Skip to main content

Resources

OT Cybersecurity GlossaryThe words this field actually uses.

The OT cybersecurity glossary defines the operational technology and industrial control terms used across this site, from PLC and SCADA to the Purdue Model, IEC 62443 and MITRE ATT&CK for ICS.

A citation names the standard that defines a term; most terms have no single defining authority.

A

Air Gap
An air gap is the claim that a network has no connection to any other network. In practice, few industrial environments are genuinely air-gapped: remote support links, vendor access, transient laptops and removable media routinely cross the boundary, and the belief in the gap often outlives the gap itself.Used on: Threat Bulletin ZionSiphon
Asset Criticality
A measure of how important an asset is to an industrial process, production environment, safety function, or critical service. Mithryl uses operational context and criticality to help distinguish important security events from routine alerts.
Asset Discovery
The process of identifying devices, systems, applications, and infrastructure operating within an OT environment. Effective asset discovery helps organizations understand what exists, where it resides, how it communicates, and what operational function it supports.
Asset Inventory
A maintained record of OT assets, including PLCs, HMIs, engineering workstations, servers, network devices, sensors, and other cyber-physical systems. An accurate inventory provides a foundation for vulnerability management, detection, incident response, and risk management.
ATT&CK for ICS
The MITRE knowledge base describing adversary tactics and techniques observed against industrial control systems. It can be used to evaluate detection coverage, identify gaps, structure threat hunting, and improve OT detection engineering.— MITREUsed on: OT Detection Engineering, OT Digital Forensics, OT Red Team Assessments
Attack Path
The sequence of systems, identities, network connections, vulnerabilities, or trust relationships an adversary could use to move toward a critical asset or operational process.Used on: OT Red Team Assessments
Attack Surface
The collection of systems, interfaces, accounts, remote connections, applications, and other potential entry points that could be targeted within an IT/OT environment.
Augmented Intelligence
The combination of artificial intelligence, automation, analytics, and human expertise to improve security decisions. In Mithryl's model, technology accelerates analysis while experienced OT security professionals provide operational judgment and oversight.Used on: OT Managed Detection & Response

B

Baseline Behavior
A representation of normal communications, processes, asset activity, and system behavior within an OT environment. Deviations from established baselines can provide important detection and threat-hunting signals.
BESSBattery Energy Storage System
Technology used to store electrical energy for later use. BESS environments increasingly contain networked industrial control systems and represent an important area of OT cybersecurity.
Blind Spot
An asset, communication path, activity, or portion of the environment for which security teams lack sufficient visibility or telemetry.
Business Continuity
The ability of an organization to maintain essential operations during and after a disruptive event. OT cybersecurity contributes directly to continuity by protecting the systems supporting physical operations.

C

Chain of Custody
Chain of custody is the documented record of who held a piece of evidence, when, and what they did with it, unbroken from collection to disposition. Evidence without it may still be true and may still be inadmissible.Used on: OT Digital Forensics
Consequence Analysis
The process of determining what an incident could mean to production, safety, availability, quality, regulatory obligations, or other operational outcomes.
Consequence-Aware Response
Incident response that considers the operational consequences of a security action before it is taken. In OT, actions such as isolating or shutting down a system can themselves affect operations.
Control System
Technology used to monitor or control physical processes. Examples include PLCs, DCS platforms, SCADA systems, and safety systems.— NIST SP 800-82 Rev. 3
CPSCyber-Physical System
A system in which computing, networking, and software interact directly with physical equipment or processes.
Critical Infrastructure
Systems and assets whose disruption could significantly affect public safety, economic activity, national security, or essential services. Examples include energy, water, transportation, manufacturing, and communications.— 42 U.S.C. 5195c(e)Used on: OT Managed Detection & Response
CSFNIST Cybersecurity Framework
A framework for managing cybersecurity risk organized around cybersecurity outcomes.— NIST
Cyber Fusion
The integration of security telemetry, threat intelligence, identity information, operational context, human expertise, and organizational workflows to create a more complete understanding of cyber events.Used on: OT Cyber Fusion Strategies
Cyber Fusion Strategy
An operating model that brings together previously separated security and operational information so organizations can make faster, better-informed decisions across IT and OT.Used on: OT Cyber Fusion Strategies

