r/OTSecurity

Best tools for PCAP analysis in OT environments?

Cybersec engineer here!

I've been digging more into extracting network traffic data (mostly from ICS) lately, and would like to get to know some good tools for this job, specially regarding data visualization.

Tshark does get the hardest part of the job (artifacts extraction, passive asset discovery, etc) done well, but I still would like to test some tools that really focus on the "analyzing" part.

Any suggestions?

reddit.com
u/rachzera — 2 days ago

Seeking recommendations for a reliable OT cybersecurity solution

Title:
Seeking recommendations for a reliable OT cybersecurity solution

Post:
I work as an Infrastructure Engineer for one of New Zealand’s larger manufacturing companies and am currently researching OT cybersecurity solutions.

I am looking for a genuine, reliable, and proven product suitable for a manufacturing environment. I would appreciate honest recommendations from people with real-world experience deploying or managing OT security tools.

Key areas I am interested in include reliability, ease of management, hardware stability, support quality, network visibility, and avoiding unnecessary blocking of legitimate software or URLs.

Which products have worked well in your environment, and which ones should be avoided?

reddit.com
u/Past-Witness-6847 — 3 days ago
▲ 1 r/OTSecurity+3 crossposts

What do you think about this latest news?

Assume Breach: If PLC Logic Can Be Manipulated, How Do We Prevent Physical Consequences?

In April 2026, the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command issued a joint advisory warning that internet-connected operational technology (OT) devices, including Rockwell Automation/Allen-Bradley PLCs, were being actively exploited across multiple critical infrastructure sectors. The advisory was later updated to include Schneider Electric and Siemens PLCs, along with guidance for detecting malicious or unauthorized PLC project code.

Cybersecurity remains the first line of defense. Strong identity management, network segmentation, monitoring, and secure engineering practices are essential.

But what if we assume breach?
If an attacker can modify PLC logic or engineering project files, what additional engineering safeguards can prevent unsafe physical consequences?

Some examples:

  1. Independent physics-based validation of process commands.
  2. Process-aware controls that reject commands outside safe operating limits.
  3. Independent safety mechanisms that remain effective even if a PLC is compromised.
  4. Resilient architectures that maintain safe operations during cyber incidents.
  5. Digital twins or process models that continuously validate expected system behavior.

The objective isn’t just to recover after an attack—it’s to prevent a cyber incident from becoming a physical incident.

This is the problem space I believe Cyber Physical Resilience Engineering (r/CPRE) should address by integrating cybersecurity, control engineering, process safety, and operational resilience.

What additional engineering approaches do you think are needed to keep critical infrastructure operating safely when cyber defenses are bypassed?

Joint Cybersecurity Advisory (Official):
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure (AA26-097A)⁠ https://www.ic3.gov/CSA/2026/260407.pdf

reddit.com
u/kukap_ — 4 days ago
▲ 2 r/OTSecurity+2 crossposts

I need help

I’m really interested in OT cybersecurity and would like some resources to learn more about it

reddit.com
u/Meg_uu7 — 6 days ago
▲ 0 r/OTSecurity+5 crossposts

Why I Believe Cyber Physical Resilience Engineering (CPRE) Is the Next Frontier

Cybersecurity has matured significantly over the last three decades. Identity, Zero Trust, EDR, SIEM, threat intelligence, AI, and incident response have all made organizations more secure.

But critical infrastructure presents a different challenge.

If a corporate network is compromised, the impact is often measured in data, money, or downtime.
If a water treatment plant, power grid, or industrial control system is compromised, the consequences can become physical.

That led me to a simple question:
What if we designed critical infrastructure assuming cyber incidents will happen?

Instead of asking only “How do we stop attackers?”, we should also ask:
How do we keep water safe?
How do we keep electricity flowing?
How do we prevent unsafe physical states?
How do we recover while maintaining safe operations?

That is the motivation behind Cyber Physical Resilience Engineering (CPRE).

Cybersecurity remains essential. CPRE builds on that foundation by integrating engineering, operations, process safety, and resilience into the design and operation of critical infrastructure.

