Resources · Glossary
OT security, in plain language.
46 terms that come up when you secure industrial control systems, from the Purdue model to zones and conduits.
- Air gap
-
Physical or logical isolation of a network from the internet and other untrusted networks. Many nuclear, defence, water and government sites require it by regulation or contract.
Synaptic OT is air-gap native: Tier 1 runs with zero internet connectivity.
Related: see how Synaptic OT handles this → - BACnet/IP
-
A protocol for building automation such as HVAC, lighting and access control.
- Baseline
-
A learned model of normal behaviour, such as which hosts talk, which function codes they use and the usual range of values, against which anomalies are measured.
- CER Directive
-
The EU Critical Entities Resilience Directive, which requires designated critical entities in sectors such as energy, transport, water and health to assess risks and strengthen their resilience against disruption, including cyber incidents.
Related: see how Synaptic OT handles this → - CERT-In
-
The Indian Computer Emergency Response Team, whose directions set incident-reporting and log-retention obligations for organisations in India.
Related: see how Synaptic OT handles this → - Configuration drift
-
Divergence between how a system was designed or approved and how it actually behaves or is configured, such as an unauthorised logic change or a new network path.
Synaptic OT detects drift by comparing approved project files with live traffic.
Related: see how Synaptic OT handles this → - Cyber Resilience Act (CRA)
-
An EU regulation that sets cybersecurity requirements for products with digital elements, including vulnerability handling, security updates and software bills of materials, phased in from 2026.
- CyOTE
-
Cybersecurity for the Operational Technology Environment, a U.S. Department of Energy programme whose Idaho National Laboratory corpus documents real OT incidents and their observables.
- Deep packet inspection (DPI)
-
Decoding network traffic beyond addresses and ports into protocol fields, for example the Modbus function code, register and value of a write.
- DNP3
-
Distributed Network Protocol 3, used heavily in electric and water utilities between control centres and outstations such as RTUs.
- Engineering workstation (EWS)
-
The computer engineers use to program PLCs and change control logic. Unexpected activity from an EWS is a high-value attack signal.
Synaptic OT lets you register authorised workstations and maintenance windows to tell planned work from attacks.
Related: see how Synaptic OT handles this → - EtherNet/IP
-
An industrial protocol carrying the Common Industrial Protocol (CIP) over Ethernet, widely used with Rockwell Automation and Allen-Bradley equipment.
- Evidence pack
-
A sealed bundle of packets, decodes, timelines and a signed manifest that shows what happened during an incident and that the evidence has not been altered.
Related: see how Synaptic OT handles this → - Human in the loop
-
A control design in which automated systems recommend actions but a person must approve them before anything changes. In running plants it prevents automated responses from causing outages or safety events.
- Human-machine interface (HMI)
-
The screen operators use to view and control a process. Good HMI practice shows normal states in grey and reserves colour for abnormal conditions.
- IEC 60870-5-104
-
A telecontrol protocol common in European and Middle Eastern power grids for communication between SCADA masters and substations.
- IEC 62443
-
The international series of standards for securing industrial automation and control systems, covering risk assessment (62443-3-2), system requirements (62443-3-3) and more.
- Indicator of compromise (IOC)
-
An observable artefact, such as an address, file hash or protocol pattern, that suggests malicious activity.
- Industrial control system (ICS)
-
The collection of control devices, networks and software that runs an industrial process, including SCADA, DCS and PLC-based systems.
- KRITIS
-
Germany’s term for critical infrastructure. Under the BSI Act, KRITIS operators must deploy systems for attack detection and are audited on it.
Synaptic OT provides passive OT attack detection, logging and incident evidence.
Related: see how Synaptic OT handles this → - MITRE ATT&CK for ICS
-
A public knowledge base of adversary tactics and techniques used against industrial control systems.
- Modbus TCP
-
A simple, widely used industrial protocol with no built-in authentication or encryption. A single function code 06 write can change a setpoint on a controller.
- MQTT
-
A lightweight publish-subscribe messaging protocol widely used by IIoT sensors and brokers.
- MSSP
-
Managed security service provider: a company that monitors and manages security for multiple client organisations.
- NCA OTCC
-
The Operational Technology Cybersecurity Controls issued by Saudi Arabia’s National Cybersecurity Authority for organisations operating industrial control systems.
Related: see how Synaptic OT handles this → - NCSC Cyber Assessment Framework (CAF)
-
The UK National Cyber Security Centre’s outcome-based framework used to assess operators under the UK NIS Regulations.
Related: see how Synaptic OT handles this → - NERC CIP
-
Mandatory Critical Infrastructure Protection standards for the North American bulk electric system.
- NESA (UAE IA)
-
The UAE Information Assurance standard, originally issued by the National Electronic Security Authority, that sets security controls for critical sectors in the UAE.
- Network TAP
-
A hardware device inserted on a network link that passes a copy of all traffic to a monitoring tool, without affecting the original traffic.
- NIS2
-
The EU directive on network and information security that raises cybersecurity and reporting obligations for essential and important entities, including energy, water and manufacturing.
- OPC UA
-
A modern, platform-independent industrial interoperability standard with optional security features and an audit-log mechanism.
- Operational technology (OT)
-
Hardware and software that monitors and controls physical processes, such as PLCs, RTUs, DCS, SCADA and safety systems, as opposed to information technology (IT) that handles data.
- OT intrusion detection system (OT IDS)
-
A system that monitors industrial network traffic for malicious or anomalous activity, using knowledge of industrial protocols rather than generic IT signatures.
Related: see how Synaptic OT handles this → - Passive monitoring
-
Observing network traffic without sending any packets to devices. In OT it avoids the risk of crashing fragile controllers that active scanning carries.
Synaptic OT is strictly passive and never sends packets to controllers.
Related: see how Synaptic OT handles this → - PCAP
-
The standard file format for recorded network packets, used for forensic analysis and replay.
- Programmable logic controller (PLC)
-
A ruggedised computer that reads sensors and drives actuators according to a control program. PLCs usually cannot run security agents, so they are protected through network monitoring.
Synaptic OT watches PLC traffic passively and compares program downloads against approved project files.
Related: see how Synaptic OT handles this → - Purdue model
-
A reference architecture that layers industrial networks from Level 0 (physical process) through Level 1 (basic control), Level 2 (supervisory), Level 3 (site operations) and a DMZ (Level 3.5) to Level 4 (enterprise IT).
- Remote terminal unit (RTU)
-
A field device that connects sensors and equipment at remote sites, such as substations or pumping stations, to a central SCADA system, often over DNP3 or IEC 60870-5-104.
- Retro-hunt
-
Searching previously recorded traffic for indicators that were only discovered later, to find out whether and when an intrusion began.
Related: see how Synaptic OT handles this → - S7comm
-
Siemens’ proprietary protocol for programming and communicating with S7 PLCs.
- SCADA
-
Supervisory control and data acquisition: software and networks that let operators monitor and control geographically spread equipment from a control centre.
- Security operations centre (SOC)
-
The team, processes and tools that monitor, investigate and respond to security events.
A virtual SOC lets a small team cover several plants from prepared cases.
Related: see how Synaptic OT handles this → - Software bill of materials (SBOM)
-
A machine-readable inventory of the components inside a piece of software, used to track vulnerabilities and licences. CycloneDX and SPDX are the common formats.
Synaptic OT ships CycloneDX 1.5 and SPDX 2.3 SBOMs with every release.
Related: see how Synaptic OT handles this → - SPAN port
-
A switch feature that copies traffic from chosen ports to a monitoring port, so a sensor can observe network traffic without being in its path.
- Tamper-evident audit log
-
A log in which each record is cryptographically linked to the previous one, so any edit or deletion breaks the chain when it is verified.
Related: see how Synaptic OT handles this → - Zones and conduits
-
The IEC 62443 approach to segmentation: group assets into zones with common security requirements and allow communication only through defined conduits.
Related: see how Synaptic OT handles this →
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.