Zscaler Blog
Get the latest Zscaler blog updates in your inbox
Securing the Unsecurable: OT, IoT, and the Factory Floor
Modern manufacturing is undergoing a massive shift toward connected operations. We are seeing a flood of advanced IoT sensors and diverse OT systems that drive everything from real-time vibration monitoring to predictive maintenance. This connectivity is the engine for growth, faster supply chain fulfillment, and the kind of innovation that keeps a manufacturer competitive.
However, in this environment, uptime and availability are the only metrics that matter. This is the primary lens through which operators are evaluated and plant managers justify their budgets. Operational resilience is the ultimate win, which means security often takes a backseat to anything that might stop the line.
This gap has made manufacturing the top target for ransomware. The recent release of Anthropic’s Claude Mythos has fundamentally changed the math for industrial security. Any connected device can be exploited; if it’s reachable, it’s breachable. In OT, you can’t simply "auto-update" to stay ahead of zero day vulnerabilities; patching requires planned outages and rigorous vendor validation to ensure a "fix" doesn't accidentally shut down the plant.
How Attacks Move from IT to the Factory Floor
Most factory breaches don’t start on the factory floor. In reality, they almost always start in IT. Attackers look for the low-hanging fruit, i.e. a weak VPN, an exposed service, or through remote access. Once they have that foothold, they don't need to break into your OT network; they just use the connectivity you’ve already built. Whether your plants are connected via MPLS, VPNs, or an SD-WAN mesh, the underlying problem is the same: these technologies extend trust, not just connectivity. You might have intended to give a vendor access to one specific machine, but by advertising a subnet over a routed tunnel, you made that entire vlan or zone routable.
The Two Highest Impact Ways to Defend Against AI Attacks
- Minimize your external attack surface - Zscaler Zero Trust Branch (ZTB) creates helps your branches go dark. We remove all inbound listeners. All the traffic comes in and goes out through Zero Trust Exchange ensuring that there is nothing for an attacker to find. If they can’t find you, they can’t exploit you. Period.
Kill lateral movement with microsegmentation: You have to assume a threat will eventually get inside, maybe through a compromised vendor laptop. Most factory networks are flat allowing attackers to laterally move within the VLAN. This makes your attack surface as wide as your subnet mask. For example, a /20 subnet mask puts 4000+ devices at risk. Zscaler Zero Trust Branch handles this by creating a "Network-of-One" for every asset. This isolates every device so one compromised machine can't trigger a plant-wide shutdown.
Microsegmentation On the Factory Floor
Segmentation has been a long-held elusive goal for many OT architects. Compliance and critical infrastructure safety directives make this mandatory to prevent lateral movement of threats. In this blog series, we will examine how microsegmentation can help you eliminate lateral threat movement in complex OT environments where traditional IT tools just won’t work..
There are three strategic pillars to doing microsegmentation right:
- Bridging the Asset Visibility Gap on a Factory Floor
- Mapping the threat landscape and defining your policy framework.
- Operations and Incident response with Ransomware Kill Switch
First Pillar: Asset Visibility
Let’s look at the visibility capabilities in four parts:
Asset Inventory: Defending OT systems starts with knowing what you have and its risk profile. Zscaler Zero Trust Branch (ZTB) provides AI-powered device discovery and classification that allows you to inventory OT/IoT devices without the need for endpoint agents, scanners, or traffic mirroring. By sitting natively inline, we fingerprint every asset in real-time as traffic flows through the gateway. By combining DHCP fingerprinting, JA3 TLS hashes, and HTTP User Agent analysis with other L2 and L3 data, ZTB builds a multi-dimensional profile of every asset in real-time.
Signature-less AI Discovery: Traditional tools usually fail when they hit a device they haven’t seen before because they’re stuck relying on a pre-built signature database. We’ve moved past that. Using AI/ML logic, Zscaler identifies new IoT and OT devices in real-time—even those we’ve never seen before. By analyzing behavioral patterns through DNS names and weblog data, we classify assets based on where they are going and how they behave.
Industrial/OT Context: This is where we speak the language of your IoT/OT assets. ZTB decodes the specific protocols used in your environment to understand exactly what a device is. This context allows us to provide vertical-specific intelligence:
- Industrial & Heavy Equipment: By inspecting OPC UA, Modbus, and ENIP communications, we can fingerprint specific PLCs or SCADA servers.
- Life Sciences & Medical Manufacturing: We look into DICOM and HL7 traffic to identify sensitive medical imaging systems like MRI, X-ray.
- Building Automation: We parse BACnet broadcasts to profile HVAC, lighting, and access control systems.
- Partnership Ecosystem: We know some of you have already invested in specialist visibility tools. We further enrich this discovery by ingesting data from partners like Armis, Ordr, or CrowdStrike. While Zero Trust Branch sees the Rockwell HMI on the wire, a partner like Armis can add deep-layer context such as the OS (Windows CE), and a Risk Level (80). This enriched data becomes the foundation for building precise, automated security policies without doubling your workload.
- Intelligence via System-Generated Tags All of this data is distilled into System-Generated Tags, which create the base for your microsegmentation policy. This is where you move away from old-school networking constructs like IPs and subnets and start using security context. We tag assets with its Manufacturer, model, and Device Category.
By using these tags, your policy becomes human-readable and automated. Instead of writing a complex rule for a specific IP address, you write a policy for "All Rockwell PLCs at Purdue Level 1."
In the next blog, we will dive into how Zscaler turns this asset visibility into actionable intelligence starting with Visualization, Threat Mapping, and finally, how to define dynamic groups for creating policies.
Was this post useful?
Disclaimer: This blog post has been created by Zscaler for informational purposes only and is provided "as is" without any guarantees of accuracy, completeness or reliability. Zscaler assumes no responsibility for any errors or omissions or for any actions taken based on the information provided. Any third-party websites or resources linked in this blog post are provided for convenience only, and Zscaler is not responsible for their content or practices. All content is subject to change without notice. By accessing this blog, you agree to these terms and acknowledge your sole responsibility to verify and use the information as appropriate for your needs.
Get the latest Zscaler blog updates in your inbox
By submitting the form, you are agreeing to our privacy policy.



