How to Find Undocumented External Connections in Your OT Network

TheWiggles1 pts0 comments

How to Find Undocumented External Connections in Your OT Network

✨ NEW GUIDE -- CIP-015 Compliance Guide helps industrial operators prepare for INSM requirements View the Guide X

Search

Blog

Contact Us

FREE PCAP Analyzer

Company

About EmberOT

Leadership

Our Partners

Events

Product

EmberOT In-Depth

Asset Inventory & Insights

Vulnerability & Risk

Detection

PCAP Analyzer Free Tool

Firewatch Assessment

IgniteOnsite

Resources

Resources

Blog

Documents

Podcasts

Newsroom

ICS Vulnerability Report

CIP-015 Compliance Guide

Solutions

Solutions

Oil & Gas

Electric Utilities

Industrial IoT

Manufacturing

Rural Co-ops

Request a Demo

Company

About EmberOT

Leadership

Our Partners

Events

Product

EmberOT In-Depth

Asset Inventory & Insights

Vulnerability & Risk

Detection

PCAP Analyzer Free Tool

Firewatch Assessment

IgniteOnsite

Resources

Resources

Blog

Documents

Podcasts

Newsroom

ICS Vulnerability Report

CIP-015 Compliance Guide

Solutions

Solutions

Oil & Gas

Electric Utilities

Industrial IoT

Manufacturing

Rural Co-ops

Request a Demo

Home1 > Resources2 > Blog3 > How to Find Undocumented External Connections in Your OT Network

Blog

How to Find Undocumented External Connections in Your OT Network

There’s probably a path out of your control network that nobody has written down. In most critical infrastructure environments, OT external connections aren’t hidden so much as forgotten. A tunnel somebody opened for a cutover and never closed. A cellular gateway sitting in a cabinet. A radio link between two buildings. An analog line with a modem on the end of it that’s been billed quietly for years.

Nobody hid any of it. Each one solved a real problem on a real day, usually under pressure, usually for a good reason. Then the technician who installed it moved to another account, the engineer who approved it retired, and the connection stayed exactly where it was.

Those are undocumented OT external connections, and most environments have a few. CISA put the category in writing on July 30. Its alert to the water sector tells water organizations, including those with mature cybersecurity processes, to validate their external connections, because the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. The alert went to one sector, but the pattern belongs to all of them.

That list of installers matters. Operators, vendors, system integrators. Two of those three likely don’t work for your organization.

OT External Connections Fall Into Two Categories

OT external connections are paths that allow traffic, access, or communications to leave or reach a control environment through vendor tunnels, cellular gateways, firewall rules, modems, radio links, remote-access systems, or other networked paths

The distinction that matters is whether the connection uses your infrastructure or brings its own, because it decides which method will ever find it.

Connections riding your own network. A vendor VPN tunnel set up for a commissioning window and never torn down. A firewall rule written for two weeks in 2021 that’s still permitting traffic in 2026. A jump host with accounts nobody has reviewed since the integrator handed over the keys. A dual-homed workstation quietly bridging two zones. These move across equipment you own, over circuits you already pay for.

Connections that never touch your network. A cellular gateway an integrator dropped into a cabinet because the site had no fiber. A legacy analog line or T1 with a modem on it, still live, still invoiced. A short-range radio bridging a remote asset back to a contractor’s equipment. A device with its own SIM, phoning a vendor’s cloud on a schedule. These carry their own way out. No amount of watching your own traffic will surface them, because they never cross it.

That second category is harder to validate. It’s genuinely invisible to network monitoring, and assuming otherwise creates a blindspot. It gets found through physical inspection, procurement records, and conversations with the people who installed it.

What a Clean OT Scan Result Actually Covers

Before any dig in the United States, you call 811. Member utilities send locators to mark the lines they own, up to a demarcation point, usually the meter or the property line. Everything past that point belongs to whoever owns the property. The conduit a contractor laid in 2014, the feed added during a parking lot expansion, the secondary run to an outbuilding: none of it gets marked, because none of it is registered with anyone. Private locating firms put the share that 811 never marks at somewhere around sixty percent of what’s actually buried on a developed site. Those firms sell that service, so weigh the figure accordingly, and it still matches what anyone who has dug on an occupied property already suspects.

The ticket comes back as a status. Depending on the...

connections external network find undocumented guide

Related Articles