Skip to content
Knowledge base Updated: February 5, 2026

The human factor in OT security: How to train engineers not to let threats in via USB?

You invest in state-of-the-art firewalls and detection systems, but your entire defense strategy can collapse because of one inconspicuous flash drive inserted into the wrong USB port. In the world of operational technology, humans are often the last and most important line of defense. Unfortunately

In the complex puzzle of industrial cyber security, amidst advanced technologies, complex network architectures and rigorous procedures, there still remains one element that is both the most error-prone and has the greatest defensive potential - humans. The statistics are inexorable: the vast majority of security incidents, both in IT and OT, have their origin in human error. It could be clicking on a link in a phishing email, using an infected USB drive, or connecting an untrusted laptop to the network.

Organizations try to address this problem with security awareness programs, but all too often this fails, especially in manufacturing environments. Engineers and technicians, bombarded with generic corporate training on data protection or clean desk policies, treat them as just another annoying chore that has nothing to do with their daily work at the machines.

The truth is that it is impossible to build digital resilience in a factory, ignoring its unique culture and work characteristics. An effective security awareness program for OTs must speak the language of engineers, address their real-world concerns and, most importantly, translate digital threats into their potential physical consequences. The goal is not to “unclick” annual training. The goal is real behavior change and transforming every employee from a potential “weakest link” to an active “human sensor” of threats.

Shortcuts

Why is the most expensive firewall useless when an employee lets the enemy in through the “main door”?

We can spend millions to build a digital fortress. Install state-of-the-art firewalls, intrusion prevention systems and advanced analytics based on artificial intelligence. We can surround our network with a multi-layered wall and a deep moat. But the entire fortress is only worth as much as its guards. If the guard at the main gate is fooled and lets an enemy disguised as a merchant inside by himself, the rest of the fortification ceases to matter.

Employees play exactly this role in the security architecture. They are the gatekeepers who make dozens of small decisions every day that can either strengthen or completely undermine the entire defense strategy. The decision whether to click on a link, whether to plug in a flash drive found in the parking lot, whether to allow a service technician to use his private laptop - these are the moments when the “main door” opens.

Attackers know this very well, which is why social engineering, or manipulating people, is their most effective and widely used weapon. It’s much easier to convince an employee to provide his or her own password than to try to crack complex encryption. This is why investing solely in technology, without simultaneously investing in people, is building a fortress with beautiful high walls, but with the gate left ajar.

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

”Here we go again with the same boring training: Why doesn’t your security awareness program work for OT engineers?

Most corporate security awareness programs are designed by IT or HR departments with office workers in mind. They focus on threats common to that environment: phishing impersonating banks or courier companies, protecting customer data (RODO), or policies for safe use of social media. From the perspective of an engineer working on the shop floor, these topics are largely abstract and irrelevant.

When an OT engineer is forced to go through e-learning that tells him how to protect credit card data, his natural reaction is irritation and a sense of wasted time. He doesn’t process such data on a daily basis. His job is to keep a machine worth millions running. Generic training not only fails to engage him, but actually builds in him the belief that “cyber security is not my problem, it’s the problem of those in the office.”

To make matters worse, the tone and language of these trainings often do not resonate with pragmatic engineering culture. Engineers value specifics, data and practical solutions to problems. Instead, they often receive theoretical policy talk and general cautions. As a result, training is “clipped through” in the shortest possible time, only for the system to record its completion, and real knowledge and behavioral change do not follow.

How can a flash drive with an update from a vendor become a digital bomb?

One of the most specific and threatening attack vectors in the OT environment is the use of portable storage media, such as USB flash drives. In the IT world, their use is often blocked or restricted. In OT, unfortunately, they are still an essential working tool. Engineers and third-party service technicians regularly use them to transfer software updates, upload new programs to PLCs or copy diagnostic logs from machines that are not connected to the network.

Any such carrier is a potential digital bomb. It can be infected with malware completely unknowingly. A service technician may have previously used the same flash drive on another, already infected facility, or on his home computer. The moment it is inserted into a USB port at an engineering station in your factory, the malware can automatically move into your seemingly isolated network.

Training for OT personnel must therefore address this problem in a very practical way. Rather than saying “beware of USBs” in general terms, clear and vital procedures must be created: “Any external media, before it is used on the OT network, must be scanned at a dedicated, isolated quarantine station. Never connect media of unknown origin to an OT network.”

What is the danger of connecting a service technician’s laptop that has just returned from another factory to the OT network?

A similar, if not greater, threat is posed by laptops belonging to third-party service companies and integrators. These are devices over which we have absolutely no control. We don’t know what operating system they have, whether it is updated, whether they have antivirus software and, most importantly, what other potentially infected networks they have been connected to recently.

