← Research

LB-2026-02 · Landscape Briefing · July 2026

The Encryption of Operational Technology: A Protocol Landscape

Executive Summary

The preceding Liscere Technical Report established, in hardware, that strong transport encryption changes the observation vantage available to a contextual evaluator of industrial control actions, not the evaluation core itself. It named, as its first research front, an empirical question: how much of operational technology is encrypted, by what mechanism, and with what trajectory. This briefing answers that question from the published evidence.

We survey the dominant OT protocol classes: the field-level real-time protocols that carry the majority of new factory-automation nodes, the supervisory layer around OPC UA, the energy-sector telecontrol and substation stack, vendor management channels, and the IIoT broker layer. For each class we document the standardised security mechanism, its treatment of confidentiality, and the measured state of adoption, labelling every claim by the strength of its evidence.

Three findings organise the landscape. First, encryption capability and encryption activation are different quantities, and the gap between them is large, persistent, and measured: internet-wide scans place TLS adoption on industrial protocols in single-digit percentages, and the misconfiguration pattern documented for OPC UA in 2020 is intact in 2025. Second, where OT security standards do land, they deliberately prioritise integrity and authenticity over confidentiality for real-time control data; in the substation domain this preference is codified, with the applicable standard stipulating that time-critical protection traffic is not to be encrypted. Third, encryption arrives stratified by functional plane: vendor management channels first, vertical supervisory links slowly, the real-time protection plane last or never. The consequence for observation is stated as a vantage matrix: the case of an opaque channel with no natural point of legitimate access is confined to a single protocol class, and even there, secondary evidence sources exist.

Open the PDF ↗

Cite this report

@techreport{salmazo_protocollandscape_2026,
  author      = {Bruno Salmazo},
  title       = {The Encryption of Operational Technology: A Protocol Landscape},
  institution = {Liscere},
  year        = {2026},
  month       = jul,
  number      = {LB-2026-02},
  type        = {Landscape Briefing},
  url         = {https://liscere.com/research/lb-2026-02/}
}

Preview unavailable on this device. Open the full PDF.

Open full PDF ↗

Liscere 2026