Protecting Legacy OT Systems That Sustain DoW Missions
Critical infrastructure security within the Department of War (DoW) extends far beyond conventional information technology. Power distribution, water systems, environmental controls, fuel operations, physical access systems, and other operational technology (OT) directly support installation readiness and mission continuity.
The challenge is that many of these systems were designed decades ago. They may operate reliably but lack modern authentication, encryption, segmentation, and endpoint protection. Replacing them can be expensive, disruptive, or operationally impossible.
CSOI provides a practical solution by placing modern Zero Trust protection around legacy and current OT systems. CSOI uses Network Cloaking to make protected resources undiscoverable and inaccessible until identity and policy requirements are satisfied. To an unauthorized user or device, the protected system does not appear as an available network destination. Identity-defined access limits connections to approved users and resources, while microsegmentation helps contain potential compromises. Together, these capabilities protect essential infrastructure without forcing immediate hardware replacement or disrupting the mission.

Critical Infrastructure Is Part of Mission Readiness
The DoW uses specific terminology to describe operational systems that support military missions. Mission Critical Control Systems monitor or control physical infrastructure directly connected to military or intelligence operations. Mission Critical Facility Related Control Systems support the continuity of mission-essential functions.
These systems can include:
- Electrical distribution and backup power
- Heating, ventilation, and air conditioning controls
- Water treatment and distribution
- Fuel storage and delivery
- Fire and life-safety systems
- Building automation
- Physical access and surveillance infrastructure
- Supervisory control and data acquisition systems
- Industrial process controls
A disruption to these systems is not simply an IT incident. Loss of control over power, water, environmental conditions, or physical access may affect personnel safety, equipment availability, installation operations, and mission execution.
Protect the Systems Behind the Mission
CSOI treats critical infrastructure security as an operational requirement. Instead of focusing only on securing the broader network, CSOI controls who and what can connect to each protected system.
Critical equipment can remain hidden from unauthorized users while approved personnel receive encrypted, policy-defined access to the specific resources required for their work. This helps protect the availability and continuity of essential systems while reducing unnecessary exposure.
- Least-privilege access to production systems
- More precise control over vendor and engineering access
- Reduced dependence on broad VPN access
- Secure connectivity across plant, cloud, and remote environments
- Policy-defined access that is easier to adjust as operations change
The result is a more controlled model where access is intentional, limited, and aligned to operational needs.
Legacy OT Cannot Always Be Upgraded or Replaced
Many operational and industrial control systems were built for reliability and long service life, not continuous exposure to modern networks. Equipment may remain in operation for decades because replacing it would interrupt essential functions, require extensive recertification, or create significant cost.
A legacy controller may perform its intended function reliably while lacking capabilities that are standard in newer IT environments. It may not support modern authentication, encrypted communications, endpoint security software, or frequent patching. Some systems also depend on specialized protocols, fixed configurations, and operating systems that cannot be safely upgraded.
Even when modernization is technically possible, maintenance windows and operational dependencies may prevent immediate action. Defense organizations therefore face a difficult security problem: stronger protection is needed now, but the equipment cannot always be changed.
Wrap Modern Protection Around Existing Equipment
CSOI places identity-defined security around the operational environment rather than requiring each controller, sensor, or building system to defend itself.
This creates a protective access layer around both legacy and current equipment. Security policy is applied to the connection and the identities requesting access, allowing organizations to strengthen protection without requiring the underlying hardware to perform modern identity and access functions.
A facilities technician can be authorized to reach a specific building management system. A contractor can be limited to the equipment covered by an assigned maintenance task. A remote engineer can monitor a designated control environment without receiving broad access to the surrounding network.
This provides a practical path toward Zero Trust while the organization develops a longer-term modernization plan based on mission priority, system condition, and available resources.
Visible Equipment Can Be Found and Targeted
Before attackers can target a system, they generally need to locate it. Network scans, exposed services, reachable addresses, and open ports can reveal potential entry points.
Traditional network defenses may block unauthorized traffic, but visible assets can still provide information that supports reconnaissance and attack planning. This is particularly concerning for legacy OT that cannot be patched quickly or equipped with modern security software.
Make Critical Equipment Invisible
CSOI uses Network Cloaking to make protected resources undiscoverable and inaccessible until identity and policy requirements are satisfied. To an unauthorized user or device, the protected system does not appear as an available network destination.
The concept is similar to a cloaking device instead of a stronger lock on a visible door. The protected asset is concealed from unauthorized discovery. Approved users can reach it only through a controlled, encrypted connection after the appropriate identity and policy checks succeed.
Reducing discoverability can interrupt reconnaissance before an attacker has the information needed to identify and probe a critical system. It also reduces the external exposure of equipment that may have limited native security capabilities.
