The words,defined.

Industrial cyber security has its own vocabulary, borrowed from control engineering, IT security and three regulators. Here it is in plain language.

A

AESCSF
The Australian Energy Sector Cyber Security Framework: a maturity framework for electricity, gas and liquid fuel operators, developed by AEMO with industry and government. Security Profile 1 is an accepted CIRMP framework. See: AESCSF explained
Asset inventory
The record of every device, system and software component in the control environment, with its role, versions, location, owner, communications and consequence. The foundation of every other control. See: Building an OT asset inventory
Assumed breach
A penetration test that starts from inside the corporate network, as if an attacker already had a foothold, to find the path from the office to the plant.

C

CEA regulations
The Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026: India's binding cyber regulation for power sector OT, in force from 1 April 2027. See: CEA 2026 guide
CERT-In
The Indian Computer Emergency Response Team, whose 2022 Directions require cyber incidents to be reported within six hours and ICT logs kept for 180 days within India.
CIRMP
Critical Infrastructure Risk Management Program: the written program the SOCI Act requires of responsible entities for named asset classes, covering cyber, personnel, supply chain and physical hazards, with an annual board-approved report. See: SOCI and CIRMP for OT
Compensating control
A control applied because the preferred one is not possible, such as network isolation and monitoring around a controller that cannot be patched.
Conduit
In IEC 62443, the communication path between two zones. Every conduit is a place a security control can be applied.
Credential exposure
Company usernames and passwords that have leaked through breaches, infostealer malware or paste sites, and can be used to log in as staff. Monitored continuously by our credential exposure service.
Crown jewel
The asset whose loss or misuse would hurt most: a safety system, a plant controller, a transmission substation. Crown jewel analysis finds them and builds the plan around them.
CSIRT-Power
India's sectoral computer security incident response team for the power sector, at the Central Electricity Authority, an extended arm of CERT-In.

D

Data diode
A hardware device that allows data to flow in one direction only. Also called a unidirectional gateway. Used where a high-consequence zone must publish data without ever accepting a connection.
DCS
Distributed control system: the integrated control platform of a continuous process plant, with controllers, operator stations and engineering tools from one vendor.
DMZ, industrial
The buffer network between the plant and the enterprise, level 3.5 in the Purdue model. Historian replication, remote access and patch distribution live here so nothing connects from the office to the controllers directly.
DNP3
A control protocol common in electricity and water SCADA, especially in Australia and North America. A secure authentication extension exists but is rarely deployed.

E

Engineering workstation
The computer used to program and configure controllers. The most valuable target on most plant networks, because it holds the logic and the vendor software.
Essential Eight
The Australian Signals Directorate's eight baseline mitigation strategies, each with three maturity levels. Maturity Level One is an accepted CIRMP framework.

H

Historian
The database that stores process values over time for trending and reporting. Often the first OT system to be connected to the business network.
HMI
Human-machine interface: the screens operators use to see and control the process.

I

ICS
Industrial control system: the general term for the systems that monitor and control physical processes, including SCADA, DCS and PLC-based systems.
IEC 60870-5-104
A control protocol used in electricity SCADA across Europe, Asia and Australia for communication between control centres and substations.
IEC 61511
The functional safety standard for safety instrumented systems in the process industries. Since 2016 it requires a security risk assessment of the safety system.
IEC 61850
The standard for communication in substation automation: relays, controllers and the station bus. Its GOOSE messages carry protection signals in real time.
IEC 62443
The international series of standards for the security of industrial automation and control systems, organised around zones, conduits and security levels. See: IEC 62443 explained
Infostealer
Malware that harvests saved passwords, session cookies and other credentials from an infected computer and sells them on. A leading source of leaked corporate logins.
IT/OT convergence
The connection of business systems and control systems, for data, remote support and efficiency. The source of most of the risk we are asked to manage.

J

Jump host
A hardened server in the DMZ through which all remote access to the plant passes, so sessions can be authenticated, limited and recorded.

L

Least privilege
Giving each account and each system only the access it needs to do its job, and nothing more.

M

MFA
Multi-factor authentication: proving identity with more than a password. Expected on all remote access to OT by the Australian and Indian regimes.
MITRE ATT&CK for ICS
A knowledge base of adversary tactics and techniques against industrial control systems, built from observed intrusions. See: Threat assessment with ATT&CK
Modbus
The oldest and most widespread industrial protocol. It has no authentication: any device that can reach a Modbus server can read and write to it.

N

NCIIPC
India's National Critical Information Infrastructure Protection Centre, under the Information Technology Act. It identifies critical information infrastructure and can have systems notified as protected systems.
NIST SP 800-82
The US National Institute of Standards and Technology's Guide to Operational Technology Security, revision 3 published in 2023.

O

OPC UA
A modern, vendor-neutral protocol for industrial data exchange with built-in security options. Increasingly used between plant systems and the enterprise.
Operational resilience
The ability to keep essential operations running through disruption and to recover them quickly, whatever the cause. Wider than cyber security and the goal it serves.
OT
Operational technology: the hardware and software that monitors and controls physical equipment and processes. Used interchangeably with ICS in most contexts.

P

Passive monitoring
Observing control-network traffic from a tap or mirror port without sending anything to the devices. The safe way to discover assets and detect changes in OT.
Penetration test
An authorised attempt to reach and compromise systems the way an attacker would, to prove what is possible rather than list what is present. In OT it is scoped by zone, passive first, and never run against live safety systems. See: Penetration testing in OT
PLC
Programmable logic controller: the ruggedised computer that runs the control logic for a machine or process, reading sensors and driving actuators.
Purdue model
The reference model that divides a plant's systems into levels from the physical process up to the enterprise network, used to reason about segmentation. See: Purdue model and segmentation

R

Remote access
Any path by which a person or system outside the plant can reach a system inside it: vendor VPNs, support tools, cellular routers. The most common initial access in real incidents.
RTU
Remote terminal unit: a controller at a remote site such as a substation, pump station or wellhead, reporting to a central SCADA system.
Rules of engagement
The written agreement before a penetration test: what is in scope, in which windows, with which techniques, and the stop conditions and who can call them.

S

Safety instrumented system
The independent system that brings a process to a safe state when something goes wrong. The highest-consequence asset in a process plant, and its own zone.
SCADA
Supervisory control and data acquisition: the systems that monitor and control geographically spread assets such as a grid, a pipeline or a water network from a central control room.
Security level
In IEC 62443, a rating from 1 to 4 of the adversary a zone must resist, from casual misuse to a state-level attacker. Set by consequence.
Segmentation
Dividing a network into zones with controlled paths between them, so a compromise in one place cannot reach everywhere else.
SOCI Act
Australia's Security of Critical Infrastructure Act 2018, as amended: the register, incident reporting, risk management program and enhanced obligations for critical infrastructure assets. See: SOCI and CIRMP for OT
Stop condition
A pre-agreed trigger that halts active testing immediately, such as an unexpected alarm or a change in a process value. Held by operations, not the tester.

T

Tabletop exercise
A facilitated walk-through of an incident scenario with the people who would handle it, to test the plan and the decisions before a real event.
Threat assessment
An assessment that starts from the adversary: which techniques are realistic against your systems, what they could do, and which controls break the paths.

V

VAPT
Vulnerability assessment and penetration testing. Required before a critical system is commissioned under India's CEA regulations; done with care on live control systems. See: Penetration testing in OT

Z

Zone
In IEC 62443, a group of assets that share the same security requirements because they do the same job and face the same consequence if compromised.

A term we have missed? Ask.

We add to this as clients ask. The guides in Insights go deeper on the ones that matter most.