How Governed Are Your Cellular OT Devices, Really? A New Benchmark for Security Leaders
A five-section assessment reveals where visibility, authentication and incident-response gaps are most likely to sit across cellular-connected OT fleets
Industrial organisations have spent the last decade hardening the IT/OT boundary, deploying network access control, and building SOC coverage for everything that touches a switch port. Cellular-connected devices — routers, gateways, remote terminal units, sensors reporting over private or carrier cellular — have often sat outside that perimeter entirely, connected by SIM rather than cable, and consequently invisible to the tools built to police everything else.
TeckNexus has partnered with OneLayer to launch an interactive cellular OT device security assessment, designed to help private network operators and OT security leaders benchmark exactly how governed their cellular fleet actually is, rather than how governed policy assumes it to be.
Why cellular OT device visibility is the starting gap
The assessment opens where most security programmes quietly fall short: can you identify the make, model, manufacturer and firmware of every device on your cellular network, including those sitting behind routers or gateways you didn’t provision? Organisations that can only confirm a SIM or subscriber ID is active — not the hardware attached to it — are working from an inventory that describes their billing relationship with a carrier, not their actual attack surface. A valid SIM in the wrong hardware is, in that scenario, functionally invisible.
This matters more now than it did five years ago. Government advisories around FCC-restricted manufacturers and NDAA Section 889 prohibitions have turned “which vendors are physically deployed on our network” from a procurement question into a compliance one. Screening at time of purchase is a reasonable baseline, but devices get redeployed, repurposed, or arrive through channels procurement never sees — which is why the assessment treats continuous, fleet-wide monitoring as a materially stronger posture than a one-time check.
Authentication, segmentation and the rogue-device problem
The second dimension the assessment probes is whether an unauthorised device could join the network undetected. Default carrier or vendor authentication, with no additional controls layered on top, is straightforward to bypass and rarely audited. The stronger posture pairs SIM authentication with IMEI correlation and enforces it actively — because a SIM alone only confirms a subscription is valid, not that the hardware attached to it hasn’t changed. A SIM pulled from an authorised device and inserted into unauthorised hardware is one of the more quietly dangerous scenarios in cellular OT environments, and the assessment specifically checks whether organisations could detect that swap at all.
Segmentation follows the same logic. Coarse network- or APN-level grouping is common, but it means a compromised device inside an “approved” group still has broad reach. Per-device policy enforced at the cellular layer — closing the loop between authentication and access — is what separates organisations that can contain an incident from those that discover it after lateral movement has already occurred.
Threat awareness: Salt Typhoon, Volt Typhoon and the compliance blind spot
The assessment’s third section addresses something increasingly hard to ignore: state-sponsored campaigns, including Salt Typhoon and Volt Typhoon, have specifically targeted telecom and cellular infrastructure to gain persistent footholds in critical infrastructure operators. Organisations that treat cellular OT as out of scope for threat modelling — because it’s “just connectivity,” not core infrastructure — are leaving a measurable exposure unmeasured, at precisely the layer that’s been shown to be actively targeted.
The same gap shows up in compliance posture. Frameworks like NERC CIP, IEC 62443 and TSA cybersecurity directives are frequently applied thoroughly to IT and traditional OT, while cellular-connected devices sit just outside their documented scope — a distinction that tends to surface during an audit rather than before one.
Response speed and who actually owns the risk
The final sections test something more operational: if a specific device type or manufacturer were confirmed compromised today, how quickly could the organisation find every affected device and restrict its access? Responses range from hours, backed by automated inventory and enforcement, to weeks of manual correlation — a gap that determines whether a compromised device type is contained during an incident or remains active throughout the investigation.
Underneath all of this sits a governance question the assessment asks directly: who currently has visibility into cellular device security posture? When that visibility stops at the network or telecom team, security decisions about cellular-connected devices are effectively being made without security input — a pattern the assessment’s data suggests is the most common root cause behind the other gaps it identifies.
Where this leaves security leaders
None of this is an argument against cellular connectivity for OT — it’s the fastest-growing deployment model for exactly the reasons that make it attractive: no trenching, rapid rollout, flexibility across sprawling sites. The assessment’s purpose is to help organisations see clearly where their governance of that connectivity actually stands, and to sequence next steps — visibility first, then authentication and segmentation, then integration with the broader SOC — rather than treating all gaps as equally urgent.
Security leaders responsible for cellular-connected OT device risk can take the five-section assessment directly and receive a maturity report benchmarked against similar organisations.






