Managed OT Services vs In-House OT Security
Most plants do not have an OT security team to keep or to replace. The real decision is what the plant's own people should own, and what a managed service should carry for them.
The short answer
Keep process knowledge, safety authority, and risk acceptance in-house; they cannot be outsourced. Use managed OT services for what a plant cannot staff on its own: 24/7 coverage with an SLA, OT security expertise that does not walk out the door, one operating model across every site, and the documentation an audit will ask for. The best-run fleets combine the two, with the managed service operating as an extension of the plant team.
Side by side
The comparison assumes a multi-plant operator without a dedicated OT security team today, which is the common case in heavy industry.
| Decision criterion | In-house OT security | Managed OT services |
|---|---|---|
| Process and plant knowledge | Strongest | Learned from your team |
| 24/7 coverage with a response SLA | Needs 4 to 5 hires | Included |
| OT security expertise retention | Key-person risk | Team, not a person |
| Consistency across plants | Varies by site | One operating model |
| Monitoring tooling and upkeep | Buy, run, tune | Operated for you |
| Vendor and contractor coordination | Adds to plant workload | Brokered and recorded |
| Audit evidence and reporting | Often ad hoc | Weekly and per audit |
| Cost structure | Fixed headcount | Scoped per plant |
When each is the right call
Building in-house is right when
- The fleet is large enough to justify a dedicated OT security team with shift coverage, typically several major plants in one region.
- Regulation or corporate policy requires employees, not contractors, in specific security roles.
- OT security is already staffed and the gap is tooling, not people.
Managed OT services are right when
- No one on staff owns the control network today, which is the case at most cement, mining, and aggregates plants.
- Sites are many, small, or remote, and no single site can justify a security hire.
- You need a defined SLA, weekly reporting, and audit-ready documentation without building the function first.
- Plant E&I and IT are stretched, and adding OT security to their load means it does not get done.
The roles ISA/IEC 62443 expects on both sides
The standard assumes the asset owner keeps certain responsibilities regardless of who does the work, and sets requirements for the service providers who do it.
- Asset owner
- Owns the security program, risk acceptance, and safety authority. These stay in-house in every model.
- Who: Your plant and corporate leadership.
- Maintenance service provider
- Operates and maintains the system's security over its life: monitoring, patch coordination, access control, documentation. 62443-2-4 sets requirements for this role.
- Who: A managed OT service, or an in-house team if you have one.
- Product supplier
- Supports its own equipment. Works with whichever party holds the maintenance role.
- Who: Your automation OEMs.
Potenza's managed model is built as an operational extension of the asset owner's team, not a replacement for it: plant E&I keeps the process, Potenza carries the OT network layer, and escalation paths are written down.
FAQ
Questions operators ask about managed OT
Short answers. The longer ones come from a conversation about your plants. Reach out to our team.