Table of Contents
ToggleIn the office, a Tuesday patch and a reboot are routine, but in a refinery the same reboot can trip a unit. Control systems still need updates, so they need a slower, tested and risk based process that fits real production windows.
Control system computers run Windows, firmware and third party software with the same vulnerabilities as office machines. Updating them safely needs asset data, vendor approval, testing and planned outages.

What Is OT Patch Management?
OT patch management is the controlled process of identifying, testing, approving and installing security and software updates on industrial control systems without disturbing safe operation. It covers HMIs, servers, engineering stations, network devices and controller firmware, and is expected by most PLC cybersecurity standards.
Rockwell Automation describes a six step process of inventory, vulnerability identification, patch matching, review, testing and deployment, and documentation. It notes that plants running 24 hours a day find scheduling the hardest part.

Unlike IT, availability and safety come first in OT. A patch that breaks an HMI or reboots a controller at the wrong time can cause a trip or unsafe condition.
The Idaho National Laboratory recommended practice for DHS set out many of these principles as early as 2008, and they still apply.
IT vs OT Patching
| Aspect | IT Patching | OT Patching |
|---|---|---|
| Priority | Confidentiality | Availability and safety |
| Timing | Days after release | Planned outage windows |
| Approval | IT team | Control system vendor plus site owner |
| Testing | Pilot group | Test bench or offline system |
| Reboots | Accepted | Must be scheduled with operations |
Most DCS and SCADA vendors qualify Microsoft and third party patches before customers install them. Installing an unqualified patch can void support.
Some legacy systems can no longer be patched at all, a key driver in migration and obsolescence planning.
6 Proven OT Patch Management Steps
Risk ranking matters because not every vulnerability is reachable in a well segmented network. Known exploited vulnerabilities on exposed hosts go first.
Redundant servers and controllers allow patching one side at a time, much like the switchover described in PLC hot standby redundancy.
When You Cannot Patch
Isolate vulnerable hosts in tighter zones.
Only approved programs can run.
Turn off unused ports and protocols.
Detect exploit attempts on the network.
These compensating controls follow the zone approach in IEC 62443 zones and conduits. Document each one against the vulnerability it covers.
A zero trust design limits the damage if an unpatched host is compromised.
Review compensating controls at least once a year, because network changes can quietly remove a protection that an old exception relied on. Close each exception as soon as a qualified patch or upgrade becomes available.
Deployment Workflow
Always take a full backup and image before patching. Restores must be tested, not assumed.
Patch Window Planning
Example:
120 hosts, 45 minutes each including backup and checks
2 crews, 4 hour windows
120 × 45 ÷ (2 × 240) = 11.25, so 12 windows
Group hosts by redundancy pair so one side stays in service. Critical servers may need their own window.
Patch Window Calculator
Share the result with operations early so windows can be aligned with planned shutdowns.
- Accurate asset inventory.
- Vendor qualified patches only.
- Test bench before production.
- Backups before every change.
- Patching without vendor approval.
- No rollback plan.
- Ignoring firmware and network devices.
- Unpatched hosts with no compensating controls.
Build team skills with the courses in free OT cybersecurity training.
INL Recommended Practice PDF
To Patch or Not to Patch OT Video
OT Patch Management FAQ
Related Articles
- Cybersecurity Standards for PLCs
- IEC 62443 Zones and Conduits
- SCADA Security Checklist
- Purdue Model ICS Cybersecurity
- Types of Cyber Attacks
External References
- Patch Management of Control Systems, Idaho National Laboratory
- Step by Step Patching Guide, Rockwell Automation
- Patch in Computing, Wikipedia
What We Learn Today
- OT patch management puts safety and availability first.
- Inventory, vendor approval, risk ranking and testing come before install.
- Use compensating controls where patches are not possible.
