
Industrial Cybersecurity: Why Connecting Your Factory to the Internet Creates a New Class of Risk

Rosie Nguyen
6 August 2026
Connecting factory OT systems to the internet exposes them to attack vectors they were never designed to resist. OT systems, including PLCs, SCADA controllers, and DCS platforms, were built for reliability and uptime, not security. Most run legacy operating systems that cannot be patched without halting production. Most operate on flat networks with no segmentation. A single intrusion can move laterally from an IT system to the factory floor in minutes, stopping production lines, damaging equipment, or triggering safety incidents. This guide covers the specific risks of OT connectivity, what a baseline security architecture looks like, and what Vietnamese manufacturers need to address before connecting operational systems to external networks.
Why OT Security Is a Different Problem from IT Security
IT security protects data. OT security protects physical processes.
In IT, a system can be taken offline for patching, rebooted after an incident, and restored from a backup. In OT, taking a PLC offline stops the line. Rebooting a SCADA system may require a full production restart. The tolerance for downtime is near zero. Standard IT security practices, such as frequent patching, endpoint agents, and regular restarts, do not apply directly to OT environments.
OT systems also have long operational lifespans. A factory floor may run PLCs installed 15 years ago on operating systems that have not received security updates for a decade. These systems were never designed to be internet-connected. Their security model assumed physical isolation. That assumption no longer holds when the same network carries both production control traffic and ERP integration, remote monitoring, or cloud data pipelines.
What Happens When OT and IT Networks Converge
Industry 4.0 connectivity, including IIoT sensors, ERP integration, remote maintenance access, and cloud data historians, requires OT and IT networks to exchange data. This convergence is operationally necessary. It also creates a new attack surface.
The risk is lateral movement. An attacker who gains access to the IT network through a phishing email, a compromised vendor credential, or a vulnerability in an internet-facing system can traverse to the OT network if the two are not properly segmented. Once in the OT network, the attacker has access to production control systems.
The consequences differ in kind from an IT breach. A ransomware attack on an IT system encrypts files. A ransomware attack on an OT system stops production. If the attacker understands the process, they can issue commands that damage equipment or create safety hazards. Recovery is measured in days or weeks, not hours.
Real incidents follow this pattern. The 2021 Colonial Pipeline attack began with a compromised VPN credential. The 2022 Nordex ransomware attack halted production at one of Europe's largest wind turbine manufacturers. In both cases, the entry point was an IT system. The operational impact was physical.
The Specific Risks for Vietnamese Factory OT Systems
Vietnamese manufacturers connecting OT systems for the first time face a particular combination of risks.
Legacy equipment without patch capability: Most factory floors in Vietnam's manufacturing sector run a mix of equipment ages. PLCs and controllers from the 2000s and early 2010s run operating systems with no available security updates. These cannot be patched. They can only be isolated.
Flat network architecture: Many factories built their OT networks for reliability, not segmentation. The engineering workstation that programs PLCs sits on the same network segment as the corporate email system. There is no firewall between them.
Remote access without controls: Remote maintenance access, opened during COVID and frequently never secured, is among the most common OT intrusion entry points. Many manufacturers have active remote access sessions with no multi-factor authentication, no session recording, and no time-limited access.
Third-party vendor access: Equipment vendors, system integrators, and maintenance contractors often have standing remote access to OT systems. Each is a potential entry point. Access granted for a specific project is frequently left open indefinitely.
What a Baseline OT Security Architecture Looks Like
The ISA/IEC 62443 standard is the reference framework for industrial cybersecurity. It defines security levels by zone and conduit. Each zone has a defined security requirement, and communication between zones passes through a conduit with specific controls.
In practice, a baseline architecture for a connected Vietnamese factory includes:
- Network segmentation: IT and OT networks separated by a firewall or DMZ. OT subnetworks further segmented by function, with production control separate from engineering workstations, separate from historian servers. No direct traffic between IT and OT without inspection.
