Many operators of small industrial environments, such as a water system, a compressor station, or a plant floor, have little idea what is happening on their control network day to day. Equipment works, until it does not, and when something odd occurs there is often no record to examine. That makes it hard to tell whether a fault was a failing part, an operator mistake, or something malicious.
You do not need a large security operations team to improve this. A modest, well-chosen set of logs and alerts can make a real difference.
Why logging matters in OT
In information technology, logs are a standard security tool. In operational technology they are often missing, because older equipment does not generate them, because networks were built for reliability rather than visibility, and because nobody was assigned to look.
When an incident occurs, logs help answer basic questions:
- What changed, and when?
- Who or what logged in?
- Which device communicated with which?
- Was the change authorized?
Without them, response is guesswork, and recovery may take longer because you cannot be sure what was touched.
Start with what you already have
Before buying anything, find out what already records activity.
- Firewalls and routers that sit between IT and OT networks typically log allowed and blocked connections.
- Remote access tools such as VPN gateways record who connected and when.
- Windows workstations and servers in the control environment generate event logs, including logins and software installations.
- PLCs, HMIs, and historians may log operator actions, alarms, and configuration changes.
- Vendor tools used for maintenance often keep their own session records.
Make a simple list of each device and whether logging is on, how long logs are kept, and where they are stored.
Prioritize the events that matter most
You cannot review everything. Focus on events that would indicate a meaningful change.
Access events
- Logins to engineering workstations and HMIs, especially outside normal hours
- Failed login bursts
- New accounts or privilege changes
- Remote sessions by vendors or staff
Configuration events
- Controller program downloads or changes
- Firmware updates
- Changes to firewall rules
- New devices appearing on the network
Network events
- Connections from the OT network to the internet
- Connections between IT and OT that are not on the approved list
- Unusual traffic volume
Centralize and protect the logs
Logs stored only on the device that generated them can be erased by an attacker or lost in a failure. If possible, forward them to a central location, with access restricted. Keep them long enough to be useful, since some incidents are discovered weeks after they begin. Decide a retention period that fits your risk and your storage capacity, and write it down.
Set a small number of useful alerts
Too many alerts get ignored. Start with a handful that you can reasonably respond to.
- A new device appears on the control network.
- A controller is programmed outside a scheduled maintenance window.
- A remote session starts without a scheduled ticket.
- A control network device connects to the internet.
- Multiple failed logins occur on an engineering workstation.
Assign each alert to a named person who knows what to check, and decide when they escalate to operations management.
Make it routine
Consider a hypothetical small pipeline operator with three technicians. A weekly fifteen-minute review of firewall logs, remote session records, and the list of new devices could catch unauthorized changes early. Pair it with a monthly check that logging is still enabled on each device. Habit matters more than tools.
Be careful with change
In OT, enabling new logging or monitoring on a live system can affect performance. Test changes on a non-critical device first, coordinate with operations, and schedule changes during planned downtime. Passive network monitoring, which listens to traffic without sending anything, is often safer for sensitive environments than active scanning.
Where Ironfield Cyber fits
Ironfield Cyber helps energy and industrial operators build practical visibility into their control environments, with logging and monitoring approaches that respect uptime and safety. If you are not sure what your network is recording today, we can review it with you and recommend a modest first step.