You've put MFA on email, on the VPN, on every admin console you could reach. Then someone on the board asks whether it protects the controllers running the production line, and the honest answer is no. In an OT — operational technology — environment, the systems you most need to defend are usually the ones multi-factor authentication can't touch.
A login is a human event. Most of OT isn't.
MFA strengthens one specific thing: a person signing in. It assumes a credential, an interactive session, and someone present to approve the second step.
A great deal of OT has none of that. Programmable logic controllers (PLCs), sensors, and drive systems don't log in — they exchange messages and act on them. A controller installed in 2009 does what the last valid-looking instruction on the wire told it to do. There's no prompt, no second factor, nothing to approve.
The assets that matter most often can't take a second factor
Where a login does exist on OT gear, it's frequently a shared local account or a password baked into firmware. Human-machine interfaces (HMIs) and remote terminal units (RTUs) running decade-old software often can't accept a modern identity provider at all. Retrofitting MFA usually means replacing equipment that's expected to run for years without a reboot.
There's a second constraint IT-only teams tend to miss: in OT, an authentication failure can be a safety event. Lock an operator out of an HMI during an upset condition and you haven't improved security — you've removed their ability to bring a process to a safe state. MFA decisions here are bounded by availability and safety, not just compatibility.
Attackers don't queue up at the OT login
Intrusions into OT rarely begin by guessing an OT password. They start in IT — a phished employee, a reused credential, a contractor's laptop — and move sideways. On a flat network, an IT foothold can reach OT directly, and once it's there it can issue commands that look entirely legitimate to a device that was never designed to question them. Standing vendor and contractor access is a common path in, because it's broad, long-lived, and rarely watched.
The attacker doesn't defeat your second factor. They arrive from a place that already cleared it.
What closes the gap when MFA can't
If the most exposed assets can't authenticate, protection has to come from the network around them rather than the device itself. A few things do the real work:
- **Segmentation**, so an IT foothold can't reach OT in a single hop.
- **Passive monitoring** of OT traffic, which catches forged or abnormal commands without touching production. Our AI-powered network detection and response reads OT protocols directly and surfaces those paths from traffic alone.
- **Oversight of third-party access**, so standing vendor connections are scoped and watched rather than assumed safe — the work our Outsourcer Oversight program is built for.
- **Ranking by exposure, not severity**, so the controller wired to a live process gets attention before a theoretical issue on an isolated box. That prioritization is what our Risk Operations Center puts in front of a board.
The honest takeaway
MFA remains one of the best controls you can put in front of people. It just answers a question OT mostly doesn't ask. Treating it as finished work on the plant floor leaves the machines that run the process defended by trust alone.
Not sure where your OT estate still relies on that trust? Talk to an MBCTG expert and we'll help you map it.