
The first three parts of this series covered policy, network architecture and secure remote access. Those are long-term foundations. Building them takes months of budgeting, procurement and coordination with vendors, and attackers will not wait for your capital plan. Tactical remedies fill that gap. They are targeted measures with a modest cost and a large reduction in risk, applied while the strategic projects take shape. A later part of this series covers measures that cost nothing at all. The remedies below need some budget or vendor time, but not a program.
Ask your IT team or a third party to scan your public IP addresses for OT interfaces, and check search engines such as Shodan for your sites. In October 2025, the Canadian Centre for Cyber Security reported hacktivists tampering with internet-exposed controls at a water facility, an oil and gas company and a farm in Canada. Every one of those systems was reachable from the internet. The Cyber Centre calls removing that exposure the most effective defence. Count your exposed OT systems before you start and again when you finish, so you know the work achieved something.
Many legacy systems sit on flat networks with no filtering. A small industrial firewall with an allow-list of the traffic each system needs, and nothing else, is inexpensive compared with the consequence of compromise.
Vendors often install their own remote desktop tools or ask for port forwards. A single secured jump host with MFA and session logging gives you one controlled entry point while you procure a permanent remote access solution.
Back up BAS databases, controller programs and configurations, and keep a copy disconnected from the network. We have seen attackers erase every backup of a BAS and security system. A backup that has never been restored is a hope, not a control.
Microsoft ended support for Windows 10 on October 14, 2025, and many BAS front-ends still run it or older versions. Where you cannot upgrade, remove internet access, restrict network access to the systems the workstation serves, and enable application allow-listing.
Run a focused campaign with your vendors to replace default, shared and vendor-wide passwords across every site. Track it like any other work order.
Most OT applications and network devices can log authentication events. Forward them to a central location and alert on repeated failures. This gives you early warning without a full monitoring platform.
Start with systems whose manipulation would cause a safety event or a major operational impact, such as the central plant, fuel systems, life safety interfaces and access control. Then work down the list.
Tactical remedies buy you time. They do not buy you a program. Use the time to build the foundation the rest of this series describes.
They are targeted measures with a modest cost and a large reduction in risk, applied while the strategic projects take shape. They need some budget or vendor time, but not a program.
Start with systems whose manipulation would cause a safety event or a major operational impact, such as the central plant, fuel systems, life safety interfaces and access control. Then work down the list.
Ask your IT team or a third party to scan your public IP addresses for OT interfaces, and check search engines such as Shodan for your sites. Count your exposed OT systems before you start and again when you finish.
Actimeta is an OT cybersecurity company focused on smart buildings and critical infrastructure.