Implicit OT Thursday Thought – Squeezing the corporate build until engineers smuggle in their own laptops
Week of 16 April 2026 • 2 min read
Corporate laptops are now so locked down that site engineers quietly pull out their own personal laptops because they’re worried they won’t be able to do their job with the standard build. I’ve watched this happen on real sites.
In OT, that means unmanaged, unpatched, unknown endpoints are walking straight into plants, substations and control rooms and plugging into the most sensitive networks you own.
Why this is a problem (beyond policy)
Personal laptops are rarely hardened to an OT standard: no baselines, no central logging, no proper EDR, and often significantly out-of-date software.
BYO devices are a perfect delivery mechanism for malware into engineering workstations and control networks, especially when USB and removable media are still the main way to move configs, firmware and logic.
Once a “trusted” engineer device is on a flat or weakly segmented OT network, it can become a bridge between internet-exposed IT services and safety-critical systems.
The harder we squeeze the corporate build, the more we incentivise a shadow IT culture that quietly routes around all that good policy work.
What we’d rather not admit: Over-restrictive controls are still risky controls.
If an engineer genuinely believes they can’t load a new vendor tool, apply a hotfix on a night shift, or pull logs or upload a temporary script or license, they will find another way.
In the field, “mission success” usually wins over “policy compliance”.
A better OT-centric approach
If we’re serious about OT cyber, we need to design usable security for the people who keep the lights on:
Provide a clearly defined “engineering laptop” pattern: hardened, monitored, but with the tools and privileges required for field work, including offline scenarios.
Wrap that device in controls that match IEC 62443 intent: network zoning, application whitelisting, strict removable-media workflows and malware scanning at every crossing point.
Make the secure path the easiest path: fast exceptions, pre-approved tool catalogues, and clear, documented ways to get “that one vendor utility” onto a box without sneaking in a personal device.
When engineers trust the corporate build to let them succeed, the temptation to reach for a personal laptop drops dramatically.
Have a good week,
Damien Pope
News by Others – What caught our eye this week
1. Vulnerability – Windows Active Directory Vulnerability Allow Attackers to Execute Malicious Code
Microsoft has released urgent patches for a critical flaw in Active Directory – the system that manages user access… Read more →
2. Incident – Prepping for ‘Q-Day’: Why Quantum Risk Management Should Start Now
Quantum computers are coming and will break the encryption that protects today’s most sensitive data, which is why… Read more →
Need help securing your OT environment? IEC 62443 • Essential Eight • Gap analysis • Network segmentation • OT incident response and more – Talk to us