWIA RRA submissions.

NIST SP 800-82 Rev 3

The September 2023 revision of NIST's Guide to OT Security introduced full alignment with NIST CSF 2.0, including the new Govern function that elevates OT cybersecurity governance to organizational leadership. It expanded coverage for cloud-connected OT, IIoT, and edge architectures, and incorporated updated threat intelligence guidance reflecting post-2015 ICS-specific malware including TRITON, INDUSTROYER2, and PIPEDREAM. Our OT security team structures findings to map to NIST SP 800-82 Rev 3 guidance, producing reports that can serve as supporting documentation for organizations building NIST CSF-aligned OT security programs.

IEC 62443

The IEC 62443 standard family governs security requirements for industrial automation and control systems. IEC 62443-2-3 addresses patch management specifically in OT environments. IEC 62443-3-2 establishes the zones and conduit model that structures network segmentation, directly informing compensating control design when patching is not feasible. GDF vulnerability management documentation maps findings to the applicable IEC 62443 series requirements and identifies gaps relative to the security levels (SL1 through SL4) defined for each zone in the client's architecture.

EU NIS2 and Cyber Resilience Act

European industrial operators newly in scope under NIS2 (which replaced NIS-1 in October 2024) face mandatory vulnerability management, 24-hour incident reporting for OT incidents, and supply chain security obligations covering digital suppliers. The EU Cyber Resilience Act, entering full application in December 2027, requires manufacturers placing products with digital elements on the EU market, including PLCs, HMIs, and industrial PCs, to maintain Software Bill of Materials documentation and active vulnerability management for a minimum of five years. Structuring programs that satisfy these overlapping European obligations is a routine engagement type for GDF's OT security practice.

OT security incidents increasingly produce legal and insurance consequences alongside the immediate operational impacts. Following a control system incident, organizations face potential regulatory scrutiny from CISA, the EPA, the NRC, TSA, and FERC, as well as civil litigation from affected parties, insurance disputes over coverage of cyber losses, and in some cases criminal investigation. The quality of pre-incident vulnerability management documentation directly affects an organization's ability to demonstrate reasonable security practices in these proceedings.

GDF provides post-incident forensic analysis documenting the vulnerability posture that existed at the time of a breach. This analysis examines which vulnerabilities were present in the affected assets, whether those vulnerabilities were known at the time (through CISA ICS advisories, NIST NVD listings, or vendor PSIRT publications), what compensating controls were in place and whether those controls were properly implemented and maintained, and whether the exploited vulnerability or attack path was identified in any prior vulnerability assessment. This technical record supports the legal and regulatory positions that attorneys and insurers develop in response to an incident.

In insurance coverage disputes following OT incidents, the technical record of pre-incident vulnerability management, compensating controls, and compliance documentation is often central to the coverage analysis. Insurers assess whether the insured maintained reasonable security practices as a condition of coverage. GDF's forensic analysis of pre-incident vulnerability management documentation provides the technical foundation for these assessments.

GDF also provides expert witness testimony in proceedings involving OT security, including regulatory enforcement matters, civil litigation where cyber intrusion is alleged as a contributing cause of an industrial incident, and vendor liability disputes where the security of a control system product or integration service is at issue. In each context, GDF's analysts provide technical analysis that attorneys and courts can rely on without overstating the scope of GDF's forensic role: GDF examines and documents the technical record; the conclusions about liability and causation are for attorneys and the trier of fact to draw.

GDF has been engaged in OT security matters for organizations across the energy, utilities, water, chemical, manufacturing, and transportation sectors. Analysts hold the security certifications applicable to classified and sensitive critical infrastructure environments. Engagements are available nationwide and internationally. Contact GDF at 1-800-868-8189 for a confidential consultation.

Last updated: April 15, 2026

OT Vulnerability Management Program Phases

  1. Scoping and Architecture Review

    Network diagrams, asset inventories, configuration documentation, and existing security policies are reviewed before any collection activity begins. This review produces an accurate picture of the environment and identifies which systems require additional coordination with operations staff.

  2. Passive Asset Discovery

    Network TAPs or mirror ports capture ICS network traffic for DPI analysis across 600 or more industrial protocols. Assets are identified from communications, with firmware version, make, model, and configuration details extracted. No probe packets are generated.

  3. Vulnerability Identification and Correlation

    Discovered assets are correlated against CISA ICS advisories, NIST NVD, vendor PSIRT feeds, and the CISA KEV catalog with version-specific matching. OT-corrected CVSS scores are applied to replace generic IT severity ratings with operationally meaningful risk levels.

  4. Risk-Based Prioritization

    Each vulnerability is evaluated across Purdue Model location, network exposure, exploit availability, operational criticality, safety system proximity, and compensating controls in place. Findings are tiered into immediate, next maintenance window, and monitor categories.

  5. Compensating Control Design and Remediation Planning

    For vulnerabilities that cannot be patched, layered compensating controls are designed and documented. Patchable findings are assigned to appropriate maintenance windows. All findings are mapped to applicable regulatory frameworks for compliance documentation.

  6. Continuous Monitoring and Reassessment

    Ongoing passive monitoring maintains asset inventory currency, surfaces new vulnerabilities matching known assets, and detects behavioral anomalies. KEV catalog additions matching the client's inventory trigger immediate notification regardless of periodic assessment schedule.

Risk-Based Prioritization

  • OT-corrected vulnerability scoring replacing generic CVSS ratings
  • Purdue Model location as a prioritization factor
  • Exploit availability and KEV catalog status
  • Safety system proximity assessment
  • Focus on the 2 to 6% that pose genuine operational risk

Compensating Controls

  • Virtual patching via IDS/IPS rule deployment
  • Protocol whitelisting for Modbus, DNP3, EtherNet/IP
  • Microsegmentation of critical process cells
  • Application-aware firewalls with ICS protocol DPI
  • Enhanced monitoring around known-vulnerable assets

Compliance-Ready Documentation

  • NERC CIP-007 patch tracking and CIP-010 assessment evidence
  • TSA pipeline directive compensating measure documentation
  • IEC 62443 zone and conduit model mapping
  • NIST SP 800-82 Rev 3 framework alignment
  • AWIA Risk and Resilience Assessment support for water utilities

Request an OT Vulnerability Assessment

All consultations are strictly confidential. GDF works with operations and security teams to design assessments that protect production systems throughout the engagement. Engagements are available nationwide and internationally.

OT Vulnerability Management Built for Industrial Environments

GDF's certified OT security analysts apply passive discovery, OT-corrected risk prioritization, and compliance-ready documentation to manage vulnerability risk in production industrial environments. Contact us for a confidential consultation.