
The devices nobody sees as computers
A production machine, a camera, a climate control unit and a phone have one thing in common: software runs on them, they hang off the network and nobody keeps them current. They rarely appear on the inventory, and that is precisely why they are where an attacker gets in.
Why the usual approach does not work here
The measures for an office workstation do not fit, and that is not carelessness.
- OT, machines and installationsA production line cannot simply be patched: the supplier certifies a fixed version and a reboot costs production. Patching here is a planned downtime window and not a Tuesday evening.
- IoT: cameras, sensors, climateSmall devices with no management agent, often with a password never changed and software no longer maintained after two years. There are more of them than anybody thinks.
- Mobile, phones and tabletsManageable, but outside the office network and often partly personal. Here it is not about the device but about the separation between work and private.
Four steps that do fit
Where patching is impossible, separating and watching is the answer.
Count what is attached
A scan of the network almost always turns up equipment on no list at all. That is step one and immediately the most revealing.
Separate into their own networks
Cameras with cameras, machines with machines, and neither with the office workstations. An infected workstation should not be able to reach a production line.
Only allow through what is needed
A camera does not need the internet and a machine does not need the accounts department. What does not need to go out is closed off, cheaper than securing every device individually.
Watch what cannot be patched
For equipment that cannot be updated, noticing that something changed is the only remaining means. That is a deliberate choice and not a shortcoming.
What belongs with this
This touches the network, the security and the physical side.
Know what is actually attached
Tell us what kind of equipment is in the building. We start by counting, because that list is almost always longer than expected.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.