Logging and Monitoring in OT: What Small Operators Can Do

You cannot defend what you cannot see. Practical, low-risk monitoring for small energy and industrial operators with limited budgets and staff.

3 min readBy Ironfield Cyber Team

Many small operators run control systems with almost no visibility. If something unusual happens, such as a new device on the network, a remote login at 2 a.m. or a controller program change, nobody knows until a process misbehaves. Enterprise-style security operations centers are out of reach for most small utilities and energy service firms, but a modest, thoughtful monitoring program is not.

The goal is realistic: collect the most valuable signals, review them regularly and respond to what matters.

Principles for OT Monitoring

  • Do no harm. Industrial devices can be fragile. Prefer passive methods that listen rather than probe.
  • Focus on boundaries. The points where the control network meets other networks, remote access and vendors deliver the most value.
  • Start small. Cover critical systems first, then expand.
  • Make it reviewable. Data nobody looks at is wasted. Choose outputs a small team can actually read.

What to Monitor First

Remote access

Log every remote connection into the control environment: who, from where, when and for how long. If you use a jump server or secure remote access gateway, its logs are among the most important you have. Alert on logins outside normal hours or from unusual locations.

Network boundaries

Firewalls between corporate and control networks should log allowed and denied traffic. Review denied connections for patterns that suggest scanning, and review allowed ones for unexpected sources and destinations.

New devices

Detect when new devices appear on the control network. A passive monitoring tool or even regular review of switch tables can reveal unauthorized equipment.

Engineering workstations and servers

These are the systems used to program controllers, and they are high-value targets. Collect logs for logins, software installation, USB device use and security alerts. Install endpoint protection that is approved for your industrial environment, in consultation with your vendors.

Controller changes

Watch for program downloads, firmware changes and mode changes on critical controllers. Some platforms provide this in their own logs, and some tools can compare current configurations to approved baselines.

Choosing Tools

Options range from simple to sophisticated.

  1. Built-in logs. Firewalls, switches and Windows systems already generate logs. Make sure they are on and retained.
  2. Centralized log collection. Send logs to a central location so they cannot be erased by an attacker on one device and are easier to search.
  3. Passive network monitoring. Tools designed for industrial protocols can inventory devices and flag unusual communications without interfering with them.
  4. Managed detection and response. A provider monitors alerts for you, which suits companies without staff for round-the-clock watching. Ensure the provider understands OT and agrees on how it will act, since isolating a device in an industrial setting has different consequences than in an office.

Establish a Baseline

Monitoring is most effective when you know what normal looks like. Spend a few weeks learning typical traffic: which devices talk to which, which protocols are used and when vendors normally connect. Document it. Unusual events then become obvious.

Decide What Triggers Action

Define in advance which events require immediate attention and which can wait.

  • Urgent: a new device on the control network, a remote login outside approved windows, unexpected controller changes, malware alerts on engineering stations.
  • Review weekly: failed login patterns, firewall denies, new software installations.
  • Review monthly: trends, device inventory changes, retention and storage.

Name who responds, and give them authority and a contact list. In OT, include operations staff, since a security response must account for safety and production.

Retain Logs Sensibly

Keep logs long enough to investigate an incident that may be discovered weeks or months later. Protect them from tampering, store copies off the affected systems and be aware of any customer or regulatory expectations about retention.

Practice Responding

Run a short tabletop exercise: a remote login occurred at midnight from an unknown address. Who sees the alert, who decides what to do and how do you confirm whether the access was legitimate? Gaps appear quickly in discussion.

Common Mistakes

  • Turning on monitoring tools and never reviewing the output.
  • Scanning aggressively and disrupting equipment.
  • Sending alerts to one person's inbox.
  • Monitoring only the corporate network.
  • Ignoring vendor connections.

A Reasonable Start

If you have nothing today, begin with remote access logs, firewall logs and a device inventory. Ironfield Cyber helps small energy and industrial operators choose proportionate monitoring, set up log collection and define response steps that respect safety and uptime.