D

Data Historian
A system that collects and stores time-series data generated by industrial processes and equipment. Historians can contain valuable operational information and may also provide useful forensic or investigative evidence.— NIST SP 800-82 Rev. 3
DCSDistributed Control System
A control architecture commonly used in industrial facilities in which multiple controllers manage portions of a physical process.— NIST SP 800-82 Rev. 3
Detection Coverage
The degree to which security monitoring and detection capabilities can identify relevant adversary behaviors across an OT environment.Used on: OT Detection Engineering
Detection Engineering
The disciplined process of designing, developing, testing, validating, tuning, and maintaining security detections.Used on: OT Detection Engineering, OT Managed Detection & Response
Digital Forensics
The preservation, acquisition, examination, and analysis of digital evidence to understand an incident while maintaining evidence integrity and chain of custody.— NIST SP 800-86Used on: OT Digital Forensics
DNP3Distributed Network Protocol 3
An industrial communications protocol commonly used in electric utilities and other infrastructure environments.— IEEE 1815 / DNP Users Group
Downtime
A period during which equipment, systems, processes, or production capabilities are unavailable. Reducing the probability and duration of cyber-related downtime is a major objective of OT cybersecurity.Used on: OT Incident Response
Dwell Time
Dwell time is the interval between an attacker gaining access and being detected. In industrial environments it is often measured in months, because the telemetry that would reveal the intrusion is either not collected or not examined.Used on: OT Managed Detection & Response

E

EDREndpoint Detection and Response
Security technology that monitors endpoint activity and supports detection, investigation, and response. In converged environments, EDR information can contribute to a broader understanding of incidents affecting OT.
Engineering WorkstationEngineering Workstation
A workstation used to configure, program, maintain, or troubleshoot industrial control equipment such as PLCs.Used on: OT Red Team Assessments
Evidence Integrity
The preservation of digital evidence in a manner that maintains its authenticity and reliability throughout an investigation.
External Access
Connectivity into an OT environment originating outside the operational network, including vendor, contractor, cloud, partner, and remote support connections.

F

False Positive
An alert that identifies activity as suspicious or malicious when the underlying activity is legitimate.
Field Device
A device that interacts directly with an industrial process, such as a sensor, actuator, transmitter, or intelligent electronic device.— NIST SP 800-82 Rev. 3
Forensic Acquisition
The process of collecting digital evidence from systems or devices in a controlled manner for forensic analysis.
Forensic Readiness
The preparation of people, processes, tools, evidence sources, and procedures before an incident occurs so investigations can begin quickly and safely.

G

Gap Analysis
The process of comparing existing security capabilities against desired controls, detection coverage, frameworks, or operational requirements to identify deficiencies.
Governance
The policies, decision structures, accountability mechanisms, and oversight processes used to manage cybersecurity risk.Used on: OT vCISO Services
Guided Investigation
An investigation process that brings relevant telemetry, context, analytical steps, and expert guidance together to help analysts determine what occurred and what should happen next.

H

Historian
A historian is a time-series database that records process values (temperatures, pressures, flows, tag states) over long periods. In an investigation it is often the only record of what the process was actually doing, which makes it both a forensic asset and a target.Used on: OT Digital Forensics
HMIHuman-Machine Interface
The interface through which operators monitor and interact with industrial equipment and processes.— NIST SP 800-82 Rev. 3Used on: OT Digital Forensics
Human Guided Response
A response approach in which security technologies provide analysis and recommendations while experienced personnel evaluate operational impact before disruptive actions are taken.
Human in the Loop
An operating model in which human experts retain oversight of important decisions while automation and AI accelerate analysis and workflows. This is particularly important in OT environments where response actions can affect physical processes.

I

ICSIndustrial Control System
A broad category of systems used to control industrial processes, including PLCs, SCADA systems, DCS platforms, HMIs, and associated infrastructure.— NIST SP 800-82 Rev. 3Used on: OT Detection Engineering, OT Digital Forensics, OT Red Team Assessments, Threat Bulletins
IEC 62443
A family of international standards addressing cybersecurity for industrial automation and control systems.— International Society of Automation / IECUsed on: OT vCISO Services
Industrial Protocol
A communications protocol designed for industrial systems. Examples include Modbus, DNP3, OPC UA, EtherNet/IP, and Siemens S7 communications.
IRIncident Response
The coordinated process used to investigate, contain, remediate, and recover from cybersecurity incidents.Used on: OT Incident Response
IT/OT Convergence
The increasing interconnection between enterprise information technology and operational technology environments.Used on: OT Cyber Fusion Strategies

J

Jump Host
A controlled intermediary system used to access another network or security zone. Jump hosts are commonly used to manage administrative or engineering access into OT environments.
Just-in-Time Access
An access-control approach in which privileged access is granted only when required and for a limited period.

K

Known Asset
An OT asset that has been identified, inventoried, and incorporated into the organization's monitoring and security processes.
Known Vulnerability
A publicly or internally identified weakness affecting a system, device, application, firmware version, or other technology component.

