Why not intrusion prevention?

Intrusion prevention systems (IPS) go a step beyond just detecting policy violations; they will block the action or drop the traffic. Although this is an accepted interaction for true malicious traffic, think of the implications of having a device block traffic in an ICS application because of false positives. My advice is to keep the IPS functionality out of the Industrial Zone of an ICS network.

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.