Key Takeaways

  • Fortinet: Evaluate how integrated OT asset visibility, network segmentation, identity enforcement, and security operations can be compared across vendors such as Dragos, Nozomi Networks, and Claroty.
  • Map programmable logic controllers, human-machine interfaces, engineering workstations, and SCADA servers before applying controls from NIST SP 800-82 Rev. 3.
  • Test multifactor-protected jump hosts, segmented Active Directory, and firewall rules that isolate essential OT systems while preserving emergency operations.
  • Track concrete indicators such as unknown assets discovered, blocked cross-zone connections, performance against a 15-minute alert-triage target, and successful recovery from configuration backups.

Fortinet addresses operational technology (OT) security challenges by combining asset visibility, segmentation, identity controls, and incident workflows. These controls limit compromises that disrupt badge access, hospital environmental systems, or water-treatment telemetry.

Many government agencies still manage operational systems using network diagrams assembled from spreadsheets, switch configurations, and institutional memory. That fragmented record leaves teams uncertain about which devices, communication paths, and physical processes an incident might affect.

The buying decision requires more than choosing an anomaly-detection product. Public-sector teams need to determine how secure networking, device controls, identity enforcement, and security operations will work together without disrupting physical processes.

How Public Agencies Should Define the OT Security Problem

Operational technology includes programmable logic controllers, remote terminal units, human-machine interfaces, historians, engineering workstations, and supervisory control and data acquisition systems. A public agency may also manage elevators, generators, cameras, HVAC controllers, and physical-access systems using BACnet, Modbus TCP, DNP3, or vendor-specific protocols.

Those assets frequently have different operating constraints from Windows and Linux servers. As NIST SP 800-82 Rev. 3 explains, OT components can have substantially longer lifecycles than conventional IT equipment; a controller may remain in service for 15 years, lack an endpoint agent, and communicate through a fixed Modbus register pattern. Rebooting it to complete an update may require a maintenance window coordinated with plant operators.

In CISA's OT mitigation guidance, reviewed in July 2026, the agency advises critical-infrastructure operators to prepare for manual operations and the isolation of OT systems during cyber incidents. For buyers, that guidance translates into practical questions: Can a firewall block traffic between an engineering workstation and a controller while retaining the SCADA path? Is there an offline control procedure? Can operators identify every device affected by an isolation decision?

Asset discovery is a sensible starting point. Passive monitoring through a network TAP or switched port analyzer avoids sending active probes that could unsettle older controllers. The resulting inventory should capture IP and MAC addresses, firmware versions, protocols, communication peers, physical locations, and operational owners.

How to Evaluate an Integrated OT Security Architecture

A buyer evaluating Fortinet's operational technology security capabilities should examine how its secure networking, user and device security, and security operations functions behave as one architecture. The relevant test is whether device identity and observed traffic can drive an enforceable firewall policy and provide enough context for an analyst to respond.

For secure networking, evaluators can build zones for enterprise IT, an industrial demilitarized zone, supervisory systems, controllers, safety systems, and vendor access. Firewall policy should allow documented flows, such as HTTPS from an operator workstation to an application server or Modbus TCP from a designated HMI to a specific controller. Broad rules permitting any source, destination, and service undermine the value of segmentation.

NIST SP 800-82 Rev. 3 identifies network segmentation and least-privilege access as central OT security practices. Its guidance also recognizes the need to balance cybersecurity with safety, reliability, and mission objectives. That balance matters when comparing the platform's policy enforcement with alternatives from Dragos, Nozomi Networks, and Claroty, particularly where existing switches, firewalls, and security information and event management systems constrain the design.

For user and device security, buyers should test multifactor authentication on remote-access gateways and jump hosts. Separate OT accounts and segmented Active Directory services can reduce dependence on enterprise credentials. Privileged sessions should also produce logs showing the user, source device, destination asset, command channel, and session duration.

