Deep Dives

OT and IT Convergence and Resilience

When the factory floor meets the boardroom: the disappearing boundaries of OT and cyber resilience

The disappearing OT boundary

For decades, operational technology (OT) environments existed within clearly defined boundaries where physical processes were governed by purpose-built controllers, closed-loop systems, air gaps, and an assumption that industrial environments were largely isolated from external threats.

Those boundaries have steadily eroded. OT environments are now routinely connected to enterprise IT systems for use cases such as predictive maintenance, cloud analytics, remote diagnostics and operational reporting. Industrial assets that were once monitored locally are increasingly networked together, while equipment manufacturers, integrators and maintenance providers frequently require remote access into operational environments. Industry 4.0, the ongoing transformation of connected, automated and data-driven technologies across industrial operations, has delivered significant gains in efficiency and visibility, but it has also fundamentally changed the security model on which many OT environments were originally built.

Today, an estimated 70% of OT systems are projected to connect to IT networks (1). The challenge is no longer confined to a discrete operational environment. The systems that support physical operations are increasingly intertwined with enterprise technology, cloud services and third-party suppliers, creating a broader and more complex attack surface than ever before.

Threat landscape

Industrial facilities across sectors including energy, manufacturing and water have seen attackers move laterally from enterprise environments into operational systems, triggering shutdowns, disrupting production and, in some cases, causing physical consequences.

Nation-state actors and sophisticated ransomware groups are increasingly targeting operational disruption itself. Many OT environments continue to rely on systems that were designed decades before modern connectivity requirements emerged, creating a growing mismatch between operational dependence and cyber resilience. In 2024, 65% of OT environments exhibited insecure remote access conditions, while one in four industrial penetration tests still identified default credentials within operational environments (1).

Strategic leadership involvement and accountability

For many organisations, OT security has historically been treated as an engineering and operational issue rather than a board-level concern. Responsibility has often sat within operational teams, shaped as much by safety considerations as cybersecurity requirements, with limited interaction between OT engineers and enterprise security functions.

The NCSC Annual Review 2025 emphasises that cyber resilience is critical to business survival and national resilience. A ministerial letter to boards and CEOs across the UK has reinforced that responsibility for cyber resilience sits at the highest levels of organisations rather than solely within technology teams. The forthcoming Cyber Security and Resilience Bill is expected to further formalise these expectations through increased regulatory oversight and accountability.

This shift is also reflected organisationally. 52% of organisations now report that the CISO is responsible for OT security, up from just 16% in 2022 (2). However, the challenge extends beyond reporting lines. OT and enterprise IT security have traditionally evolved through different governance structures, different operating models and different priorities. OT environments are often managed through an operational and engineering lens, where safety and availability are primary concerns, while enterprise cybersecurity and resilience are typically managed through corporate risk and information security functions, with a greater focus on protecting information and digital services. Therefore, bringing these cultures together into a coherent approach is one of the defining organisational challenges facing critical infrastructure today.

OT environment challenges

Strategic leaders often inherit a conceptual model built on enterprise IT security assumptions, but OT environments operate under a fundamentally different set of challenges.

Different priorities: IT security is traditionally framed around the CIA triad: confidentiality, integrity and availability. In OT environments, practitioners often describe those priorities as AIC. Maintaining safe and continuous operations is the primary objective with system integrity close behind because, if an industrial process begins operating outside expected parameters, this is not just a cyber issue, it is a safety failure with a higher potential for detrimental real-world consequences. Confidentiality remains relevant but rarely carries the same weight as it does within corporate IT environments. Security controls and incident response measures that are effective in enterprise IT can therefore be disruptive or counterproductive when applied to OT environments without consideration of operational and safety requirements.

Legacy by design: Many industrial environments continue to rely on systems that were never designed with modern connectivity. Decades-old controllers are now being connected to cloud platforms, enterprise applications and remote management services without the security architecture that would be expected of modern systems. Patching and system upgrades are often constrained by operational requirements and the potential impact of downtime.

