How Far Could an Attacker Get Inside Your Operational Network?
Renaissance has spent much of this year in conversation with organisations running operational technology across Ireland. Utilities, manufacturing, transport, a number in pharma. Different environments, different constraints, but one pattern keeps repeating.
Ask about perimeter security and the answer comes quickly. Firewalls, segmentation between IT and OT, remote access controls, monitoring on the boundary. People know what they have and they can talk you through it.
Ask what happens after something gets past that boundary and the conversation changes. It slows down. There is usually a pause, then something along the lines of “well, it depends what it landed on.”
That pause is worth examining.
The numbers behind the pause
ColorTokens research puts the average time for an attacker to begin moving laterally inside a network at around 27 minutes, against an average detection time of roughly 95 days.
That is the whole problem in one line. The intruder is exploring the environment for three months before anybody knows they are there.
Two more from the same research explain why. Over 86% of data centre traffic moves east to west, which is to say between systems inside the environment rather than in and out of it. And more than 70% of breaches involve lateral movement at some stage.
So the majority of traffic in an environment is internal, the majority of breaches depend on internal movement, and most security investment sits at the edge watching things come and go.
Why this lands harder in OT
Everything above applies to any network. What makes operational environments harder is what you cannot do about it.
Much of the equipment cannot host an agent. A good deal of it runs protocols the security tooling does not speak. Patching happens in maintenance windows that come round twice a year if you are lucky. And isolating a suspect device is not a decision an engineer makes lightly, because the consequence is a stopped process rather than an inconvenienced user.
The result is that a lot of OT estates are flatter than people realise. Not through negligence, but because segmenting a live production environment is genuinely difficult and the equipment was specified for availability rather than inspection.
Meanwhile the questions are arriving. NIS2 has put accountability with management personally. Insurers are asking for evidence before they will quote. Customers in scope are sending questionnaires to their suppliers. All of them want to know what is watching the operational network, and “we have a firewall between IT and OT” is no longer a sufficient answer.
Knowing before somebody else finds out
You cannot fix what you cannot see, and most organisations have never mapped what an attacker could actually reach once inside.
That is why Renaissance is running free Breach Readiness and Impact Assessments with ColorTokens for Irish organisations. The assessment takes five days. It maps assets and attack surface, identifies the lateral paths an attacker could take using known MITRE techniques, and produces a prioritised roadmap of what to close first.
The output is a visual picture of the blast radius and a list of the gaps that matter most, which is useful whether the party asking is a regulator, an insurer, a customer or the board.
There is no cost and no obligation afterwards. For organisations already running CrowdStrike, SentinelOne or Microsoft Defender for Endpoints, it moves faster again because it builds on what is already in place.
Details are here: https://colortokens.com/breach-readiness-impact-assessment-renaissance-it/
The OT Forum
Alongside this, Renaissance is running an OT Forum series aimed at people working in operational environments rather than a general IT audience.
The first session is on 20th October and covers NIS2 and what it means in practice for operational estates. The second is on 24th November, looking at AI threat resilience.
Registration links will be available shortly. Get in touch if you would like them sent across once they are live.
If nothing else, the question at the start of this piece is worth putting to your own environment. If something landed on the operational network this afternoon, how far could it get before anyone noticed? Most organisations do not know. The ones that do tend to sleep better

