What Is OT Cybersecurity? A Guide for Malaysian Manufacturing and Industrial Plants

As Malaysian manufacturers adopt connected machinery, smart sensors, remote monitoring, industrial automation and data-driven production systems, the line between traditional factory equipment and digital infrastructure is disappearing.

A production plant that once operated largely as an isolated environment may now contain connected PLCs, SCADA systems, distributed control systems, industrial computers, engineering workstations, remote access connections and cloud-connected monitoring platforms.

These technologies improve efficiency and visibility, but they also introduce a new operational risk: cybersecurity threats reaching the systems that physically control production.

This is where OT cybersecurity becomes critical.

Operational technology cybersecurity focuses on protecting the systems responsible for controlling industrial processes, machinery and physical infrastructure. Unlike conventional IT cybersecurity, where the main concern is often protecting information, OT cybersecurity must also protect production availability, equipment reliability, operational continuity and human safety.

For manufacturing and industrial organisations in Malaysia, understanding OT cybersecurity is becoming increasingly important as factories become more connected and cyber threats become more sophisticated. For Foxboro Malaysia (Foxmay), OT cybersecurity is not a new area of focus. As part of Schneider Electric, Foxmay has been supporting industrial customers with cybersecurity technologies, services and practices for many years. With industrial connectivity and cyber threats becoming increasingly prominent, Foxmay is highlighting its established cybersecurity capabilities to help Malaysian organisations strengthen the protection and resilience of their operational environments.

What Is OT Cybersecurity?

OT cybersecurity refers to the technologies, processes and practices used to protect Operational Technology (OT) systems from cyber threats.

Operational technology includes hardware and software that directly monitors or controls physical equipment, processes and industrial operations.

According to the U.S. National Institute of Standards and Technology (NIST), operational technology includes programmable systems and devices that interact with the physical environment by monitoring or controlling devices, processes and events.

Common examples include:

NIST’s Guide to Operational Technology Security (SP 800-82 Rev. 3) specifically addresses the cybersecurity challenges associated with these environments and highlights the importance of maintaining reliability, safety and operational performance while protecting OT systems.

For Malaysian factories, these systems may control anything from production lines and packaging machines to water treatment systems, boilers, pumps, compressors, power distribution and process plants.

What Is the Difference Between IT and OT Cybersecurity?

IT and OT environments increasingly communicate with each other, but their priorities can be very different.

Traditional Information Technology (IT) cybersecurity primarily protects systems such as:

  • Email servers
  • Business applications
  • Databases
  • Employee laptops
  • Cloud platforms
  • Customer information
  • Enterprise networks

OT cybersecurity protects equipment involved in physical operations.

A simple way of understanding the difference is:

IT cybersecurity protects information.
OT cybersecurity protects operations.

In an IT environment, shutting down a compromised server temporarily may be an acceptable security response.

Inside a manufacturing plant, however, suddenly shutting down a production controller could stop an entire production line, damage equipment or even create safety risks.

For this reason, NIST emphasises that OT cybersecurity must take into consideration the specific performance, reliability and safety requirements associated with industrial environments.

Availability is particularly important.

A few hours of IT downtime may inconvenience employees.

A few hours of factory downtime can potentially result in missed production targets, material wastage, disrupted deliveries and significant financial losses.

Why OT Cybersecurity Is Becoming More Important in Malaysia

Modern industrial facilities are significantly more connected than they were ten or twenty years ago.

Factories increasingly rely on technologies such as:

  • Industrial Internet of Things devices
  • Remote monitoring
  • Cloud analytics
  • Predictive maintenance
  • Smart instrumentation
  • Connected production systems
  • Remote engineering support
  • Centralised plant monitoring
  • Digital energy management

These technologies bring major operational advantages, but connectivity also creates additional pathways through which attackers may potentially reach industrial systems.

A PLC that previously operated inside an isolated production network, for example, may now indirectly connect to corporate networks through SCADA servers, historians, engineering workstations or remote maintenance platforms.

If these connections are not properly secured, an attacker who compromises the IT environment may potentially move towards the OT environment.

This process is sometimes known as IT-OT convergence.

As convergence increases, organisations can no longer assume that industrial networks are automatically protected simply because they are located inside a factory.

What Are the Most Common OT Cybersecurity Risks?

Industrial environments often contain a combination of modern technology and equipment that has been operating for many years.

This creates cybersecurity challenges that are quite different from conventional corporate networks.

1. Legacy Industrial Systems

Industrial equipment frequently remains operational for 10, 15 or even 20 years.

Some systems may run older operating systems or industrial protocols that were originally designed when cybersecurity was not a major consideration.

Replacing these systems may not always be practical because they are closely connected to production equipment.

As a result, manufacturers need cybersecurity controls that can protect legacy assets without disrupting operations.

2. Flat Industrial Networks

One of the biggest vulnerabilities in many plants is a network where too many systems can communicate freely with each other.

If office computers, engineering workstations, SCADA servers and controllers operate within poorly segmented environments, a compromised device could potentially provide attackers with access to more sensitive parts of the plant network.

Network segmentation helps reduce this risk by separating systems according to their operational role and security requirements.

Foxboro Malaysia, as part of Schneider Electric, delivers industrial cybersecurity solutions that include network segmentation as part of the company’s Permit security layer alongside authentication, multi-factor authentication and secure remote access.

3. Insecure Remote Access

Remote access has become common in industrial environments.

Equipment vendors, system integrators, maintenance teams and engineers may need remote connectivity to diagnose problems or maintain industrial systems.

However, poorly secured remote access can become a major cybersecurity vulnerability.

Common risks include:

  • Shared passwords
  • Weak authentication
  • Exposed remote desktop services
  • Unmonitored vendor connections
  • Excessive access permissions

Industrial remote access should therefore use controlled authentication, access policies, monitoring and preferably multi-factor authentication.

4. Malware and Ransomware

Ransomware does not necessarily need to directly infect a PLC to disrupt production.

If malware compromises systems such as:

  • SCADA servers
  • HMIs
  • Engineering workstations
  • Active Directory infrastructure
  • File servers
  • Production databases

operators may lose the ability to monitor or safely manage industrial processes.

Production may therefore need to be stopped even if the underlying machinery remains physically functional.

5. Unmanaged Industrial Assets

Many organisations cannot confidently answer a basic cybersecurity question:

What devices are connected to our OT network?

A factory may contain thousands of connected components including switches, controllers, sensors, servers, computers and third-party systems.

Without accurate asset visibility, organisations may struggle to identify:

  • Unsupported equipment
  • Unpatched systems
  • Unauthorised devices
  • Vulnerable firmware
  • Unexpected communication between systems

Asset identification and management therefore form an important foundation for OT cybersecurity.

6. Removable Media

USB drives and other removable storage devices continue to be used in many industrial environments to transfer configurations, firmware updates and engineering files.

Unfortunately, removable media can also introduce malware into otherwise isolated systems.

Appropriate removable media controls, scanning policies and operational procedures can significantly reduce this risk.

7. Human Error

Not every cybersecurity incident begins with sophisticated hacking.

Employees, contractors and vendors may accidentally create vulnerabilities through actions such as:

  • Using weak passwords
  • Connecting unauthorised devices
  • Clicking malicious attachments
  • Sharing credentials
  • Misconfiguring industrial systems
  • Bypassing cybersecurity procedures

Cybersecurity therefore requires a combination of people, processes and technology rather than technology alone.

Why Traditional IT Cybersecurity Is Not Enough

Many organisations already have firewalls, antivirus software and corporate cybersecurity policies.

These measures are important, but applying conventional IT security approaches directly to OT environments can create problems.

Industrial systems often have unique operational characteristics.

For example:

  • Production may operate continuously.
  • Equipment cannot always be restarted for updates.
  • Patches may require vendor certification.
  • Industrial protocols behave differently from conventional IT traffic.
  • Systems may have strict latency requirements.
  • Availability may be more important than confidentiality.
  • Unexpected system changes can create safety risks.

This is one reason industry-specific cybersecurity frameworks such as ISA/IEC 62443 have become important.

The ISA/IEC 62443 series defines cybersecurity requirements and processes for industrial automation and control systems and covers areas such as risk assessment, system security and cybersecurity programmes.

The International Society of Automation states that the standards take a holistic approach that addresses the relationship between operations, information technology, process safety and cybersecurity.

What Is IEC 62443?

IEC 62443 is a widely recognised series of cybersecurity standards designed specifically for Industrial Automation and Control Systems (IACS).

It provides guidance for several groups involved in industrial cybersecurity, including:

  • Asset owners
  • System integrators
  • Equipment manufacturers
  • Product suppliers
  • Service providers

Rather than relying on one security technology, IEC 62443 encourages organisations to build cybersecurity systematically across the industrial environment.

The framework addresses areas such as:

  • Cybersecurity risk assessment
  • Security policies and procedures
  • Network architecture
  • Access control
  • System hardening
  • Patch management
  • Secure product development
  • Security monitoring
  • Incident response

ISA describes shared responsibility between asset owners, suppliers, integrators and service providers as a key principle behind the ISA/IEC 62443 framework.

For Malaysian manufacturers operating complex production environments, frameworks such as IEC 62443 can provide a structured reference for evaluating and improving OT cybersecurity maturity.

Malaysia’s Cyber Security Act 2024 and Industrial Organisations

Malaysia’s cybersecurity regulatory environment has also evolved.

The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into operation on 26 August 2024.

The legislation establishes requirements relating to Malaysia’s National Critical Information Infrastructure (NCII) and addresses cybersecurity risk management, cybersecurity incidents and cybersecurity service providers.

Malaysia’s NCII sectors include areas such as:

  • Government
  • Banking and finance
  • Transportation
  • Healthcare
  • Water, sewerage and waste management
  • Energy
  • Agriculture and plantation
  • Trade, industry and economy
  • Science, technology and innovation

NACSA defines NCII as systems and infrastructure where disruption or destruction could affect areas including national security, economic stability, government operations, public health or public safety.

Not every manufacturing facility will automatically be classified as an NCII entity.

However, the direction of regulation reinforces a broader trend: organisations operating important industrial infrastructure are increasingly expected to understand and actively manage cybersecurity risk.

How Can Manufacturers Improve OT Cybersecurity?

Effective OT cybersecurity should be approached as an ongoing programme rather than a one-time technology installation.

Several areas deserve particular attention.

1. Create an Accurate OT Asset Inventory

You cannot protect industrial assets if you do not know they exist.

A comprehensive inventory should identify systems including:

  • PLCs
  • SCADA servers
  • HMIs
  • Engineering workstations
  • Industrial switches
  • Firewalls
  • Servers
  • RTUs
  • Network-connected instruments
  • Remote access gateways

The inventory should also record information such as:

  • Device manufacturer
  • Model
  • Firmware version
  • IP address
  • Network location
  • Operating system
  • Business function
  • Criticality

Asset identification also helps organisations prioritise their cybersecurity resources towards systems that are most important to plant operations.

2. Conduct an OT Cybersecurity Risk Assessment

A risk assessment evaluates where vulnerabilities exist and what could happen if those vulnerabilities are exploited.

An OT cybersecurity assessment may examine:

  • Network architecture
  • Remote connectivity
  • Access control
  • Firewall configuration
  • Unsupported systems
  • Patch management
  • Backup procedures
  • Asset inventory
  • Cybersecurity policies
  • Incident response readiness

The objective should not simply be to generate a long list of vulnerabilities.

The assessment should help management understand which vulnerabilities represent the greatest operational risk.

Foxmay provides cybersecurity consulting services based on Schneider Electric’s industrial cybersecurity solutions and expertise, including policy and procedure review, asset inventory, gap analysis and risk and threat compliance assessment.

3. Segment IT and OT Networks

Industrial systems should not generally share unrestricted network access with corporate computers.

Segmentation can create controlled security zones between areas such as:

Corporate IT Network

↓

Industrial DMZ

↓

SCADA / OT Network

↓

Controllers and Field Equipment

Firewall rules can then control which systems are permitted to communicate between each zone.

Good segmentation helps prevent a compromise in one environment from automatically spreading across the entire organisation.

4. Secure Remote Access

Remote connectivity should follow the principle of least privilege.

