Every industry that evolves quickly develops its own language. New technologies need new terminology, and new roles need new ways of being described. OT security has grown rapidly, pulling concepts from industrial engineering, IT, and cybersecurity and forging its own vocabulary in the process.
If you’re coming to it from the outside – an IT professional weighing a move, an HR manager hiring for a role you haven’t recruited for before, or someone trying to make sense of a job description full of acronyms – that vocabulary can feel like a wall.
It shouldn’t. Here are 22 of the most common terms in OT security, explained in a way that actually makes sense:
Operational Technology (OT)
The hardware and software that monitors or controls physical equipment and industrial processes. Think PLCs running a production line, SCADA systems managing a water network, or sensors tracking pressure in a gas pipeline. OT is the technology that makes the physical world run.
Information Technology (IT)
The systems most people are familiar with – servers, laptops, cloud platforms, databases. IT handles data. OT handles physical processes. The two are increasingly connected, which is why the boundary between them is one of the most contested areas in cybersecurity right now.
Industrial Control System (ICS)
An umbrella term for the systems used to control industrial processes. SCADA, DCS, and PLCs are all types of ICS. When a job description references “ICS security,” it means the security of these industrial control environments as a whole.
SCADA (Supervisory Control and Data Acquisition)
A system that remotely monitors and controls industrial equipment across wide geographic areas, pipelines, electricity networks, water distribution. SCADA collects real-time data from sensors and sends control commands back to field devices. It’s one of the most common targets in OT cyber-attacks.
PLC (Programmable Logic Controller)
A ruggedised industrial computer that controls machinery and processes, like opening valves, starting motors, managing conveyor belts. PLCs are everywhere in manufacturing and utilities. Many run outdated firmware that’s difficult or impossible to patch, making them a persistent security challenge.
DCS (Distributed Control System)
Similar to SCADA, but typically used in continuous industrial processes such as chemical plants or oil refineries. A DCS is more tightly integrated with a single facility, whereas SCADA tends to cover larger, more dispersed infrastructure.
HMI (Human-Machine Interface)
The screen or panel through which operators interact with OT systems. If you’ve seen a control room operator monitoring pipeline pressure or tank levels on a display, they’re using an HMI. Compromising an HMI gives an attacker a window into the process, and potentially control over it.
RTU (Remote Terminal Unit)
A device deployed in the field – at a remote substation or pump station – that collects data from sensors and relays it back to a central SCADA system. RTUs are often in physically remote locations with limited security, which makes them an attractive target.
Engineering Workstation (EWS)
A computer used by engineers to program and configure PLCs, DCS systems, and other OT devices. EWSs are high-value targets because an attacker who compromises one can push malicious configurations directly to industrial equipment.
Data Historian
A database that logs time-series data from industrial processes – pressure readings, temperatures, flow rates. Historians are used for reporting, compliance, and process optimisation. They’re also increasingly connected to IT networks, which creates a potential bridge between OT and IT environments.
OT/IT Convergence
The growing integration of operational technology and information technology systems. Convergence improves efficiency and visibility but introduces IT-style cyber risks into OT environments that were never designed to handle them. Most of the complexity in modern OT security stems from this trend.
Air Gap
A security measure where an OT network is physically isolated from IT networks and the internet, no connection at all. Air gaps were once standard in critical infrastructure. They’re increasingly rare as operators demand remote access and data connectivity, but the principle still shapes OT security architecture.
Network Segmentation
Dividing a network into separate zones to limit how far an attacker can move if they gain access. Rather than a flat network where everything can communicate with everything, segmentation creates boundaries; for example, separating a SCADA system from engineering workstations and from the corporate IT network.
The Purdue Model
A hierarchical framework for organising and segmenting OT networks. Developed in the 1990s, it divides industrial systems into levels, from field devices at the base up to the enterprise network at the top. It’s widely used as a reference architecture for OT security, though modern cloud-connected environments are pushing it to its limits.
IEC 62443
The international standard for industrial cyber security. It defines security requirements for OT systems and supply chains across sectors including energy, manufacturing, and water. IEC 62443 certification is increasingly sought by employers, particularly for architecture and consultancy roles.
GICSP (Global Industrial Cyber Security Professional)
A certification from GIAC – administered by SANS – that validates both OT operations knowledge and cyber security skills. It’s widely recognised by UK employers as a benchmark for OT security competence, particularly in hands-on technical roles. If you see GICSP on a job description, the employer wants someone who genuinely understands both sides.
Safety Instrumented System (SIS)
A system designed to bring a process to a safe state if it detects dangerous conditions; for example, automatically shutting down a reactor if pressure exceeds safe limits. SIS and OT security intersect critically: an attacker who compromises a SIS can prevent safety functions from triggering when they should.
Industrial Protocol
The communication language used by OT devices. Common examples include Modbus (one of the oldest, widely used in PLCs), DNP3 (used in utilities and water systems), and OPC-UA (a more modern protocol with better IT compatibility). Unlike most IT protocols, industrial protocols were often designed with no authentication or encryption built in.
Asset Inventory
A complete record of every device on an OT network – what it is, where it is, what firmware it runs, and what it communicates with. In IT, asset inventories are basic hygiene. In OT, they’re often incomplete or absent, partly because OT environments weren’t built to be network-managed. You can’t secure what you can’t see.
Patch Management (OT context)
Applying software updates and security patches to OT systems. In IT, patching is routine. In OT, it’s complicated: systems often can’t be taken offline, vendors may not release patches for legacy equipment, and an untested patch can cause operational failures. Managing this tension is a significant part of an OT security professional’s role.
Critical National Infrastructure (CNI)
Sectors and systems whose disruption would have severe consequences for national security, the economy, or public safety. In the UK, this includes energy, water, transport, communications, and defence. OT security professionals working in CNI often require security clearance and are subject to specific regulatory obligations.
Zero Trust (in OT)
A security model based on the principle that no device or user should be automatically trusted, regardless of where they are on the network. In IT, Zero Trust has been widely adopted. In OT, it’s more complex to implement because many legacy systems weren’t designed to verify every connection, but the concept is increasingly influential in OT network design.
Ready to talk?
Understanding the language is one thing. Finding professionals who can apply it in a live industrial environment is another. We find OT security candidates need to bridge two worlds – the engineering culture of operational technology and the risk culture of cybersecurity.
At Paradigm Tech, OT security is all we do. We understand the language, but we also understand how that language applies to real-world scenarios.
Get in touch: charlie@paradigmtech.co
About the author
Charlie Hackett founded Paradigm Tech with his long-time friend and partner. His experience in IT and cyber security recruitment forged a unique appreciation for the technical specificity found OT security. It’s not just IT security with a fancier name. Getting it right requires specific certifications and deep knowledge of the physical assets OT systems manage. At Paradigm Tech, they only focus on OT recruitment. That’s how they move quickly to deliver exceptional and qualified candidates. Connect with Charlie on LinkedIn.