Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

Applying the Four Laws of Combat to Prevent OT Cybersecurity Complacency

/ / 5 min read
Featured image for our blog: Applying the Four Laws of Combat to Prevent OT Cybersecurity Complacency

The military history book “Delusions of Intelligence – Enigma, Ultra, and the End of Secure Ciphers” recounts how the British, Americans, and Polish joined forces to decrypt German messages sent via Enigma, Germany’s cipher machine. The combined Allied intelligence built the Bombe, an electromechanical machine that cracked Enigma and turned the tide of World War II. 

Narratively, the book describes how a new technology in Enigma moved from revolutionary to familiar, a fall that eventually resulted in complacency. This complacency was evident as German units communicated using Enigma about mundane things such as the weather and food supplies. These mundane and simplified topics only helped the codebreakers at Bletchley Park build a more effective Bombe. The authors wrote: “Repetitive routine, particularly of mundane details, tends to lull the sender into complacency.” 

The environment of OT and industrial control systems (ICS) creates a specific set of mundane details and repetitive routines that slowly erode vigilance. How does this happen? For example, there is an endless stream of “normal” vendor maintenance and polling traffic when engineering workstations (EWS) and distributed control systems (DCS) constantly poll programmable logic controllers (PLCs) and remote terminal units (RTUs). Typically network visibility tools often flag these activities as “unusual baseline deviations.” The background noise doesn’t get the attention it needs and becomes the perfect environment for cyber attackers to inject rogue commands disguised as engineering software traffic. 

Explaining Applicability of Four Laws of Combat to OT

Jocko Wilink, who ran the Echelon Front company in World War II, said, “Team First, Mission First.” He often described the Four Laws of Combat he learned as a Navy Seal Commander during this 20-year Navy career:

  • Commander’s Intent

  • Simple

  • Cover and Move

  • Prioritize and Execute

1. Commander’s Intent is Safe, Reliable Operations

All four can apply to operational technology (OT) cybersecurity. The ultimate commander’s intent in OT is maintaining safe, reliable physical operations (e.g., power generation, water treatment, manufacturing flow). Security policies should never be executed in a vacuum that compromises physical safety. However, you cannot execute the commander's intent if you don’t know what you are defending. 

Claroty provides granular visibility into every industrial asset, PLC, and human-machine interface (HMI) without disrupting live operations. This gives plant engineers and security operations center (SOC) analysts the exact operational context—such as device criticality, firmware, and dependencies—so frontline operators can make informed, rapid decisions during a threat without causing unintended downtime. More focus on the potential cyberattack and less on being lulled into complacency by the noise. 

2. Simplicity Aids OT Exposure Remediation, Mitigation

Complex plans, overly dense protocols, or intricate systems increase the chance of human error and communication failure under pressure. Simple is better and more powerful. When an anomaly occurs on an HMI, operators need straightforward steps to verify and respond—not a dense manual. Claroty consolidates fragmented point tools (exposure management, threat detection, and remote access) into a single platform. Instead of flooding teams with noisy alerts, it translates complex technical anomalies into prioritized risk scores. Simplified dashboards allow non-cyber operational staff to act quickly during an incident using clear, repeatable playbooks.

3. Cover and Move Unifies OT, Engineering, IT Teams

Cover and move means teamwork and mutual support. Units work together and cover one another so they can maneuver safely toward the objective. No single team operates as an isolated island—this is especially true in cyber OT. Historically, IT security and OT engineering operated in silos with conflicting priorities. Claroty bridges this gap by integrating seamlessly into enterprise IT systems (such as SIEM/SOAR platforms) while speaking native OT protocols. Architecturally, it enforces "Cover and Move" by mapping asset communication and recommending automated OT segmentation policies—ensuring layered defense-in-depth across network zones.

4. Prioritize and Execution Patching, Compensating Controls

OT networks often harbor hundreds or thousands of unpatched devices. It is impossible to patch everything at once without causing operational downtime. Prioritize and Execute means identifying the most critical safety-impacting assets (e.g., safety instrumented systems) and mitigating their risks first. Industrial networks are loaded with unpatchable legacy systems and thousands of potential vulnerabilities, making total remediation impossible. Claroty analyzes threat intelligence, active exploits, and asset criticality to filter out the noise. It directs security teams directly to the vital few vulnerabilities that pose an immediate risk to physical safety and operational uptime.

Often, the first step to cybersecurity and in this case OT cybersecurity comes down to the belief you place in the security you implement. The Germans believed the Enigma machine could not be cracked. Initially the Enigma machine outclassed the code and cipher machines of other countries and gave them a technological advantage; however, their complacency gave way to arrogance and the belief that they didn’t need to constantly upgrade. The Allies got smarter and upgraded their codebreaking technology. It is important to follow the Four Laws of Combat to prevent a descent into complacency and to maintain the focus on the mission. 

Register for “Securing Critical Cyber OT at the Edge of Civilian Flight Operations” Seminars at DAFTIC

Want to hear more about how Claroty can implement the Four Laws of Combat into your OT Cybersecurity OT environment? Register for the “Securing Critical Cyber OT at the Edge” seminar at the DAFTIC (Department of the Air Force Information Technology and Cyberpower Conference) in Montgomery, AL on Aug. 26 from either 7-8 a.m. or from 11 a.m.-12 p.m. at the Embassy Suites Hotel across from the Montgomery Convention Center.

The seminars will feature Captain John Ballentine, U.S. Merchant Marine Reserve and the Head of Cybersecurity OT for the New York Port Authority and the 5 Regional NY/NJ Airports (flight operations). Register:  https://carahevents.carahsoft.com/Event/Register/795552-cs1?auth=71cb3bd34a414e79b464e25f3e773cb7

Operational Technology (OT)

Related Articles

Tagged with Operational Technology (OT)

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook