Skip to content
Knowledge base Updated: February 5, 2026

OT Cybersecurity Myths: Is a Firewall Enough? 5 Myths About Security

Many myths - half-truths and outdated beliefs that give a false sense of security - still circulate in conversations about production network security.

In a field as complex and dynamic as operational technology (OT) cyber security, simplifications and myths are extremely dangerous. They act like a fog that obscures the real picture of threats and puts vigilance to sleep, leading to wrong strategic decisions. Many industrial companies, often unknowingly, build their entire defense strategy on a foundation of just such myths, inherited from an era when industrial networks were simple, isolated islands.

Unfortunately, cybercriminals don’t believe in myths - they believe in vulnerabilities. They ruthlessly exploit every error in thinking, every vulnerability arising from a false sense of security. Attacks such as NotPetya and incidents at global manufacturing concerns have vividly demonstrated that the traditional approach based on a few simple assumptions simply no longer works in today’s connected world.

The purpose of this article is to confront the most popular and harmful myths about OT security. We want not only to debunk them, but, above all, to show what the reality is and what concrete steps should be taken to replace the illusion with real, multi-layered protection. This is knowledge that can protect your company from a catastrophic collision with reality.

Shortcuts

Myth #1: “We have a firewall at the edge of the network, so we are safe.” Why is this not true?

This is one of the oldest and most persistent myths. Many companies invest in a powerful, expensive next-generation firewall (NGFW) at the interface between the corporate network (IT) and the Internet, and sometimes at the border between IT and OT. This is, of course, an absolutely necessary step, but seeing it as the ultimate and sufficient security is a fundamental mistake. This approach, known as the “castle and moat” model, assumes that all evil comes from the outside, and that everything inside is trusted.

The reality is much more complicated. First, a threat can bypass this edge firewall in a number of ways - for example, on an external service technician’s laptop or an infected USB drive. Second, the threat can be born inside the network, as a result of a disgruntled employee. Third, and most importantly, once the attacker manages to penetrate this first line of defense, inside the flat, unsegmented network, he no longer faces any resistance.

An effective defense must be multi-layered (defense-in-depth). In addition to the wall at the border, we must build internal walls (segmentation) that limit the spread of the attack. We must also monitor what is happening inside these walls. Relying solely on a single perimeter firewall is like having a massive front door to a house with no partitions or locks on the doors to individual rooms.

📚 Read the complete guide: OT/ICS Security: Bezpieczeństwo systemów OT/ICS - różnice z IT, zagrożenia, praktyki

Myth #2: “Our OT network is isolated (air-gapped).” Why is this myth so dangerous?

The myth of the “air gap,” or the complete physical isolation of an OT network from other networks, is probably the most dangerous of all, as it gives the strongest yet most illusory sense of security. In theory, a network that is not connected to anything cannot be attacked remotely. In practice, true 100% air gaps in modern industry are virtually nonexistent.

The growing convergence of IT/OT, driven by the need for data analysis and remote monitoring, has created myriad, often undocumented connections. SCADA servers need to exchange data with ERP systems. Engineers need remote access. Machine manufacturers require connectivity for service purposes. Then there are the “hidden bridges” - computers with two network cards, unauthorized LTE modems or misconfigured firewalls.

The danger of this myth is that it puts vigilance to sleep. Organizations that believe they are protected by the “air gap” often neglect to implement any other internal security mechanisms. They don’t segment their networks, they don’t manage vulnerabilities, they don’t monitor traffic. The moment it turns out that their “air gap” has long been an illusion, the attacker finds himself in a completely vulnerable environment.

Myth #3: “We have antivirus on the HMI, so the PLCs are protected.” What does this look like in reality?

Deploying anti-virus software or more advanced EDR (Endpoint Detection and Response) systems on workstations and servers in an OT network (e.g., on computers running HMI/SCADA software) is, of course, a good and necessary practice. The problem lies in the myth that this is a sufficient measure to protect the entire control layer.

Antivirus protects a computer’s operating system (e.g. Windows) from known malware. However, it has no insight or understanding of what is happening at the level of industrial protocols. An attacker who has taken control of an HMI station does not need to install an additional virus on it at all. He can simply use the legitimate engineering software installed on it to send a fully legitimate but malicious command to the PLC, such as “change the motor speed to a critical value.”

To an antivirus, such activity is completely transparent and invisible. He only sees that a legitimate program is sending legitimate network traffic. It is unable to understand that this command could lead to the physical destruction of the machine in a moment. Protecting PLCs requires dedicated tools that understand the world of physics, not just the world of files.

Myth #4: “Our systems can’t be updated, so we can’t do anything.” What are the alternatives to patching?

This is a myth based on resignation that leads to total inaction. It is true that regular patching (patching) of OT systems is extremely difficult or even impossible due to the long life cycle, stability risks and lack of manufacturer support. However, to say that as a result “there is nothing we can do” is not true.

As we described in a previous article, in the OT world, where we cannot eliminate vulnerabilities at the source, we must use compensating controls. Instead of fixing the hole in the device itself, we build protective barriers around it to prevent it from being exploited. This is a fundamental shift in thinking, from reactive patching to proactive risk management.

The most important alternatives to patching include network segmentation, which isolates a vulnerable device; virtual patching with IPS systems that block attack attempts at the network level; configuration hardening, which is the disabling of unnecessary services; and network monitoring, which detects attempts to exploit a vulnerability. Inactivity is not an option.

Myth #5: “Cyber security is an IT problem.” Why does such thinking lead to disaster?

This is a cultural and organizational myth that is the source of most conflicts and negligence. It stems from the historical division in which the IT team was responsible for computers and the OT team for machines. In the age of convergence, this division no longer makes sense, but in many companies, it still lingers in the mindset of employees.

Trying to shift all responsibility for OT security to the IT department is doomed to failure. The IT team, even with the best of intentions, lacks key process knowledge. It cannot independently assess what the physical security implications of a given decision will be. It may implement security that is technically correct, but in practice will disrupt factory operations.

Cyber security in OT is a shared responsibility. It requires the creation of interdisciplinary teams and partnerships in which IT experts bring their knowledge of defense threats and technologies, and OT engineers bring invaluable knowledge of the process, its priorities and limitations. Any attempt to act alone leads to mistakes and mutual frustration.

How does the myth of “we’re too small to be a target” clash with the reality of automated attacks?

Many managers of smaller and medium-sized manufacturing companies live in the belief that they are not an interesting target for hackers. “Who are we? Just a small factory in the province. Who would want to attack us when they can attack banks or large corporations?” This is an extremely dangerous error in thinking.

Most of today’s attacks, especially those involving ransomware, are not precisely targeted. It is indiscriminate and automated in nature. Cybercriminals release bots into the Internet that scan the entire network for any easy targets - unsecured servers, systems with weak passwords or known vulnerabilities. It doesn’t matter to the bot whether it attacks a global corporation or a small family business. It attacks whoever can be attacked most easily.

What’s more, smaller companies are often seen as an ideal “entry point” to attack their much larger and better-protected business partners in a supply chain attack. Your company may not be the ultimate target, but it can become an unwitting beachhead for an attack on your largest customer. In today’s world, every company connected to the Internet is a target.

Belief in OT security myths is not harmless ignorance. It is an active form of risk-taking that has very real and painful financial and operational consequences. Each of the myths debunked leads to concrete losses.

Belief in the myth of “all you need is a firewall” leads to a lack of segmentation, which, in the case of a ransomware attack, results in the paralysis of the entire plant, not just one part of it. Belief in the “air gap” myth leads to a lack of monitoring, which means that an attacker can operate in our network unnoticed for months. Belief in the “antivirus protects PLC” myth leads to ignoring threats at the level of industrial protocols, which can end up sabotaging and physically damaging machines.

Ultimately, the cost of believing in myths is the cost of downtime, the cost of recreating systems, the cost of lost contracts and customer trust. That’s millions of zlotys that could have been avoided if the defense strategy had been based on facts and best practices rather than outdated and untrue beliefs.

What is the difference between a dedicated industrial firewall (OT) and a next-generation corporate firewall (NGFW)?

Many companies, in an attempt to secure the IT/OT border, install a standard corporate NGFW firewall there. While this is better than nothing, it is not an optimal solution. Dedicated industrial firewalls have a number of unique features that make them much more effective in this specific environment.

