Bears. Beets. SASE. A Dunder Mifflin Guide to OT Security
In this blog
Think about Dunder Mifflin for a second.
On the main floor, you've got Michael Scott, Dwight, Jim and Pam. They're on laptops, sending emails, managing accounts and calling clients. The firewall, VPN and security policies were all built for their team.
Meanwhile in the warehouse, Darryl and his crew live in a different world. They have different schedules, equipment and priorities. They care about getting pallets out the door, not the Threat Level Midnight screening going on upstairs.
Now imagine someone from corporate schedules the same customer service training for the entire company. It makes sense for Michael's team but has nothing to do with someone operating a forklift. No one stopped to look at how the warehouse operates and what it actually needs.
This dynamic plays out constantly in real life as organizations work to apply Secure Access Service Edge (SASE) to Operational Technology (OT) environments. On first instinct, SASE, which was built with Information Technology (IT) in mind, may feel irrelevant to the OT space. However, this security stack can actually help solve some serious issues that industrial environments deal with. The tools can still apply to an extent, but how you deploy them changes.
Understanding what makes OT different
To apply SASE effectively in an OT environment, it helps to understand where OT diverges from the IT world the framework was originally designed for.
In IT, the CIA triad is the core principle that cybersecurity is built around: confidentiality, integrity and availability. But with OT, the order gets flipped. The priority is availability first, then integrity, then confidentiality. Availability takes precedence because even small amounts of downtime in these systems can have huge consequences, such as knocking out production, revenue loss and extreme reputational damage. Let's just say it's much worse than a bad batch of pretzel day.
The other main way that OT differs from IT is that the technology itself works very different. OT devices like Programmable Logic Controllers (PLCs) can't run agents and they communicate over industrial protocols like Modbus and DNP3. These focus on reliability and speed over security, and most have no built-in authentication or encryption. This means that a message sent over Modbus has no way to verify who sent it or tell if the data has been tampered with. Many security tools can't even read these protocols, which makes it difficult or impossible to protect and inspect traffic.
What SASE doesn't solve
Based on these differences, SASE is limited in how it can be applied to the OT space. SASE operates at Level 3.5 of the Purdue Model, a framework that organizes all the parts of an OT network into a layered architecture. Level 3.5 is the Demilitarized Zone (DMZ), a boundary layer where traffic crossing between the OT environment and the IT network gets inspected and policy is enforced. This is an important space but it's as far as SASE reaches, and even at this layer it still has its constraints.
Consider these limitations when it comes to implementing SASE with OT:
- SASE authenticates based on the identity of the user. IT has human users, and OT deals with physical assets. Most OT traffic is machine to machine, not user to user, so the identity model that SASE is built around doesn't map perfectly to that.
- SASE can't run directly on most OT devices. You have to build SASE around OT instead of applying it directly. Because of this, SASE can only be applied to OT up to a certain point. It's not a one-and-done solution. It can solve part of the problem but needs to be paired with other OT-specific security tools.
- Deep packet inspection is part of how SASE enforces policy. This becomes very limited or impossible with OT because the traffic is often in a protocol the tool doesn't understand. At most, SASE can see that traffic is moving between two devices, but it can't identify if anything suspicious is happening or what commands are being used.
- SASE is good at dealing with north-south traffic, what comes in and goes out. However, it cannot address east-west traffic for OT systems, which means it can't limit an attacker from moving laterally once they've infiltrated a network. This is another reason why SASE isn't a standalone solution for OT security and should be combined with an OT visibility solution to provide better context into your environment.
Where SASE fits
SASE's reach is limited in OT environments, but there are specific problems it addresses well. When thoughtfully integrated with the right OT security tools, SASE can address some crucial issues and be a piece of the bigger puzzle that is your OT security strategy.
The best benefits that SASE provides for OT are secure access and visibility, especially when it comes to vendor remote access. Traditionally, organizations have used VPN to give third parties access to their OT systems. You get authenticated by the VPN at the perimeter and then once inside, you have broad network access. This means that a vendor connecting through a VPN could potentially reach far more of the OT network than they need to.
SASE brought on Zero Trust Network Access (ZTNA) as a replacement for VPN. ZTNA is a fantastic first step towards a greater Zero Trust (ZT) strategy. Once you're authenticated, you get access to only the one thing you need and for a single session. ZTNA also provides continuous verification instead of only authenticating at the perimeter. On top of that, everything that happens in the session is logged extensively, a feature that many VPNs don't offer.
Where to start
Getting started on securing your OT environment doesn't have to be overwhelming, and you don't need to secure everything all at once. Most organizations do better when they begin by protecting one high-risk area and building from there. Think of it like Dwight's beet farm: you protect the most valuable crop first, then work outward.
Segmentation is a great starting point. Once you've built those walls, then allow access through SASE solutions like ZTNA. It'll control who crosses the boundaries you've set in place, log every session in detail and make sure vendors and remote users only have access to what they need. And it's worth noting that some vendors have already done the integration work for you. The Netskope and Illumio partnership is a good example, pairing Netskope's SASE capabilities with Illumio's segmentation for east-west traffic.
WWT works with organizations in every stage of securing their OT habitats, from initial security assessments to full architecture design and implementation. Whether you're just starting to think about how SASE can fit into your OT space or you're already mid-deployment, we can help you figure out what makes sense for your situation. No two OT environments are the same, and we take your unique needs into account. Schedule a briefing with one of our experts and we'll help you build a plan that fits.