Many small operators have no idea what is happening on their control networks day to day. If an unfamiliar device appeared, if a controller were reconfigured, or if a vendor logged in at an odd hour, would anyone know? In most small environments, the honest answer is no.
Logging and monitoring in operational technology do not need to look like a large security operations center. Even modest visibility makes incidents easier to detect, investigate, and recover from, and it supports compliance expectations that increasingly assume basic logging.
Why monitoring is harder in OT
Operational environments differ from office networks in ways that shape monitoring choices.
- Many devices cannot run monitoring software and produce few or no logs.
- Aggressive scanning can disrupt fragile equipment.
- Network traffic is often predictable, which helps detection but requires understanding normal first.
- Uptime and safety take priority, so changes must be careful.
- Staff who run the systems are usually not security specialists, and vice versa.
The right approach is to observe quietly and avoid disrupting operations.
What to log first
You do not need everything. Start with the events that matter most.
Access to the control network
- Remote access sessions, including who connected, when, and from where
- Vendor access, with start and end times
- Logins to engineering workstations, servers, and human-machine interfaces
- Failed login attempts and account lockouts
Changes
- Configuration or logic changes on controllers, where supported
- New user accounts or privilege changes
- Firewall rule changes
- Software installations on engineering workstations
Network boundary activity
- Traffic crossing between business and control networks
- Connections to the internet from control devices, which are often unexpected
- New devices appearing on the network
Practical collection options
Use what you already have
Firewalls, switches, remote access gateways, and Windows servers already generate logs. Make sure logging is turned on, retained for a useful period, and sent to a central place rather than sitting on the device where an attacker could erase it.
Passive network monitoring
Some tools observe network traffic through a mirror port without sending anything to devices, building a map of assets and communications and flagging changes. These are designed for industrial environments and can fit well, though budget and staff capacity matter. Evaluate cost and who will review alerts before buying.
Centralized log storage
Forward key logs to a protected collector. Keep the retention period aligned with your needs and any regulatory or contract requirements. Back the logs up and restrict who can alter them.
Establish a baseline
Monitoring is only useful when you know what normal looks like. Document which devices exist, which should communicate, and typical patterns, such as scheduled vendor access. Deviations become easier to spot. Review the baseline when equipment changes.
Decide who looks and what happens next
Logs nobody reads do not help. Define responsibilities.
- Name who reviews alerts and how often.
- Define which alerts are urgent, such as a new device on the control network or a login outside normal hours.
- Write down who to call, including operations leadership, IT, and any vendor, and what the manual fallback is.
- Practice the response in a tabletop exercise.
Start small
A reasonable first set of goals:
- Turn on and centralize logs from firewalls and remote access systems.
- Record all vendor sessions.
- Maintain an up-to-date asset list.
- Alert on new devices and unexpected internet connections.
- Review logs on a defined schedule, even if monthly at first.
Expand as you gain experience and confidence.
Coordinate with operations
Always involve the people who run the process. Changes to logging settings can affect performance on older devices, and operators often notice oddities first. Treat them as partners in detection.
Where Ironfield Cyber fits
Ironfield Cyber provides awareness-level OT security assessments and helps small operators set up practical logging and monitoring without disrupting operations. If you want to know what visibility you have today, we can help take a first look.