1. “Security isn’t necessary; our ICS is air‑gapped.”
Very few industrial networks are truly air‑gapped anymore, and most have some form of connectivity to business networks, remote vendors, or cloud services. Even if you were fully isolated, threats can still enter through infected laptops, USB drives, engineering workstations, and supply-chain compromises. Treating “air‑gapped” as a security strategy creates blind spots and leads to underinvestment in basic controls like monitoring, segmentation, and access management.
2. “Proper security is impossible; we can’t use AV or patch regularly.”
It’s true that traditional IT practices like weekly patch cycles and generic antivirus on every endpoint often don’t fit OT realities. But that doesn’t make security impossible—it just means you need an OT‑aware approach. Compensating controls such as strict network segmentation, whitelisting, secure remote access, protocol‑aware inspection, and rigorous change management can meaningfully reduce risk even when patches are delayed and AV is limited.
3. “Security is someone else’s job; it belongs purely to IT.”
Industrial cybersecurity sits at the intersection of IT and OT, so neither side can handle it alone. IT teams understand networks, identity, and infrastructure, but OT teams understand the processes, safety constraints, and what “normal” looks like on the plant floor. Effective security requires shared responsibility: joint risk assessments, coordinated change control, and clear roles so that cyber decisions are made with both operational and security impacts in mind.
4. “ICS security is the same as enterprise IT; the same tools and strategies will work.”
Industrial networks have different priorities (safety and availability first), protocols, and operating constraints than office IT environments. Approaches that work fine in IT—like aggressive network scans or frequent reboots—can cause outages or safety risks in OT. While some technologies overlap, ICS security strategies must be tailored: think deterministic traffic baselines, Purdue-model segmentation, protocol‑aware inspection, and change controls aligned to maintenance windows, not just copying IT playbooks.



