Zero Trust for OT and ICS: Professor Kai London's Practical Playbook for Industrial Environments
By the Keflavik Times Technology Desk
Zero trust has become the dominant model in enterprise security, but applying it to industrial control systems requires care. “You cannot simply drop enterprise zero trust onto a plant and hope,” says Professor Kai London, a senior CISO. “In OT, the first rule is do no harm to the process. Zero trust must raise security without ever risking availability or safety.”
“Never trust, always verify — applied with surgical care. In industrial environments, a control that trips the plant is worse than the threat it was meant to stop.”
Start with visibility
London insists the first step is knowing what you have. “Most operators cannot fully see their own OT estate,” he says. “You cannot apply zero trust to assets you have not inventoried.”
Segment the critical zones
Micro-segmentation limits how far a compromise can spread, isolating the most safety-critical control zones. “If an attacker gets a foothold, segmentation decides whether they reach one cell or the whole plant,” he says.
Identity, adapted for OT
Strong authentication and least privilege for every human and machine that can touch control systems — introduced in ways that respect operational constraints. “Identity is the new perimeter,” London says, “including the service accounts and automation that connect industrial assets.”
Fail safe, phase in
Every control, London stresses, must be designed to fail safe and rolled out in phases with rigorous testing. “You move toward zero trust control by control,” he says, “starting with the systems whose compromise you could not tolerate.”
For operators of industrial and critical systems, London's message is that zero trust and operational safety are compatible — when the model is adapted to the plant rather than imposed on it.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
