Why Can’t Manufacturers Just Update and Restart Their Systems to Fix Security Vulnerabilities?

Manufacturers can’t simply update and restart their systems because Operational Technology (OT) equipment such as PLCs, SCADA systems, HMIs, and industrial control systems run production processes that can’t be interrupted without operational and financial consequences. Patching in an OT environment requires manufacturer approval, planned downtime, and production testing. IT patch cycles require none of those. Managing that gap between known vulnerability and applied patch requires a strategy, not just a schedule.

What Makes Patch Management Different in Manufacturing OT Environments?

OT patch management is different from IT patch management because the systems being patched control physical equipment, run on manufacturer-governed update cycles, and often can’t be rebooted without stopping production.

In a standard IT environment, patching is a scheduled and largely automated process. An endpoint receives an update, restarts, and returns to operation within minutes. The workflow is disrupted briefly. The process is low-risk and low-cost.

In an OT environment, none of those assumptions hold.

Factor

IT Environment

OT/Manufacturing Environment

Patch source

Microsoft, software vendors

Equipment manufacturer only

Patch approval

Internal IT

Manufacturer-validated; may void warranty if bypassed

Restart impact

Brief workflow interruption

Production line stoppage

Patch frequency

Monthly or continuous

Quarterly, annual, or longer

Testing requirement

Staging environment

Full production simulation or scheduled downtime

Legacy system support

Vendor patches most supported systems

Many OT systems on end-of-life OS with no patches available

The manufacturer-approval requirement is the constraint that most significantly separates OT from IT patching. A patch that hasn’t been validated by the equipment manufacturer can break the PLC, create safety issues, or void the warranty. This means manufacturers can’t simply apply a security patch the moment it’s available. They have to wait for the manufacturer to test and release it—a process that can take months.

What Is the Real Security Risk of Unpatched OT Systems in Manufacturing?

Unpatched OT systems are among the highest-risk exposures in manufacturing environments because they sit at the intersection of high operational value and limited defensive capability. Attackers know this.

When a vulnerability is publicly disclosed for a Programmable Logic Controller (PLC) model or Supervisory Control and Data Acquisition (SCADA) platform, that disclosure is visible to everyone, including threat actors who actively scan for vulnerable industrial systems. The window between vulnerability disclosure and exploitation attempt in OT environments has been shrinking. Meanwhile, the manufacturer’s patch development, testing, and release process runs on its own timeline.

The specific risks of unpatched OT systems include:

  • Remote exploitation: Vulnerabilities in remote access interfaces and communication protocols allow attackers to reach OT systems from the IT network or directly from the internet if exposure exists.
  • Lateral movement: A compromised OT device can be used to move through the production network, reaching other equipment or crossing back into the IT environment.
  • Production disruption: Exploited OT vulnerabilities can cause equipment malfunction, process disruption, or safety system interference. These are consequences that go beyond data theft into physical operational impact.
  • Ransomware deployment: OT systems are increasingly the target of ransomware operators specifically because recovery requires specialized expertise and extended downtime, increasing the pressure to pay.

How Should Manufacturers Manage Patches They Can’t Apply Immediately?

Manufacturers should manage unapplied patches through a compensating controls program that treats each unpatched system as a known, documented risk with an active mitigation in place.

A compensating control doesn’t eliminate the vulnerability. It limits the pathways an attacker can use to reach or exploit it. The most effective compensating controls for unpatched OT systems are:

  1. Network segmentation: Place vulnerable OT systems on isolated network segments that limit communication to only what production requires. A PLC that can only communicate with its designated HMI and historian has a much smaller attack surface than one that can reach the entire plant network.
  2. Disable unnecessary services and protocols: OT systems often run services and communication protocols that aren’t needed for their function. Disabling them reduces the exploitable surface without requiring a patch.
  3. Restrict remote access: Limit who can connect to OT systems remotely, from where, and through what mechanisms. Require MFA on all remote access. Log all sessions.
  4. Apply behavioral monitoring: Deploy monitoring that establishes a baseline of normal activity for each OT system and alerts on deviations. Unusual communication patterns, unexpected connections, and off-hours activity are often the first indicators of compromise.
  5. Document and track: Maintain a patch status record for every OT system, including the known vulnerability, the current compensating control, the manufacturer’s patch timeline (when known), and the planned remediation date. This documentation is what demonstrates due diligence in a regulatory review or insurance claim.

How Do Manufacturers Build an OT Patch Management Program?

An OT patch management program starts with a complete asset inventory and builds from there through manufacturer engagement, risk prioritization, compensating controls, and a maintenance window cadence.

The components of a functioning program, in order:

  1. Asset inventory: Document every OT device: manufacturer, model, firmware version, network location, and communication requirements. You can’t manage a patch status you haven’t recorded.
  2. Vulnerability mapping: Cross-reference the asset inventory against known vulnerabilities for each device model and firmware version. This is where you find out what’s exposed.
  3. Manufacturer engagement: Establish a direct relationship with each major equipment manufacturer’s security or support team. Understand their patch release cadence, how they communicate updates, and what their validation process requires before a patch can be applied.
  4. Risk prioritization: Not all vulnerabilities carry the same risk. Prioritize by exploitability, network exposure, and operational criticality. A vulnerability on a system that’s air-gapped and monitored is lower priority than the same vulnerability on a system reachable from the business network.
  5. Compensating controls: For every vulnerability without an available patch, document the active compensating control and review it on a defined schedule.
  6. Maintenance window planning: Work with operations leadership to schedule planned downtime for patch application. This is a business conversation, not just an IT one — it requires coordinating with production scheduling, the equipment manufacturer, and potentially customers with delivery commitments.

Vertikal6 works with manufacturers to build OT patch management programs that are connected to real operational schedules, not theoretical frameworks. Our ADVANTAGE service brings the vCISO leadership and structured program management that turns patch management from a reactive problem into a controlled risk.

Recent Posts

We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.