Back to Field Notes
Alexa Research/Field Note

Alexa Research — OT and Utility Sector Field Notes

Across 23 OT engagements in 2025, the patterns are remarkably consistent — and the gaps are too.

Author

Hiroshi Tanaka

OT Security Lead

Published

March 24, 2026

Read

10 min

Share
AI-generated illustration of a power plant facility
AI-generated illustration of a power plant facility
Key Takeaways
  • 01Across 23 OT and utility engagements in 2025, patterns are remarkably consistent. The maturity gap between IT and OT cybersecurity is closing slowly; the engineering challenges of OT environments are not.
  • 02What we consistently find: asset inventories 60-80% accurate at best, engineering workstations with internet access and no segmentation from control networks, remote vendor access via shared credentials and weak MFA, patch management with no risk-based cadence (everything waits for the annual outage), backups that exist but have not been restored in years.
  • 03What works: passive asset discovery via tap or span ports rather than active scans, vendor remote access through a single hardened jump host with session recording, backup restoration drills as part of every annual outage. Baseline catching up to threat reality, not exotic.
  • 04Where regulation helps: TSA pipeline directives, NERC CIP refinements, EU NIS2 transposition for critical infrastructure. Use the regulatory push to fund the program — and run the program for the operational benefit, not just the audit posture.

Across 23 OT and utility engagements in 2025, the patterns are remarkably consistent. The maturity gap between IT and OT cybersecurity is closing slowly; the engineering challenges of OT environments are not.

What we consistently find

  • 01Asset inventories that are 60-80% accurate at best
  • 02Engineering workstations with internet access and no segmentation from the control network
  • 03Remote vendor access via shared credentials and weak MFA
  • 04Patch management with no risk-based cadence; everything waits for the annual outage
  • 05Backups that exist but have not been restored in years

What works in this environment

Passive asset discovery using tap or span ports rather than active scans. Vendor remote access through a single hardened jump host with session recording. Backup restoration drills as part of every annual outage. None of these are exotic — they are the baseline catching up to the threat reality.

Where regulatory motion helps

TSA pipeline directives, NERC CIP refinements, EU NIS2 transposition for critical infrastructure operators. The push from regulators is moving boards to fund OT cybersecurity work that was historically deferred. Use the regulatory push to fund the program — and run the program for the operational benefit, not just the audit posture.

#Alexa Research#OT#Utilities

/WRITTEN_BY

Hiroshi Tanaka

OT Security Lead · Alexa Cybersecurity