L

Lateral Movement
Techniques used by an adversary to move from one compromised system to other systems within an environment.— MITRE ATT&CK for ICS
Legacy System
Older hardware or software that remains operational because of process dependencies, equipment lifecycles, certification requirements, or replacement constraints.
Log Analysis
The examination and correlation of system, security, network, authentication, and application logs to identify suspicious activity and reconstruct events.

M

MDRManaged Detection and Response
A managed cybersecurity service combining continuous monitoring, detection, investigation, and response expertise.Used on: OT Managed Detection & Response
MESManufacturing Execution System
Software used to monitor, coordinate, document, and manage manufacturing processes and production activities.— ANSI/ISA-95 (IEC 62264)
Mithryl
A name representing strength without burden, reflecting the idea that cybersecurity should strengthen critical operations without creating unnecessary complexity, friction, or operational disruption. It is the foundation of the Mithryl Systems brand and its approach to protecting critical infrastructure.
MITRE ATT&CK for ICS
A structured knowledge base of adversary behaviors relevant to industrial control systems that can support threat modeling, detection engineering, hunting, and security assessments.— MITREUsed on: OT Detection Engineering, OT Digital Forensics, OT Red Team Assessments
Modbus
A widely used industrial communications protocol that enables communications between industrial devices and control systems.— Modbus OrganizationUsed on: OT Detection Engineering

N

NERC CIPCritical Infrastructure Protection
The North American Electric Reliability Corporation Critical Infrastructure Protection standards governing cybersecurity requirements for portions of the North American bulk electric system.— North American Electric Reliability CorporationUsed on: OT vCISO Services
Network Segmentation
The separation of networks into controlled zones to restrict communications, limit exposure, and reduce potential attack paths.
NIST SP 800-82
NIST guidance addressing the security of operational technology environments.— NIST
Non-Invasive Monitoring
Security monitoring designed to observe OT environments without interfering with industrial processes or introducing unnecessary operational risk.

O

OPC UAOpen Platform Communications Unified Architecture
A platform-independent communications standard widely used for exchanging industrial data between devices, applications, and systems.— OPC Foundation / IEC 62541
Operational Consequence
The effect that a cyber event or response action could have on production, availability, process integrity, safety, quality, or other operational outcomes.
Operational Context
Information describing how a cyber event relates to assets, processes, dependencies, engineering workflows, production, safety, and business operations. Operational context is central to Mithryl's approach because cybersecurity significance cannot always be determined from technical telemetry alone.
Operational Intelligence
Cybersecurity information enriched with operational context so security teams and operational leaders can make informed decisions.Used on: Operational Intelligence for Critical Infrastructure, OT Managed Detection & Response, OT Cyber Fusion Strategies
Operational Resilience
The ability to prepare for, withstand, respond to, and recover from disruptive events while maintaining or restoring critical operations.Used on: OT Managed Detection & Response, OT Cyber Fusion Strategies
OTOperational Technology
Hardware and software that monitors or controls physical equipment, processes, and environments.— NIST SP 800-82 Rev. 3Used on: OT Managed Detection & Response, OT Cyber Fusion Strategies
OT MDROperational Technology Managed Detection and Response
A managed detection and response capability designed specifically for operational environments. Mithryl OT MDR combines 24x7x365 monitoring, OT-native expertise, cyber fusion, Augmented Intelligence, and operational context to help organizations determine what is happening, what matters, what could affect operations, and what action should come next.Used on: OT Managed Detection & Response
OT XDR
An extended detection and investigation capability adapted to converged IT/OT environments. In the Mithryl architecture, it connects detection intake, signal triage, guided investigation, operational context, compliance-aware workflows, and escalation while integrating with existing customer technologies.

P

Passive Monitoring
The observation of network communications without actively querying or interacting with industrial devices.
PLCProgrammable Logic Controller
An industrial computer used to automate and control machinery and physical processes.— NIST SP 800-82 Rev. 3Used on: OT Digital Forensics, BAUXITE PLC Campaign
Process Integrity
The assurance that an industrial process operates according to intended parameters, logic, and control conditions.
Production Continuity
The ability to maintain manufacturing or industrial operations despite cybersecurity events, equipment failures, or other disruptions.
Purdue Awareness
Understanding where systems and communications exist within an industrial architecture and how security activity at one level may affect systems and processes at another.
Purdue Model
A hierarchical model commonly used to describe the relationship between enterprise, supervisory, control, and industrial process systems.— Purdue Enterprise Reference Architecture, Purdue UniversityUsed on: OT Incident Response

Q

Quality Impact
A potential consequence in which a cyber event affects product specifications, process consistency, manufacturing quality, or other operational quality measures.
Quality of Detection
The effectiveness and relevance of security detections, including their ability to identify meaningful adversary activity while minimizing unnecessary noise.