When a service technician plugs such a “traveling” laptop directly into a network port in your control cabinet to diagnose a problem with the machine, he is de facto creating an uncontrolled bridge between your network and the world at large. If his laptop is infected, the malware can spread to your infrastructure within seconds.

Therefore, the awareness program must cover not only its own employees, but also the rules for working with subcontractors. A clear policy should be developed and enforced that specifies what the security requirements are for third-party equipment. In mature organizations, service technicians are not allowed to plug in their laptops. Instead, they are given a company-prepared, “clean” and hardened laptop, which is the only one allowed to access the OT network.

Are manufacturing engineers also clicking on phishing, or what do social engineering attacks look like in the industry?

Engineers and production managers, like office workers, use email and are just as vulnerable to phishing attacks. The difference is that attacks targeting them are much more personalized and use a different context. An attacker will not impersonate a courier company, but a machine manufacturer, a business partner or even an IT department.

Imagine an email that looks like an official message from Siemens, informing you of a “critical security update for S7 controllers that must be installed immediately to avoid failure.” The message contains a link to download the “update,” which is actually malware. Such a spear phishing attack has a much higher chance of success because it appeals to an engineer’s professional responsibility and concerns.

Phishing training for OT personnel must therefore use just such, realistic examples. Instead of showing generic fake invoices, attacks that employees may realistically encounter in their work should be simulated. Only in this way will they learn to take a critical look at communications that they have so far seemed to fully trust.

How to talk about security in OT language, i.e. from bits and bytes to physical security?

The key to effective training is to speak in a language of benefits and risks that the audience understands. For an OT engineer, abstract concepts such as “data integrity” or “risk of information leakage” are much less appealing than concrete, physical consequences. That’s why communication about cyber security must be “translated” into OT language.

Instead of saying: “Clicking on this link could lead to unauthorized access to the server,” say: “Clicking on this link may allow someone to remotely disable the cooling pump, threatening to overheat and destroy a machine worth two million zlotys.” Such a message is immediately understandable and alarming.

The awareness program must constantly emphasize the connection between operations in cyberspace and their effects in the physical world. It must be shown how seemingly innocuous digital errors can lead to production stoppages (financial losses), equipment damage (repair costs), workplace accidents (health and life risks) or environmental disasters. This emphasis on Safety (physical safety) is what distinguishes effective OT communication from ineffective communication.

Why must training scenarios reflect real-world hazards on the shop floor?

People learn best through stories and examples they can identify with. That’s why it’s so important for training materials and simulations to be based on realistic scenarios that might happen in a manufacturing plant.

Instead of a theoretical lecture on ransomware, hold a workshop where you analyze a case study of a real-world attack on another company in the same industry. Instead of general e-learning about passwords, create a short video tutorial showing how an attacker can guess the default password for an HMI panel that employees see every day.

The more “tailor-made” the training is, the greater the involvement will be and the more lasting the knowledge remembered. It is worth involving the engineers themselves in the creation of these materials. Ask them to describe what safety situations they find most problematic in their daily work. Tapping into their own experiences and concerns is the best way to create content that will be seen as authentic and valuable.

Pillars of a successful Security Awareness program in OT

PillarDescriptionExample of action1. accuracyContent and scenarios must relate to real threats and daily work in OT.Simulated phishing impersonating a machine supplier, not a bank.2. translating to physical riskCommunications must emphasize the impact of cyber threats on human and process security.Explanation of how malware can lead to a machine crash or accident.**3. culture of “report without fear”**Employees must feel safe reporting their mistakes and suspicions.Reward, not punish, an employee who reports having clicked on a suspicious link.4. practical formsTraining should be short, frequent and engaging, tailored to the factory environment.Short “talks” to start the change, posters, practical workshops.5. measurability and adaptationThe effectiveness of the program must be regularly measured and optimized.Regular simulated attacks (phishing, tossed USBs) and analysis of the results.

How do you create a culture where bug reporting is rewarded rather than punished?

The biggest enemy of security is fear. If employees are afraid to admit that they made a mistake - for example, that they clicked on a suspicious link or connected a private phone to a workstation - they conceal the fact. This gives the attacker invaluable hours or days to operate covertly. Early reporting of the incident is absolutely key to limiting the damage.

Therefore, the goal of the awareness program must not only be to educate, but also to build a “report without fear” (no-blame culture). Employees must receive a clear and consistent message from top management: “It is your responsibility to report all suspicions and errors, immediately and without fear of consequences. We value your sincerity far more than the illusion of perfection.”

Moreover, such behavior should be actively rewarded. An employee who reports that he was fooled into phishing should be publicly commended for his responsible attitude. His story should be used (with his permission and in an anonymized manner) as a positive example for others. This is the only way to build trust and transform employees from passive recipients to active participants in the security system.

Other than e-learning, what forms of training work well in a factory environment?

Traditional hour-long e-learning, which takes the employee away from his or her workstation, is often not the best form of knowledge transfer in a dynamic factory environment. An awareness program for OTs should use a much more diverse and “digestible” format.

Short, 5-10 minute “safety talks” (toolbox talks) given by the foreman or shift leader at the beginning of the work day are very effective. Discussing one specific hazard or reminding people of one key rule is much more effective than trying to impart a huge amount of knowledge all at once.

Other proven forms include visual communication: simple, easy-to-read posters and infographics hung in rest areas, reminding people of key principles (e.g. “Don’t trust? Report!”, “USB? Only after quarantine!”). It’s also a good idea to use short instructional videos or hold hands-on workshops where employees can see for themselves what an attempted attack looks like.

Who are the “security ambassadors” and how can they help build a new culture?

Culture change is a long-term process and cannot be imposed from above. It is most effective when it is supported by informal leaders and people with authority within their teams. It is worth identifying such employees and inviting them to participate in the “security ambassadors” (security champions) program.

A security ambassador is usually an experienced engineer or technician who is not a cybersecurity specialist, but who shows interest in the subject and has the respect of his or her colleagues. Such a person, after receiving additional training, becomes the “translator” and security point of contact for his or her team.

Ambassadors can help conduct short training sessions, answer questions from colleagues, promote best practices and provide “front line” feedback to the security team. A message delivered by “one of us” is often much better received than an official communication from the IT department.

How to measure the effectiveness of the awareness program so that it is not just “art for art’s sake”?

Any investment in a company, including that in training, should have measurable performance indicators (KPIs). The goal is not just to “deliver training,” but to realistically “improve behavior.” How to measure this?

The most effective tool is regular, controlled simulated attacks. We can periodically send simulated (but safe) phishing emails to employees and measure the click rate. The goal, of course, is to lower it systematically. We can also from time to time deliberately “lose” USB flash drives on the premises and check how many of them will be connected to computers and how many will go to the security department.

Other indicators are the number and quality of reports from employees. The increase in the number of reported suspicious emails and incidents, even fake ones, is paradoxically a very good sign. It indicates an increase in vigilance and confidence in procedures. Measuring and regularly reporting on these indicators allows us to evaluate the effectiveness of the program and adapt it based on hard data.

How does building staff awareness implement the key requirements of the NIS2 directive?

The NIS2 directive explicitly points to the human factor as a key component of a risk management system. Article 21 requires companies to implement, among other things, “cyber security policies and procedures” and provide “cyber security training.” Having a mature, OT-specific security awareness program is therefore a direct implementation of these requirements.

In the event of an audit, auditors will not just ask whether training took place, but what it looked like and whether it was effective. Being able to present a documented, cyclical program that includes realistic scenarios, various forms of communication and measurable performance indicators demonstrates the due diligence and maturity of the organization.

Moreover, a culture in which employees proactively report incidents directly supports the implementation of NIS2’s stringent reporting requirements. Early detection of an incident by a vigilant employee can give a company invaluable time to conduct analysis and prepare the required report within 24 hours.

How does nFlo help create and run security awareness programs that really work in the industry?

At nFlo, we know that effective training is training that resonates with the recipient. That’s why we don’t offer generic, boxed e-learning solutions. Our approach to building awareness in OT is based on an in-depth understanding of your organizational culture, specific processes and the daily challenges of your employees.

Our consultants work with your teams to create a tailor-made program. We develop realistic scenarios of attacks that could happen in your factory. We create engaging training materials - from short videos to posters to workshop scenarios and talks - that speak the language of your engineers.

We specialize in planning and conducting controlled simulated phishing campaigns and USB tests to measure the real level of resistance. Based on the results, we help optimize the program and provide management with clear reports on its effectiveness. Our goal is not just to educate, but to realistically change behavior and build a lasting, positive security culture in your company.

The perspective with which we look at the human factor is fundamental. If we treat employees as a problem that needs to be controlled, and the weakest link that will always fail - that’s exactly what we will get. They will be passive, uninvolved, and will try to bypass safeguards that impede their work.

But if we change our perspective and start treating our people as our greatest potential and first, most important line of defense, we will open the door to entirely new opportunities. A well-trained, informed and engaged employee is worth more than the most expensive technological system. He or she can spot an anomaly that no algorithm can detect. He can question a suspicious command and report his concern.

Investing in building such a human “fire wall” is one of the most profitable cyber security investments you can make. It’s up to you and your approach whether your people will be a passive target or an active defender of your company.

Learn key terms related to this article in our cybersecurity glossary:


Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


Explore Our Products

Solutions mentioned in this article that can help protect your organization:

Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist