A customer asked me something once that I've thought about many times since. We'd just been through our risk reduction roadmap together, and they said: Valeriy, if we only have limited time to understand the cybersecurity status of our system during the day, where should we look?
It's a question I hear from engineers and operations leads who understand their plant well, have real responsibility for cyber security, and are trying to fit it in alongside everything else. And it reveals something important. There are organisations that have already invested in multiple tools — malware protection, cybersecurity dashboards, network visibility platforms. The problem isn't that they lack tools. The problem is knowing how to use them together, in practice, when time is short.
And many people I meet — those responsible for both engineering and cyber security — simply don't have hours each morning to navigate multiple systems just to understand where they stand.
This plays out differently depending on the organisation. Larger companies may have a Security Operation Centers (SOC) or a dedicated cyber security team to carry this burden. Smaller ones rarely do — but their systems need the same level of protection.
Zoom out before you look in
When someone is responsible for both engineering and cybersecurity, they can't afford to open five different systems every morning. They need to know:
- Where do I get an overview?
- What actually needs my attention today?
- When do I need to go deeper?
The instinct is often to monitor individual systems — checking whether each component is healthy, whether it's been updated. That's not wrong, but it gives you a system-by-system picture rather than an environment-wide one.
In OT, risk rarely sits in one place. It moves through connections between systems, through components that haven't been updated, through parts of the network that weren't fully documented when they were installed.
That's also why having many tools doesn't automatically make your system more secure. Security only works when the right tools are integrated into your daily operations.
What a five-minute check should cover
If I'm helping a customer define their daily review, I focus on three things: identifying the right tools for their environment, integrating those tools so they present a connected picture, and defining a clear workflow for using them. The goal is that five minutes should be enough to answer the questions that matter.
Is anything behaving differently from yesterday? Are there alerts from the last 24 hours that haven't been acted on? And critically — are there decisions sitting with your team that nobody has moved forward on?
Five minutes a day, done consistently, and you'll have a reliable sense of your environment. You'll catch changes early, and you'll know when something needs deeper investigation.
The things I'd say first to any operator
If your current setup requires too much time just to understand what's happening, something needs to change. And if you don't have a structured plan yet, a proper cyber security risk assessment of you OT environment is where to start. Without it, you can spend a lot of time and money on individual issues while your overall postures stays weak. With it, everything that follows becomes much more straightforward.