Frequently asked questions about IoT, IoMT and OT Security
Answers about IoT, IoMT and OT Security
Production systems, medical devices and other connected OT/IoT systems often cannot be patched or replaced like traditional IT systems. Our FAQs answer questions about asset visibility, network segmentation and continuous monitoring, and how these measures can improve the security of IoT, OT, ICS and IoMT environments without putting operations and availability at risk.
In OT environments, availability, operational safety and often very long lifecycles are the main priorities. Systems often cannot simply be patched or replaced. Security measures must therefore take operational constraints into account and must not interfere with critical processes.
Key measures include network segmentation between IT and OT, dedicated monitoring solutions for OT protocols, virtual patching via firewalls/IPS, and strict access controls for remote maintenance access, also known as Secure Remote Access. An OT-specific risk assessment helps identify the most significant vulnerabilities.
Asset visibility is a key prerequisite for effective OT security. With suitable discovery and monitoring approaches, devices, communication relationships and potential risks can be identified without unnecessarily affecting ongoing operations.
Consistent segmentation between IT and OT is essential, as is the control of all necessary transitions between the environments. Access should be reduced to the required minimum, authenticated and monitored. In addition, continuous monitoring helps detect unusual communication patterns at an early stage.
Segmentation alone is not sufficient. Continuous monitoring is also required, ideally as Managed Detection & Response, in order to detect anomalies in real time. This is particularly important because attacks on critical infrastructures are often targeted and long-term, such as Advanced Persistent Threats.
Many IoMT devices have long lifecycles, limited update options or cannot be changed easily for operational and regulatory reasons. Compensating security measures are therefore especially important: complete visibility of devices and their communication, risk-based network segmentation, restrictive access controls and continuous monitoring for vulnerabilities and suspicious behaviour. Security must be improved without affecting availability and medical processes.
The basis is the most automated possible detection and classification of connected medical devices, including manufacturer, device type, communication behaviour, known vulnerabilities and network relationships. Based on this, risks can be prioritised and, for example, vulnerable devices or devices with unusual communication patterns can be specifically segmented and monitored. This allows the security team to focus on the IoMT risks with the greatest potential impact on clinical operations.