Users should receive only the access they require for their specific tasks.

Good practices can include:

  • Multi-factor authentication
  • Individual user accounts
  • Role-based access control
  • Session monitoring
  • Time-limited access
  • Approval workflows
  • Secure remote access gateways

Vendor access should also be regularly reviewed rather than remaining permanently active.

5. Harden Industrial Systems

System hardening reduces unnecessary opportunities for attackers.

Depending on the equipment, this may involve:

  • Disabling unnecessary services
  • Removing unused accounts
  • Changing default passwords
  • Restricting administrative privileges
  • Configuring firewall rules
  • Applying application whitelisting
  • Restricting removable media

The key is to perform hardening carefully so that operational reliability is not affected.

6. Implement Patch and Vulnerability Management

Patching in industrial environments requires more planning than patching ordinary office computers.

Before updates are deployed, organisations may need to consider:

  • Compatibility with industrial software
  • Vendor recommendations
  • Production schedules
  • System redundancy
  • Testing requirements
  • Recovery procedures

Where immediate patching is not possible, compensating security controls such as firewall rules or segmentation may be necessary.

7. Monitor OT Networks Continuously

Traditional cybersecurity methods often focus heavily on prevention.

But organisations should also assume that some threats may eventually bypass preventative controls.

Monitoring helps identify unusual behaviour such as:

  • Unexpected network connections
  • New devices appearing on the OT network
  • Communication with unusual destinations
  • Abnormal authentication attempts
  • Unexpected configuration changes
  • Suspicious industrial protocol activity

Security Information and Event Management, or SIEM, can help consolidate security events and support investigation.

Foxmay delivers Schneider Electric’s industrial cybersecurity capabilities, including firewall security, device management, threat management, device security and OT SIEM support.

8. Prepare for Cyber Incidents

No cybersecurity programme can guarantee that an organisation will never experience an incident.

Manufacturers therefore need a clear response plan.

The plan should define:

  • Who makes decisions during a cybersecurity incident?
  • Who contacts equipment vendors?
  • Who isolates compromised systems?
  • When should production be stopped?
  • How will critical systems be restored?
  • Where are backups stored?
  • How will management communicate during the incident?

Backup and disaster recovery planning are particularly important.

Recent NIST OT cybersecurity publications continue to emphasise practical OT resilience topics including backup and secure remote access, reflecting how central recovery and controlled connectivity have become to industrial security.

OT Cybersecurity Should Follow Defence in Depth

Industrial cybersecurity should not depend on a single firewall, antivirus product or security technology.

Instead, organisations should implement multiple layers of protection.

This approach is commonly known as defence in depth.

One layer may prevent unauthorised access.

Another may protect endpoints.

Another may monitor unusual activity.

Another may allow the organisation to recover if the previous controls fail.

Foxmay structures its industrial cybersecurity solutions around four cybersecurity functions:

As part of Schneider Electric, Foxmay delivers industrial cybersecurity solutions across four key cybersecurity functions: Permit, Protect, Detect and Respond.

Permit

Control who and what can access industrial systems through measures such as:

  • Authentication
  • Authorisation
  • Multi-factor authentication
  • Network segmentation
  • Secure remote access

Protect

Reduce the ability of malware and unauthorised activity to affect industrial systems through:

  • Endpoint protection
  • Application whitelisting
  • Anti-malware
  • Patch management
  • Removable media controls

Detect

Identify suspicious behaviour through:

  • Security Information and Event Management
  • Network monitoring
  • Asset identification
  • Anomaly detection
  • Intrusion detection

Respond

Prepare the organisation to contain and recover from cybersecurity incidents through:

  • Backup
  • Disaster recovery
  • Digital forensics
  • Incident response

Together, these controls create multiple layers between attackers and critical industrial operations.

Who Should Be Responsible for OT Cybersecurity?

OT cybersecurity should not belong exclusively to the IT department.

Industrial cybersecurity normally requires collaboration between:

  • IT cybersecurity teams
  • Plant engineers
  • Automation engineers
  • Operations teams
  • Maintenance teams
  • Management
  • Equipment vendors
  • System integrators

This collaboration is important because cybersecurity decisions can affect production.

