Few attackers begin inside an OT network. They begin in IT, through phishing, a vulnerable service or stolen credentials, and then move toward operations. The journey from an enterprise foothold to an operational system is lateral movement across the IT/OT boundary.

Understanding the specific pivots attackers use is what turns boundary security from a vague aspiration into a concrete task: find the paths that cross the boundary and remove the ones that should not be there.

01Key takeaways

  1. 01

    Most OT incidents originate in IT and reach operations through lateral movement, not a direct attack on the plant.

  2. 02

    Common pivots include jump hosts, dual-homed machines, shared credentials and flat networks that span the boundary.

  3. 03

    Detection helps but cannot be the only defense, because a path that exists can be used faster than it is investigated.

  4. 04

    Removing the path is stronger than watching it: a boundary an attacker cannot cross needs no alert.

  5. 05

    Reducing reachability across the IT/OT boundary directly shrinks the opportunity for lateral movement.

02What lateral movement is

Lateral movement is how an attacker progresses from an initial foothold to their actual target. Having compromised one system, they use the access and connectivity available to reach the next, repeating until they arrive somewhere that matters.

In an industrial context, the target is often an operational system, and the foothold is almost always somewhere in IT. The boundary between the two is therefore the decisive terrain.

The plant is rarely the entry point. It is the destination, reached by moving across the boundary from IT.

03The IT-to-OT path in real incidents

Documented industrial incidents repeatedly follow the same arc: compromise an enterprise system, establish persistence, find a route toward operations, and cross it. The crossing is the moment a contained IT incident becomes an operational one.

Threat knowledge bases such as MITRE ATT&CK for ICS describe these techniques, and the recurring lesson is that the boundary is crossed through paths that already existed for legitimate reasons, not through novel exploits.

04The pivots attackers use

Jump hosts
Intermediary systems meant to broker access become a single, valuable stepping stone if they are always reachable or weakly protected.
Dual-homed assets
Machines with a foot in both networks, such as engineering workstations, provide a direct bridge across the boundary.
Shared credentials
Accounts and directory services that span IT and OT let an attacker authenticate across the boundary with stolen secrets.
Flat networks
Where segmentation exists only on paper, an attacker can route directly from IT into OT with no boundary to cross at all.

05Why detection alone is insufficient

Monitoring for lateral movement is valuable and worth doing. But detection is a race: it assumes you can notice, investigate and respond faster than the attacker can move. Across a boundary that an attacker can cross at will, that race is not one you want to depend on.

Detection also struggles in OT, where unusual-but-legitimate activity is common and where adding intrusive monitoring can be operationally sensitive. An alert on a crossing is far less valuable than a boundary that cannot be crossed.

06Removing the path versus watching it

The strongest defense against lateral movement is to remove the path the attacker needs. If there is no route from the enterprise foothold into operations, there is nothing to detect and nothing to respond to.

Reducing reachability across the boundary does exactly this. An AIRGAPNET controlled connectivity pattern can keep the crossing physically absent by default, so even a fully compromised enterprise network has no standing path into operations, and inbound access exists only during deliberate, controlled windows.

07Reachability reduction in practice

  • Eliminate dual-homed assets, or strictly control any machine that must touch both networks.
  • Replace standing jump-host access with time-boxed, brokered sessions.
  • Separate identity so a compromised IT credential cannot authenticate into OT.
  • Make data-out flows one-way so they cannot be reversed into an inbound path.
  • Keep inbound paths disconnected by default and opened only for approved tasks.

Each step removes a pivot. Together they turn the boundary from a road with several lanes into one that is closed unless deliberately and temporarily opened.

08Closing thought

Lateral movement is the mechanism by which an IT incident becomes an OT crisis. The attacker does not need a brilliant exploit; they need a path, and the path is usually one that was left open for convenience.

Watch the boundary, but do not rely on watching it. Find the pivots, remove the ones that should not exist, and reduce reachability so that crossing from IT to OT is not something an attacker can simply do.

FAQFrequently asked questions

What is lateral movement in an OT context?

Lateral movement is how an attacker progresses from an initial foothold to their target. In industrial environments the foothold is usually in IT and the target is an operational system, so the attacker moves across the IT/OT boundary to reach it.

How do attackers move from IT to OT?

Through pivots that already exist for legitimate reasons: jump hosts that are always reachable, dual-homed assets like engineering workstations, shared credentials and directory services that span both networks, and flat networks where segmentation exists only on paper.

Why is detection not enough against lateral movement?

Detection is a race that assumes you can notice and respond faster than the attacker moves. Across a boundary an attacker can cross at will, and in OT where unusual-but-legitimate activity is common, an alert on a crossing is far weaker than a boundary that cannot be crossed.

How do you stop lateral movement from IT to OT?

Remove the path the attacker needs. Eliminate or control dual-homed assets, replace standing jump-host access with time-boxed sessions, separate identity, make data-out flows one-way, and keep inbound paths disconnected by default.

Does reducing reachability help against lateral movement?

Directly. If there is no standing route from an enterprise foothold into operations, there is nothing to detect or respond to. Reducing reachability across the boundary shrinks the opportunity for lateral movement to the few controlled windows you allow.

SRCSources of record

Remove the path, not just the alert

Make crossing from IT to OT something attackers cannot simply do.

Reduce reachability across the boundary so a compromised enterprise network has no standing path into operations, with inbound access opened only for deliberate, controlled windows.

Related article

Continue the thread Securing IT/OT Convergence: Controlling the Boundary Where Two Worlds Meet