For DoW installations, Network Cloaking helps protect building controls, utilities, industrial systems, and other mission-supporting infrastructure without changing the equipment’s primary operational function.
Remote Access Can Weaken Isolation
Physical air gaps have historically protected sensitive operational systems by disconnecting them from outside networks. That isolation can reduce exposure, but it also limits remote monitoring, centralized management, vendor support, and timely operational response.
Modern facilities frequently require some level of connectivity. Operators, engineers, contractors, and equipment specialists may need remote access to maintain availability and respond to problems.
The challenge is providing necessary access without turning an isolated OT environment into a broadly reachable network.
Create a Virtual Air Gap
CSOI helps create what can be described as a virtual air gap. Protected equipment remains isolated from general network access, while specifically authorized identities can establish encrypted, policy-defined connections to approved resources.
This virtual isolation is not the same as physically disconnecting equipment. It is an architectural method for preserving the security benefits of isolation while supporting controlled operational access.
Instead of admitting a user to the broader OT network, CSOI connects that authorized identity to the specific resource required for the task. Unauthorized systems remain hidden and inaccessible.
This approach can support facilities personnel, engineering teams, authorized contractors, and equipment support providers while reducing dependence on broad remote-access pathways.

One Compromise Can Spread Across a Flat Network
Critical infrastructure security must account for the possibility that a user, credential, device, or system could eventually be compromised. The architecture must limit what an attacker can reach next.
Flat or broadly connected networks allow a compromise in one area to become a pathway into others. An attacker who reaches a less critical device may attempt to move laterally toward building controls, power systems, administrative services, or additional operational environments.
In a mission environment, a compromise should not be allowed to spread simply because multiple systems share the same network.
Contain the Breach With Microsegmentation
CSOI uses identity-based microsegmentation to divide access into small, policy-controlled relationships. Communication is allowed only between identities and resources with an approved operational reason to connect.
If one device is compromised, that compromise does not automatically create an authorized route to other systems. Each connection remains governed by identity and policy.
This supports several critical outcomes:
- Reduced lateral movement
- Smaller potential blast radius
- Separation of different mission functions
- Containment of compromised devices or credentials
- More precise contractor and vendor access
- Greater control over authorized communication paths
Microsegmentation is a defined component of the DoW Zero Trust architecture. Its operational value for OT is straightforward: a compromise affecting one building or control system should not provide unrestricted access to the rest of the installation.
Network Location Is Not Proof of Trust
Legacy access models frequently grant trust based on network location. Once a user connects through a remote-access service or enters a trusted network segment, that user may gain visibility into more systems than the assigned task requires.
This creates unnecessary exposure. Being connected to the network does not prove that a person, device, workload, or service should be allowed to reach every resource on it.
Make Identity the Basis of Access
CSOI replaces network-based trust with identity-defined access. The central question becomes: Is this verified identity authorized to access this specific resource under the current policy?
Access is tied to the user, device, workload, or service identity rather than relying primarily on an IP address, subnet, or physical location. Authorized users receive the minimum connection required to complete their work, while unrelated infrastructure remains hidden.
Identity-defined access also allows security policy to remain consistent as networks change. Equipment can move, addresses can change, and personnel can work from different approved locations without making network position the primary basis of trust.
An Operations-First Path to Securing Legacy OT
Critical infrastructure security cannot succeed if the protection creates unacceptable operational disruption. OT environments require careful planning, coordination with facility operators, and a clear understanding of system dependencies.
A practical implementation begins by identifying:
- Which control systems support mission-essential functions
- Who currently accesses those systems and why
- Which remote-access pathways are in use
- Which resources are visible from broader networks
- Where unnecessary connectivity permits lateral movement
- Which connections are truly required for operations
Security teams can then prioritize high-consequence systems, cloak protected resources, establish identity-based policies, and create microsegments around operational functions.
This supports incremental modernization. Organizations can reduce exposure around existing systems without waiting for a large, disruptive replacement project. Protection can evolve as equipment is upgraded, mission requirements change, and Zero Trust capabilities mature.
Critical Infrastructure Security Must Protect the Mission
Protecting legacy OT systems is ultimately about maintaining the installations, facilities, and physical processes that DoW missions depend on.
The challenge is clear: essential systems may be old, difficult to upgrade, visible to unauthorized discovery, dependent on remote access, and connected through networks that permit unnecessary lateral movement.
CSOI provides a practical answer. Network Cloaking makes protected systems undiscoverable and inaccessible to unauthorized users and devices. Identity-defined access replaces broad network trust with precise authorization. Virtual isolation supports controlled remote operations. Microsegmentation contains potential compromises before they spread.
Together, these capabilities allow defense organizations to place modern protection around legacy systems while preserving the uptime, availability, and continuity the mission requires.
Ready to reduce exposure around legacy OT and mission-critical control systems?







