Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When legacy operational technology (OT) cannot be patched or cannot run modern security controls, protect it through the systems and processes around it: understand its role and exposure, restrict the pathways to it, monitor those pathways, and prepare a safe way to keep operating if the network must be isolated. These measures reduce risk; they do not fix the device’s underlying weaknesses. The right plan depends on the equipment, the process it controls, and the consequences of changing or losing it.

Start with the asset’s role in the process

Before changing network rules or access, establish what the device does, what depends on it, and what could happen if it is unavailable or manipulated. A device list alone is not enough: the inventory should show how the asset participates in operations and which systems or people can reach it.

The 2025 joint guide Foundations for OT Cybersecurity: Asset Inventory recommends identifying critical assets, documenting redundancy plans and whether operations can continue under compromise, and using risk information to strengthen architecture.

  • Record the asset’s owner, location, function, software or firmware version where known, and support status.
  • Map its network connections, required communications, and dependent systems, processes, and people.
  • Document its operational criticality, available redundancy, and the consequences of loss, disruption, or unauthorized changes.
  • Identify which changes require engineering, vendor, or safety review before implementation.

Use this operational context to prioritize controls. Two devices with similar technical weaknesses may warrant different treatment if one has a safe redundant alternative and the other is essential to a process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SafeBiz - Wireless Cybersecurity Solution, Next-Gen Firewall, Web Filtering, Phishing/Ransomware/Malicious Website Protection - Wifi6E, 4.3 Gbps, 3000 Sq.Ft Coverage
  • BUSINESS CYBERSECURITY SOLUTION: SafeBiz is an advanced cybersecurity solution that protects your work network and safeguards your Business data and all internet connected devices in your business from cyber threats and hackers. SafeHome blocks phishing, malware, ransomware, online scams and dark web threats.
  • ADVANCED THREAT PREVENTION: SafeBiz includes a Next-Gen Firewall, DNS Security, Web Filtering, Dark Web Protection, Geo-fencing and other AI Powered cybersecurity features protecting your Business and Sensitive Data from internet threats and hackers.
  • BUSINESS DATA & IDENTITY SECURITY: Safeguards your Official and financial data, protecting them from online theft and unauthorized access.
  • EASY SETUP: Connects effortlessly to any existing wireless router or internet connection, setting up in minutes without the need for any changes to your Business internet connection.
  • HIGH SPEED CONNECTIVITY: Supports an aggregate throughput of up-to 4.3 Gbps, maintaining high-speed browsing and streaming performance for up to 128 devices.

Reduce exposure with controls around the device

If the device cannot enforce modern security features itself, place safeguards at the network boundaries and on the routes used to reach it. The National Security Telecommunications Advisory Committee (NSTAC) identifies firewalls, network access control, segmentation, and additional monitoring as possible compensating controls when patching is not possible in its report on IT and OT convergence. These measures reduce exposure around the asset; they do not remove its vulnerabilities.

Separate business IT from OT

Define which data must cross between business IT and OT, and allow only those necessary exchanges through a controlled boundary, such as an OT demilitarized zone (DMZ). Within OT, group assets according to operational need and consequence, then define and filter the permitted communications between groups. CISA’s Primary Mitigations to Reduce Cyber Threats to Operational Technology recommends separating OT from the public internet where possible and using controlled network boundaries; the guidance also addresses access and least privilege.

Rank #2
Milf Man I Love Firewalls Funny Cybersecurity CISSP T-Shirt, Men, Black, Small
  • A funny, tech themed cybersecurity design for those who work in IT security. Perfect for anyone who works in cyber security, sysadmin roles, network engineering and tech support.
  • Reads - "MILF Man I Love Firewalls"
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Limit communication to what the process requires

Map the device’s necessary connections before restricting them. Permit only required communications, and avoid unnecessary pathways between networks or protocols. Filtering an unknown or essential connection without understanding its operational role can disrupt the process; validate proposed rules with the people responsible for engineering and safe operation.

Do not rely on segmentation alone

Segmentation can be misconfigured or accidentally broken. CISA and partner agencies’ Secure by Demand: Priority Considerations for Operational Technology Owners and Operators cautions against assuming that an attacker will never gain access to the OT network. Treat segmentation as one layer, alongside access restrictions, monitoring, and recovery planning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restrict remote and human access

Review who can reach the legacy asset, from where, and for what task. CISA’s 2025 OT mitigations guidance recommends removing OT assets from the public internet where possible. Where remote access is necessary, it recommends VPN functionality with phishing-resistant multifactor authentication (MFA) for users, least privilege scoped to the asset and work, and disabling dormant accounts.

Apply access changes through a controlled process that accounts for equipment capabilities, vendor or support dependencies, and process safety. Do not assume a legacy device can support a control it was not designed to use; where it cannot, enforce the restriction at an appropriate surrounding boundary.

Monitor access and prepare for isolation

Monitoring should cover the asset and the network pathways leading to it. The 2025 CISA-led asset-inventory guide treats monitoring as part of effective OT security architecture, and the NSTAC report names additional monitoring as a possible compensating control. Decide what activity is expected, who reviews alerts, and how operators can respond without creating an unsafe process condition.

Map IT/OT dependencies and define how to keep critical functions safe if network connections need to be taken offline. CISA, the FBI, and the NSA recommend developing workarounds or manual controls and testing them regularly so critical functions can continue if OT/ICS networks must be isolated. A plan that has not been tested may not work when needed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose between continued operation, replacement, and redesign

There is no universal rule that every legacy device must be removed immediately: the NSTAC report notes that some legacy devices have no available replacement. But keeping a vulnerable asset in service should be a documented risk decision, not an indefinite default. The 2025 CISA-led asset-inventory guide recommends comparing the potential cost of downtime or degraded service with replacement or compensating controls.

Path When to consider it What to assess
Continue operation with compensating controls When immediate patching or replacement is not feasible, including cases where no replacement is available. Whether feasible network and access controls reduce exposure; what residual risk remains if a control fails; and whether monitoring and tested recovery measures support safe operation. The cited guidance does not establish a universal risk score.
Replace or redesign When the lifecycle, exposure, or consequences make continued operation with compensating controls an unacceptable risk, and a feasible alternative exists. Replacement feasibility and support, transition and downtime consequences, process dependencies, and whether the proposed design’s security assumptions fit the environment. The cited guidance recommends comparing downtime or degraded-service costs with replacement or compensating controls, but does not prescribe a universal threshold.

Record the assumptions behind the decision, the residual risk, operational constraints, and conditions that would trigger reassessment. When planning a new design or eventual replacement, ask manufacturers about their threat models, communication capabilities, intended operating environments, and assumed security controls, as recommended by the Secure by Demand guide.

Put the controls into an operating plan

Assign owners for the asset inventory, network rules, access reviews, alert response, and recovery procedures. Document approved communications and the process for reviewing changes. Revisit the plan when the asset’s support status, connections, dependencies, or operational role changes. The cited guidance supports this risk-based approach, but it does not provide a site-specific safety case or a one-size-fits-all engineering design; those require assessment of the actual system and process.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.