top of page

Patching in OT: Compensating Controls When You Can't Patch

7 days ago
4 min read

In corporate IT, the advice is simple: patch quickly and patch often. In a plant, a pipeline control room or a water treatment facility, that advice runs into hard realities, because patches can take months to qualify, some systems cannot be rebooted outside a turnaround, and some cannot be patched at all. That does not mean nothing can be done; it means OT patching needs a different approach, built on risk-based priorities and solid compensating controls.

Why patching is hard in OT

Several factors combine to make OT patching slower and more complicated than IT patching:

  • Vendor qualification: many control system vendors test operating system and application patches against their software before approving them. Applying an unapproved patch can break functionality or void support.

  • Downtime: installing a patch often requires a reboot, and rebooting a server or controller that runs a continuous process may mean stopping production.

  • Legacy operating systems: HMIs and servers still running Windows XP or Windows 7 are common in industrial settings. Microsoft ended support for Windows XP in 2014 and for Windows 7 in 2020, so no regular security updates are available for most of these systems.

  • Certification and validation: in regulated industries, and for safety instrumented systems, changes may require formal revalidation or recertification.

  • Embedded firmware: updating PLC, relay or RTU firmware is often a hands-on job at the device, sometimes requiring a site visit and a process outage.

  • Limited test environments: few sites have a full replica of their control system to test patches on before rollout.

The result is that many OT environments carry known vulnerabilities for long periods. The goal is to manage that risk deliberately rather than ignore it.

Prioritize by risk, not by volume

Diagram: exposure, exploitability (CISA KEV) and consequence combine into a priority; high priority gets compensating controls now and a patch in the next window
Rank vulnerabilities by exposure, evidence of exploitation and consequence; use compensating controls until a patch can be applied safely.

Vulnerability scanners and advisories can produce hundreds of findings. Treating them all as urgent leads to paralysis. A more useful approach weighs three factors:

  1. Exposure: can an attacker actually reach the vulnerable system? A device reachable from the internet or the corporate network is in a very different position from one deep inside a well-segmented zone.

  2. Exploitability: is there evidence the vulnerability is being exploited, or public exploit code available? CISA's Known Exploited Vulnerabilities (KEV) catalog is a practical reference here, because it lists vulnerabilities with evidence of exploitation in the wild.

  3. Consequence: what would happen if the system were compromised? A plain-language answer is often the clearest: ask operations what the process would do if this HMI, server or controller stopped working or behaved incorrectly.

A vulnerability in the KEV catalog, on an internet-facing remote access appliance that protects a critical process, belongs at the top of the list. A theoretical flaw on an isolated, low-consequence device can usually wait for the next planned window.

An accurate asset inventory makes this possible. Without one, you cannot tell which advisories even apply to you.

Compensating controls when you can't patch

When a patch is not available, not approved or not practical yet, compensating controls reduce the chance that a vulnerability can be exploited, or limit the damage if it is.

Reduce exposure

  • Remove internet exposure: no OT device should be directly reachable from the internet. This single step removes a large share of real-world risk.

  • Segmentation: place vulnerable systems in tightly controlled zones, with firewall rules that allow only the specific traffic they need.

  • Restrict remote access: route all remote sessions through a hardened gateway in the DMZ with multi-factor authentication.

Harden the system itself

  • Disable unneeded services: turn off protocols and services that are not required, such as file sharing, remote desktop or web interfaces nobody uses.

  • Application allow-listing: on Windows-based HMIs and servers, allow only approved software to run. This is often well suited to OT hosts, which run a stable, predictable set of applications.

  • Hardened configurations: remove default accounts, change default passwords, and apply vendor-recommended security settings.

Watch and control what comes in

  • Network monitoring: passive OT monitoring can detect unusual connections, new devices or attempts to exploit known vulnerabilities.

  • Removable media control: USB drives are a well-known route into isolated networks. Use scanning stations, approved media and clear procedures for anything brought onto site.

Document each compensating control against the vulnerability it addresses, so the reasoning is clear to auditors, insurers and future staff.

Plan patches into turnarounds

Compensating controls buy time; they do not replace patching. Build a patch plan that fits the operational calendar:

  • Maintain a running list of approved patches and firmware updates, ranked by risk

  • Align installation with scheduled turnarounds, shutdowns and maintenance windows

  • Prepare in advance: test where possible, take backups, confirm rollback steps and book vendor support

  • Verify after installation that the process, HMIs, alarms and historians all work as expected

  • Update the asset inventory with new versions once work is complete

For systems that will never receive another patch, such as those on unsupported operating systems, plan for replacement and include it in capital budgets.

Work with your vendors

Vendors are central to OT patching. Ask them for their patch qualification schedule and how they communicate approved updates. Subscribe to their security advisories and to CISA's ICS advisories. When buying new systems, make security update support, timelines and end-of-life commitments part of the contract.

How QBits Networks can help

Our OT security assessments identify which vulnerabilities matter most in your environment, based on real exposure and consequence rather than raw scanner output. Our network segmentation reviews then help you put practical compensating controls in place while patches work their way through qualification and planned outages. Tell us what you need through our contact page and we'll scope it with you.

bottom of page