How to Find Undocumented External Connections in Your OT Network
✨ NEW GUIDE -- CIP-015 Compliance Guide helps industrial operators prepare for INSM requirements View the Guide X
Search
Blog
Contact Us
FREE PCAP Analyzer
Company
About EmberOT
Leadership
Our Partners
Events
Product
EmberOT In-Depth
Asset Inventory & Insights
Vulnerability & Risk
Detection
PCAP Analyzer Free Tool
Firewatch Assessment
IgniteOnsite
Resources
Resources
Blog
Documents
Podcasts
Newsroom
ICS Vulnerability Report
CIP-015 Compliance Guide
Solutions
Solutions
Oil & Gas
Electric Utilities
Industrial IoT
Manufacturing
Rural Co-ops
Request a Demo
Company
About EmberOT
Leadership
Our Partners
Events
Product
EmberOT In-Depth
Asset Inventory & Insights
Vulnerability & Risk
Detection
PCAP Analyzer Free Tool
Firewatch Assessment
IgniteOnsite
Resources
Resources
Blog
Documents
Podcasts
Newsroom
ICS Vulnerability Report
CIP-015 Compliance Guide
Solutions
Solutions
Oil & Gas
Electric Utilities
Industrial IoT
Manufacturing
Rural Co-ops
Request a Demo
Home1 > Resources2 > Blog3 > How to Find Undocumented External Connections in Your OT Network
Blog
How to Find Undocumented External Connections in Your OT Network
There’s probably a path out of your control network that nobody has written down. In most critical infrastructure environments, OT external connections aren’t hidden so much as forgotten. A tunnel somebody opened for a cutover and never closed. A cellular gateway sitting in a cabinet. A radio link between two buildings. An analog line with a modem on the end of it that’s been billed quietly for years.
Nobody hid any of it. Each one solved a real problem on a real day, usually under pressure, usually for a good reason. Then the technician who installed it moved to another account, the engineer who approved it retired, and the connection stayed exactly where it was.
Those are undocumented OT external connections, and most environments have a few. CISA put the category in writing on July 30. Its alert to the water sector tells water organizations, including those with mature cybersecurity processes, to validate their external connections, because the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. The alert went to one sector, but the pattern belongs to all of them.
That list of installers matters. Operators, vendors, system integrators. Two of those three likely don’t work for your organization.
OT External Connections Fall Into Two Categories
OT external connections are paths that allow traffic, access, or communications to leave or reach a control environment through vendor tunnels, cellular gateways, firewall rules, modems, radio links, remote-access systems, or other networked paths
The distinction that matters is whether the connection uses your infrastructure or brings its own, because it decides which method will ever find it.
Connections riding your own network. A vendor VPN tunnel set up for a commissioning window and never torn down. A firewall rule written for two weeks in 2021 that’s still permitting traffic in 2026. A jump host with accounts nobody has reviewed since the integrator handed over the keys. A dual-homed workstation quietly bridging two zones. These move across equipment you own, over circuits you already pay for.
Connections that never touch your network. A cellular gateway an integrator dropped into a cabinet because the site had no fiber. A legacy analog line or T1 with a modem on it, still live, still invoiced. A short-range radio bridging a remote asset back to a contractor’s equipment. A device with its own SIM, phoning a vendor’s cloud on a schedule. These carry their own way out. No amount of watching your own traffic will surface them, because they never cross it.
That second category is harder to validate. It’s genuinely invisible to network monitoring, and assuming otherwise creates a blindspot. It gets found through physical inspection, procurement records, and conversations with the people who installed it.
What a Clean OT Scan Result Actually Covers
Before any dig in the United States, you call 811. Member utilities send locators to mark the lines they own, up to a demarcation point, usually the meter or the property line. Everything past that point belongs to whoever owns the property. The conduit a contractor laid in 2014, the feed added during a parking lot expansion, the secondary run to an outbuilding: none of it gets marked, because none of it is registered with anyone. Private locating firms put the share that 811 never marks at somewhere around sixty percent of what’s actually buried on a developed site. Those firms sell that service, so weigh the figure accordingly, and it still matches what anyone who has dug on an occupied property already suspects.
The ticket comes back as a status. Depending on the...