# Defense OT cybersecurity

> The systems on bases and ships that keep people alive and defended: utilities, fuels, shipyard controls and facility-related control systems. Mission assurance starts at the PLC.

Canonical: https://blackbirdcyber.com/sectors/defense  
Blackbird Cyber · https://blackbirdcyber.com/ · sales@blackbirdcyber.com

## The exposure — FRCS is the soft edge of the mission.

Facility-related control systems and installation utilities were connected long before they were defended. An adversary who cannot reach the network reaches for the power, water and fuel that the network needs.

Regulations and guidance: RMF · NIST 800-82, UFC 4-010-06, CMMC.

- FRCS boundaries and authorization packages
- Contractor and vendor access on installation networks
- Continuity of utilities under attack

## Typical topology

A representative control network for defense installations, by Purdue level:

- L3.5 · DMZ: Enclave boundary
- L2 · HMI: UMCS front end
- L2 · SCADA: Utility SCADA
- L2 · Historian: Historian
- L1 · PLC: Switchgear PLC
- L1 · RTU: Fuel farm RTU
- L1 · Safety: Safety PLC
- L0 · Process: Power · water · fuel · HVAC

Exposed path: vendor VPN → L2 · Historian (Historian).

## Where we start — Recommended engagements for defense installations.

- [OT Cyber Consulting](https://blackbirdcyber.com/capabilities/ot-cyber-consulting): Fractional OT security leadership for operators without a full-time ICS team.
- [OT Network Architecting](https://blackbirdcyber.com/capabilities/ot-network-engineering): Segmented control networks designed and built to keep the process running.
