Years ago I stood in a control room watching a wall of screens that all agreed with each other. Tank levels, flow rates, valve positions, every tile green. I asked the plant manager a question that seemed reasonable at the time and turned out to be the only question worth asking. If that number on the third screen were wrong, how would you find out?
He thought about it for a while. Then he said, honestly, that somebody would probably notice downstream. Eventually.
That answer has stayed with me because it is the correct answer for almost every industrial environment I have walked through since, and because it describes a problem that no amount of segmentation work fully solves.
What OT security is actually protecting
Start with the thing everyone already accepts. The air gap is gone in most plants, IT and OT are connected whether or not anyone drew it that way, and industrial environments are now squarely in scope for financially motivated attackers rather than only for nation states. Nobody serious argues with any of that.
Now go one layer down. In IT, the thing you are protecting is data, and data leaves evidence in several places at once. A single login produces a record on the endpoint, a flow across the network, an entry at the identity provider, and often a session log in the application. Four independent witnesses to one event. That redundancy is why detection engineering works at all. Corroboration is the whole game.
In OT, the thing you are protecting is a physical process, and a physical process typically has exactly one witness. A sensor reports a value to a controller. The controller passes it to the historian and the operator screen. The alarm logic evaluates the same reported value. Every element in that chain is downstream of the first assertion, and none of them can independently confirm it.
Which brings the argument to the point it turns on. A control you cannot independently witness is a control you are taking on faith. Not a weak control. Not an unpatched control. A control whose correct operation you have no second way to establish.
Why adversaries are mapping control loops
The 2026 Dragos OT and ICS Cybersecurity Year in Review documented something that deserves more attention than it received. Dragos tracked 26 threat groups engaged in OT operations, with 11 active during 2025, and described adversaries moving from device-level reconnaissance to mapping entire control systems. One group, which Dragos designates KAMACITE, systematically mapped control loops across United States infrastructure, scanning HMIs, variable frequency drives, metering modules and cellular gateways.
Read that as an engineer rather than as a security analyst. Mapping a control loop is not what you do when you want to break something. Breaking an industrial process is trivially easy once you have access. You stop it. Mapping the loop is what you do when you want the process to keep appearing normal while it is not.
You cannot spoof a process value convincingly unless you know what convincing looks like. You need the normal operating range, the rate at which the value moves, the relationship between that value and three others, and the alarm thresholds. That is exactly the reconnaissance being reported. It is the homework required to become the single witness rather than to remove it.
What it looks like in practice
Take a mid-size water utility with a competent operations team and a recently completed segmentation project. An attacker reaches the OT network through a vendor's remote support path, spends several weeks doing nothing but reading, and builds a model of one chemical dosing loop.
Then they change a setpoint by a small amount. Not a dramatic amount. An amount well inside the operating range, applied at the controller, while the value reported upward remains the old one.
Nothing alarms, because the alarm evaluates the reported value and the reported value is fine. The historian records a clean week. The operator sees green. The shift handover notes say normal. The only things in the building that know the truth are the physical process itself and the attacker.
Discovery comes, if it comes, from outside the control system. A lab sample. A customer complaint. An engineer who happens to read a local gauge and frowns. Every one of those is slow and none of them is a control.
The same Dragos report put average adversary dwell time in OT environments at 42 days, and found that organisations with comprehensive OT visibility detected and contained in an average of five. That is not a nine-fold difference in tooling budget. It is the difference between a process with one witness and a process with more than one.
The objection worth taking seriously
Anyone who has run an industrial security program will already have the response ready. This is Stuxnet. It is a nation-state problem, it happens roughly never, and the actual threat to my plant is ransomware, which is loud by definition and announces itself with a note on every screen.
That objection is fair, and it fails for two separate reasons.
The first is that the witness problem is not only about deception. It is about how long anything at all takes to notice, including the loud things. A ransomware operator who reaches OT still moves quietly for weeks before the noisy part. Forty-two days versus five is a measurement of corroboration, not of adversary sophistication. The same architecture that lets a subtle attacker lie to you lets an unsubtle one wander.
The second is that capability diffuses. It always has. The same report counted 119 ransomware groups targeting industrial organisations in 2025 and a 49 percent increase in ransomware groups with reach into OT environments, alongside a 64 percent year over year rise in attacks. Techniques that required a national program fifteen years ago become tooling, then become a service. Planning your defences around the sophistication of today's median attacker has never worked in any other domain and will not work in this one.
Adding a second witness
This does not start with a platform purchase, and it does not require touching the control system. Pick the one control loop where a wrong value sustained for 24 hours would cause the most damage. Just one. Then add a second, independent way of knowing what that loop is doing.
Independent is the operative word and it has a specific meaning. A different physical sensor, on a different network path, reporting to a different system, ideally read-only. A scheduled manual reading of a local gauge, logged and compared. A downstream quality measurement that would have to move if the process moved. Any of these works. What does not work is a second view of the same reported value, which is most of what gets sold as OT visibility.
Then run the test that matters. Ask your engineering team to make the two witnesses disagree, in a maintenance window, on purpose. If nobody notices the disagreement within an hour, you have learned something about your monitoring that no assessment report was going to tell you.
Three questions for Monday. Name the three physical processes where a wrong reported value sustained for a day would do real harm. For each one, list every source that could independently tell you the reported value is wrong. Then count how many of those sources sit outside the trust boundary the attacker would already be inside.
If the count is one, or if the answer to the third question is that they are all inside, you now have the finding. That is not a failure of your program. It is the default architecture of nearly every plant running today, and it is the thing worth spending next year's money on.
What this changes
The outcome is not a new dashboard. It is the ability to disbelieve a screen, which is a capability most operations teams do not currently have and cannot buy.
It also converts a question leadership and the board cannot answer into one they can. Asking whether the plant is secure produces an opinion. Asking how many independent witnesses exist for the three processes that matter most produces a number, a gap, and a cost to close it.
The attacker's objective was never to shut your plant down. Shutting it down tells you they were there. The objective is to be the only one telling you what your plant is doing.