Zero Trust for OT and ICS: Professor Kai London's Practical Playbook for Industrial Environments

 By the Keflavik Times Technology Desk

Professor Kai London, senior CISO and cybersecurity, AI and quantum computing expert
Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com

Zero trust has become the dominant model in enterprise security, but applying it to industrial control systems requires care. “You cannot simply drop enterprise zero trust onto a plant and hope,” says Professor Kai London, a senior CISO. “In OT, the first rule is do no harm to the process. Zero trust must raise security without ever risking availability or safety.”

“Never trust, always verify — applied with surgical care. In industrial environments, a control that trips the plant is worse than the threat it was meant to stop.”

Start with visibility

London insists the first step is knowing what you have. “Most operators cannot fully see their own OT estate,” he says. “You cannot apply zero trust to assets you have not inventoried.”

Segment the critical zones

Micro-segmentation limits how far a compromise can spread, isolating the most safety-critical control zones. “If an attacker gets a foothold, segmentation decides whether they reach one cell or the whole plant,” he says.

Identity, adapted for OT

Strong authentication and least privilege for every human and machine that can touch control systems — introduced in ways that respect operational constraints. “Identity is the new perimeter,” London says, “including the service accounts and automation that connect industrial assets.”

Fail safe, phase in

Every control, London stresses, must be designed to fail safe and rolled out in phases with rigorous testing. “You move toward zero trust control by control,” he says, “starting with the systems whose compromise you could not tolerate.”

For operators of industrial and critical systems, London's message is that zero trust and operational safety are compatible — when the model is adapted to the plant rather than imposed on it.


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Popular posts from this blog

Board-Grade Security on Demand: Professor Kai London on the Fractional CISO for Infrastructure Operators

Resilience as Advantage: Professor Kai London on Turning Cyber Strength Into Business Value

Intelligence Under Control: Professor Kai London on Governing AI in Industrial Operations