BPL Logo Banner
CareersContact

Managing an Operational Technology (OT) attack surface is one of the most critical challenges facing industrial and critical infrastructure organizations today. You invest heavily in building strong walls, robust firewalls, secure remote access, and clear segmentation between IT and OT networks. These are essential, but they primarily defend a well-understood perimeter.

But what if the biggest threat isn’t trying to break down the front gate, but is already slipping through an unlocked window? The reality is that your true attack surface is far larger and more complex than any network diagram. It includes your people, your physical sites, and your entire supply chain. To effectively defend it, you must first see it as an attacker does: a dynamic environment full of opportunities.

This complex, layered reality is perfectly captured by an old story. When asked what holds up the world, a wise woman replies, “It rests on the back of a giant turtle.” But what does that turtle stand on? “A bigger turtle.” And that one? You guessed it: it’s turtles all the way down.

This was the focus of a recent talk our own Ray Blasko gave at OT.SEC.CON. (You can watch the full presentation here.) In this four-part blog series, we’ll use this idea to help you visualize your own security stack and understand the risks. For this first post, we’ll introduce the stack and explain why a vulnerability in just one turtle can threaten the entire tower and your operations along with it.

OT Attack Surface Management: A Neat Stack Of Defensive Layers.

Imagine your Operational Technology (OT) environment in a similar way: a neat, orderly stack.

Defenses like perimeter firewalls and IT/OT segmentation are built around these layers. While essential, this view is dangerously incomplete because attackers don’t follow your blueprint.

The Traditional vs. True Attack Surface in OT Security

As defenders, you’re trained to build and maintain your organization’s strengths. An attacker, however, has a completely different mindset. They are trained to look for a single weakness they can exploit. While you see a fortress, they see a collection of potential entry points.

This is the true OT attack surface. It’s not just your external-facing assets. It’s everything. An attacker’s view of your environment includes vectors you might not actively monitor or defend against:

The scary part? These attacks don’t start at the top. They can give an attacker initial access to any layer, with any level of privilege.

Adopting an “Assumed Breach” Mindset

So, what do you do? You start thinking like an attacker.

In offensive security, we have a concept called “assumed breach”. Assume the attacker is already in. What happens next? Is it game over, or do you have defenses, monitoring, and response plans at every level to stop them from reaching their goal? This is the essence of a true defense-in-depth strategy.

Nothing is ever 100% secure, unless you’re willing to turn off all your machines, and we know that’s not an option for your customers. The only way to truly defend your organization is to understand your attack surface from an attacker’s perspective and build defenses accordingly. It’s time to look past the first turtle and ask what lies beneath.


Up Next: In our next post, we’ll dive deeper into the unseen risks that can compromise your network from within: Managing OT Supply Chain Security and Insider Threats.

Is your organization prepared to face the real attack surface? The offensive security experts at BreakPoint Labs can help you identify the weaknesses attackers see. Contact us today to learn more.

Author Image

About the Author

Ray Blasko is the Technical Director for offensive operations at BreakPoint Labs and a Red Team Operator for a DoD-certified Red Team, responsible for assessing and securing critical ICS/SCADA assets. He is recognized as a subject matter expert in both attacking and defending IT and OT environments, and he excels at resolving the technical and strategic issues that arise in protecting critical infrastructure. Ray holds numerous professional certifications and regularly presents at DoD Red Team conferences, trade conventions, and information security events.

chevron-down