An OT ICS security assessment in India has one hard constraint that IT testing does not: the thing you are testing is holding a physical process together. A scan that would be routine on a corporate subnet can crash a twenty-year-old PLC and take a plant down. So we start passively, and we earn the right to touch anything.
Operational technology was built for availability and safety on isolated networks, and then quietly connected: to the business network for reporting, to a vendor for remote maintenance, to a historian in the cloud. The controllers themselves cannot be patched on an IT cadence and were never designed to authenticate anything. The security has to come from architecture.
We map the estate by listening to the traffic, place every asset in the Purdue model, and test the boundaries between levels, which is where a compromise of the corporate network turns into a compromise of the process. The same work applies to IoT fleets, where the device is small, numerous and outside your building. Segmentation findings usually continue into network architecture review.