Frequently Asked Questions
How should a manufacturing company respond to an OT cybersecurity incident?
Unlike IT incidents, an OT response must prioritise physical safety before network containment. Bring production processes to a safe state through pre-engineered Emergency Shutdown sequences before severing any network interface, because cutting a running process outside its designed stop sequence can damage equipment or create a safety hazard. Then, restore to an air-gapped staging environment and verify every recovered PLC configuration against cryptographically signed baselines before any controller drives physical equipment again. Re-energise production cell by cell, and return control to operators only after Safety Instrumented Systems complete their self-tests.
Will factory floor systems become more connected to IT networks in the future?
Yes, and most plants are already there. Industry 4.0 connected PLCs and SCADA systems to corporate ERP platforms, cloud analytics pipelines, and vendor remote-access tools because the operational efficiency gains are real and measurable. Edge computing is extending that further, placing data processing directly on the plant floor and creating new network paths between OT devices and external infrastructure. A PLC that was air-gapped five years ago now sits on a network that touches the internet, which means decades-old controllers that were never designed with cybersecurity in mind are reachable by the same adversaries that target corporate IT.
Are industrial control systems still fully isolated from outside networks?
Rarely. True air-gapping is now the exception. Plants connect OT to corporate IT, cloud platforms, and vendor remote access because those links make operations more efficient. SolarWinds showed how air-gapping can fail in its goal if not done correctly, since a compromise in data-centre software still crossed into plant networks in that case. However, true air gapping is often seen as best practice when used as a control you maintain on specific assets, such as tape unloaded from a library, not as a property the plant network still has. Bacula offers strong differentiation with its advanced tape and true air-gapping solutions, at a time when it is enjoying somewhat of a renaissance in security-conscious organizations.
Do I need to secure every OT asset, or only the ones at highest risk, and how do I identify which ones those are?
Every asset, but not with the same controls. Uniform SL4 wastes resources on low-consequence zones, and uniform SL1 leaves the dangerous ones underdefended. Start with an inventory, because an undocumented controller never gets rated. Then group assets into zones and rate each by consequence: what fails physically, whether anyone gets hurt, and how long the plant runs without it. A turbine valve and an office printer sit at opposite ends of that scale.
Does Bacula Enterprise protect OT environments?
Yes. Bacula Enterprise protects both OT and IT environments under one platform. Its five-component architecture distributes across IEC 62443 zone boundaries, and it can back up both the live historian and databases through native plugins without halting the system.