Why you cannot scan an OT network
The single most common way an IT security programme causes an industrial incident, and what to do instead.
The thing IT security gets wrong here
Vulnerability scanning is so ordinary in enterprise security that it is barely a decision. You point the scanner at a range, it enumerates, you get a report.
Point the same scanner at a control network and you can stop production. This is not caution or folklore. Industrial controllers have limited network stacks, tight timing assumptions and no expectation of malformed or unexpected traffic, because they were built for a deterministic network that no untrusted party could reach.
What actually goes wrong
A scanner opens connections a controller was not built to handle and exhausts its session table. A probe sends a malformed packet and the device faults. An enumeration sweep introduces enough latency that a time-sensitive process misses its window.
None of these are exotic. They are ordinary scanner behaviour meeting equipment that has been running continuously since before the scanner existed.
Why "just do it in a maintenance window" fails
Maintenance windows on a process plant are measured in hours and negotiated months ahead against production commitments. On a vessel under way there is no window at all.
Even where a window exists, a scan tells you about the estate during the window. Change happens the rest of the time, and OT estates change more than people expect: vendors connect, engineers swap parts, temporary fixes become permanent.
Passive discovery, and why it is better anyway
Passive discovery listens rather than asks. From observed traffic you can identify what is on the network, what firmware it runs, what protocols it speaks and which processes it participates in, without sending anything at all.
It is often argued that this is a compromise, an inferior substitute accepted for safety reasons. In practice it produces a better inventory. A scan gives you a point-in-time list of what answered. Passive observation gives you a continuous picture, including the devices that would never have answered and the relationships between them, which is the part that actually matters when you are trying to understand consequence.
What you still cannot learn passively
Passive discovery will not confirm exploitability. It tells you a device is running a firmware version with a known vulnerability; it does not tell you whether an attacker could reach and use it given your segmentation.
That question is answered by validation, carried out deliberately and under approval, against targets you have agreed. The distinction worth holding onto is that discovery should be continuous and safe, while validation should be occasional and controlled. Collapsing the two into one activity is how the industry ended up pointing scanners at plant.
Questions, answered
Is passive monitoring enough on its own?
Our vendor says their scanner is OT-safe. Is it?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.