Webcast recap: see + secure everything in your OT environment

|
Updated

OT environments are notoriously sensitive. Many devices were built for serial lines decades ago and only later adapted to TCP/IP. They tend to be underpowered, rarely updated, and expected to operate for ten to twenty years without interruption. No one wants to bring down a production line or a power grid because of a routine scan.

But ignoring them due to their fragility is a recipe for disaster. These same devices often end up directly exposed to the public internet, whether by design, accident, or slow drift. And while they may not be prime targets for opportunistic botnets, even noisy background internet traffic can be enough to cause outages. Visibility is not optional.

On last week’s webcast, the runZero research team dug into the hard-earned lessons of managing sensitive OT environments, and how our research into protocols like Modbus and DNP3 shapes safer techniques for active discovery and exposure detection. Here’s a recap of what we covered.

What safe discovery looks like #

Discovery doesn’t have to be reckless. It’s not about flooding a network and hoping it stays upright. It’s about approaching OT the way you would approach a delicate, mission-critical system that people’s lives and livelihoods depend on:

  • Start with respect. OT protocols like Modbus or DNP3 were never designed for today’s internet. Treating them like REST APIs is asking for trouble. The right way is to use the identification functions they already provide. Politely ask “who are you?” instead of hammering away with random requests. That gets you clarity without chaos.

  • Pace yourself. Imagine walking into a control room. You wouldn’t shout over the operators and flip every switch just to see what happens. The same principle applies here. Safe discovery means rate-limiting scans, tuning probe sets for the environment, and letting devices breathe between requests.

  • Think about the middle. It’s not just the endpoints that matter. Routers, switches, and firewalls in OT networks are often just as brittle. A careless scan that leaves half-open sessions or fills up state tables can cause as much pain as a crashed PLC. Safe discovery closes the loop politely.

  • Avoid the cowboy move. Fuzzing unknown protocols, blasting “Christmas tree” packets with every TCP option set, or running mass scans at pure wire speed doesn’t make you thorough, it makes you reckless. Safe discovery is disciplined: valid traffic only, every time.

Fragility is not an excuse #

The myth that OT is “too fragile to see” is holding defenders back. Fragility is real, but it’s also the reason you must look carefully, consistently, and with the right approach.

Check out the recording to learn about the history of industrial control protocols, live data showing the age and exposure of OT devices today, and how runZero can help arm you with safe techniques for active discovery.

Watch the webcast #

You can catch the full webcast on demand below:

Written by runZero Team

Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

More about runZero Team
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.

Explore more runZero

Product
runZero 5.1 is here: Secure AI workflows, enhanced integrations, and expanded autonomous discovery
runZero 5.1 takes on the heavy lifting across five key areas, enabling you to unmask and remediate exposures with less friction and more speed.
Podcasts
Know Your Adversary with HD Moore
runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
runZero Perspective
BOD 26-04: A new era of prioritized remediation
A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
runZero Perspective
Dawn of the apex agentic adversary
When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
Webcasts
runZero Hour, Ep. 33: Hacker Summer Camp: we survived the Vegas heat (and the bugs)
In this post-Hacker Summer Camp recap, the runZero team break down the research, tools, and trends discussed at BSides Las Vegas, Black Hat and DEF...
Podcasts
The Internet's biggest point of failure
Join Tod Beardsley on Secure & Scale as he explores the future of vulnerability management, CVE fragmentation, and how AI is changing security...
Webcasts
Mind the gaps: securing the modern IT/OT attack surface
In this webcast, HD Moore and GigaOm Analyst Chris Ray discuss key methods for hardening OT defenses and share insights from the new OT report.
Webcasts
runZero Hour, Ep. 32: AI-pocalypse now? Why the 2026 DBIR is actually good news
In this episode of runZero Hour, Tod Beardsley, Brianna Cluck, and Verizon's Alex Pinto broke down 2026 DBIR trends, AI threats, and runZero 5.0.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.