Why OT cybersecurity must move from visibility to protection
I was recently talking with a customer about how big a cybersecurity zone should be. His comment stayed with me: the size of a cyber zone should match the size of the safety zone. He explained using the big red button. When something goes wrong on a production line and someone hits the emergency stop, what actually stops? One machine, one line, or only the part of the process that must stop safely?
Safety and cybersecurity solve different problems, but what made the comment useful was the thinking behind it. A safety boundary reflects operational consequence. It asks what must respond together, what can continue safely, and how far the effect of an incident should be allowed to spread. That’s a useful way to think about OT cybersecurity.
If one asset is compromised, what else becomes exposed? What can be isolated without creating a bigger operational problem? What must keep running? And most importantly, have we designed the network to contain the issue? That conversation about zone size quickly grew into a much bigger one about risk, resilience, and what we should expect from the industrial network.
What safety teaches us about cyber risk
The safety comparison starts with the outcome. We look at the process and ask where someone could be harmed, what might cause it and only then work back to the safeguards needed to reduce the risk.
Most of those safeguards will spend their entire lives doing very little, but they’re there, tested and ready. If a hand crosses a light curtain, hazardous motion stops. If someone presses an emergency stop, the relevant part of the process moves to a safe state. Nobody is improvising when something goes wrong – the response is already built in.
In cybersecurity, we can be too quick to focus on the vulnerability alone. The vulnerability matters, but it isn’t the whole risk. Real risk depends on where that weakness sits, who can reach it, what the affected system can communicate with, and what could happen to the operation if it were compromised. A vulnerable asset with limited reach is a different problem from one that can communicate freely across the plant.
So, the better question is not, “What is vulnerable?” It is, “If this is compromised, what can happen next?”
The time between weakness and exploitation is disappearing
That question is getting more urgent because the threat is moving faster than industrial organizations can respond.
Anthropic’s Mythos shows where frontier models are heading. These models are becoming capable of finding complex weaknesses, turning them into the building blocks of a working attack, and assembling those pieces into complete attack chains. For OT environments with internet-connected legacy systems, such acceleration means the window between a discoverable vulnerability and automated attacks is now measured in hours, not weeks.
Just recently, OpenAI was running an internal cyber-capability benchmark and the agent found a way out of the evaluation sandbox via a zero-day, reached the open Internet, and then compromised parts of Hugging Face infrastructure. Just to do well on a test. The gap between finding a weakness and weaponizing it is collapsing, and with AI making autonomous decisions, it’s the type of incident that should make us all pause.
Poor network hygiene only amplifies this issue for critical infrastructure. Cyber intrusions involving water and wastewater systems have been identified in at least 12 states. Confirmed activity involved internet-facing PLCs, allowing attackers to change passwords, disrupt monitoring and, in some cases, control.
AI will make campaigns like this quicker to develop, cheaper to run, and easier to repeat at scale. We still need strong perimeter defenses, but we can no longer treat them as a guarantee. We must ask the question – is your architecture ready for the day the first line fails?
A strong network changes what happens next
A strong network isn’t one that never has a vulnerable device or a compromised account. It’s one that doesn’t turn either into unrestricted reach. A perimeter failure shouldn’t become a plant-wide compromise. A stolen remote-access credential shouldn’t let someone explore the entire industrial environment. One vulnerable workstation shouldn’t inherit access to every production line because that was the easiest way to build the network years ago. But that is exactly what happens in a flat or overly permissive architecture.
We’ve become too reliant on trying to add security products around weak networks. A new risk appears, so we add another appliance, dashboard, or detection engine. Many of those tools are useful, but they cannot remove communication paths that were never properly designed or governed. A monitoring tool may tell us that someone is moving laterally. A strong network can prevent that movement in the first place. That is the difference between seeing the cracks and strengthening the structure.
If I had to choose the most important foundation for protecting an industrial environment, it would be a strong, intentionally designed network: one where assets are grouped by operational purpose, communication is limited to what the process actually requires, remote access is specific rather than broad, and a compromise in one area doesn’t automatically spread into another. This is what defense in depth means. We still protect the perimeter, patch, monitor, and detect. But when one layer fails, the architecture behind it changes the outcome.
Where Cisco Cyber Vision moves from visibility to protection
This is why the evolution of Cisco Cyber Vision matters. It has always started in the right place: understanding what really happens inside the OT environment. It identifies connected assets, recognizes industrial communications, maps dependencies, and surfaces vulnerabilities and behaviors that shape their risk. That gives us the evidence to assess risk properly – not just that an asset is vulnerable, but what it talks to, which protocols it uses, and what role it plays.
But visibility is only half of the job. Knowing that an engineering workstation can communicate with four production cells doesn’t reduce the risk. Knowing that a remote user has more access than they need doesn’t limit that access. At some point, what we have learned has to shape what the network allows. Cyber Vision’s new segmentation capabilities are designed to close that gap.
Its first role is helping create the zones. Using the assets and communication patterns it observes, Cyber Vision recommends process-aligned zones – its view of where the cyber equivalent of the big red button boundary might sit. Teams can start with how the process operates, not an IP plan or an old spreadsheet.
Once the zones are set, the next step is to define the policy between them. Cyber Vision turns observed communications into rule recommendations: what should be allowed, in which direction, over which ports and protocols. It can propose new rules where none exist and recommend changes where the current policy no longer matches the process. This is where visibility becomes protection. What Cyber Vision sees is translated into an explicit statement of what the network should permit.
Simulation then becomes critical. Cyber Vision tests that ruleset against live traffic and shows what would be allowed, what would be denied, and which assets and protocols sit behind each result. Because it never stops observing, this isn’t a one-off check. As the process changes, teams can keep testing whether the rules still match reality – without using production as the test environment. In OT, that matters. Nobody wants to discover a missing dependency by stopping a line.
When the team is comfortable, approved policy can move into supported industrial switches, where its behavior can be monitored before enforcement. At that point, the network becomes more than transport: modern industrial switches become security appliances for the lower layers of the plant, enforcing policy at line rate and close to the assets without compromising latency-sensitive operations. For brownfield sites, this does not require a rip-and-replace strategy. Secure switches can be deployed first at aggregation layers, protecting key zones today, then pushed deeper into the architecture as future modernization allows. The workflow becomes a continuous loop: observe, recommend, simulate, apply, and keep watching.
The network that connects also protects
The real significance of this evolution is where all those capabilities live – built into the same switch already doing the networking. The infrastructure creating the path also enforces the boundary. That is security built into the network, not another layer trying to compensate for it from the outside.
That matters because we won’t prevent every vulnerability from being exploited or every credential from being compromised. We should not assume the perimeter will always hold. What we can control is the architecture an attacker finds on the other side and how far they can travel once they are there.
Cyber Vision’s evolution from visibility to protection makes that practical. It uses what the network knows about the process to help teams decide what should communicate, turns observation into policy, and keeps checking that the policy still reflects reality. A strong network does more than connect the operation; it limits the impact when one defense fails.
The network is where the exposure begins. It should also be where protection begins.
The post The Network That Connects Must Also Protect appeared first on Industrial Cyber.

