Resources · Glossary
OT security, in plain language.
39 terms that come up when you secure industrial control systems, from the Purdue model to zones and conduits.
- Air gap
-
Physical or logical isolation of a network from the internet and other untrusted networks. Many nuclear, defence, water and government sites require it by regulation or contract.
Synaptic OT is air-gap native: Tier 1 runs with zero internet connectivity.
Related: see how Synaptic OT handles this → - BACnet/IP
-
A protocol for building automation such as HVAC, lighting and access control.
- Baseline
-
A learned model of normal behaviour, such as which hosts talk, which function codes they use and the usual range of values, against which anomalies are measured.
- Configuration drift
-
Divergence between how a system was designed or approved and how it actually behaves or is configured, such as an unauthorised logic change or a new network path.
Synaptic OT detects drift by comparing approved project files with live traffic.
Related: see how Synaptic OT handles this → - CyOTE
-
Cybersecurity for the Operational Technology Environment, a U.S. Department of Energy programme whose Idaho National Laboratory corpus documents real OT incidents and their observables.
- Deep packet inspection (DPI)
-
Decoding network traffic beyond addresses and ports into protocol fields, for example the Modbus function code, register and value of a write.
- DNP3
-
Distributed Network Protocol 3, used heavily in electric and water utilities between control centres and outstations such as RTUs.
- Engineering workstation (EWS)
-
The computer engineers use to program PLCs and change control logic. Unexpected activity from an EWS is a high-value attack signal.
Synaptic OT lets you register authorised workstations and maintenance windows to tell planned work from attacks.
Related: see how Synaptic OT handles this → - EtherNet/IP
-
An industrial protocol carrying the Common Industrial Protocol (CIP) over Ethernet, widely used with Rockwell Automation and Allen-Bradley equipment.
- Evidence pack
-
A sealed bundle of packets, decodes, timelines and a signed manifest that shows what happened during an incident and that the evidence has not been altered.
Related: see how Synaptic OT handles this → - Human in the loop
-
A control design in which automated systems recommend actions but a person must approve them before anything changes. In running plants it prevents automated responses from causing outages or safety events.
- Human-machine interface (HMI)
-
The screen operators use to view and control a process. Good HMI practice shows normal states in grey and reserves colour for abnormal conditions.
- IEC 60870-5-104
-
A telecontrol protocol common in European and Middle Eastern power grids for communication between SCADA masters and substations.
- IEC 62443
-
The international series of standards for securing industrial automation and control systems, covering risk assessment (62443-3-2), system requirements (62443-3-3) and more.
- Indicator of compromise (IOC)
-
An observable artefact, such as an address, file hash or protocol pattern, that suggests malicious activity.
- Industrial control system (ICS)
-
The collection of control devices, networks and software that runs an industrial process, including SCADA, DCS and PLC-based systems.
- MITRE ATT&CK for ICS
-
A public knowledge base of adversary tactics and techniques used against industrial control systems.
- Modbus TCP
-
A simple, widely used industrial protocol with no built-in authentication or encryption. A single function code 06 write can change a setpoint on a controller.
- MQTT
-
A lightweight publish-subscribe messaging protocol widely used by IIoT sensors and brokers.
- MSSP
-
Managed security service provider: a company that monitors and manages security for multiple client organisations.
- NERC CIP
-
Mandatory Critical Infrastructure Protection standards for the North American bulk electric system.
- NESA (UAE IA)
-
The UAE Information Assurance standard, originally issued by the National Electronic Security Authority, that sets security controls for critical sectors in the UAE.
- Network TAP
-
A hardware device inserted on a network link that passes a copy of all traffic to a monitoring tool, without affecting the original traffic.
- NIS2
-
The EU directive on network and information security that raises cybersecurity and reporting obligations for essential and important entities, including energy, water and manufacturing.
- OPC UA
-
A modern, platform-independent industrial interoperability standard with optional security features and an audit-log mechanism.
- Operational technology (OT)
-
Hardware and software that monitors and controls physical processes, such as PLCs, RTUs, DCS, SCADA and safety systems, as opposed to information technology (IT) that handles data.
- OT intrusion detection system (OT IDS)
-
A system that monitors industrial network traffic for malicious or anomalous activity, using knowledge of industrial protocols rather than generic IT signatures.
Related: see how Synaptic OT handles this → - Passive monitoring
-
Observing network traffic without sending any packets to devices. In OT it avoids the risk of crashing fragile controllers that active scanning carries.
Synaptic OT is strictly passive and never sends packets to controllers.
Related: see how Synaptic OT handles this → - PCAP
-
The standard file format for recorded network packets, used for forensic analysis and replay.
- Programmable logic controller (PLC)
-
A ruggedised computer that reads sensors and drives actuators according to a control program. PLCs usually cannot run security agents, so they are protected through network monitoring.
Synaptic OT watches PLC traffic passively and compares program downloads against approved project files.
Related: see how Synaptic OT handles this → - Purdue model
-
A reference architecture that layers industrial networks from Level 0 (physical process) through Level 1 (basic control), Level 2 (supervisory), Level 3 (site operations) and a DMZ (Level 3.5) to Level 4 (enterprise IT).
- Remote terminal unit (RTU)
-
A field device that connects sensors and equipment at remote sites, such as substations or pumping stations, to a central SCADA system, often over DNP3 or IEC 60870-5-104.
- Retro-hunt
-
Searching previously recorded traffic for indicators that were only discovered later, to find out whether and when an intrusion began.
Related: see how Synaptic OT handles this → - S7comm
-
Siemens’ proprietary protocol for programming and communicating with S7 PLCs.
- SCADA
-
Supervisory control and data acquisition: software and networks that let operators monitor and control geographically spread equipment from a control centre.
- Security operations centre (SOC)
-
The team, processes and tools that monitor, investigate and respond to security events.
A virtual SOC lets a small team cover several plants from prepared cases.
Related: see how Synaptic OT handles this → - SPAN port
-
A switch feature that copies traffic from chosen ports to a monitoring port, so a sensor can observe network traffic without being in its path.
- Tamper-evident audit log
-
A log in which each record is cryptographically linked to the previous one, so any edit or deletion breaks the chain when it is verified.
Related: see how Synaptic OT handles this → - Zones and conduits
-
The IEC 62443 approach to segmentation: group assets into zones with common security requirements and allow communication only through defined conduits.
Related: see how Synaptic OT handles this →
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.