Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Is the best way to watch a movie on a pair of sunglasses?

    August 29, 2026

    You Need Cyber Deception for OT

    August 29, 2026

    Meta Tests Robots to Handle Data Center Work

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Is the best way to watch a movie on a pair of sunglasses?
    • You Need Cyber Deception for OT
    • Meta Tests Robots to Handle Data Center Work
    • 7 Indigenous Guarani killed after loose grain trailer hits car in central Brazil
    • Wisconsin prisons hit record population as crowding strains staffing and programs
    • Exiled Publishers Are Helping Russians Get Around the Kremlin’s Censorship
    • USDA recalled 30K pounds of beef from Argentina. Trump’s import plan wasn’t to blame
    • Somali piracy surges as the impact of the US-Iran war ripples outwards
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    You Need Cyber Deception for OT

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    OPINION

    There are three statements that sum up the frustrating reality for defenders responding to a cyberattack on operational technology (OT) systems: The attack data is not there. There is no trail to follow. There is no history to sort through.

    While these dynamics will always be true for OT, defenders are getting help from cyber deception as it matures beyond honeypots to a more sophisticated, proactive cyber-defense tool.

    To illustrate the problem, let’s go back in time. Nearly 12 years ago, portions of Ukraine’s electric grid went dark. It was an IT-to-OT attack, one that originates in the IT portion of the network and moves to the OT network. The adversary first established a position in enterprise systems, performed extensive reconnaissance, harvested credentials, found the paths toward operational systems, and then crossed into the technology that controlled the key components of the grid.

    Related:How an Emerging Industrial Protocol Family Could Put OT at Risk

    The pivot from IT into OT creates a debilitating problem: The OT half of the environment produces no useful security telemetry. It’s also not so great at providing logs or forensics. The result is an uncomfortable reality: After an attacker reaches OT, the defender will be looking for evidence in an environment that was never designed to produce it.

    Where Are the Attackers?

    In a normal IT investigation, a security team will ask familiar questions: Which user authenticated to the system? Was the login interactive or remote? What process executed? Which parent process launched it? Was PowerShell used? Did the host make a connection to a known command-and-control (C2) address? Was a new service created? Was an endpoint detection agent disabled? Did a file hash match known malware? Did a security information and event management (SIEM) system correlate the activity with other suspicious events?

    In OT environments, those questions are difficult or impossible to answer with confidence.

    A programmable logic controller (PLC) will not tell you that an attacker queried it. A remote terminal unit (RTU) will not produce meaningful authentication logs. A camera system will not provide security event details. A printer VLAN will not be monitored at all. A building management controller will provide little visibility into reconnaissance, failed access, enumeration, or command attempts.

    Even when logs exist, they may be retained locally, overwritten quickly, unavailable to the SIEM, or written in formats that do not map cleanly to normal security analytics. For defenders relying on signature or heuristics tools, the likelihood of detecting the attacker will be low. A signature-based tool cannot match a signature against telemetry it never receives. A SIEM cannot correlate events that were never collected. A log analytics tool cannot detect an attack path that passes through assets with no meaningful logs.

    Related:Multistate Water System Attacks Widen, Iran Suspected

    Cyber Deception Is a Tool for Both Sides of IT-to-OT Attacks

    Cyber deception addresses these problems while providing insights across the entire attack path from IT to OT. In a well-designed deception defense, the attacker will be presented with the exact information and devices needed to continue the attack. There will be information about the network, and there will be vulnerable assets to navigate. Each of these will capture forensics and alert defenders in real time.

    Attackers do not respect organizational boundaries. They follow whatever route gets them closer to the operational objective. That cross-domain view is important because the most meaningful evidence may not come from the OT asset itself. It may come from the attacker’s path toward it.

    Deception can connect those dots. A fake credential touched on an IT workstation, a beaconing OT network diagram opened by an attacker, a decoy engineering workstation accessed from a compromised host, and a simulated PLC queried from an unexpected source can all be part of the same detection story. The value is not only that each alert is high fidelity. The value is that the alerts show movement across the boundary that matters most.

    Related:Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

    Deception gives defenders a way to cover these spaces without pretending that every device can be converted into a modern IT endpoint. A decoy printer, camera, badge controller, or building management server doesn’t need to protect the real device by understanding every possible exploit. It simply needs to be believable enough that an attacker interacting with the network sees it as a useful target. Once touched, it tells the defender something valuable: Someone is exploring a system or segment where legitimate users had no reason to interact with the decoy.

    This also improves response. In OT, response decisions are hard because the cost of getting them wrong can be high. Blocking a host, resetting credentials, disabling a vendor tunnel, segmenting a subnet, or interrupting a workstation will have operational consequences. Low-confidence alerts are difficult to act on. Deception alerts are different. If a honey credential is used, a fake OT document is opened, or a decoy PLC is queried, we know an unusual event is occurring. That gives defenders the confidence to respond faster and with more precision.

    The Ukraine attack illustrates these points. The adversary’s success depended on preparation, access, knowledge, and the ability to move from enterprise compromise into operational control. Deploying deceptive elements in both IT and OT would have allowed defenders to detect earlier and receive intelligence across both domains.

    Cyber Deception
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network

    PaperCut releases second emergency patch for exploited flaws

    McKesson discloses breach after ShinyHunters claims patient data theft

    Offensive Security Investments Surge as AI Threats Increase

    Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

    Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Is the best way to watch a movie on a pair of sunglasses?

    August 29, 2026

    You Need Cyber Deception for OT

    August 29, 2026

    Meta Tests Robots to Handle Data Center Work

    August 29, 2026

    7 Indigenous Guarani killed after loose grain trailer hits car in central Brazil

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Is the best way to watch a movie on a pair of sunglasses?

    August 29, 2026

    You Need Cyber Deception for OT

    August 29, 2026

    Meta Tests Robots to Handle Data Center Work

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.