First, they are physically robust - designed to operate in harsh industrial environments (temperature, vibration, dust). Second, they can operate in transparent mode, allowing them to be deployed without changing IP addressing. Third, and most importantly, they have deep packet inspection (DPI) capability for industrial protocols.

This means that such a firewall “understands” machine language. It can distinguish a legitimate read command from a dangerous write command in the Modbus protocol. This allows the creation of much more precise and secure rules that block threats without disrupting normal operational communication.

How to carry out OT network segmentation in practice without stopping production?

As we described in detail in a previous article, this is possible through the use of the aforementioned transparent industrial firewalls. This process, carried out methodically, is completely safe for business continuity.

It starts with a passive mapping of the network to understand what works in it and how it communicates. Then, based on this map, logical segments are planned. A key step is to deploy firewalls in monitoring mode, where they learn normal traffic without blocking anything. Only after the creation of a precise “whitelist” of allowed communications is it switched to active blocking mode. Such an evolutionary method eliminates the risks associated with a revolutionary change in architecture.

How do you verify the myth of “we have an old system, so it’s safe because no one writes viruses for it”?

This is a very dangerous and completely false belief. In fact, old, unsupported systems like Windows XP are one of the easiest targets for attackers. There are thousands of publicly known, well-documented and unpatched vulnerabilities for them. There are ready-made, automated tools (exploits) circulating on the Internet that allow even a novice hacker to take control of such a system in seconds. Attackers don’t need to “write new viruses” - they can take advantage of the huge ready-made arsenal. The best way to verify this myth is to conduct a controlled penetration test, which under safe conditions will show how trivially easy it is to break into such a system.

The IEC 62443 international standard is the de facto handbook that systematically dispels all the myths discussed. Its fundamental concept of zones and channels directly contradicts the myth of the sufficiency of a single, edge firewall, mandating the construction of deep, internal segmentation. The requirement to conduct a risk analysis and define Security Levels dispels the “we’re too small to be a target” myth, forcing an informed assessment of threats. Finally, the entire standard is built on a philosophy of shared responsibility, involving factory owners as well as integrators and manufacturers in the process, contradicting the “security is an IT problem” myth.

How do you convince your board to invest in OT security in three simple steps?

Convincing the board requires switching from technical language to the language of business and risk.

  • Show the real financial risks: Conduct, even in a simplified form, an analysis of downtime costs. Show how much the company loses for each hour of an inoperable production line. This appeals to the imagination.

  • Invoke legal obligation: Use the NIS2 directive as a final argument. Inform management of the legal requirements, potential penalties and, most importantly, their personal liability.

  • Present a ready-made, prioritized solution: Don’t come with a list of problems, but with a ready-made, audit-based action plan. Show that you have a well-thought-out roadmap and know how to cost-effectively reduce identified risks.

Are there free tools to help you with a basic audit and verification of myths?

Yes, there are a number of free tools that, used with care, can help with the first step and basic diagnosis. Tools such as Nmap (for port scanning), Wireshark (for network traffic analysis) and OpenVAS (for vulnerability scanning) can provide valuable information. However, it is important to keep in mind that their incompetent use in an OT network, especially active scanning tools, can be risky. Therefore, it is recommended that they be used by technically knowledgeable individuals. For many organizations, a safer and more effective approach will be to use a professional audit from an outside company.

How does nFlo, based on facts and experience, help dispel myths and build real safety in factories?

At nFlo, our work begins where the myths end. We don’t believe in simple, one-size-fits-all solutions. We believe in in-depth, data-driven diagnosis and strategy tailored to each client’s unique needs. Our audit process, using secure, passive technologies, is designed to provide you with an objective, fact-based picture of the real state of security, without any simplification or guesswork. We help our clients understand that true resilience does not come from believing in a single, magical measure (like an “air gap” or “firewall”), but from building a multi-layered, holistic program that combines technology, processes and people. Our role is to be your guide on this journey - providing the knowledge, tools and experience to replace dangerous myths with a robust, engineered approach to risk management.

Learn key terms related to this article in our cybersecurity glossary:

  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
  • Firewall — A firewall, also known as a network firewall or security barrier, is a security…
  • Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
  • Network Security — Network security is a set of practices, technologies, and strategies aimed at…
  • NIST Cybersecurity Framework — NIST Cybersecurity Framework (NIST CSF) is a set of standards and best…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist