Introduction: The New Attack Surface

Twenty years ago, the most exposed thing in your electrical room was the keys hanging by the door. Today, your switchgear has an IP address. Your protective relays talk to a SCADA system. Your meters stream data to the cloud. The convenience is enormous — and so is the new attack surface.

For facility managers, operational technology (OT) cybersecurity has moved from “an IT problem” to a shared responsibility. The same network connectivity that enables monitoring, automation, and predictive maintenance also makes electrical systems reachable by attackers. The good news: you don’t have to become a cybersecurity expert to do your part. You just have to understand what’s at stake and what to ask for.

IT vs. OT: Why They’re Different

IT cybersecurity protects information — emails, financial records, intellectual property. OT cybersecurity protects physical processes — generators, transformers, ATS equipment, building automation systems.

The differences matter:

Lifespan: IT systems are replaced every 3–5 years. Protective relays and switchgear can stay in service for 20–40 years.

Patching: IT patches frequently. OT devices often can’t be patched without scheduled outages — and many older devices can’t be patched at all.

Priorities: IT prioritizes confidentiality. OT prioritizes availability and safety — a hospital can’t take its life safety branch offline for a security update.

Consequences: An IT breach leaks data. An OT breach can cause equipment damage, outages, or physical harm.

Key point: Standard IT security tools and policies, applied without modification, can themselves cause outages on OT networks. Aggressive vulnerability scans have been known to crash older industrial controllers.

What Counts as OT in a Facility

If you have any of the following, you have OT assets that need to be considered:

Smart meters with Ethernet, Wi-Fi, or cellular communications

Protective relays using IP-based protocols (Modbus TCP, DNP3, IEC 61850)

Building automation systems (BAS / BMS)

Generator controllers with remote monitoring

UPS systems with network interface cards

ATS controllers with communication modules

EV charging stations

VFDs and motor control centers with networked drives

Many of these were never designed with security as a primary concern. They were designed to be reliable, deterministic, and long-lived.

Real-World Threats

OT attacks aren’t theoretical. Documented incidents in recent years include:

Utility-targeted attacks that disrupted grid operations in multiple countries.

Ransomware that crossed from IT into OT networks, halting industrial operations and forcing emergency shutdowns.

Compromised vendor connections used to reach customer OT systems through legitimate remote-access channels.

Hospital incidents where ransomware affected building systems, including HVAC and access control.

The common pattern: attackers rarely target OT directly. They get into IT first, then move laterally to OT through poorly segmented networks or shared credentials.

The Standards Landscape

Several frameworks address OT cybersecurity. The ones worth knowing:

IEC 62443: The leading international standard for industrial automation and control system security. Defines security levels, zones, and conduits.

NIST Cybersecurity Framework (CSF): Broadly applicable. Useful for organizing risk assessment and response planning.

NIST SP 800-82: Specific to industrial control systems.

NERC CIP: Mandatory for bulk electric system assets. Influences best practices even where not legally required.

You don’t need to memorize them. You need to know they exist so you can ask vendors and integrators: “How does this product align with IEC 62443?”

Network Segmentation: The Single Most Important Idea

If you take one concept from this post, take this: OT and IT networks should be separated.

This is often described through the Purdue Model — a layered architecture that puts physical processes at the bottom and corporate/enterprise IT at the top, with controlled boundaries between layers.

In practice, for a facility:

OT devices (meters, relays, generator controllers) live on a dedicated OT network or VLAN.

A DMZ (demilitarized zone) sits between OT and IT, with carefully controlled data flow.

Remote access goes through a hardened jump server with multi-factor authentication — not a direct VPN to the OT network.

Vendor remote access is time-limited, logged, and revocable.

Reality check: Many facilities still have OT devices on the same flat network as office computers. That’s the single biggest fixable risk in most buildings.

What Facility Managers Should Actually Do

You don’t need to write firewall rules yourself. You need to:

Inventory your OT assets. What’s on your electrical network? What firmware versions? Who can access them?

Bring your IT team to the table. Most IT teams have never been told that protective relays exist on the network. Map the OT traffic together.

Require vendor cybersecurity documentation. New equipment should come with security capabilities documented. Older equipment may need compensating controls.

Control physical access. Cybersecurity isn’t only digital — a USB stick plugged into an HMI is a real threat.

Plan for incident response. If a generator controller is compromised, who do you call? Have the answer before you need it.

Train your team. Phishing emails are still the most common entry point. Facility staff with admin credentials are targets.

The Monitoring Role

Cybersecurity and operational monitoring overlap in useful ways. A platform that tracks your electrical system also creates a baseline — and baselines are how anomalies get detected:

Sudden communication failures across multiple devices

Unexpected configuration changes

Devices going silent or coming online unexpectedly

Logins from unusual locations or at unusual times

NovaVue isn’t a cybersecurity tool, but as a centralized data platform, it provides visibility that complements your IT team’s security monitoring. Knowing what normal looks like is the first step toward recognizing what abnormal looks like.

Final Thoughts

The same digitalization trends that make modern facilities more efficient, more compliant, and more reliable also make them more exposed. Facility managers don’t need to become security engineers — but they do need to understand that OT cybersecurity is now part of the job.

The facilities that handle it best treat cybersecurity the way they treat arc flash: as a serious, ongoing risk that requires standards, planning, training, and the right partners. The ones that ignore it are the ones we’ll be reading about in the news.