Why can you often not simply install the usual security measures on OT systems?
Three constraints: the hardware has no headroom for the extra load, the plant is bound by production regulations and operational safety, and any measure must be free of reaction back onto the controlled process.
Operational technology is cyber systems that control production systems. In its early days signals ran over dedicated lines; today network connections are used — which is where the security problem came from, since the isolation that once carried the whole security model has been opened up by business demands for interconnectivity. Technologically it sits in the era of early perimeter security, or before it.
The three obstacles in detail:
- Insufficient hardware performance. Controllers are sized for their control task and often for a decade of service life. There is no spare capacity for an endpoint agent, an encryption layer or a scanning process — and adding one can miss the real-time deadlines the process depends on.
- Compliance with regulations in production environments — plant approvals, certifications, safety cases and vendor warranties. A patch or an added agent can invalidate a certification, so "just update it" is a regulatory act, not a maintenance task.
- Operational safety and Rückwirkungsfreiheit — freedom from reaction back onto the process. Any measure must be provably unable to disturb what the system is controlling. A scan that pauses a server is a nuisance in an office; the same pause on a filling line spoils a batch, and on a safety function it endangers people.
Which is also why the architectural answer for OT is rarely "install more on the device". It is to put the controls around it — segmentation, zones, gateways and jump hosts — and to accept that the device itself will not change soon.
Go deeper:
Wikipedia — IEC 62443 — the OT security standard family, built around zones and conduits rather than agents on devices.
NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security — how to secure OT while keeping performance, reliability and safety intact.