Supply chain exposure: Modern OT environments increasingly depend on external parties. Manufacturers, maintenance providers, integrators, cloud analytics platforms and remote monitoring services often form part of the operational ecosystem. High-profile supply chain attacks have demonstrated how these relationships create additional pathways into operational environments that organisations may not fully understand or monitor.

Building cyber resilience: what it means in practice

Boards should be treating cyber incidents as a realistic and inevitable operational risk rather than an exceptional event. The priority is ensuring the organisation can respond, recover and continue operating when incidents occur. Building that capability requires moving beyond reactiveness and treating OT cybersecurity and resilience as a core business function embedded in governance.

Governance and oversight: Most operators already recognise the consequences of operational disruption within enterprise risk frameworks. The challenge is ensuring cyber threats are recognised as credible causes of those same disruption scenarios. OT cybersecurity should therefore be integrated into enterprise risk discussions, with organisations explicitly considering how cyber-attacks could trigger operational disruption, safety incidents or loss of service. Boards require visibility of these risks through clear ownership structures and reporting that translates technical issues into operational and business impacts.

Increased visibility: Many organisations possess excellent visibility of operational performance but significantly less visibility of the security posture of those systems. Establishing continuous security monitoring of OT environments, including unmanaged and third-party connected assets, is therefore essential. Hybrid security operations models that bring together IT and OT monitoring functions are increasingly emerging as a practical means of detecting cross-domain threats and reducing organisational blind spots.

Incident response exercising: Incident response in OT environments presents challenges that are fundamentally different from those found in enterprise IT. Leaders may face decisions involving production shutdowns, safety implications, environmental impacts or prolonged recovery periods, often under conditions of uncertainty and outside normal working hours. Board members and senior executives should therefore participate in realistic cyber exercises that reflect the operational realities of OT environments rather than purely digital disruption scenarios.

Supply chain assurance: Visibility must extend beyond organisational boundaries. Understanding critical supplier dependencies, assessing resilience across the supply chain and identifying external services that support operational processes are all essential components of cyber resilience. Particular attention should be paid to remote access arrangements, cloud-hosted services and specialist operational systems whose compromise could have disproportionate operational consequences.

Strategic questions worth asking now

  • Do we know every point at which our OT systems connect to IT networks, cloud services and external suppliers?
  • Have we quantified the operational and financial impact of an OT-targeted cyber incident, not just a data breach but a disruption to physical operations?
  • Have we identified the operational risks on our enterprise risk register that could be triggered by a cyber-attack?
  • Does our incident response plan account for scenarios where physical operations are compromised, not just digital systems?
  • Is our CISO, or equivalent, actively engaged with OT cyber risk, and do they have direct access to board-level conversations?
  • Does our organisation have the capability to engage effectively with OT teams and make difficult operational decisions under uncertainty during a cyber incident?
  • Are we testing our resilience, or merely assuming it?

Strong cyber governance is increasingly viewed as an indicator of organisational maturity by regulators, insurers, customers and partners. That scrutiny is only intensifying as governments and oversight bodies place greater emphasis on cyber resilience across critical infrastructure sectors in response to a threat landscape shaped increasingly by nation-state activity and operationally focused attacks.

The challenge facing organisations is no longer simply the convergence of IT and OT. It is the disappearance of the boundaries that once separated operational systems from the wider digital ecosystem. How organisations govern that reality, understand the dependencies it creates and prepare for its consequences will increasingly determine their ability to sustain critical operations in the face of disruption.

Sources

  1. Dragos/Zero Networks, OT Security Trends 2025
  2. Fortinet, State of Operational Technology and Cybersecurity Report, 7th Edition

Want to speak to us?

If you would like to discuss a cyber or resilience problem with a member of the team, then please get in touch however you feel most comfortable. We would love to help you and your business prepare to bounce back stronger.