I’d love to hear your thoughts. What capabilities do you think are missing today?

reddit.com
u/kukap_ — 6 days ago
▲ 0 r/OTSecurity+2 crossposts

Is cybersecurity enough for critical infrastructure?

I've worked in cybersecurity for about 25 years. Over the last year, I've spent much more time with water utilities, power systems, and industrial control environments.

One thing keeps bothering me.

When something goes wrong in critical infrastructure, the real failure usually isn't the network, the firewall, or even the PLC.

It's things like:

  • Unsafe chemical dosing at a water treatment plant
  • Power instability or blackouts
  • Pumps or valves operating incorrectly leading to say water overflow
  • Operators no longer trusting the data they're seeing
  • Essential public services becoming unavailable

In other words, the real problem isn't that a computer was compromised.

The real problem is that a physical (e.g., electric, water, hospital etc.,) mission failed.

That made me wonder whether we're trying to solve an engineering problem using only cybersecurity thinking.

Over the past few months, I've been exploring a concept I'm calling Cyber-Physical Resilience Engineering (CPRE).

The basic idea is simple.

Instead of asking:

>

Start by asking:

>

Cybersecurity is still essential, but it becomes one part of a broader engineering discipline that also includes:

  • Operational Technology (OT/ICS)
  • Systems Engineering
  • Control Systems Engineering
  • Process Safety
  • Reliability Engineering
  • Resilience Engineering
  • Digital Twins
  • AI-assisted Operations

The goal isn't just preventing cyberattacks.

The goal is ensuring that drinking water remains safe, electricity stays on, transportation keeps moving, hospitals continue operating, and other critical services remain available, even under cyber, physical, or operational stress.

I'm not suggesting this replaces frameworks like NIST CSF, NIST SP 800-82, or IEC 62443. Those remain foundational.

I'm simply asking whether we've reached a point where protecting physical outcomes deserves its own engineering discipline.

I'm genuinely looking for feedback, not trying to promote a framework.

For those who work in or around critical infrastructure:

  • Does this describe a real gap you've experienced?
  • During incidents, did the hardest problems end up being cybersecurity, or engineering and operations?
  • If a discipline like Cyber-Physical Resilience Engineering existed, what capabilities would you expect it to add that don't exist today?

Some incidents that shaped my thinking:

• Oldsmar, Florida Water Treatment Facility (2021)
https://www.bbc.com/news/world-us-canada-55989843

• Colonial Pipeline Ransomware (2021)
https://www.cisa.gov/news-events/alerts/aa21-131a

• Muleshoe, Texas Water System Attack (2024)
https://www.govtech.com/security/overflowing-water-tank-linked-to-russian-cyber-attack

• CISA, EPA & FBI – Top Cyber Actions for Securing Water Systems
https://www.cisa.gov/news-events/alerts/2024/02/21/cisa-epa-and-fbi-release-top-cyber-actions-securing-water-systems

• Ukraine Power Grid Attack (2015)
https://www.cisa.gov/news-events/ics-alerts/IR-ALERT-H-16-056-01

I'd appreciate your thoughts, especially from people working in water, energy, manufacturing, transportation, healthcare, utilities, industrial automation, or engineering.

--------------------
If this resonates and you’d like to go deeper, we’re building r/CPRE as a focused community around Cyber‑Physical Resilience Engineering, bringing together cybersecurity folks, engineers, operators, researchers, students, and critical infrastructure leaders.

u/kukap_ — 9 days ago

Resume review

I have a year of experience in OT security please check out my resume and give me advice on which areas I can focus on in the future or just the resume itself, I have hidden certain personal details please don't mind.

Thank youu !

u/Present-Housing4010 — 10 days ago

Shall we change OT FW password every 90 days ?

Hi guys, I have four process plants with around 40 firewalls deployed across different process areas. Most of them are managed locally, which means we have to physically access the Engineering Workstation (EWS) or go down to the site to perform any administration. There is no remote management capability.

Our Group Security now requires us to change all firewall passwords every 90 days and enforce a password history of the last three passwords.

The challenge is that I’m the only OT Cybersecurity Engineer supporting all four plants, while our E&I engineers are already fully occupied with daily operations. Requiring on-site password changes every 90 days for around 40 firewalls will create a significant operational burden and consume resources that could be better spent on higher-risk cybersecurity activities.

