The key difference from IT security is priorities: in OT, availability and (human/environmental) safety usually come before confidentiality. Legacy systems can be sensitive to patching and active scanning, many industrial protocols were designed without authentication, and downtime is expensive.
Practical starting points are therefore asset visibility (inventory), network segmentation, controlled remote access, backups and an incident response plan. Industrial Defender ASM securely collects existing data from industrial control systems to provide asset visibility, anomaly detection, and vulnerability and compliance management.