Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

OT telemetry and OT security: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: OT telemetry and OT security solve different problems, and DataBahn argues that confusing them leaves visibility gaps, mis-sized licenses, and incomplete coverage because collection and normalization are pipeline functions, not detection functions. The practical implication is that plants usually need better telemetry routing before they need another monitoring platform.

NHIMG editorial — based on content published by DataBahn: Why are Legacy SIEMs a problem?

Questions worth separating out

Q: What breaks when OT telemetry is not fully normalised before security tools use it?

A: Security tools lose context, coverage becomes uneven, and teams pay for detection on an incomplete feed.

Q: Why do OT environments need a telemetry pipeline as well as a security platform?

A: Because the pipeline decides what data exists, in what shape, and where it goes, while the security platform decides how to detect and respond.

Q: How should teams decide whether to fix data collection or buy more OT security tooling?

A: Start with a coverage review.

Practitioner guidance

  • Map telemetry coverage before renewing tools Inventory every OT and IoT source, then document which feeds reach a SIEM, data lake, or detection platform in raw or normalized form.
  • Separate collection gaps from detection gaps Run a renewal review that asks whether the failure is incomplete collection, malformed parsing, or weak alerting.
  • Push enrichment upstream of the SIEM Attach asset identity, protocol context, and threat intelligence during collection or stream processing so routing decisions happen before ingestion costs are incurred.

What's in the full article

DataBahn's full article covers the operational detail this post intentionally leaves for the source:

  • How its collection layer separates source discovery, parsing, and enrichment across OT protocols
  • How telemetry routing is used to reduce SIEM ingestion cost without losing investigative value
  • How the pipeline is designed to avoid latency or load on OT environments
  • How the data control plane maps sources, transformation, and routing across security destinations

👉 Read DataBahn's analysis of why OT telemetry and OT security must be separated →

OT telemetry and OT security: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Telemetry enrichment is becoming a security control, not a plumbing task: once data feeds determine what a SOC can see and retain, the pipeline becomes part of the control stack. That changes procurement logic, because coverage gaps cannot be solved by adding another detector on top of a broken feed. Practitioners should treat enrichment, routing, and normalization as governed security functions, not just data engineering.

A question worth separating out:

Q: What is the difference between OT telemetry and OT security in practice?

A: OT telemetry is the data produced by industrial systems, and OT security is the set of controls that defend those systems from attack. Telemetry is the input, security is the response. When organisations confuse them, they often buy monitoring before they have a reliable pipeline, which leaves both visibility and defence incomplete.

👉 Read our full editorial: OT telemetry vs OT security: why pipeline design matters



   
ReplyQuote
Share: