Glossary

Defense-in-Depth

Defense-in-Depth is the practice of layering independent security controls so that no single failure exposes the process. In OT it typically combines network segmentation, governed access, hardened devices, monitoring, and response procedures.

The principle comes from military doctrine and is the organizing idea of NIST SP 800-82 and ISA/IEC 62443. Each layer assumes the one outside it may fail: if the firewall is misconfigured, segmentation still limits movement; if a controller is compromised, monitoring still detects the change.

For OT the layers are chosen for availability first. Controls that could interrupt a control loop, such as active scanning or agents on controllers, are avoided in favor of passive and architectural measures.

Why it matters in cement, mining, and aggregates

In practice the layers arrive in order: inventory and topology first, then segmentation, then governed access, then monitoring, then an accountable owner. A plant that jumps to monitoring without segmentation gets alerts it cannot act on.

See these terms applied to your plant

A scoped Topology Assessment turns the vocabulary into an inventory, a topology of record, and a segmentation plan for your own OT network.

Schedule a Conversation