Your Factory Floor Is on the Internet. Nobody Told the PLC. [2026]

CONNECTED OPERATIONS · COMPANION TO THE OT/IIoT NETWORK TECHNICIAN BLUEPRINT
Your Factory Floor Is on the Internet. Nobody Told the PLC.
OT equipment runs for 25 years without patches. It is now connected to enterprise networks that touch the internet. The person who manages that boundary without breaking production or leaving the plant exposed is the most under-hired specialist in manufacturing.

Is This You?

  • You are in IT networking or industrial operations and you have watched IT and OT teams argue about a network change that could either fix a security gap or shut down the production line — and neither side fully understood the other’s constraints.
  • You have noticed that the person who could have resolved that argument in ten minutes does not seem to exist at your company.
  • You want to be that person.
  • All three: read the blueprint. Two of three: this piece explains why that person is worth becoming.
NOT THE RIGHT PIECE IF
  • You are starting from zero. The IoT Field Technician blueprint below this rung maps the entry cert stack. Read that first.
  • You want cybersecurity policy, not network operations. This piece is about owning the boundary operationally. The governance angle is the OT Cybersecurity Analyst seat, documented elsewhere on the board.
IF YOU READ NOTHING ELSE
Ask your company’s IT team and your company’s OT or maintenance team the same question: “Who owns the network boundary between the plant floor and the enterprise?” If neither can give you a clean answer, the seat exists at your company and nobody is in it yet. That is the opening.

The Problem That Created the Seat

  • IT and OT have incompatible priorities. IT cybersecurity prioritizes confidentiality of data, with regular patching cycles and standard endpoint protection on systems with 3–5 year lifespans. OT cybersecurity prioritizes availability and physical safety, protecting equipment that runs for 15–25 years and often cannot accept software agents or regular patches without risking production shutdowns. A breach in IT typically means data loss; a breach in OT can cause physical damage, safety hazards, or production downtime.
  • The equipment was connected without a plan. The typical industrial facility has legacy OT systems — PLCs running Windows XP-era firmware, Modbus devices from the 1990s, SCADA systems that communicate in cleartext — that were connected to enterprise networks because operations needed the data in the ERP system. The connection happened; the security plan did not follow it. IEC 62443-1-6, published in 2026, addressed IIoT device security in standards for the first time. The regulation is catching up to an installed base that has been exposed for years.
  • The workforce gap is structural. IT professionals know TCP/IP and VLANs. OT engineers know PLCs and Modbus. The person who knows both — fluently, at the level required to design and implement an IEC 62443 zone-and-conduit segmentation without breaking production — is assembled from self-taught career changers and people who happened to work at the intersection. No formal pipeline exists. Every OT cybersecurity report published in 2025–2026 names the talent shortage as the primary barrier to remediation.

What the Boundary Looks Like in Practice

IT AssumptionOT RealityWhat the OT/IIoT Network Tech Resolves
“We can patch this device remotely overnight.”The device runs a 1990s-era embedded OS. A patch attempt crashes the firmware. Production stops for 6 hours.Isolates the device in a segmented OT zone per IEC 62443, compensating controls in place, patch scheduled for the next planned outage window.
“This Modbus traffic on our network is a security risk.”It is. It is also running every motor on the floor. Blocking it shuts down manufacturing.Implements a DMZ with an OPC-UA gateway that translates Modbus to a monitored, authenticated protocol at the boundary. Both sides get what they need.
“All devices on this network need to be in our asset management system.”Half the OT devices do not have an IP address. The other half were installed by a contractor who is no longer available.Runs a passive OT asset discovery (Claroty, Dragos, or Nozomi) that identifies devices without sending active probes that could crash unpatched OT equipment.
“We need to connect this new sensor to the cloud for analytics.”“That sensor is physically attached to a $2M CNC machine. If the connection causes a fault, the machine is down for a week.”Provisions the sensor through an edge gateway with local failsafe logic: cloud connectivity optional, machine operation never dependent on it.

What Builds the Credential at This Rung

  • The Wireshark/Modbus experiment (from the blueprint’s first-move box) — reading industrial protocol traffic on an IP network is the core diagnostic skill. Document it.
  • An IEC 62443 zone-and-conduit diagram for a mock or real industrial facility, with the firewall rules and allowed protocols at each boundary documented. This is what an auditor or a hiring manager asks for first.
  • CCNA + ISA/IEC 62443 Cybersecurity Fundamentals — the combination that appears most frequently in OT network specialist postings, and the credential pair that signals both sides of the boundary.
  • One real boundary event you resolved — even informally, at your current employer — documented as a one-page case study. IT policy, OT constraint, solution implemented, outcome. That case study is the FDE-style artifact for this seat.
THE SCOT FREE TAKE

I have spent a career in audit and program management watching the same failure pattern repeat: two functions that each know their half of a problem, separated by a boundary neither was trained to cross, and a gap in between that everyone acknowledges and nobody owns. The IT/OT boundary is that gap, at industrial scale, with a safety consequence attached.

The difference between this board’s earlier entries and this rung is the nature of the failure mode. An IT network going down costs a company uptime and data. An OT network going down the wrong way costs a company a production run, or a machine, or in the worst documented cases, a person. That stakes differential is why this seat is paid what it is and why the standard (IEC 62443) is as specific as it is. The zone-and-conduit model is not bureaucracy for its own sake. It is the engineered answer to a specific failure mode that has happened enough times to be codified in an international standard.

The person who can read both sides of that standard — who can sit with the IT team in the morning and the maintenance team in the afternoon and translate between them without breaking either one’s trust — is not just solving a technical problem. They are solving an organizational one. And organizational problems that carry a safety consequence pay accordingly. The boundary exists at your company right now. The question is whether anyone is standing on it.

Sources

IIoT World, "OT Cybersecurity for Manufacturers: 2026 Guide" (IT vs. OT priority framework; 15–25 year lifecycle; patch constraints; breach consequences; zone-and-conduit architecture) · Fortinet, IEC 62443 Standard overview, 2026 · ISA, IEC 62443-2-1 update, January 2025 · Abhisam / IIoT World, IEC 62443-1-6 (IIoT device security, 2026). Full salary and certification citation in the OT/IIoT Network Technician Blueprint.

Read the full blueprint for the seat itself.
The OT/IIoT Network Technician Blueprint maps the four versions of the title, the CCNA + IEC 62443 cert combination, the paths in from IT networking and industrial maintenance, and a twelve-month plan that starts with a free Wireshark download and a Modbus simulation.
READ THE OT/IIoT NETWORK TECHNICIAN BLUEPRINT →
Knock twice. Tell them Scot Free sent you.
Previous
Previous

OT/IIoT Network Technician: The $82K Career Blueprint [2026]

Next
Next

Industrial Data Analyst: The $100K Career Blueprint [2026]