Skip to content
FortaRisks
Back to the glossaryAttacks and incidents

OT / ICS (operational technology and industrial control systems)

OT (operational technology) refers to the equipment that runs physical processes: controllers, sensors, operator interfaces. ICS (industrial control systems) are its core. Designed for closed networks, they become a target as soon as they can be reached from the Internet.

Updated on October 4, 2026

What are OT and ICS?

Operational technology (OT) covers the equipment that commands and monitors physical processes: programmable controllers, operator interfaces, sensors, gateways. Industrial control systems (ICS) are the part that runs production, energy, water or buildings.

Why it matters for your organization

This equipment was designed for closed networks. Remote maintenance and the convergence of IT and plants open access paths nobody decided on: a maintenance access left open, a controller plugged straight into the Internet, a forgotten gateway.

The protocols involved

Each family of equipment speaks its own protocol: Siemens S7, Modbus TCP, EtherNet/IP, DNP3, OPC UA, IEC 60870-5-104, among others. The IEC 62443 standard frames the security of these systems, from the asset owner down to the components.

To know what can be reached from the Internet in your plants, and how to check it without touching production, see the Factory security page.

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities.

Frequently asked questions

What is the difference between IT and OT?

IT handles information; OT acts on the physical world. An IT outage interrupts a service, an OT outage can stop a production line or trip a safety system.

Why is an exposed controller so serious?

Because several industrial protocols require no authentication: whoever reaches the port can read, and sometimes change, what the machine does.