What is an OT SOC?

An OT SOC is a Security Operations Centre that continuously monitors an organisation’s operational technology and industrial control systems (ICS) for cyber threats, detects anomalies and coordinates the response with the people who run the process. Where a conventional SOC mainly watches office systems, servers and cloud workloads, an OT SOC looks at PLCs, SCADA servers, engineering workstations and industrial network protocols. The defining difference lies in its priorities: in OT, the safety of people and plant and the availability of the process always come first.


πŸ”„ What is the difference between an IT SOC and an OT SOC?

An OT SOC builds on the same principles as an IT SOC, but the environment, the data sources and above all the way it responds are very different.

Aspect IT SOC OT SOC
Assets Laptops, servers, cloud, identities PLCs, RTUs, HMIs, historians, engineering workstations
Protocols HTTP(S), DNS, SMB, Kerberos Modbus TCP, S7comm, EtherNet/IP, DNP3, OPC UA
Priority Confidentiality and integrity of data Safety, availability, integrity of the process
Detection source Agents (EDR), logs, identity platform Passive network monitoring, firewall and historian logs
Response Isolate the endpoint, disable the account Consult operations, bring the process to a safe state first
System lifetime 3–5 years 15–25 years, often unpatched

Many OT systems cannot run an agent and do not tolerate active scanning. An OT SOC therefore relies on listening to the network rather than on software installed on the systems themselves.


πŸ”§ Which sources give an OT SOC visibility of the plant?

The foundation is passive monitoring: a sensor receives a copy of network traffic from a SPAN port or a network TAP and dissects the industrial protocols using deep packet inspection. Specialised NDR platforms for OT include Nozomi Guardian, Claroty xDome, the Dragos Platform (which decodes more than 600 industrial protocols) and Tenable OT Security, which grew out of Tenable’s acquisition of Indegy in December 2019. These platforms build an asset inventory automatically and learn what normal traffic looks like.

Additional sources include:

  • Firewall and IDMZ logs β€” which connections between IT and OT are allowed or blocked
  • Windows event logs from SCADA servers, HMIs and engineering workstations
  • Syslog from industrial switches, routers and remote access solutions
  • Historian and alarm data β€” process deviations that may have a cyber cause
  • Remote access sessions β€” who connected to which installation, and when

All of these security monitoring events come together in a SIEM, often the same platform the IT SOC already uses. That allows analysts to follow an attack that starts with phishing in the office and works its way down the Purdue levels into the production network.


🎯 Which use cases and detections are typical for an OT SOC?

Detection in OT is less about malware signatures and more about deviations from a highly predictable baseline. Industrial networks are deterministic: the same devices talk to the same peers, day in, day out.

Use case What is detected ATT&CK for ICS
New device Unknown MAC or IP address on the process network T0864 Transient Cyber Asset
PLC program download Download or online edit outside a change window T0843 Program Download
Operating mode change PLC switched from RUN to PROGRAM or STOP T0858 Change Operating Mode
Firmware change New firmware version or firmware update mode Persistence / Inhibit Response Function
Unusual write commands Modbus function codes 5, 6, 15 or 16 from an unknown source T0836 Modify Parameter
Network scanning Scans or enumeration inside the OT network T0846 Remote System Discovery

The MITRE ATT&CK for ICS framework, published in January 2020, gives an OT SOC a shared vocabulary. It has 12 tactics, including the OT-specific Inhibit Response Function and Impair Process Control, which describe how attackers disable protective functions and manipulate the physical process, as seen with TRITON in 2017 and Industroyer in 2016. The team uses the framework to design detections, measure coverage and carry out focused threat hunting.


πŸ” How does an OT SOC respond to an incident?

In IT, isolating an infected machine is a standard reaction. In OT, blind isolation can be dangerous: pulling an HMI off the network leaves the operator without a view of a running process. An OT SOC therefore works with playbooks written together with operations. The SANS Five ICS Cybersecurity Critical Controls (2022) list an ICS-specific incident response plan as the very first control, alongside network visibility and monitoring.

