A flat OT network has all PLCs, HMIs, engineering workstations, and a historian on one /16 subnet with no internal filtering. Which risk is most directly amplified by this design?
- A.Excessive use of public IP address space
- B.Mandatory encryption of all control traffic
- C.Inability to assign IP addresses to devices
- D.Unrestricted lateral movement, so a single compromised host can reach and attack every other device
Why D is correct
A large flat network gives any compromised node unfiltered reachability to every other asset, enabling worm-like spread and broad lateral movement. Segmentation into zones with controlled conduits is the standard remediation.
Know someone studying for OT Security Fundamentals? Send them this one.