Security is usually presented as a product decision. On a live plant or a running hospital it is an operating decision first, and the product follows from it.
Zoning and monitoring come before enforcement, because a control that changes the operating path has to be understood before it is installed. On a plant network the change window is the real constraint, and that calendar belongs to operations. Automation belongs after visibility: a repeatable change is only safe once you can see what it did.
The decisions that slow an incident are commercial before they are technical. Who can authorise an isolation, what a support contract permits, which vendor has to be on the call. Those are settleable on a quiet afternoon, and they are the ones that cost hours during an event.
Questions Worth Taking Forward
- What does each control do to the operating path?
- Who can authorise an isolation at 2 a.m. without calling a meeting?
- Which of these decisions are commercial rather than technical?
- What is genuinely visible today, and what is assumed?
