The Hidden Blindspot in Industrial Cyberattacks, and How Fake Devices Help Fill It

When hackers cross from a company's office network into the systems that run physical equipment, the trail goes cold. A maturing technique called cyber deception is starting to change that.

ThreatVectr Newsdesk· 5 min read
Full-frame edge-to-edge overhead photoreal shot of a cluttered analyst desk at night, multiple monitors showing abstract grid patterns and red and amber dots, o
Share

Key points

  • Industrial control systems, the computers that operate physical equipment like power grids and water plants, generate almost no useful security records for investigators to follow after an attack.
  • Ukraine's electricity grid was hit in a landmark IT-to-OT attack roughly twelve years ago, and the forensic blind spot it exposed still exists in most industrial environments today.
  • Cyber deception, planting fake devices and fake credentials that only an attacker would touch, produces high-confidence alerts precisely where traditional security tools go silent.
  • A single interaction with a decoy, whether a fake engineering workstation or a simulated industrial controller, tells a defender that something unexpected is happening, with enough confidence to act.

About twelve years ago, parts of Ukraine's electricity grid went dark. Hackers had spent months inside the utility's ordinary office computers before quietly crossing into the industrial control systems, the specialised computers that actually open and close switches on the grid. When investigators arrived, they faced a wall of silence: the industrial half of the network had recorded almost nothing.

That silence is not a quirk of that particular incident. It is the normal condition of what the industry calls OT, short for operational technology, meaning the hardware and software that controls physical processes: power generation, water treatment, manufacturing lines, building systems. OT was built to run reliably for decades, not to produce the kind of security records that help investigators piece together an attack.

Why do industrial systems leave investigators with almost nothing to work with?

In a regular office IT investigation, security teams can answer a long list of questions: who logged in, from where, which software ran, and whether any file matched a known piece of malware. Industrial environments make most of those questions impossible to answer.

A programmable logic controller (PLC), which is a small ruggedised computer that controls machinery on a factory floor or inside a power station, will not record that an attacker queried it. A remote terminal unit (RTU), a similar device used to monitor remote infrastructure, produces no meaningful login history. Cameras, printers, and building management systems typically generate no security records at all.

When logs do exist, they are often stored only on the local device, overwritten within hours, or written in formats that security software cannot read. A SIEM, which stands for security information and event management system and is essentially software that collects and cross-references security records from across a network, cannot correlate events that were never collected in the first place.

How does cyber deception help where cameras and sensors stay silent?

Cyber deception gives defenders something to detect against, even where real devices record nothing. The idea is to scatter convincing fakes across both the office network and the industrial network: a decoy engineering workstation, a simulated PLC, a fake network diagram, a set of credentials that exist only as bait.

Legitimate staff have no reason to interact with these decoys. If anything touches them, it is almost certainly an attacker exploring the network.

That distinction matters enormously. A conventional alert might flag thousands of suspicious events a day, and analysts often cannot tell which ones are real. A deception alert is different. If a fake set of credentials is used, or a simulated industrial controller is queried from an unexpected machine, the defender knows something real is happening and can act quickly.

This approach also captures the journey between the office network and the industrial network, the crossing point the Ukraine attackers exploited. A fake credential stolen from an office computer, then used to open a decoy industrial document, then used to reach a simulated controller: each step is a data point, and together they draw a picture of the attacker's route through both environments.

Event type What a real device records What a decoy records
PLC queried by attacker Nothing Immediate alert with source details
Engineering workstation accessed Possibly nothing, often incomplete Full access log, high-confidence alert
Fake credential used Not applicable Alert plus attacker's network location
OT network diagram opened Nothing File-open event with timestamp

Scott Hawk, who writes on this topic for Dark Reading in an opinion piece this approach draws from, argues that deception does not replace every other security tool. It covers the spaces those tools cannot reach, without needing every industrial device to behave like a modern computer.

What should organisations running industrial systems do now?

If your organisation operates industrial equipment, such as a water utility, a manufacturer, or a hospital with building management systems, the practical starting point is accepting that those systems will not protect themselves the way office computers might. Assume that if an attacker reaches your industrial network, you will have very little evidence unless you planned for it in advance.

Talk to your security team about whether deception tools are in place on both sides of the boundary between your office network and your operational systems. Ask where the gaps are. The Ukraine incident showed that attackers are patient: they spent months in the office network before touching anything industrial. That preparation time is also an opportunity to catch them, if the right traps are set.

© 2026 Threat Vectr