Skip to content

Cybersecurity

Zero Trust in OT: Applicable Principles and Real Limits in Industrial Environments

Zero Trust is the security framework of the moment, but applying it to OT environments requires pragmatism: here is what actually works and where the model shows its limits.

4 min read
Zero Trust architectural diagram applied to an industrial OT network

The Perimeter Is Dead: What This Means for Industrial Networks

For decades, OT security was based on a simple assumption: the industrial network is physically separated from the outside world, therefore it is secure. The air gap, the physical perimeter, isolation from the IT network — these were the primary defenses.

That assumption is obsolete. IT/OT convergence, remote access, telecontrol systems, cloud connections for production data analysis: every modern industrial organization has breached its own perimeter in one way or another. And when the perimeter no longer exists, perimeter-based security stops working.

Zero Trust begins with this recognition: trust no user, device, or network flow by default, regardless of where it is located. Every access must be authenticated, authorized, and continuously validated. It is a philosophy designed precisely for the perimeter-free world we live in.

The Five Zero Trust Pillars Applied to OT

1. Verified Identity Every user and device must prove its identity before gaining access. In OT this translates to: strong authentication for operators and technicians, machine identity for devices communicating with each other, and no shared or default credentials ever left active.

2. Least Privilege Access A PLC that needs to send data to an MES system should not be able to communicate with anything else. An operator working on a specific line should not see the others. The principle: access to exactly the necessary resources, nothing more.

3. Micro-Segmentation Instead of dividing the network into two large zones (IT and OT), define very small perimeters around specific systems or functions. A breach in one segment does not automatically propagate to others. In OT this maps naturally onto IEC 62443's concept of zones and conduits.

4. Continuous Monitoring Zero Trust is not a configuration state reached once. It requires constant visibility over all traffic, anomaly detection, event correlation. In OT, where device behavior is highly predictable, deviations from baseline are high-value signals.

5. Assume Breach The fifth pillar is more mental than technical: design systems assuming that eventually something will be compromised, and build defenses to contain damage and detect the compromise as early as possible.

Real Limits: Legacy PLCs, Protocols Without Authentication

Applying Zero Trust to OT is more complex than applying it to IT. The reasons are both technical and practical.

Incompatible legacy devices: a PLC from the early 2000s cannot authenticate. It lacks the computational capacity, does not support modern protocols, and cannot be updated without risking operability. These devices exist in every industrial plant and will remain in service for years or decades.

Industrial protocols without native security: Modbus, DNP3, Profibus do not include authentication or encryption. This is not an implementation flaw — it is a design choice from the era in which they were developed. Enforcing Zero Trust on these protocols requires compensating architectures (gateways, proxies), not device configuration.

Latency and reliability above all: in OT, an extra millisecond of latency can be unacceptable. Security solutions that introduce latency or that can block legitimate traffic risk interrupting processes. Zero Trust in OT must be designed with operational constraints that simply do not exist in IT.

Decade-long update cycles: an IT system is updated every 3-5 years. A SCADA system controlling a critical plant can remain unchanged for 15-20 years. Maintenance windows are rare and architectural changes require extensive validation.

A Gradual Approach: Where to Start

Zero Trust in OT is not implemented in a single project — it is built over time with incremental steps.

Priority 1 — Visibility: you cannot apply Zero Trust to what you cannot see. The first step is always a complete asset inventory and a network traffic baseline. Without knowing who communicates with whom, you cannot decide what to authorize and what to block.

Priority 2 — Coarse segmentation: separating IT and OT with a DMZ is the next step. This is not yet Zero Trust, but it drastically reduces the attack surface and creates the foundation for more granular segmentation.

Priority 3 — Human access control: operators and technicians (including vendors) are the most controllable vector. Implementing MFA and just-in-time access for remote sessions is achievable today without touching legacy devices.

Priority 4 — Progressive micro-segmentation: starting from the most critical (or most recently installed) areas, introduce increasingly granular segmentation as visibility and understanding of traffic improves.

Zero Trust Is Not a Product — It Is a Strategy

The market responded to Zero Trust hype with a proliferation of products promising to "implement Zero Trust" in a few months. In OT, this promise should be taken with caution.

Zero Trust is a direction, not a destination. It is a set of principles that guide architectural, process, and technology decisions over time. In OT, where operational constraints and legacy systems impose real limits, the value lies in taking concrete steps in the right direction — not in pursuing an ideal model that does not fit the real environment.

The practical goal: every year, implicit trust in the industrial network should be a little less implicit than before.

The MON5 Angle

It is worth stating clearly: explicit trust is enforced by the Zero Trust strategy's enforcement mechanisms — the firewalls and micro-segmentation tools that decide what passes and what does not. MON5 is not one of these: it does not apply segmentation and does not block inline traffic. Its contribution lies upstream and downstream of enforcement, providing the visibility that makes enforcement possible and measurable.

"Priority 1: visibility" is also the starting point of the MON5 journey. The DISCOVER phase builds the asset inventory and traffic baseline with passive or hybrid discovery, without stopping production — exactly the data needed to decide, within a Zero Trust strategy, what to authorize. Progressive micro-segmentation is then supported by the ANALYZE phase, which maps zones and conduits according to IEC 62443.

Downstream, the continuous monitoring of the PROTECT phase verifies over time that real traffic flows match the intended ones and flags communications that violate the architecture. To measure how much implicit trust exists in your network today, start with an OT assessment.

Related articles

Secure remote access in OT environments: attack vectors and defensive controls

Cybersecurity

Secure remote access in OT environments: the most underestimated attack vector

Remote access to OT environments exploded after the pandemic, but security practices never caught up. Here is why it became the attackers' favorite entry vector.

4 min read
Abstract illustration: artificial intelligence and vulnerability discovery in OT systems

Cybersecurity

AI changed vulnerability discovery: but there is an OT gap you cannot ignore

New AI models discover vulnerabilities autonomously and at industrial scale. But the tools stay tuned for IT: the OT world risks falling behind just as attackers accelerate.

2 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna