← Latest papers
💻 computer science

Cyber security of OT networks: A tutorial, survey of attacks and overview of current state of defense tools, protocols, & challenges

This paper provides a comprehensive tutorial and survey on OT/IT cybersecurity, synthesizing attack taxonomies, defensive technologies, a quantified historical record of 69 incidents, and the global regulatory landscape to guide investment and resilience strategies for critical infrastructure.

Original authors: Sarthak Kapoor, Sumit Kumar, Harsh Vardhan, Daniel Balasubramanian, Sandeep Neema

Published 2026-07-14
📖 7 min read🧠 Deep dive

Original authors: Sarthak Kapoor, Sumit Kumar, Harsh Vardhan, Daniel Balasubramanian, Sandeep Neema

Original paper dedicated to the public domain under CC0 1.0 (http://creativecommons.org/publicdomain/zero/1.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the world's critical machines—power plants, water treatment facilities, hospital life-support systems, and car factories—as a giant, ancient castle. For decades, this castle had a thick, impenetrable moat separating the "Office Tower" (where emails and spreadsheets live) from the "Workshop" (where the real, physical machines run). The Workshop was safe because no one could get in; it was air-gapped, meaning it was physically cut off from the outside world.

But recently, the castle architects decided to build a glass bridge between the Office and the Workshop to make things run smoother. They called this Industry 4.0. While this bridge allowed for cool new things like predicting when a machine would break before it actually did, it also accidentally left the front door of the Workshop wide open to hackers.

This paper is a massive detective report that looks at what happened when that glass bridge was built, how the bad guys crossed it, and just how much money it cost the good guys to fix the mess.

The Main Discovery: The "Office" is the Weak Link

The biggest surprise in this report is that the most dangerous attacks don't usually start by hacking the machine itself. Instead, the hackers start in the Office Tower.

Think of it like this: A hacker sends a fake email to a factory manager (Phishing). The manager clicks a link, and the hacker gets a key to the Office. From there, they walk across the glass bridge into the Workshop. Once inside, they don't need to be a genius engineer; they just need to know that the Workshop's locks are old and rusty. They find a door labeled "Modbus" or "DNP3" that has no lock at all, or a password that is still set to "12345" (Default Credentials).

The paper found that two-thirds of the 69 major attacks they studied started this way. The hackers didn't need to invent a super-complex robot to break the machine; they just needed to trick a human in the office and then walk through an unlocked door.

What This Paper Says is NOT the Answer

The paper is very clear about what doesn't solve the problem. It explicitly argues against the idea that we can just rely on old-school "signature" detectors (like a security guard who only stops people wearing a specific red hat).

  • The "Red Hat" Problem: If a hacker wears a blue hat (a new, unknown virus), the guard doesn't stop them. The paper shows that new, scary viruses like Triton or INCONTROLLER are often so unique that old guards miss them completely.
  • The "Just Pay the Ransom" Myth: The paper argues that paying the ransom is rarely the solution. In fact, for most big attacks, the ransom payment is tiny compared to the cost of the mess. For example, when the Colonial Pipeline was hit, they paid about $4.4 million. But because they had to shut down the pipeline for five days, they lost over $25 million per day in business. The ransom was just a drop in the bucket; the real cost was the factory stopping.

The Evidence: A Timeline of Chaos

The authors didn't just guess; they compiled a list of 69 real-world incidents from 2010 to 2025. They verified every single one with government reports, court filings, and company statements.

Here is how the story changed over time, according to their data:

  • The "Special Ops" Era (2010–2016): Attacks were rare and required super-spy skills. The most famous was Stuxnet in 2010, which used a USB drive to sneak into a secret nuclear facility in Iran and physically break centrifuges. This was like a master thief picking a specific, high-tech lock.
  • The "Worm" Era (2017–2021): Then came NotPetya in 2017. It wasn't even trying to break machines; it was just a computer virus that spread like a flu. But because it infected the office computers of shipping companies and factories, the whole world stopped. It cost the world about $10 billion.
  • The "Ransomware" Era (2022–2025): Now, the attacks are everywhere. Hackers aren't just nation-states; they are criminal gangs. They hit Jaguar Land Rover in 2025, stopping all car production in the UK for five weeks. The paper estimates this cost the UK economy about £1.9 billion. They hit Change Healthcare in 2024, messing up prescriptions for 192.7 million people, costing $2.46 billion.

The "Healthcare" Deep Dive: When Machines Stop, People Suffer

The paper takes a special look at hospitals. In an office, a computer crash means you can't send an email. In a hospital, a computer crash means an MRI machine stops, or a patient monitor goes dark.

The authors found that hospitals are a perfect storm:

  1. Old Machines: They have medical devices that are 15–20 years old and can't be updated.
  2. Flat Networks: Often, the network for the doctors' computers is the same as the network for the life-support machines.
  3. The Cost: When Ascension Health got hit in 2024, they lost $1.8 billion in a single year. When Synnovis (a lab for the UK's NHS) got hit, 1,134 surgeries were cancelled in just 13 days.

The Tools We Have (And the Gaps We Need to Fill)

The paper reviews the tools defenders are using, but it's honest about where they fall short.

  • What Works:

    • Zero Trust: Imagine a castle where every single person, even if they have a key, has to show ID at every door. This stops hackers from moving freely once they get in.
    • AI Detection: Instead of looking for a "red hat," AI watches how the machines act. If a valve opens at 3 AM when it usually stays closed, the AI sounds the alarm. The paper suggests this is great at finding new, weird attacks.
    • Digital Twins: This is like building a video game version of the factory. Hackers can try to break the game version without risking the real machine.
  • The Big Gaps (What We Still Don't Have):

    • Patch Management: We can't just "update" a nuclear plant or a water filter like we update a phone. It takes too long and might break things. The paper says we need better ways to fix these old machines without shutting them down.
    • Data Scarcity: To train AI, we need examples of attacks. But we don't have many real examples of hackers breaking into factories, so the AI is learning from a small, incomplete library.
    • Old Protocols: Many machines still talk using languages (like Modbus) that were invented before security existed. We need to wrap these old languages in new, secure blankets, but it's hard to do without replacing the whole machine.

The Bottom Line

The paper concludes that the bad guys are getting faster and cheaper, while the good guys are still figuring out how to protect the glass bridge.

The most important lesson? Business interruption is the real killer. It's not the stolen data or the ransom payment that hurts the most; it's when the factory stops making cars, the power plant stops making electricity, or the hospital stops treating patients.

The authors suggest that to win, we need to stop treating IT (the office) and OT (the workshop) as separate worlds. We need to build better bridges, put up more guards at every door, and use smart AI to watch for anything that looks suspicious. But until we fix the gaps in our tools and our data, the glass bridge will remain a risky place to walk.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →