Podcast Episode with 
Andreas Happe & Siegfried Hollerer

In this episode, OMICRON's OT security expert Simon Rommer, along with security research experts Andreas Happe and Siegfried Hollerer, discuss their work and experience with the open-source OWASP OT Top 10 Project, which addresses critical industrial cybersecurity challenges affecting OT environments. Simon and his guests describe how critical cybersecurity risks are mapped directly to global frameworks like IEC 62443 and NIST, providing actionable countermeasures and a shared vocabulary for improved industrial resilience.

quote

“Each of the OT top 10 item is mapped to the matching standard requirements. Then you have based on the link from the risk to the mapping table a pretty comprehensive list of security measures which you can then place into your OT systems to protect against the corresponding risk.”

Siegfried Hollerer

Security Architect & Analyst & NIS Auditor at the Ministry of the Interior (BMI) in Austria & Lecturer at Fh St. Pölten
quote

“When we started to write the individual top 10 items we tried to take a very wholistic approach. Not only focusing on technology problems but also on organizational or awareness problems.”

Andreas Happe

Security Research & PhD Student at the Tu Wien

Listen

to the podcast episode on Spotify and Apple Music – or directly on OMICRON Energy:

Listen to the Episode

Why OT Security Needs Its Own Top 10

Operational Technology is becoming increasingly interconnected with IT systems. This brings clear benefits for efficiency and data exchange, but it also exposes industrial environments to cyber threats that were once primarily associated with IT.

Because OT systems interact directly or indirectly with physical processes, however, the consequences of an incident can extend far beyond data. A cyber attack may affect system availability, equipment, critical infrastructure and, ultimately, safety, which is why OT security needs to account for the particular technologies, priorities and operational constraints of these environments.

This is one of the reasons why we created the OWASP Operational Technology Top 10. Together with an international community of OT and cybersecurity experts, we wanted to provide a practical, vendor-neutral resource that helps developers, operators, integrators and other stakeholders understand the security problems they are most likely to encounter in OT.

As one of the project leaders, what stood out to me during the discussions and research behind the project was how often we came back to the fundamentals. Many of the risks we considered most important are not highly sophisticated attack techniques, but security problems that organizations can address systematically if they understand where to begin. In practice, of course, getting these fundamentals right usually proves to be anything but simple.

The Foundations of Effective OT Security

During the discussions around the OWASP OT Top 10, we agreed on the items that should be included, while the exact ranking remained much more subjective. OT environments differ significantly, and the relevance of an individual risk always depends to some extent on the system and its operational context. But also, on the individual's background. A penetration-tester might have different viewpoints from, for example, a forensics expert. There was, however, consensus that four topics are fundamental to OT security:

🟪 Unknown assets and unmanaged external access
🟪 Devices with known vulnerabilities or issues
🟪 Inadequate supplier and supply chain management
🟪 Loss of availability

I find this particularly revealing because cybersecurity discussions often gravitate toward new malware, sophisticated threat actors and advanced detection technologies. All of these deserve attention, but an organization can still be exposed through much more fundamental weaknesses. If it does not know which assets are connected to its OT environment, who has external access, which known vulnerabilities affect its devices, or how suppliers interact with its systems, advanced security measures are being built on an incomplete foundation.

For organizations that are beginning their OT security journey, or reassessing an existing security program, I would therefore start with visibility and understanding rather than with the most sophisticated technology available. Knowing what needs to be protected and how it is connected creates the basis for deciding which additional security measures are actually required.
 

OT Cybersecurity Goes Beyond 
Vulnerability Management

From the beginning, the intention behind the OT Top 10 was broader than creating another list of software vulnerabilities. When cybersecurity risks are discussed, the conversation can quickly focus on vulnerable software, missing patches or insecure protocols; in operational environments, however, technical weaknesses are only part of the picture. Organizational structures, processes, access management and awareness can all influence whether an incident occurs and how serious its consequences become.

The remaining OWASP OT Top 10 categories reflect this broader perspective:

🟪 Insufficient access control
🟪 Missing incident detection and reaction capabilities
🟪 Broken zones and conduits design
🟪 Missing awareness
🟪 Components or protocols with insufficient security capabilities
🟪 Missing hardening

The final item is an interesting example of this broader approach. Missing hardening is not a security issue by itself, but we included it because hardening would have prevented many of the incidents reported from the field. Rather than looking only at individual vulnerabilities, the list therefore also considers the conditions that can make an incident possible or increase its impact.

In my view, this broader perspective is important for OT security. Technology remains an essential part of the equation, but architecture, processes, access management, awareness and the way systems are configured need to be considered to secure the whole plant.

Applying IT Security Principles to OT

OT systems cannot simply be treated like another part of the enterprise IT environment. Many industrial systems remain in operation for years or even decades, maintenance windows may be limited, and availability and reliability are fundamental operational requirements. Safety may also need to be considered when security measures affect systems that interact with physical processes. As a result, measures that appear straightforward in an IT environment can become considerably more difficult to implement in OT.

Take a device with a known vulnerability as an example. Addressing a software vulnerability in an office environment may be comparatively straightforward, whereas changing software or firmware on an industrial device performing a critical operational function can require significantly more preparation. The operator has to consider the effect of the change on the process as well as the opportunities available for carrying it out.

