Guest Contributor, Kai Jolonen, Head of Sales and Business Development, Asia-Pacific of SensorFu
Is Your Operational Technology(OT) Network Really Isolated? Why Trust Isn’t Enough
When we think about protecting Singapore’s critical infrastructure—our power grid, water supply, transport systems, manufacturing plants and healthcare services—we often assume that these systems are safely separated from the internet and corporate networks.
But what if they aren’t?
Many organisations believe their Operational Technology (OT) networks are isolated simply because they were designed that way. Unfortunately, in reality, that isn’t always the case.
Network Segmentation Is No Longer Optional
As more industrial systems become connected and organisations embrace digital transformation, protecting OT environments has become increasingly important.
In Singapore, the Cyber Security Agency (CSA) requires Critical Information Infrastructure (CII) owners to implement network segmentation, separating systems based on their risk level and limiting unnecessary communication between them.
The goal is simple:
If a cyber attack happens in one part of the network, it shouldn’t be able to spread to the systems that keep essential services running.
Segmentation is one of the strongest cybersecurity defences available today.
But there’s one important question many organisations don’t ask:
How do you know your network is actually isolated?
The Hidden Gaps Nobody Sees
Even with the best intentions, network isolation can slowly break down over time.
A firewall rule added during maintenance.
A contractor connecting new equipment.
A routing or VLAN misconfiguration.
An overlooked third-party system.
Individually, these changes may seem harmless. Together, they can quietly create unexpected communication paths between networks that were never meant to talk to each other.
These hidden gaps often go unnoticed because everything appears to be working normally—until a cyber incident occurs.
Verification Is Just as Important as Implementation
Building a segmented network is only the first step.
The bigger challenge is making sure it stays that way.
This is where continuous verification becomes valuable.
Instead of assuming firewall rules and network configurations are working as intended, organisations can regularly test whether traffic can actually cross network boundaries.
Think of it like checking whether a locked door is still locked, rather than simply trusting that someone closed it months ago.
What We’ve Learned from Real Deployments
![]()
Over the past decade, organisations using SensorFu Beacon have discovered that network isolation isn’t always as strong as they believed.
In fact, hidden isolation weaknesses have been found in around 80% of deployments.
One of the most common issues isn’t sophisticated malware or advanced hacking techniques.
It’s ordinary DNS traffic.
Systems that should never communicate were quietly exchanging DNS requests, creating unintended pathways between supposedly isolated networks.
In another case, a customer’s own security product unintentionally created a covert communication channel, demonstrating that even security tools themselves can introduce unexpected risks.
The lesson is clear:
Even well-designed environments can contain hidden weaknesses that only become visible when they’re actively tested.
A Real Example
One industrial organisation deployed SensorFu Beacon across its environment to validate its network segmentation.
Within a short period, the solution identified an old firewall rule that was accidentally allowing traffic between two network segments that should have been completely isolated.
The issue had existed unnoticed for years.
Once identified, it was corrected immediately—before it could become a security incident.
Continuous Assurance Builds Real Cyber Resilience
Cybersecurity isn’t just about installing firewalls or meeting compliance requirements.
It’s about having confidence that your security controls continue to work as intended every single day.
For organisations operating critical infrastructure, manufacturing facilities or industrial environments, continuous verification provides that assurance.
Because when it comes to protecting essential services, assuming your network is isolated simply isn’t enough. Verifying it is.
Follow us on LinkedIn for the latest happenings/updates.



