
Operational Technology Services – yesIT.png
Written by: Aiden Frearson
I walked onto a site in Central Queensland last month and watched an engineer patch a laptop straight into a programmable logic controller because the vendor said it needed a firmware update.
Nobody isolated the network first. Nobody flagged it as a risk. That’s what happens when operational technology gets bolted onto an IT security plan built for office laptops and email servers.
The two environments don’t run on the same rules, and as IT and OT networks keep converging across manufacturing, utilities, and resources, treating them like they do is how a breach becomes a shutdown.
What do operational technology services actually cover?
Operational technology is the layer of tech that runs physical equipment. Pumps, conveyors, gas sensors, safety interlocks, the systems that keep a site producing rather than just communicating.
IT keeps the business talking. OT keeps the site running. When the two stay separate, an IT incident stays an IT incident. When they’re connected, and on most modern sites they are, a phishing email in the front office can end up shutting down a compressor three kilometres away.
Standard IT tools don’t translate well here, and that’s the distinction I see skipped over constantly. A vulnerability scanner built for a corporate network can crash a controller that’s been running the same firmware since 2014, because nobody built it to be interrupted mid job.
Patching schedules that suit a laptop fleet don’t work on equipment that can’t come offline without stopping production. An IT team can push an update at 2am and call it done. An OT team has to plan around a shutdown window that might only come around once a quarter.
Operational technology services cover asset management across every controller and sensor on site, network segmentation between the plant floor and the corporate network, ongoing monitoring, and the system integration work that lets old equipment talk to newer platforms without opening a door nobody’s watching. That’s the core of what operational technology services actually need to deliver on a working site.
Why does OT need its own cyber security approach?
A breach on the OT side doesn’t mean a locked file and a ransom note. It means a controlled shutdown, or an uncontrolled one, and on a site with pressure vessels or moving machinery, an uncontrolled shutdown is a safety incident before it’s anything else. There’s a regulatory side too.
Sites operating critical infrastructure carry reporting obligations that a straightforward IT outage doesn’t. Legacy infrastructure makes all of this worse, not better. Half the control systems I look at on Queensland sites were installed when the biggest security concern was someone walking through the front gate, not someone routing in from another country.
Nobody was thinking about remote access when that equipment went in, and it shows. That gap is exactly why OT has become a growing target. It’s often the least defended part of the network, sitting behind the most consequential equipment, which is exactly why OT needs its own cyber security approach rather than an extension of the corporate one.
What does this look like in practice?
This isn’t a security operations centre watching for the same alerts as a bank. A plant manager doesn’t need to understand the technical detail, only that it’s being handled without adding downtime to their week. In practice, this looks like four things.
- Asset visibility across every OT device on the network, not just the ones on a spreadsheet
- Segmentation between corporate IT and the plant floor, so one breach can’t cross the fence
- Threat detection tuned to the industrial protocols your systems actually run, not generic IT traffic
- Vulnerability assessments scheduled around a shutdown window, never run live on equipment that can’t be interrupted
None of it should ask a site to choose between staying secure and staying productive. If a security measure can’t run around a production schedule, it’s not built for OT, and it will get switched off the first time it gets in the way.
Why does proximity matter?
Distance matters here in a way it doesn’t in a capital city office tower.
Queensland’s resources, infrastructure, utilities, and manufacturing sites aren’t always close to anything, and a lot of them run around the clock. When something goes wrong on a plant floor, the difference between a call to an interstate helpdesk and a team that can be on site within hours is the difference between hours of exposure and days of it.
On-site assessments need someone who can walk the floor and see the actual equipment, not read a network diagram from another state. That’s the kind of on-the-ground support that only comes from a partner already working in your region.
Operational technology security isn’t a category of IT problem. It’s an operational risk, sitting on the same list as workplace safety and production uptime, and it deserves the same seriousness. If you’re not sure where your own exposure sits, an initial OT assessment is usually the fastest way to find out.
Aiden Frearson is the Managing Director of yesIT, an Australian managed IT provider working across mining, energy, and infrastructure operations.
