Detection
Logging & Log Centralisation
Collect the OT logs that matter, safely, and retain them long enough to investigate.
Defensive guide
Why should I care?
Investigations depend on evidence that must already exist when the incident starts.
How to implement it
- Prioritise: boundary firewalls, remote access, authentication, engineering hosts, controller change events
- Forward from OT to a collector via the DMZ; never let the SIEM query into control zones
- Retain long enough to cover the dwell times seen in documented OT intrusions
What good looks like
- Time-synchronised logs across OT
- Retention aligned to investigation needs
Common failure modes
- Agents installed on fragile systems without vendor approval
- Log volume so noisy it is never reviewed
How to verify it
- Pick a recent change and reconstruct it entirely from logs