What are your thoughts? Do you think there are valid reasons to request an exception or an alternative control? In an OT environment, would it be more practical to retain strong, unique passwords, implement strict access control and logging, and only require password changes when there is evidence of compromise or personnel changes, rather than enforcing a fixed 90-day rotation?

reddit.com
u/zm-joo — 11 days ago

Need Career Advice

Hey so I've just finished my second year in electrical engineering and i want to work in OT security, and i'm confused because i've been learning cybersecurity, particularly the SOC analyst path. And i don't know if i should continue it though because although i will be familiar with ICS in the coming years but don't know if this IT SOC analyst path will help me in that field. What should I do in these remaining 2 years?

reddit.com
u/Quirky_City5777 — 9 days ago

OT cybersec role

Hey! Right now I work as a controls commisioning engineer, purely with siemens, I did some networking work on the past, but for now I do purely coding and commisioning stuff.

I am very young and I would like to work in the Cybersecurity field, especifically in the OT section.

How can I pivot into this position? What job roles should I look forward too and what skills should I learn?
Thanks!

reddit.com
u/Fragrant-Monitor5437 — 10 days ago
▲ 2 r/OTSecurity+1 crossposts

OT Pen Testers: what's your actual criteria for moving from passive recon to active testing on a live asset?

This is a scoping decision we hit on basically every OT engagement, and I don't think there's a clean industry-standard answer, so genuinely curious how others draw the line.

The core tension: unlike IT, even routine scanning carries real risk on OT gear.

  • Many PLCs run on embedded CPUs with very limited headroom - a scan that's unremarkable on a Windows server can overload one.
  • Most industrial protocols (Modbus, DNP3, etc.) have no built-in authentication, so once you're on the network there's often nothing stopping you writing directly to a controller.
  • A lot of the hardware is end-of-life and permanently unpatched, so patch level isn't a reliable signal either.

Given that, we always start with passive reconnaissance only, mapping the environment without generating any traffic that could disturb operation, before any active testing happens. Even then, we try to stick to non-production systems or agreed maintenance windows wherever possible.

What I'm actually asking: what's your practical criteria for deciding it's safe to move from passive to active on a specific live asset? Ops team sign-off, documented maintenance windows, device-specific research beforehand or something else? And has anyone had a client push back and insist on IT-speed active scanning against OT assets - how did that conversation go?

reddit.com
u/CyberLab_Security — 12 days ago

Student research question: medical device cybersecurity vs clinical continuity

Hi everyone. I’m a student working on a healthcare cybersecurity research prototype, and I’m trying to understand the real-world workflow before I make wrong assumptions.

This is not a product pitch, and I’m not asking for patient data, internal documents, network details, hospital names, or anything sensitive.

The problem I’m exploring is:

When hospitals have network-connected medical devices, cybersecurity decisions can’t always be “just block the traffic,” because the wrong action could interrupt clinical workflow or device visibility.

I’m trying to understand how this is handled in real hospitals.

Questions:

  1. Who usually owns the inventory of network-connected medical devices?- IT?- biomedical engineering?- clinical engineering?- security team?- vendors?- nobody clearly?
  2. If a device or device network has a cybersecurity issue, who gets involved first?
  3. Are medical devices usually visible to the hospital SOC/security team, or mostly managed separately?
  4. Does your organization track whether a security action could affect clinical workflow?
  5. If a tool only ran in shadow mode and produced a risk/evidence report without blocking anything, would that be useful or just noise?
  6. What would make a student-built tool in this space sound instantly unserious or unsafe?
  7. Are there audit/accreditation/compliance processes where device inventory, incident logs, or continuity evidence matter?
  8. What terminology would real hospital teams use for this problem? “Cyber-continuity” sounds clear to me, but I’m not sure if it sounds natural in hospital language.

Again, I’m not looking for confidential information. I’m trying to learn the ownership/workflow reality so I don’t build a fantasy system.

If you work in hospital IT, biomedical engineering, clinical engineering, or healthcare cybersecurity and are open to a few follow-up questions, I’d appreciate a DM. No product pitch, no data request.

reddit.com
u/Saiprasanth-22 — 14 days ago