How to Plan an OT Security Rollout

During discovery, the implementation team typically includes OT engineers, network architects, identity administrators, security operations analysts, safety personnel, procurement staff, and system owners. Their first deliverable should be an asset and data-flow baseline, not a stack of blocking rules.

The pilot phase can focus on one bounded environment, such as a municipal pumping station or government building-automation network. Passive sensors observe BACnet, DNP3, or Modbus TCP traffic, while firewall logs feed a SIEM through syslog or an API. Analysts then compare discovered connections with approved engineering diagrams.

During controlled enforcement, the team can convert validated flows into allow-list policies. Changes should pass through the agency's configuration-management process, with backups of PLC logic, firewall configurations, and HMI projects stored offline. A maintenance window provides room to test failover, but operators should retain a rollback procedure if latency or protocol inspection affects the process.

Secure remote access deserves its own exercise. Through its Securing Water and Wastewater Utilities project, NIST's National Cybersecurity Center of Excellence has developed example approaches for reducing cyber risk in water and wastewater environments, including controls relevant to remote connectivity. A buyer can adapt that model by routing contractors through an MFA-protected jump host, limiting access to named assets, recording sessions, and disabling accounts automatically when an approved service period ends.

Which OT Security Outcomes Should Agencies Measure?

Product demonstrations often highlight alert volume. Agencies gain more from measuring whether alerts support operational decisions.

Useful measures include the number of previously unknown OT assets identified, the share of connections assigned to approved data flows, and the number of privileged sessions passing through the designated jump host. A security operations team can also conduct an exercise with a 15-minute triage target for a controller communication anomaly and determine whether analysts can identify the affected network zone within that period.

Isolation drills provide a more demanding measure. The team can simulate loss of the enterprise connection, activate an alternative SCADA path, and verify that operators retain visibility of pressure, temperature, or power-state data. Recovery testing should confirm that offline controller configurations and network-device backups can be restored in a lab before an incident occurs.

Because specific performance metrics vary significantly across public-sector deployments, buyers should request evidence from a pilot using their own protocols, latency tolerances, staffing model, and incident workflow rather than relying on generalized efficiency claims.

OT Security Lessons for Public-Sector Buyers

Passive discovery should precede active enforcement because an incomplete inventory can turn a technically valid firewall rule into a service interruption. The pilot also needs representative legacy equipment; testing only current-generation controllers gives buyers little information about the assets most likely to resist scanning or deep protocol inspection.

Identity testing should include expired contractor accounts, shared maintenance credentials, and loss of the MFA service. Those scenarios reveal whether emergency access procedures preserve accountability or quietly restore implicit trust.

Finally, the isolation exercise should involve operators, not just cybersecurity staff. A firewall can block the intended connection while the operational response still fails because no one knows which local HMI or manual procedure replaces the unavailable supervisory path.

Where the OT Security Model Also Applies

Healthcare facilities, financial data centers, and retail distribution sites can adapt the same model for HVAC, generators, refrigeration, and physical access. The zone design and protocols will differ, but asset discovery, controlled remote access, logged policy enforcement, and tested recovery remain applicable.

Frequently Asked Questions About OT Security

How long does an OT security implementation take?

Timing depends on asset count, maintenance windows, procurement rules, and the quality of existing diagrams. Buyers should expect separate discovery, pilot, controlled-enforcement, and expansion phases to extend over several months, with firewall changes aligned to approved operational maintenance periods.

What should an OT security proof of concept test?

A proof of concept should identify unmanaged assets, decode at least one operational protocol such as BACnet or Modbus TCP, and send contextual alerts to the agency's SIEM. It should also demonstrate an MFA-protected contractor session and isolate one test zone without interrupting the approved HMI-to-controller flow.

Is zero trust practical for legacy OT systems?

It can be, provided identity and policy controls are placed around devices that cannot support modern agents. Segmented network zones, named jump-host accounts, destination-specific firewall rules, and session logging can reduce implicit trust while leaving the controller firmware unchanged.