R

Recovery
The process of restoring systems, processes, and operations following a cybersecurity incident or disruption.
Red Team Assessment
An authorized exercise that emulates realistic adversary behavior to evaluate security controls, detection capabilities, investigation processes, and response readiness.Used on: OT Red Team Assessments
Remote Access
Connectivity that allows personnel, vendors, contractors, or systems to access OT environments from another location or network.— NIST SP 800-82 Rev. 3
Response Playbook
A documented set of procedures and decision points used to guide investigation and response to particular types of security incidents.
Risk Assessment
The process of identifying threats, vulnerabilities, potential consequences, and existing controls to understand cybersecurity risk.— NIST SP 800-82 Rev. 3Used on: OT Red Team Assessments
RTURemote Terminal Unit
A Remote Terminal Unit is a field device that collects sensor data at a remote site and relays it to a supervisory system, typically over a wide-area link. RTUs are common at substations, wellheads and pump stations, where a full controller would be excessive but telemetry is still required.— NIST SP 800-82 Rev. 3

S

S7
A family of Siemens industrial technologies and associated communications commonly found in automation environments.
Safety-First Response
An OT incident-response principle that evaluates potential effects on people, equipment, and industrial processes before disruptive containment actions are performed.
SCADASupervisory Control and Data Acquisition
Systems used to monitor and control geographically distributed or industrial processes.— NIST SP 800-82 Rev. 3Used on: OT Red Team Assessments
Security Telemetry
Data generated by security tools, endpoints, networks, applications, identities, and industrial systems that can be analyzed for suspicious activity.
SIEMSecurity Information and Event Management
Technology that collects, normalizes, correlates, and analyzes security information from multiple sources.
SISSafety Instrumented System
A specialized control system designed to place an industrial process into a safe state when predetermined unsafe conditions are detected.— NIST SP 800-82 Rev. 3

T

Telemetry Gap
A situation in which an asset is known but does not provide sufficient security data for effective monitoring or investigation.
Threat Hunting
The proactive search for evidence of adversary activity that may not have generated an existing security alert.Used on: OT Managed Detection & Response
Threat Intelligence
Information about threat actors, campaigns, techniques, infrastructure, vulnerabilities, and indicators that can improve detection and investigation.
Threat Modeling
The structured analysis of potential adversaries, attack paths, targets, consequences, and defensive controls.
TSA Security Directives
Cybersecurity requirements issued by the Transportation Security Administration for certain regulated transportation and pipeline operators.— Transportation Security Administration

U

Unified Defense
An approach that connects previously separated security capabilities, telemetry, teams, and operational context to provide a more complete understanding of threats to critical systems.
Unknown Asset
A device or system operating within the environment that has not yet been properly identified, inventoried, classified, or incorporated into security monitoring.
Uptime
The amount of time a system, process, or facility remains available and operational.Used on: OT Managed Detection & Response

V

vCISOVirtual Chief Information Security Officer
A fractional cybersecurity leadership service providing strategic guidance, governance, program development, risk management, compliance support, and executive advisory capabilities.Used on: OT vCISO Services, OT Cyber Fusion Strategies
Visibility
The ability to observe assets, communications, identities, behaviors, dependencies, and activity across an environment.
Visibility Gap
An area in which security teams lack sufficient information to understand assets, communications, or activity.Used on: OT Detection Engineering
Vulnerability Management
The continuous process of identifying, assessing, prioritizing, mitigating, and tracking vulnerabilities.

W

Workaround
A temporary operational or technical measure used to reduce risk when a permanent remediation cannot immediately be implemented, a common consideration in OT environments where patching or system changes may require planned outages.
Workflow
A defined sequence of analytical, investigative, escalation, approval, or response activities used to manage a security event.
Workstation, Engineering
A system used by engineers or technicians to configure, program, troubleshoot, or maintain industrial systems.

X

XDRExtended Detection and Response
A security approach that brings together information from multiple detection sources to improve investigation and response.

Y

Yield Impact
The potential effect of a cyber event on the quantity or quality of usable output produced by an industrial process.
Yield Protection
Security and resilience practices intended to reduce the possibility that cyber events, system manipulation, or response actions negatively affect production output.

Z

Zero Trust
A security model based on continuously evaluating access rather than automatically trusting users, systems, or network locations.— NIST SP 800-207
Zone
A logical or physical grouping of systems with similar security, operational, or functional requirements. Zones are an important concept within industrial cybersecurity architectures such as IEC 62443.— ISA/IEC 62443-1-1
Zone and Conduit Model
An IEC 62443 architectural concept that groups assets with similar security requirements into zones and defines controlled communication paths, or conduits, between those zones.— ISA/IEC 62443-1-1

Ready to Strengthen Operational Confidence?