An IT team may identify a vulnerable industrial server and recommend immediately installing a security patch.

However, the automation team may know that the patch must first be tested because the server controls production-critical software.

Neither side is necessarily wrong.

Effective OT cybersecurity requires both teams to understand the organisation’s cybersecurity risk and operational risk simultaneously.

How Should a Malaysian Manufacturer Start?

For organisations that have not yet developed a formal OT cybersecurity programme, the process does not have to begin with a large technology investment.

A practical starting point is to answer five questions:

1. What OT assets do we have?

2. How are our IT and OT networks connected?

3. Who can remotely access our industrial systems?

4. Which systems are most critical to production and safety?

5. What would happen if those systems became unavailable tomorrow?

The answers often reveal the organisation’s highest-priority cybersecurity risks.

From there, companies can develop a roadmap covering areas such as:

  • Asset management
  • Risk assessment
  • Network segmentation
  • Secure remote access
  • System hardening
  • Threat monitoring
  • Patch management
  • Cybersecurity training
  • Incident response

Frequently Asked Questions About OT Cybersecurity

What does OT mean in cybersecurity?

OT stands for Operational Technology.

It refers to hardware and software used to monitor or control physical equipment and industrial processes.

Examples include PLCs, SCADA systems, DCS platforms, HMIs and industrial control systems.

What is OT cybersecurity?

OT cybersecurity is the practice of protecting operational technology systems from cyber threats while maintaining the reliability, safety and availability of industrial operations.

Is OT cybersecurity different from IT cybersecurity?

Yes.

IT cybersecurity primarily protects data and information systems, while OT cybersecurity protects systems that control physical processes and equipment.

OT environments also place greater emphasis on operational availability and safety.

What industries need OT cybersecurity?

OT cybersecurity is relevant to industries including:

  • Manufacturing
  • Oil and gas
  • Water and wastewater
  • Energy
  • Utilities
  • Chemicals
  • Food and beverage
  • Pharmaceuticals
  • Transportation
  • Building infrastructure
  • Data centres

Any organisation using automated equipment or industrial control systems may face OT cybersecurity risks.

What is the difference between ICS and OT?

Industrial Control Systems, or ICS, are a major category within operational technology.

OT is the broader term and can include ICS as well as building automation, physical monitoring systems and other technologies interacting with physical environments.

What is IEC 62443?

IEC 62443 is a series of cybersecurity standards specifically designed for industrial automation and control systems.

It provides guidance for asset owners, system integrators, suppliers and product manufacturers on managing cybersecurity throughout the industrial system lifecycle.

Can ransomware affect manufacturing equipment?

Yes, although ransomware does not necessarily need to directly infect machinery.

If ransomware disrupts SCADA servers, engineering workstations, HMIs, industrial databases or supporting IT infrastructure, an organisation may lose the ability to safely operate its production processes.

Building a More Resilient Industrial Environment

Digitalisation is bringing major opportunities to Malaysian manufacturing.

Connected automation, smart instrumentation, advanced analytics and remote monitoring can improve efficiency, productivity and reliability.

However, every new connection also needs to be considered from a cybersecurity perspective.

The objective of OT cybersecurity is not to prevent industrial digitalisation.

It is to ensure that organisations can adopt connected technologies without unnecessarily exposing critical operations to cyber risk.

A strong OT cybersecurity programme combines asset visibility, risk assessment, secure network architecture, controlled access, system protection, monitoring, incident response and employee awareness.

For manufacturers that rely heavily on automation and industrial control systems, protecting operational technology is increasingly becoming part of protecting the business itself.

As part of Schneider Electric, Foxmay provides access to industrial cybersecurity solutions and expertise covering cybersecurity consulting, secure architecture, system hardening, network segmentation, secure remote access, OT SIEM monitoring, threat management, maintenance, incident response and cybersecurity training.

Learn more about Foxmay’s Industrial Cybersecurity Solutions in Malaysia and how a structured OT cybersecurity strategy can help strengthen the resilience of your industrial operations.

Share:

Facebook
Twitter
Pinterest
LinkedIn

How would you rate your experience?