OPINION
There are three statements that sum up the frustrating reality for defenders responding to a cyberattack on operational technology (OT) systems: The attack data is not there. There is no trail to follow. There is no history to sort through.
While these dynamics will always be true for OT, defenders are getting help from cyber deception as it matures beyond honeypots to a more sophisticated, proactive cyber-defense tool.
To illustrate the problem, let’s go back in time. Nearly 12 years ago, portions of Ukraine’s electric grid went dark. It was an IT-to-OT attack, one that originates in the IT portion of the network and moves to the OT network. The adversary first established a position in enterprise systems, performed extensive reconnaissance, harvested credentials, found the paths toward operational systems, and then crossed into the technology that controlled the key components of the grid.
The pivot from IT into OT creates a debilitating problem: The OT half of the environment produces no useful security telemetry. It’s also not so great at providing logs or forensics. The result is an uncomfortable reality: After an attacker reaches OT, the defender will be looking for evidence in an environment that was never designed to produce it.
Where Are the Attackers?
In a normal IT investigation, a security team will ask familiar questions: Which user authenticated to the system? Was the login interactive or remote? What process executed? Which parent process launched it? Was PowerShell used? Did the host make a connection to a known command-and-control (C2) address? Was a new service created? Was an endpoint detection agent disabled? Did a file hash match known malware? Did a security information and event management (SIEM) system correlate the activity with other suspicious events?
In OT environments, those questions are difficult or impossible to answer with confidence.
A programmable logic controller (PLC) will not tell you that an attacker queried it. A remote terminal unit (RTU) will not produce meaningful authentication logs. A camera system will not provide security event details. A printer VLAN will not be monitored at all. A building management controller will provide little visibility into reconnaissance, failed access, enumeration, or command attempts.
Even when logs exist, they may be retained locally, overwritten quickly, unavailable to the SIEM, or written in formats that do not map cleanly to normal security analytics. For defenders relying on signature or heuristics tools, the likelihood of detecting the attacker will be low. A signature-based tool cannot match a signature against telemetry it never receives. A SIEM cannot correlate events that were never collected. A log analytics tool cannot detect an attack path that passes through assets with no meaningful logs.
Cyber Deception Is a Tool for Both Sides of IT-to-OT Attacks
Cyber deception addresses these problems while providing insights across the entire attack path from IT to OT. In a well-designed deception defense, the attacker will be presented with the exact information and devices needed to continue the attack. There will be information about the network, and there will be vulnerable assets to navigate. Each of these will capture forensics and alert defenders in real time.
Attackers do not respect organizational boundaries. They follow whatever route gets them closer to the operational objective. That cross-domain view is important because the most meaningful evidence may not come from the OT asset itself. It may come from the attacker’s path toward it.
Deception can connect those dots. A fake credential touched on an IT workstation, a beaconing OT network diagram opened by an attacker, a decoy engineering workstation accessed from a compromised host, and a simulated PLC queried from an unexpected source can all be part of the same detection story. The value is not only that each alert is high fidelity. The value is that the alerts show movement across the boundary that matters most.
Deception gives defenders a way to cover these spaces without pretending that every device can be converted into a modern IT endpoint. A decoy printer, camera, badge controller, or building management server doesn’t need to protect the real device by understanding every possible exploit. It simply needs to be believable enough that an attacker interacting with the network sees it as a useful target. Once touched, it tells the defender something valuable: Someone is exploring a system or segment where legitimate users had no reason to interact with the decoy.
This also improves response. In OT, response decisions are hard because the cost of getting them wrong can be high. Blocking a host, resetting credentials, disabling a vendor tunnel, segmenting a subnet, or interrupting a workstation will have operational consequences. Low-confidence alerts are difficult to act on. Deception alerts are different. If a honey credential is used, a fake OT document is opened, or a decoy PLC is queried, we know an unusual event is occurring. That gives defenders the confidence to respond faster and with more precision.
The Ukraine attack illustrates these points. The adversary’s success depended on preparation, access, knowledge, and the ability to move from enterprise compromise into operational control. Deploying deceptive elements in both IT and OT would have allowed defenders to detect earlier and receive intelligence across both domains.