None of this means that established cybersecurity principles become irrelevant in OT. Access control, segmentation, vulnerability management, monitoring and hardening remain important; what changes is the context in which these measures have to be implemented. For anyone coming from IT security into the OT world, I believe this is an important distinction to understand: the security objective may be familiar, while the operational constraints can lead to a very different implementation.

From Awareness to Action

Raising awareness and providing guidance was one of the primary objectives of the OWASP OT Top 10, particularly for people who are not yet familiar with the security risks of operational environments. At the same time, simply knowing that a problem exists does not tell a developer, integrator or operator what to do next. The individual risk categories therefore provide background information, explain why the respective issue matters, and include examples and mitigation approaches.

The project also maps its risks to established cybersecurity standards and guidance, including:

🟪 IEC 62443
🟪 NIST SP 800-82
🟪 NIST Cybersecurity Framework 2.0
🟪 MITRE ATT&CK concepts and mitigations
🟪 Risk management measures related to NIS2 implementation requirements

For me, these mappings are particularly useful because they connect the awareness created by a Top 10 list with the frameworks organizations may already be using. Instead of stopping at "we have identified a problem," practitioners can use the references as a starting point for finding relevant controls and improvement measures.

This also means that the resource can be useful at different stages of OT security maturity. Someone entering the field can use it to understand common problems and the particular requirements of OT, while organizations with established security processes can use the list as another perspective from which to examine existing controls and potential gaps.

Bridging the IT/OT Knowledge Gap

When IT security and OT specialists work together, technology is not the only challenge. The two disciplines have developed from different backgrounds, use terminology differently and approach risks with different priorities. This can make communication more difficult even when both sides are ultimately working toward the same objective.

We therefore included introductory material and a glossary alongside the OWASP OT Top 10. A shared vocabulary may appear less significant than a technical security measure, but it helps establish the common understanding that developers, integrators, operators and security specialists need when they assess risks or discuss possible mitigations.

The same principle becomes even more relevant when different disciplines have to collaborate on a security issue. Bridging IT and OT is not only about connecting technologies or introducing cybersecurity tools into an industrial environment; it also requires the people responsible for those systems to understand one another.

Why OT Security Needs Shared Expertise

Operational Technology covers an exceptionally broad range of systems and use cases. The scope of the OWASP OT Top 10 itself extends from devices at the core of an operational process to related systems such as HMIs, virtualization infrastructure and other components directly connected to the OT purpose. That diversity makes it difficult for any single perspective to represent the entire field.

For me, this is one of the strengths of developing the project as an open community effort. The list emerged from discussions between contributors with different backgrounds, and those discussions also showed why the ranking cannot be completely objective. What is critical in one environment may have a different priority in another, even though many of the underlying security challenges are shared.

Rather than trying to provide one universally correct answer, the OWASP OT Top 10 offers a common foundation for those discussions. Because the project is developed openly, practitioners can review the material, propose changes and contribute their own experience as OT technologies and cybersecurity challenges continue to develop.

Where to Start with OT Cybersecurity?

Ten risk categories can still seem like a lot to address at once, particularly for an organization that is only beginning to structure its approach to OT cybersecurity. Based on what we learned while working on the Top 10, I would return to the same fundamentals that shaped the first four categories and use them to start asking practical questions:

🟪 Do we know which assets are part of our OT environment?
🟪 Do we know who can access them, including external parties?
🟪 Do we know which known vulnerabilities affect those assets?
🟪 Do we understand our dependencies on suppliers?
🟪 Do we know how we would detect and respond to an incident?
🟪 Is the network architecture appropriately segmented?
🟪 Do the people responsible for IT and OT have a common understanding of the risks?

The purpose is not to produce perfect answers to every question immediately. It is to establish visibility, identify the most relevant gaps and then improve them systematically. In that sense, I do not see the OWASP OT Top 10 as a checklist that an organization completes once and puts aside, but as a starting point for discussions between developers, integrators, operators, security teams and decision makers about the risks that matter in their particular environment.

What OWASP OT Top 10 Teaches Us

Cyber threats will continue to evolve, just as the technologies and architectures used in OT will continue to change. New vulnerabilities and attack techniques will inevitably become part of the discussion, but the work on the OWASP OT Top 10 reinforced for me how much effective OT security still depends on getting the fundamentals right.

Knowing what an organization operates, understanding who can access those systems, recognizing where weaknesses and dependencies exist, and enabling the people responsible for IT and OT to work together provide the foundation on which more advanced cybersecurity measures can be built. The OWASP OT Top 10 is intended to help organizations establish and continuously question that foundation rather than treating security as a list of individual technical problems.

The OWASP OT Top 10, its supporting materials, glossary, standards mappings and contribution guidelines are openly available through the OWASP OT project:

OWASP OT Top 10

Listen

to the podcast episode on Spotify and Apple Music – or directly on OMICRON Energy:

Visit OMICRON Energy

Resources

Simon Rommer

OT Cybersecurity Expert, OMICRON

Simon combines hands-on experience in SOC analysis, forensics, and IT/OT interfaces with a knack for tackling complex challenges. From securing Austria's largest energy provider to optimizing security at the IT/OT edge, he's dedicated to making the protection of critical systems smarter and safer.