{"id":16817,"date":"2026-07-29T14:10:19","date_gmt":"2026-07-29T08:10:19","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=16817"},"modified":"2026-07-29T14:10:21","modified_gmt":"2026-07-29T08:10:21","slug":"agentless-security-for-ot-ics-networks-how-netflow-telemetry-covers-the-devices-you-cannot-touch","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/agentless-security-for-ot-ics-networks-how-netflow-telemetry-covers-the-devices-you-cannot-touch\/","title":{"rendered":"B\u1ea3o m\u1eadt Kh\u00f4ng c\u1ea7n T\u00e1c nh\u00e2n cho M\u1ea1ng OT\/ICS: C\u00e1ch Vi\u1ec5n tr\u1eafc NetFlow Ph\u1ee7 s\u00f3ng c\u00e1c Thi\u1ebft b\u1ecb B\u1ea1n Kh\u00f4ng Th\u1ec3 Ch\u1ea1m t\u1edbi"},"content":{"rendered":"<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2026\/07\/image-137-1024x576.png\" alt=\"\" class=\"wp-image-16818\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Operational Technology (OT) networks were never built with modern IT security in mind. The systems that power industrial control environments, manufacturing facilities, building automation, and critical infrastructure all share one important limitation: you can't install security agents on them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These devices often run proprietary firmware, follow rigid maintenance schedules, and in many cases cannot be patched or rebooted without disrupting production. Taking a controller offline may mean stopping an entire manufacturing line or interrupting a critical operational process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This reality immediately rules out many of the security tools commonly used in enterprise IT environments. There are no endpoint detection and response (EDR) agents, no host-based logging, and no vulnerability scanners that can safely interact with these systems. For security teams responsible for OT and Industrial Control System (ICS) visibility, the challenge isn't deciding which endpoint agent to deploy\u2014it's determining what passive, non-intrusive telemetry is already available from the surrounding infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In most OT environments, the answer is the network itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Routers, switches, and firewalls positioned between IT and OT segments continuously export NetFlow and IPFIX telemetry. When that flow data is collected, enriched, and forwarded into a SIEM, it provides meaningful visibility into network activity without requiring any interaction with the OT devices themselves.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This blog explains where NetFlow Optimizer (NFO) fits within an OT\/ICS security architecture, what visibility it provides, and just as importantly, where its limitations begin.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Traditional Security Tools Don't Work in OT<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Purdue Model remains the primary architectural framework for OT and ICS network design. It separates industrial control systems from enterprise IT through multiple security zones and a demilitarized zone (DMZ).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Levels 0 through 2 contain the physical process and industrial equipment, including PLCs, DCS, and SCADA systems. Level 3 represents the manufacturing operations network. Between Level 3 and the enterprise network at Level 4 sits the IT\/OT DMZ, introduced in later versions of the Purdue Model and formalized in IEC 62443.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most enterprise security tools assume conditions that simply don't exist inside OT environments. They expect IP reachability, open management ports, and endpoints capable of running security software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Industrial devices provide none of these assumptions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A PLC controlling a water treatment facility, a historian server inside a power substation, or an HMI operating a production line cannot accept endpoint agents. Many continue running operating systems that have remained unpatched for years\u2014not because of poor security practices, but because vendor support agreements or the operational risks associated with downtime make patching impractical.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Active scanning creates another challenge.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sending probe traffic into an OT network can trigger unexpected behavior in devices that were never designed to receive unsolicited requests. Certain industrial protocols may respond to unfamiliar traffic by faulting, restarting, or entering a safe-stop state. As a result, tools that IT security teams routinely rely on\u2014such as vulnerability scanners, network mapping utilities, or SNMP walkers directed at OT devices\u2014can introduce genuine operational risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That leaves passive monitoring as the safest approach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among all available passive data sources, network flow telemetry exported by the infrastructure carrying the traffic provides the richest and least intrusive visibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What NetFlow Telemetry Can\u2014and Cannot\u2014See in OT Networks<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">NetFlow Optimizer (NFO) collects flow telemetry exported by routers, switches, and firewalls located at key points throughout the OT environment, including the IT\/OT boundary, the DMZ, and the perimeter of OT network segments. Understanding this collection boundary is essential.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NFO gathers NetFlow and IPFIX records from infrastructure devices capable of exporting flow data. It does <strong>not<\/strong> collect information directly from OT endpoints, nor does it perform packet capture or deep packet inspection (DPI) for industrial protocols such as Modbus, DNP3, or EtherNet\/IP.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What Flow Telemetry from Boundary Devices Provides<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Traffic crossing zone boundaries<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every connection between enterprise IT and OT environments passes through a boundary device. Flow records capture the source, destination, protocol, port, byte count, and session duration for each network conversation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>New or unexpected endpoints<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a device that has never previously communicated outside its segment suddenly appears in the flow records, it becomes immediately visible. NFO provides the source IP, destination IP, destination port, and traffic volume, allowing the SIEM or security analyst to determine whether the activity is expected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Protocol and port deviations<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OT networks are highly predictable. The same systems typically communicate with the same destinations using the same protocols and ports every day. When that pattern changes\u2014for example, if a historian server suddenly initiates outbound HTTPS connections to an external IP address, or a device located near a PLC begins communicating over an unexpected port\u2014those deviations are visible through flow telemetry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Volume anomalies<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A sudden increase in traffic leaving an OT segment toward the enterprise network or an external destination can be detected using flow volume information alone, even without visibility into the actual packet contents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>East-west traffic within visible segments<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where switches export NetFlow or IPFIX (although not all OT switches do), NFO also provides visibility into east-west communications occurring within those network segments.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2026\/07\/image-138-1024x576.png\" alt=\"\" class=\"wp-image-16820\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What Flow Telemetry Does Not Provide<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Industrial protocol contents<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Flow records do not reveal Modbus function codes, DNP3 commands, EtherNet\/IP payloads, or any other industrial protocol content. Inspecting protocol-level communications requires a dedicated OT security platform connected through SPAN or TAP access that can perform deep packet inspection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>OT endpoint inventory<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NFO uses SNMP polling for network infrastructure devices only. It does not discover or inventory OT endpoints. Organizations requiring comprehensive OT asset discovery need purpose-built OT asset management platforms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Visibility into isolated OT segments<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an air-gapped OT segment is served by switches that do not export NetFlow or IPFIX, NFO has no visibility into that portion of the network. This remains a common limitation within Levels 0 and 1 of the Purdue Model.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where NFO Fits in the OT Security Architecture<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The IT\/OT DMZ is the highest-value deployment point. Traffic crossing between enterprise and OT environments passes through these boundary devices, and they almost always run enterprise-grade networking equipment that exports standard NetFlow or IPFIX. Deploying NFO to collect from firewalls, layer 3 switches, and routers at this boundary gives security teams visibility into every cross-zone conversation without any contact with OT endpoints.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NFO enriches that flow data with context that makes it actionable in a SIEM:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Enrichment<\/strong><\/td><td><strong>What Raw NetFlow Shows<\/strong><\/td><td><strong>What NFO Adds<\/strong><\/td><\/tr><tr><td>User identity<\/td><td>Source IP: 10.4.1.15<\/td><td>User: ops-engineer@company.com (resolved from AD\/Entra ID)<\/td><\/tr><tr><td>Threat intelligence<\/td><td>Destination IP: 185.220.101.1<\/td><td>Threat score: malicious \/ Category: known C2 infrastructure<\/td><\/tr><tr><td>Application context<\/td><td>Port: 502<\/td><td>Application: Modbus (via NFO application catalog)<\/td><\/tr><tr><td>Bidirectional flow<\/td><td>Separate ingress\/egress records<\/td><td>Single stitched record with full conversation context<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">That enriched, CIM-compliant telemetry lands in\u00a0Splunk ES, Sentinel, Exabeam, or any other downstream SIEM where security teams have built detection logic. The detection, alerting, and investigation happen in the SIEM. NFO delivers the data layer those workflows depend on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Air-Gapped and Zero-Egress Deployment<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OT environments in critical infrastructure, defense, and other regulated industries often prohibit any data from leaving the network perimeter. To support these requirements, NFO is a software-only solution that deploys entirely on-premises with zero data egress.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">User identity resolution is performed against on-premises Active Directory or Entra ID, while custom application catalogs are maintained locally. Threat intelligence feeds and GeoIP databases are updated from external sources on a configurable schedule, after which NFO caches the data on-premises. All enrichment is then performed locally using the cached information during flow processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This architecture is particularly important in OT environments where even a management-plane connection to a cloud service raises compliance concerns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NFO has been deployed in air-gapped federal and Department of Defense (DoD) environments since 2016. The same architecture that meets those stringent security requirements can be deployed directly into air-gapped industrial control system (ICS) networks without modification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations pursuing CMMC compliance or operating under FISMA frameworks can also use NFO to support evidence collection for network flow logging requirements without introducing external data dependencies. As discussed in <em>The Unsung Hero of CMMC Compliance<\/em> v\u00e0 <em>OMB M-21-31 and Network Flow Logging<\/em>, network flow telemetry is a specific evidence requirement under both frameworks. NFO provides the collection, enrichment, and delivery pipeline needed to help satisfy those requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Practical Starting Point<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most organizations looking to improve OT network visibility do not begin by deploying a dedicated OT security platform.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, they start with the infrastructure they already have: network devices at the IT\/OT boundary that are already exporting flow data, along with the SIEM their security operations team already relies on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NFO collects that existing flow telemetry, enriches it, and delivers it to the SIEM in a format that integrates with existing detection content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is a significant improvement in visibility without touching a single OT device, deploying endpoint agents, installing additional sensors within the OT network, or requiring the security operations team to manage a separate OT-specific platform or console.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For organizations with stricter security requirements and the budget for dedicated OT tooling, NFO complements those investments by providing the network-layer data foundation they do not cover. It collects multi-vendor flow telemetry from the broader network infrastructure, enriches it, and delivers it to the SIEM, extending visibility across enterprise and cloud-connected environments that OT-focused platforms are not designed to address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OT and ICS security begins with accepting a fundamental constraint: you cannot install agents on these devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What you <em>can<\/em> do is collect, enrich, and deliver flow telemetry from the infrastructure surrounding them. NFO transforms that telemetry into actionable security data without touching OT endpoints, introducing cloud egress, or adding another console for the security operations team to manage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The network boundary is visible. The conversations crossing it are recorded. NFO provides the enrichment that turns those records into actionable security intelligence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>About DT Asia<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How we help<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you need to know more about Agentless Security for OT\/ICS Networks: How NetFlow Telemetry Covers the Devices You Cannot Touch, you\u2019re in the right place, we\u2019re here to help! DTA is Netflow Logic\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click here and here and here to know more:&nbsp;<a href=\"https:\/\/dtasiagroup.com\/vi\/netflowlogic\/\">https:\/\/dtasiagroup.com\/netflowlogic\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Operational Technology (OT) networks were never built with modern IT security in mind. The systems that power industrial control environments, manufacturing facilities, building automation, and critical infrastructure all share one important limitation: you can&#8217;t install security agents on them.<\/p>","protected":false},"author":11,"featured_media":16818,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-16817","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/16817","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=16817"}],"version-history":[{"count":2,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/16817\/revisions"}],"predecessor-version":[{"id":17166,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/16817\/revisions\/17166"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/16818"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=16817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=16817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=16817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}