A typical OT playbook covers:

  1. Triage by the SOC β€” was the event planned (change request, maintenance) or not?
  2. Contact with the shift operator or process engineer β€” through a fixed escalation line that is reachable 24/7
  3. Assess process impact β€” is there a risk to safety, the environment or production?
  4. Controlled containment β€” for example shutting down remote access or closing a conduit in the firewall, rather than isolating the PLC itself
  5. Safe state β€” when in doubt, operations decide, not the SOC, whether the process continues manually or is shut down
  6. Recovery and forensics β€” using known-good backups of PLC programs and configurations

🧱 Which staffing models are there?

Model Characteristics Suited to
In-house Own analysts with OT knowledge, 24/7 Large energy, chemical and water companies
MSSP External provider monitors sensors and SIEM Mid-sized organisations without their own SOC
Hybrid MSSP handles 24/7 first-line monitoring, internal OT team handles triage and response Organisations that want 24/7 coverage without a full in-house team

As a rule of thumb, a seat staffed around the clock requires five to six FTE: a year has 8,760 hours, while a full-time employee is productively available for roughly 1,500 to 1,700 hours after leave, training and sickness. For many organisations this is the reason to outsource first-line monitoring, while process knowledge and the decision to intervene stay in-house.


🏭 How do you build an OT SOC step by step?

  1. Visibility β€” deploy passive sensors on the most important network segments and build an asset inventory
  2. Baseline β€” let the NDR platform learn for a few weeks and tune out known noise
  3. Integration β€” feed the alerts into the SIEM and the ticketing process of the (IT) SOC
  4. Use cases β€” start with a small set of high-value detections: new device, program download, remote access outside working hours
  5. Playbooks β€” agree with operations who may intervene and how
  6. Exercises β€” run tabletop exercises with operations, IT and management
  7. Maturity β€” extend with threat hunting, threat intelligence and assessment against IEC 62443

Each step delivers value on its own: even without 24/7 monitoring, a reliable asset inventory and a list of unexpected connections often reveal forgotten remote access routes and unmanaged devices.


πŸ“‹ What do NIS2 and the Dutch Cybersecurity Act mean for an OT SOC?

The Cybersecurity Act (Cyberbeveiligingswet), the Dutch transposition of NIS2, has been in force since 15 August 2026. Essential and important entities must report a significant incident in three stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The clock starts when the organisation becomes aware of the incident. Reports go through the NCSC’s central reporting point and are forwarded to the sectoral CSIRT and the competent supervisor. Without an OT SOC, many organisations simply cannot recognise an incident in the production network within 24 hours, let alone assess it.


❓ Frequently asked questions

Does every organisation with OT need its own OT SOC?

No, a dedicated OT SOC mainly makes sense for large organisations running critical processes. Smaller organisations can buy OT SOC services from an MSSP, provided the provider understands OT protocols and agrees clear escalation and response arrangements with your operations team.

Can an existing IT SOC also monitor OT?

An existing IT SOC can monitor OT if it adds OT-specific sensors, use cases and playbooks and trains its analysts in industrial protocols. The biggest risk is an IT SOC without OT knowledge isolating systems too quickly. That is why an OT SOC is often set up as a specialised function within the existing SOC.

What tools does an OT SOC use?

An OT SOC usually relies on a passive NDR platform for industrial networks, such as Nozomi Networks, Claroty, Dragos or Tenable OT Security, combined with a SIEM and a ticketing system. It also collects logs from firewalls, Windows systems and remote access solutions.

Is passive monitoring safe for PLCs?

Passive monitoring is safe for PLCs because the sensor only receives a copy of the network traffic and never sends packets to the controllers itself. Some platforms also offer active querying; an OT SOC should only use it in a controlled way and in agreement with operations.

How much does an OT SOC cost?

The cost of an OT SOC consists of sensors and licences per site, SIEM capacity and, above all, people. A seat staffed 24/7 requires about five to six FTE, which is why many organisations choose a hybrid model with an MSSP for first-line monitoring.


πŸ“Œ In summary

An OT SOC monitors industrial control systems with passive network monitoring, OT-specific detections and playbooks agreed with operations, so that you spot attacks early without endangering the safety of the process. With the reporting obligations of NIS2 and the Dutch Cybersecurity Act, that visibility of OT is no longer a luxury but a precondition for reporting within 24 hours.