Remote operational-technology (OT) sites—including water and wastewater pump and lift stations, roadside traffic-control cabinets, distribution substations, and oil-and-gas remote terminal unit locations—often combine legacy endpoints, remote administration, sparse staffing, and shared or insufficiently segmented field networks. Standards and government guidance correctly prioritize reducing external exposure, segmenting networks, and replacing or hardening insecure equipment. In documented small-system settings, however, cost, outage, and workforce constraints can delay those preferred controls. This paper asks a narrower question: which packet-layer capabilities could reduce cyber-physical risk while full segmentation, protocol modernization, or equipment replacement remains incomplete? It presents a conceptual synthesis rather than an experimental validation or systematic review. A purposively selected primary-source incident corpus is used to identify recurring stages of attack: discovery or remote access, traversal of weak boundaries, and manipulation through authorized interfaces or well-formed control actions. Cases involving direct OT manipulation show that the final process effect can be delivered through legitimate control-system functionality even when malware enables access or persistence. Colonial Pipeline is treated separately as a boundary case because public reporting found no lateral movement into OT; its operational disruption followed loss of confidence in interconnected business and operational dependencies rather than demonstrated command-level compromise. The paper defines a candidate packet-layer capability triad: (1) automated moving target defense (AMTD) with embedded deception; (2) cyber-physical anomaly enforcement based on communication and process state; and (3) command-aware industrial-protocol enforcement. The triad is intended to operate on the network path without requiring software agents on protected controllers. It is not presented as equivalent to zones-and-conduits segmentation, nor as a substitute where segmentation is feasible. The paper maps the three capabilities to the derived attack path, relates them to NIST cyber-resiliency guidance and IEC 62443 compensating-measure concepts, and specifies a falsifiable evaluation program covering security efficacy, process safety, availability, false decisions, bypass resistance, and deployment economics. Important limitations include direct physical bypass, encrypted traffic, authorized-but-malicious command paths, model drift, inline-device failure modes, and the concentration of economic evidence in the U.S. water sector.
Francesco Trama (Fri,) studied this question.