Canonical: https://www.vinetu.co.il/ot-security
Language: en
Modified: 2026-09-25
Publisher: Vinetu Technologies

OT security · ICS · Critical infrastructure

# Cybersecurity for industrial and operational technology networks

Vinetu Technologies designs and implements cybersecurity for operational technology (OT) and industrial control networks: separating OT from IT, segmenting control systems, securing remote vendor access, deploying industrial-grade firewalls and connecting OT events to monitoring, without interrupting production.

[Discuss OT security](mailto:info@vinetu.co.il?subject=OT%20%2F%20industrial%20cybersecurity%20enquiry)[See the scope](https://www.vinetu.co.il/ot-security#scope)

By Vinetu Technologies · Reviewed 25 September 2026

## What makes OT security different?

In an office network the priority is protecting data. In a plant, a tunnel or a utility the priority is keeping a physical process running safely. Controllers and SCADA systems often run for many years, cannot be patched on demand, and may fail if scanned or rebooted at the wrong time. Security measures that are routine in IT can stop production in OT.

Vinetu approaches OT security as a network engineering problem first: understand how the process communicates, then separate and control those paths. Most risk reduction comes from segmentation between IT and OT, restricting and recording remote access, and knowing exactly which devices are on the control network.

This work draws on Vinetu’s background in resilient networks, command-and-control systems and industrial IoT, and on published engagements such as ICL, where the scope included network and OT cybersecurity.

## Who it is for

- Manufacturing plants and process industries with PLC, DCS or SCADA systems.
- Transport and infrastructure operators with control networks in tunnels, roads or facilities.
- Engineering and operations managers who need to connect OT data to IT without exposing the control network.
- Organizations that give equipment vendors remote access to production systems.

## Problems it solves

- Flat networks where office IT and control systems share the same address space.
- Permanent, unmonitored remote-access paths used by integrators and equipment vendors.
- No reliable inventory of what is connected to the control network.
- Ransomware on the IT side that can spread into production because there is no enforced boundary.

## Scope and deliverables

- Discovery of OT assets, communication flows and existing connections to IT and external parties.
- Architecture for IT/OT separation and segmentation of control zones.
- Deployment of firewalls and network equipment suitable for industrial environments.
- Secure remote-access design for vendors and engineers, with approval and logging.
- Integration of OT events into security monitoring where it can be done safely.
- Change planning coordinated with operations, including maintenance windows and rollback.
- Documentation of the resulting architecture and rules for ongoing change management.

## How we deliver it

- ### Assess Map assets and communication flows passively where possible, together with the operations and maintenance teams.
- ### Design Design zones, boundaries and allowed flows, and agree the remote-access model and monitoring points.
- ### Implement Implement changes in maintenance windows, one boundary at a time, with a tested rollback for each step.
- ### Validate Verify with operations that the process runs normally, that only intended flows pass, and that logging works.
- ### Operate Maintain rules as equipment and vendors change, and review the architecture periodically.

## Technologies and partners

- **Fortinet** — firewalls for IT/OT boundaries and segmentation
- **Extreme Networks** — segmented network fabric (Fabric Connect / VOSS)
- **CyRay** — SIEM/SOC monitoring of IT and OT events, delivered with Vinetu as CyRay MSP partner

OT changes are planned with the site’s operations team and carried out only in agreed maintenance windows. Vinetu does not perform active scanning of control networks without explicit approval from the asset owner.

## Why Vinetu

- Network engineering depth: OT security is mostly about designing and enforcing the right paths.
- Founder experience in mission-critical cybersecurity, command-and-control systems and industrial IoT.
- Published engagements in industrial and infrastructure environments, including ICL (network and OT cyber).
- One team for the IT network, the OT boundary and the monitoring that connects them.

## Related projects

Published industrial and infrastructure engagements (scope as listed in our portfolio):

- **ICL** — Network & OT Cyber
- **Carmel Tunnels** — Network & Cyber Consulting
- **Netivei Ayalon** — Consulting, IT & Cyber
- **Netivei Israel** — Consulting, IT & Cyber
- **Spuntech** — Network & Cyber Consulting
- **CIVIQ Smartscapes** — Smart City Network, Cyber & IoT

## Frequently asked questions

### Will securing the OT network interrupt production?

It should not. Discovery is passive where possible, changes are made in agreed maintenance windows, and every step has a rollback. Operations staff take part in validating each change.

### Where do you start in an OT environment?

With visibility and the IT/OT boundary: knowing what is on the control network and making sure the office network and the internet cannot reach it except through controlled, logged paths.

### How should equipment vendors connect remotely?

Through a single controlled access path that requires approval, is limited to the systems the vendor supports, is time-bound and is logged. Permanent, direct connections are replaced as part of the project.

### Can OT be monitored by a SOC?

Yes, when collection is designed not to create new paths into the control network. Vinetu can connect OT events to SIEM/SOC monitoring delivered with CyRay.

Vinetu service

## Review your IT/OT boundary

Describe your site, control systems and how vendors connect today. We will propose a segmentation and remote-access plan that operations can accept.

Vinetu Technologies · Operating since 2010 · ISO 27001, ISO 27017 and ISO 9001 certified · EMCloud private cloud on AS35435

[Discuss OT security](mailto:info@vinetu.co.il?subject=OT%20%2F%20industrial%20cybersecurity%20enquiry)[Call +972-722-477477](tel:+972722477477)[Use the contact form](https://www.vinetu.co.il/#contact)

## Related services

[Managed Cybersecurity](https://www.vinetu.co.il/managed-cybersecurity)[SIEM & SOC](https://www.vinetu.co.il/siem-soc)[Network & Datacenter](https://www.vinetu.co.il/network-datacenter)[Consulting & Architecture](https://www.vinetu.co.il/consulting)[Services →](https://www.vinetu.co.il/services)
