An OT Device Starts Beaconing 

An OT Device Starts Beaconing 

An OT Device Starts Beaconing 

A building management controller starts making regular outbound connections to an external host nobody recognizes. No agent runs on it. No agent will ever run on it. Every endpoint tool on the estate is blind to the device by design. This is the scenario that decides whether an MSP's stack covers the client's environment or only the parts an agent reaches. 


enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. 

The situation


The client runs a smart building: HVAC controllers, access systems, CCTV, meters. The MSP won the IT contract and inherited the operational technology by default, because the client assumes the network is the network. One controller, running old firmware with a known weakness, is compromised and begins beaconing: short, regular check-ins to an external command host, waiting for instructions. 


On an endpoint-only stack, this continues indefinitely. The device holds no agent, so nothing reports. 

What we detect


The network sensor sees every device by its traffic, agent or not. The controller's baseline is boring: local chatter to its management server, vendor updates on a known schedule. The new pattern breaks the baseline in three ways: an external destination the device has never contacted, machine-regular timing, and a protocol out of character for building equipment. That combination correlates into a High case with the device identified by its network fingerprint. 

What gets automated


The external destination is blocked at the firewall, cutting the command channel. Isolation of an OT device itself is not automated, deliberately: containment actions on operational equipment carry physical consequences, so the posture agreed at onboarding routes OT cases to human review with the channel already severed. 

Where humans step in


An analyst confirms the device, the firmware version, and whether anything else on the OT segment shows the same pattern. The Fractional Security Director briefs the MSP with the specifics: which controller, which weakness, and the remediation path, usually firmware from the vendor plus network segmentation so building equipment stops sharing a flat network with workstations. The MSP takes a concrete plan to the client, not an alarm. 

The outcome


The command channel is dead, the device is scheduled for remediation, and the segmentation conversation the client needed anyway now has a live example behind it. The MSP walks into a smart-building security discussion as the provider who caught what agent-based tooling never sees. 

Check your own stack


  • List your clients' devices with no agent. Who watches them? 

  • Would a building controller talking to an unknown host raise anything today? 

  • Do OT and IT share a flat network at any client site? 

  • Who decides containment on a device with physical consequences? 

Want to know what your current setup does in this scenario?

Want to know what your current setup does in this scenario?

Want to know what your current setup does in this scenario?

Book a 30-minute call with Hannah Lloyd, our co-founder