An IT firewall rule can be patched at 2am with no one on site. A control system patch on a running turbine can't — it waits for an outage window, and until then the vulnerability just sits there. Power plant cybersecurity is built around that gap, and NIST CSF, IEC 62443, and the UK NIS Regulations each give a different piece of the answer for how to manage it. Sign up to keep your OT asset inventory, segmentation records, and patch status tracked against every controller and RTU in one CMMS.
Why It Matters
Operational technology wasn't built with cybersecurity in mind — much of it predates the concept entirely, and it can't simply be rebooted or patched on IT's schedule. A generating station's SCADA, DCS, and protection relays run a physical process where an unplanned interruption isn't an inconvenience, it's a safety and generation event. That's why OT security frameworks focus less on stopping every intrusion and more on knowing exactly what's connected, segmenting it so one compromised device can't reach the rest, and being able to prove that posture during an audit.
Three Frameworks, One OT Environment
A UK power station rarely picks just one framework — NIST CSF, IEC 62443, and the NIS Regulations tend to work together, each covering a different layer of the same problem.
NIST CSF
Organises the whole program around five functions — identify, protect, detect, respond, recover — as a management-level structure for the security effort.
IEC 62443
Gets specific to industrial control systems — zones, conduits, and security levels for segmenting a plant network device by device.
UK NIS Regulations
Sets the legal duty for operators of essential services, requiring appropriate security measures and incident reporting to the regulator.
NIST CSF tells a plant what categories of activity to organise around, IEC 62443 tells the engineering team how to actually segment the control network, and the NIS Regulations set the legal floor that both of those have to meet in practice.
The OT Security Layer Stack
| Layer |
What It Protects |
Typical Control |
| Asset Inventory |
Visibility into every device that could be a target |
Live register of controllers, RTUs, HMIs, and firmware versions |
| IT/OT Boundary |
Stops a corporate network breach from reaching control systems |
Demilitarised zone between business and process networks |
| Network Segmentation |
Contains a compromise to one zone instead of the whole plant |
IEC 62443 zones and conduits with restricted traffic between them |
| Access Control |
Limits who and what can reach a given control system |
Role-based permissions, logged remote access, vendor session controls |
Know Every Device On Your OT Network
Oxmaint keeps a live asset inventory tied to firmware versions, patch status, and segmentation zone for every controller and RTU on site, so audit evidence is a report, not a scramble. Sign up for a free trial to run it on your own network, or book a demo to see it configured for your plant.
Where OT Cybersecurity Programs Have Gaps
Incomplete Asset Inventory
Legacy controllers added decades ago never logged, so they're invisible to the security team
Flat Network Architecture
IT and OT systems sharing the same network with no meaningful segmentation between them
Patches Deferred Indefinitely
A known vulnerability waits for the next outage window and then gets deferred again
Vendor Remote Access Unlogged
Third-party maintenance connections into control systems with no session record kept
No Incident Reporting Process
No defined path to notify the regulator within the timeframe the NIS Regulations require
Security Evidence Scattered
Inventory, patch records, and access logs held across separate spreadsheets with no single source
Frequently Asked Questions
Q
Do NIST CSF, IEC 62443, and the UK NIS Regulations overlap or conflict?
They complement rather than conflict — NIST CSF structures the overall program, IEC 62443 provides the technical segmentation detail for control systems, and the NIS Regulations set the legal obligation that ties both back to regulatory accountability.
Q
Why is asset inventory the starting point for OT cybersecurity?
Every other control — segmentation, patching, access management — depends on knowing what's actually connected. A device missing from the inventory is a device nobody is protecting, regardless of how strong the rest of the program is.
Q
Why can't OT systems just be patched the way IT systems are?
A control system patch usually requires taking the associated equipment offline, which on a running turbine or boiler means waiting for a planned outage — so OT programs rely more heavily on segmentation and compensating controls to manage risk in the gap before that window arrives.
Walk Into Your Next NIS Audit With Evidence Ready
Oxmaint keeps OT asset inventory, segmentation zones, patch status, and access records tied to their evidence in one auditable log, so proving your security posture doesn't mean chasing spreadsheets. Sign up for a free trial to run it on your own sites, or book a demo to see it configured for your team.