Why xOT Monitoring Matters: Lessons from an OT Threat Hunter

Table of Contents

I started my career programming Allen-Bradley PLCs and HMIs as a systems integrator. Back then, security meant locking the control room door. Networks were air-gapped, protocols were proprietary, and the prevailing wisdom was that if attackers couldn’t see your systems, they couldn’t touch them.

That world is gone. And most organizations have not fully reckoned with what replaced it.

Over twenty years later, I perform threat hunts across industrial networks through Dragos OT Watch service. I have worked inside petrochemical plants, water utilities, manufacturing facilities, and power generation sites. What I see consistently across all of them, is the same divide: organizations that can see what is happening in their extended operational technology (xOT)environment, meaning every system that influences their physical operations, and organizations that are flying blind.

The difference between those two groups is not theoretical. I have seen it play out in real incidents, and the consequences are severe enough that I think every OT operator needs to understand what that gap actually looks like in practice.

A small electric utility came to us not because they had built a mature security program, but because they had received a grant that covered OT monitoring services. Security investment was not a priority. They had no visibility into their OT network traffic.

They also had no idea they had been compromised.

The call that changed that did not come from inside their organization. It came from the FBI. Federal investigators had identified the utility’s external IP communicating with infrastructure tied to a state-sponsored threat group tracked by Dragos. The adversary had been present in their environment for over 300 days before anyone knew.

My team was brought in immediately. Within the first hour of reviewing their network data, I found it. Two devices on their network communicating with known malicious IP addresses, actively scanning internally and looking for OT devices. The traffic was not hidden. It had simply never been looked for.

Three hundred days undetected. One hour of visibility to find it. That gap is not a technology problem. The technology existed. It is a monitoring problem.

This is what operating blind costs. Not just the risk of an incident, but the loss of any ability to make informed decisions when one occurs. When Colonial Pipeline was hit in 2021, the ransomware only affected IT systems. But the company shut down OT operations for six days because they lacked the visibility to know whether their control systems had been touched. The lesson is that systems outside the traditional OT boundary can still decide whether operations run. You only know which ones if you can see them. That is the premium you pay when you cannot see your own environment.

The OT mission has not changed. The environment it has to cover has extended. The visibility problem below applies to the systems we have always called OT, and to anything else whose failure would stop operations.

OT environments break the assumptions that most security tools are built on. Signature-based detection cannot catch novel attacks against industrial protocols. Endpoint agents cannot run on legacy HMIs or embedded systems that are decades old and cannot be patched. The standard IT security playbook simply does not translate.

Network security monitoring works in OT because the network does not lie. Every command sent to a PLC, every query from an HMI, every configuration change has to cross the wire. If you are watching that traffic with the right context, you can see things that nothing else will catch.

Through OT Watch, we find threats that would have been invisible otherwise. Unauthorized attempts to reprogram PLCs. Reconnaissance patterns that indicate someone is mapping the environment. Credential abuse on engineering workstations. Process manipulation that looks legitimate at the protocol level but breaks from every established operational pattern.

The utility case is a clear example. The adversary traffic was not exotic. It was two devices talking to bad IPs and scanning the network. Completely detectable, if someone had been watching. Nobody was.

Every operational environment has a rhythm. Production schedules drive traffic patterns. Devices communicate in predictable sequences. Engineers access systems during expected windows. That rhythm is not just operational context. It is your primary detection mechanism.

When you establish a real baseline, deviations become obvious. PLC logic modified at 3 AM stands out. A workstation that has never talked to a particular subnet suddenly scanning it stands out. The baseline is what separates a real alert from noise, and it is what allows experienced threat hunters to move fast when something is actually wrong.

It also changes how you respond. With continuous visibility, you can answer the questions that matter during an incident. Has the threat crossed into OT? Which systems are affected? What commands were executed? Are the control systems still doing what they are supposed to do? Without that visibility, you are guessing. And in OT, guessing is expensive.

This is where a lot of organizations get it wrong. They take tools built for IT networks and drop them into OT environments and wonder why they create more problems than they solve.

In OT, availability is everything. A monitoring solution that introduces any risk to operations is not a security improvement, it is a liability. OT Watch runs on the Dragos Platform, which observes traffic passively without touching it. I have seen inline solutions deployed in OT environments that created single points of failure. That is not security. That is added risk with a security label on it.

Industrial networks also speak languages most security platforms do not understand. Modbus, DNP3, EtherNet/IP, PROFINET, OPC. Without the ability to interpret those protocols in operational context, you are collecting data you cannot act on. And the systems generating that data are often running firmware that has not been updated in fifteen years on operating systems that have not been supported for a decade. Effective monitoring has to work within those constraints, not pretend they do not exist.

The skills gap is real too. Having the right platform matters, but threat hunting in OT requires people who understand both cybersecurity and industrial operations. That combination is rare. It is a large part of why organizations use OT Watch rather than trying to build that capability from scratch internally.

The Minnesota attacks in July 2026 made this concrete for an entire sector at once. Over a single weekend, more than 30 municipal water utilities had their OT systems compromised, not through sophisticated exploits, but because PLCs were sitting exposed on the internet with default or weak credentials. CISA had warned about exactly this exposure weeks earlier. It is one thing to know that PLCs are sitting exposed on the internet somewhere. It is another to know whether yours are among them. Most of these utilities are small operations with no dedicated OT security staff and budgets that do not stretch to cover it. That is the real constraint, and it is not going away. But it is also why visibility matters more, not less. When you cannot fix every exposure, you need to at least know what exposures are in your environment and when someone takes advantage of them.

Regulatory requirements across critical infrastructure sectors are expanding. Cyber insurers are moving toward technical verification of security controls, and organizations that can’t demonstrate visibility into their OT environments may face higher premiums, coverage exclusions, or reduced limits.

None of that creates the underlying need for monitoring. The operational risk has always been there. What is changing is that the business and regulatory environment is finally catching up to a problem that threat hunters have been watching grow for years.

The question is not whether to monitor. It is how fast you can do it well.

I keep coming back to that utility. Grant-funded. No visibility. Three hundred days of adversary presence nobody knew about until a federal agency made a phone call.

They are not an outlier. They are a warning. The threat groups targeting OT environments are patient, deliberate, and increasingly capable. The organizations that will come through this period are the ones that can see their environments clearly enough to find the threats that are already there, and respond to them before the impact reaches operations.

That requires continuous monitoring. It requires people who know what they are looking at. And it requires treating visibility not as a nice-to-have but as the foundation everything else is built on.

In OT security, and across the full xOT environment, monitoring is not optional anymore. It never really was. We just did not have the visibility to know it.

No dedicated OT security team? See how OT Watch gives you 24/7 monitoring and expert threat hunting from Dragos.

Learn more

Danielle Gauthier is a Senior Product Marketing Manager for Cyber Threat Intelligence at Dragos. After gaining an interest in digital cultures while studying anthropology at the University of Western Ontario, Danielle Gauthier launched her career in early-stage technology start-ups and found success in product management and product marketing roles starting in 2011. Spending time first at retail marketing and shopper experience technology companies based in Canada, then later specializing in open-source intelligence and threat intelligence products, Danielle is committed to making the world a better and safer place. In her free time, Danielle enjoys spending time with her German Shepherd, kayaking, and foraging mushrooms.