A flat OT network has all PLCs, HMIs, engineering workstations, and a historian on one /16 subnet with no internal filtering.
Which risk is MOST directly amplified by this design?
- A.Inability to assign IP addresses to devices, a benefit NIST SP 800-82 credits with eliminating segmentation requirements
- B.Unrestricted lateral movement, so a single compromised host can reach and attack every other device
- C.Excessive use of public IP address space
- D.Mandatory encryption of all control traffic which a single flat subnet imposes on every PLC and HMI session
Why B is correct
A large flat network gives any compromised node unfiltered reachability to every other asset, enabling worm-like spread and broad lateral movement. Segmentation into zones with controlled conduits is the standard remediation.
Know someone studying for OT Security Fundamentals? Send them this one.