Skip to main content

Understanding your OT environment: the first step to stronger cyber security

If you can’t see your entire operational technology environment, you can’t defend it. New guidance from the NCSC will help you gain that visibility.
Olga Rolenko via Getty Images

If you work in operational technology (OT), you already know what’s at stake.

OT systems keep the lights on, the water pumping, the manufacturing lines moving and our critical national services running. When these systems are compromised or disrupted, the real-world impacts affect safety, operations, the economy, and even national resilience.  

That’s why today the NCSC is launching new guidance to help OT organisations create and maintain a ‘definitive record’ of their environment, an accurate and up-to-date view of the system that will change over time to maintain its accuracy and authority.  

Connectivity, complexity and change are part of today’s OT reality. Systems that were once air-gapped now interact with enterprise IT, cloud platforms, remote vendor management tools and external data services. Large, long-lived environments bring the extra challenge of undocumented changes, where temporary fixes become permanent, devices are swapped without records being updated, and network paths evolve over time. And without a complete, current understanding of your whole environment, effective cyber security controls can’t be designed, implemented or maintained.  

The ‘definitive record’ the guidance describes isn’t just a technical asset list; it reflects how your OT supports your mission and your operations, and includes:  

  • Components: individual devices, controllers, software and virtualised systems, classified by their criticality, exposure, and availability requirements.
  • Connectivity: how those assets interact within the OT network and beyond, including external connectivity, protocols in use, and any limitations like latency or bandwidth.
  • Wider system architecture: zones, conduits and segmentation measures; resilience provisions such as redundancy or high-availability pairs; and the documented reasoning behind design choices.
  • Supply chain and third-party access: which vendors, integrators and service providers connect into your environment, how they are managed, and how those connections are protected.
  • Business and impact context: understanding what would happen operationally, financially and from a safety perspective if an asset or connection failed or were compromised, and using that to shape priorities.

The more an adversary knows about your OT, the easier it is for them to plan and execute effective attacks. Every diagram, configuration and description is valuable intelligence to a skilled attacker. This means your definitive record is one of the most sensitive collections of information you will hold. It should only be accessible to those who need it, protected against tampering, and managed with secure change control. The guidance will help you protect this information appropriately while still enabling its operational and security value. Building your definitive record won’t happen overnight, and it’s not a ‘one and done’ task. Even a partial view to begin with is better than none, and it will mature as you work systematically through assets, networks and supplier relationships.

For many organisations, pieces of the puzzle already exist, in design documents, vendor manuals, maintenance logs or monitoring tools. The goal is to bring these together, validate them, and keep them up to date. By taking this approach, you can make informed, risk-based decisions on patching, architecture changes, third-party access, and contingency planning, ensuring your controls are proportionate and targeted where they matter most.

If you can’t see your whole OT environment, you can’t truly defend it. This guidance will help you gain that visibility, turning fragmented knowledge into a definitive, living record, and enabling you to protect the OT systems, services and supply chains that matter most.

This guidance has been produced by the NCSC in partnership with:

  • Australian Signals Directorate (ASD)
  • US Cybersecurity and Infrastructure Security Agency (CISA)
  • Canadian Centre for Cyber Security (Cyber Centre)
  • US Federal Bureau of Investigation (FBI)
  • New Zealand’s National Cyber Security Centre (NCSC-NZ)
  • Netherland's National Cyber Security Centre (NCSC-NL)
  • Germany’s Federal Office for Information Security (BSI)

We thank all our partners who have contributed to this guidance.

David G
Security Architect, NCSC

Written by

David G Security Architect NCSC