Webcast recap: see + secure everything in your OT environment

|
Updated

OT environments are notoriously sensitive. Many devices were built for serial lines decades ago and only later adapted to TCP/IP. They tend to be underpowered, rarely updated, and expected to operate for ten to twenty years without interruption. No one wants to bring down a production line or a power grid because of a routine scan.

But ignoring them due to their fragility is a recipe for disaster. These same devices often end up directly exposed to the public internet, whether by design, accident, or slow drift. And while they may not be prime targets for opportunistic botnets, even noisy background internet traffic can be enough to cause outages. Visibility is not optional.

On last week’s webcast, the runZero research team dug into the hard-earned lessons of managing sensitive OT environments, and how our research into protocols like Modbus and DNP3 shapes safer techniques for active discovery and exposure detection. Here’s a recap of what we covered.

What safe discovery looks like #

Discovery doesn’t have to be reckless. It’s not about flooding a network and hoping it stays upright. It’s about approaching OT the way you would approach a delicate, mission-critical system that people’s lives and livelihoods depend on:

  • Start with respect. OT protocols like Modbus or DNP3 were never designed for today’s internet. Treating them like REST APIs is asking for trouble. The right way is to use the identification functions they already provide. Politely ask “who are you?” instead of hammering away with random requests. That gets you clarity without chaos.

  • Pace yourself. Imagine walking into a control room. You wouldn’t shout over the operators and flip every switch just to see what happens. The same principle applies here. Safe discovery means rate-limiting scans, tuning probe sets for the environment, and letting devices breathe between requests.

  • Think about the middle. It’s not just the endpoints that matter. Routers, switches, and firewalls in OT networks are often just as brittle. A careless scan that leaves half-open sessions or fills up state tables can cause as much pain as a crashed PLC. Safe discovery closes the loop politely.

  • Avoid the cowboy move. Fuzzing unknown protocols, blasting “Christmas tree” packets with every TCP option set, or running mass scans at pure wire speed doesn’t make you thorough, it makes you reckless. Safe discovery is disciplined: valid traffic only, every time.

Fragility is not an excuse #

The myth that OT is “too fragile to see” is holding defenders back. Fragility is real, but it’s also the reason you must look carefully, consistently, and with the right approach.

Check out the recording to learn about the history of industrial control protocols, live data showing the age and exposure of OT devices today, and how runZero can help arm you with safe techniques for active discovery.

Watch the webcast #

You can catch the full webcast on demand below:

Written by runZero Team

Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

More about runZero Team
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
Webcasts
runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
Product Videos
runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
Beyond the Zero-Day: Mapping the network attackers actually see
Breaches are inevitable. Learn from HD Moore how attackers exploit the seams between IT, IoT, and OT networks — and how to fix the segmentation...
Podcasts
Risky Biz Interview: Navigating the AI vibe shift with HD Moore
runZero Founder and CEO HD Moore drops by in this week's Risky Biz sponsor interview to talk about the concerning AI vibe shift and what to do...
Podcasts
From two weeks to three days: The KEV deadline debate
Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...
Solution Briefs
runZero for NIS2 compliance
You can’t secure what you can’t see. runZero provides the complete asset visibility and continuous reporting you need to satisfy strict NIS2...

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.