Insider Risk in OT: USB Drives, Laptops and Maintenance Windows
When people picture an insider threat, they often imagine a disgruntled employee deliberately sabotaging equipment. That does happen, but it is rare. Far more often, the risk comes from a trusted technician plugging in an infected USB drive, a contractor connecting a laptop that was last used at another client's site, or a rushed change during a maintenance window that nobody reviewed.
Accidental far more often than malicious
Control systems depend on people: operators, controls staff, maintenance technicians, integrators and vendor field service personnel. Many of them need hands-on access to the equipment, and many of them move between sites and organizations.
That access is necessary, and it is also where a lot of OT risk enters. The common patterns are familiar:
A USB drive used to transfer a program or collect logs also carries malware picked up elsewhere.
A vendor laptop with outdated patches and no endpoint protection is plugged directly into a control network.
A contractor's account remains active long after the project ends.
A change made under time pressure is not recorded, tested or reviewed.
Treating these as security failures by bad actors misses the point. They are process gaps that put good people in a position to make mistakes.
Transient devices: laptops and removable media
The North American electric sector has a useful term for this category. NERC CIP standards define Transient Cyber Assets as devices such as laptops that are connected to a protected network temporarily, typically for maintenance or troubleshooting, and Removable Media as portable storage such as USB drives. NERC CIP-010 sets out requirements for managing them at high and medium impact sites, and CIP-003 covers similar ground for low impact assets.
Even if you are not subject to NERC CIP, the concept is worth borrowing. Every device that comes and goes from your control network deserves the same basic questions:
Who owns it, and who is allowed to use it?
Is it patched and running up-to-date protection?
Has it been scanned before connecting?
What is it allowed to connect to, and for how long?
Many organizations solve the laptop problem by providing dedicated, company-owned maintenance laptops that never leave the site or never touch the corporate network, rather than allowing vendor machines to connect directly.
USB scanning kiosks and media controls

USB drives remain one of the most practical ways to move files in and out of isolated networks, which is exactly why they need controlling rather than banning outright. Outright bans tend to be quietly worked around.
A sensible approach includes:
Scanning stations or kiosks at the entrance to control areas, where any removable media is checked with multiple malware engines before use.
Approved, company-issued media for transfers into the control network, kept separate from personal or general-use drives.
Technical controls on HMIs and workstations that block unknown USB devices, or allow only approved ones.
Clear procedures for what to do when a scan finds something, so that staff report it instead of trying another drive.
Contractor onboarding and offboarding
Contractors and vendors are essential, but their access is often granted quickly and removed slowly, if at all. A consistent process helps.
At onboarding, confirm who the person is, what work they will do, which systems they need and for how long. Provide site-specific security expectations in plain language. Issue named accounts rather than shared logins, so activity can be traced.
At offboarding, disable accounts and remote access promptly, recover any company equipment or media, and change any shared credentials the contractor knew. A quarterly review of active accounts will usually turn up a few that should have been removed months ago.
Least privilege, supervised maintenance and change control
Least privilege simply means people get the access they need to do the job, and no more. A technician calibrating instruments does not need administrator rights on the historian server. A vendor supporting one packaged unit does not need visibility of the whole plant network.
Maintenance windows deserve particular attention. They are when the most changes happen, often by outside parties, under schedule pressure. Good practice includes:
Having a knowledgeable staff member present or monitoring remote sessions.
Agreeing the scope of work in advance and checking it afterwards.
Taking backups before changes and comparing controller logic afterwards.
Logging who connected, when, from what device and what they changed.
Change management is often seen as paperwork, but in OT it is one of the most effective security controls available. A simple, consistent process ensures changes are reviewed, tested where possible, recorded and reversible.
The key is making it workable. If the process is so heavy that people bypass it for small changes, it is not working. Emergency changes should be allowed, but recorded and reviewed after the fact.
Build a culture, not a blame game
The most important factor in insider risk is culture. People need to understand why the controls exist, and they need to feel safe reporting mistakes. A technician who plugs in an infected drive and reports it immediately has done the right thing. If the response is punishment, the next person will stay silent.
Awareness training tailored to OT roles, regular conversations between security and operations, and leaders who model good habits all help. Security works best when it is seen as part of doing the job safely, alongside lockout procedures and permits.
How QBits Networks can help
Our policy and procedure development work can help you put practical rules in place for removable media, transient devices, contractor access and change management, sized to how your sites actually operate. We also deliver awareness training built around the real situations operators, technicians and contractors face. Tell us what you need through our contact page and we'll scope it with you.