- OT-specific monitoring: IT security tools do not understand OT protocols such as Modbus, PROFINET, EtherNet/IP, or DNP3. OT monitoring platforms passively observe OT traffic without disrupting production and detect anomalies based on process behavior.
- Remote access controls: All remote access through a jump server with multi-factor authentication. Session recording enabled. Time-limited access provisioned per session, not standing credentials. Vendor access reviewed and revoked when projects close.
- Asset inventory: A complete OT asset inventory covering every PLC, HMI, controller, and network device. Most factories do not have one. You cannot protect what you cannot see.
- Incident response plan specific to OT: Who is notified when a production system behaves anomalously? What is the procedure for isolating a compromised segment without stopping the entire line? Who has authority to take a PLC offline?
What Vietnamese Manufacturers Should Do First
Before connecting any OT system to an external network, complete three steps.
Map the network. Identify every device, every connection, and every point where IT and OT traffic currently intersects. Many manufacturers discover undocumented connections during this process.
Segment before connecting. Install a firewall or DMZ between IT and OT networks before enabling any Industry 4.0 connectivity. Data can flow through the DMZ. Direct traffic cannot.
Audit remote access. Identify every active remote access session to OT systems. Revoke standing vendor credentials. Implement MFA on all remaining access paths. This single step eliminates the most common entry vector.
These three steps do not require a large security budget. They require time, an accurate network diagram, and the authority to enforce access controls.
Frequently Asked Questions
What are the cybersecurity risks of connecting factory OT systems to the internet?
OT systems were designed for physical isolation, not network security. Connecting them to external networks exposes PLCs, SCADA, and DCS platforms to lateral movement from IT networks, ransomware, and remote access compromise. The consequences differ from IT breaches: production stops, equipment can be damaged, and safety systems can be affected. Recovery is measured in days or weeks.
What is the difference between OT security and IT security?
IT security protects data systems that can be patched, rebooted, and restored from backup with minimal operational impact. OT security protects physical production processes where downtime means lost production and equipment risk. OT systems run legacy software on long operational cycles, cannot tolerate the downtime required for standard patching, and use industrial protocols that IT security tools do not understand.
What is lateral movement in an OT cyberattack?
Lateral movement is the technique attackers use to move from an initial access point, typically an IT system, to a target OT network controlling production. If IT and OT networks are not segmented, an attacker who gains access through phishing or a compromised vendor credential can reach production control systems without any additional exploit.
What is the ISA/IEC 62443 standard for industrial cybersecurity?
ISA/IEC 62443 is the international reference standard for securing industrial control systems. It defines security levels by zone and specifies what controls govern communication between zones. It is the framework most commonly referenced in OT security assessments and the basis for most ICS security programs in manufacturing.
What should a Vietnamese manufacturer do before connecting OT systems to external networks?
Three steps before any external connectivity: map the OT network completely, segment IT and OT with a firewall or DMZ, and audit all remote access to revoke standing vendor credentials and implement multi-factor authentication. These steps address the three most common entry vectors without requiring significant budget.
What OT security monitoring tools are available?
OT-specific monitoring platforms such as Claroty, Dragos, and Nozomi Networks passively observe OT network traffic using industrial protocol awareness. They detect anomalies based on process behaviour rather than signature matching, without disrupting production. Standard IT security tools are not suitable for OT environments and can cause instability when deployed on legacy OT hardware.
Take the Next Step
Gradion works with manufacturers across Vietnam and Southeast Asia on OT security assessments, network segmentation, and ICS security programme design. Contact our team to start with a network mapping exercise.

About the author
Rosie Nguyen
Rosie Nguyen works at the intersection of Marketing, Communications, and meaningful Storytelling at Gradion. She covers leadership and scaling, writing for the founders and operators building across Asia.
Is your factory floor exposed?
We help manufacturers map OT/IT risk and design network segmentation before an intrusion reaches production.