The Realm of OT Cyber
Back to Insights
ICS / OT SecuritySIEM StrategyGRC

IT vs OT: Why Asset Classification Matters for Your SIEM Strategy

|The Realm of OT Cyber

During a recent ICS cybersecurity audit, an IT security consultant made an observation that sparked an important discussion about how we classify and monitor assets inside industrial environments. While reviewing the OT network, he referred to certain systems—such as servers, workstations, and database systems that are physically or logically placed within the ICS/OT environment—as "IT equipment."

Based on this interpretation, he recommended forwarding security logs from these IT-type systems located inside the OT environment to the enterprise SIEM, while directing logs from Purdue Level 2 industrial control devices to a dedicated OT SIEM.

At first glance, this recommendation may appear structured and logical. However, it reflects a common misunderstanding of how the Purdue Model and asset classification should be applied in industrial cybersecurity.

The Common Misconception

A frequent mistake during ICS audits is assuming that any system resembling traditional IT infrastructure—such as Windows servers, engineering workstations, or databases—should automatically be treated as "IT equipment," even when it resides within the OT environment.

This leads to a simplified view:

"IT-like systems in OT should go to IT SIEM"

"Control systems should go to OT SIEM"

However, this classification is not aligned with industrial cybersecurity principles.

The Reality

The Purdue Enterprise Reference Architecture (PERA) defines network segmentation and functional layers, not asset ownership or classification as IT or OT.

In ICS environments, Purdue Level 3 and even Level 2 often contain systems such as:

  • Engineering Workstations
  • Domain Controllers dedicated to OT environments
  • Patch and update servers for industrial systems
  • Database servers supporting historians or SCADA data
  • Virtualization hosts running control system services
  • Backup and recovery systems for plant operations

Although these systems use standard IT technologies, they are operationally part of the OT environment because they directly support industrial processes.

Their classification is therefore not based on technology type, but on operational function and impact on industrial processes.

Classification Should Be Based on Function, Not Technology

Instead of asking:

"Is this an IT system or an OT system?"

The correct question is:

"Does this system support industrial operations, and what is the impact if it is compromised?"

A Windows server inside a control network that manages SCADA authentication is not an enterprise IT asset—it is a critical OT supporting system.

Similarly, an engineering workstation may look like a standard IT machine, but it directly influences PLC logic, process control, and plant safety.

SIEM Strategy Should Reflect Operational Risk

Log forwarding decisions should not be based on whether a system "looks like IT" or "looks like OT," but rather on:

  • Operational criticality
  • Security ownership (IT vs OT responsibility)
  • Incident response requirements
  • Regulatory and compliance requirements (IEC 62443, NIST 800-82)

In many mature architectures:

  • OT-critical supporting systems are monitored within OT security operations
  • Enterprise IT systems are monitored within enterprise SOC
  • Shared or hybrid systems may require coordinated visibility across both environments

The goal is not separation for its own sake, but context-aware visibility aligned with risk.

A GRC Perspective

Industrial cybersecurity frameworks such as IEC 62443 emphasize zones and conduits, asset criticality, and security levels—not simplistic IT vs OT labeling based on technology stack.

Misclassifying OT-supporting IT systems as enterprise IT assets can lead to:

  • Loss of visibility in OT incident response
  • Fragmented security monitoring
  • Incorrect escalation paths during cyber incidents
  • Gaps in compliance reporting

Final Thoughts

The Purdue Model remains a foundational reference for industrial network segmentation, but it should not be used as a classification tool for determining whether a system is IT or OT.

In ICS environments, function defines classification—not technology, and not network layer alone.

Understanding this distinction is essential for building effective SIEM strategies, improving incident response, and ensuring that cybersecurity controls truly reflect operational reality.

At The Realm of OT Cyber, we emphasize this principle in every engagement: secure what the system does, not just where it sits in the network.

Copyright © 2026 The Realm of OT Cyber – All Rights Reserved.

OT CYBER