Tech

‘Keeping OT security up to date is more than patching systems’

Published

on

Integrity360’s An Nguyen discusses the cyberthreats affecting industrial environments and what makes an effective OT security plan.

Operational technology (OT) has become a growing priority in the world of cybersecurity in recent years.

Securing OT systems, which operate and control physical processes in industrial environments while maintaining safety, reliability and operational continuity, is more important than ever amid the rising threat of disruption from cybercriminals and state-sponsored bad actors – who increasingly target OT systems in critical infrastructure in particular.

Sectors particularly affected by these types of cyberattacks include the likes of manufacturing, energy, transport, water and healthcare.

Advertisement

In fact, recent data from Statista found that the manufacturing industry was hit by the largest share of cyberattacks in 2025, with companies in this sector experiencing 27.7pc of total attacks for the year.

An Nguyen, OT practice lead at cybersecurity specialist Integrity360, tells SiliconRepublic.com that OT security considerations differ quite considerably from those of traditional IT security.

“Unlike traditional IT environments, where the primary objective is often the protection of information, industrial environments must balance cybersecurity with operational and safety requirements,” says Nguyen. “Effective OT cybersecurity requires not only cyber expertise, but also an understanding of industrial processes, operational dependencies and real-world constraints.”

Here, Nguyen discusses the concerns and complexities of OT security further.

Advertisement
What are some of the biggest threats facing OT environments?

Ransomware remains one of the biggest concerns, especially when attacks start in the corporate IT environments and then pivot to industrial operations. Critical infrastructure operators also face risks from sophisticated threat actors, supply chain compromises and insecure remote access.

However, what we often see is that successful attacks are not always the result of highly sophisticated techniques. They are frequently the result of more basic weaknesses such as poor asset visibility, weak network segmentation, legacy systems or uncontrolled third-party access.

As IT and OT become increasingly interconnected, organisations need to focus not only on external threats, but also to understand how disruptions to digital systems could propagate to critical industrial processes and services.

What are the biggest priorities in an efficient OT security plan?

An effective OT security strategy should start with understanding the business and operational environment. The first step is to identify critical processes, understand how they depend on digital systems and gain visibility over assets, communications and third-party connections.

Advertisement

Organisations also need a clear governance and operating model across IT and OT environments. One of the most common challenges is defining roles and responsibilities between operations, engineering, IT and cybersecurity teams. Without clear ownership, accountability and decision-making processes, even well-designed security programmes will face difficulties to provide sustainable improvements.

From there, organisations can assess their maturity level and build a roadmap based on risk and operational priorities. Typical focus areas include remote access security, network segmentation, change management practices, vulnerability management, third-party vendors assessment, monitoring, incident response and recovery capabilities.

The challenge is not to deploy as many security controls as possible. The challenge is to build a security model that takes into account the operational reality of the organisation and can be maintained over time.

Why is it important to keep OT security up to date?

Keeping OT security up to date is more than patching systems. It requires maintaining visibility of the environment, reassessing risks as the environment evolves and making sure preventive measures, detection and response capabilities remain effective.

Advertisement

This is particularly important because many industrial systems stay in operation for decades. You cannot always patch, upgrade or replace them at the same pace as you would in an IT environment. As connectivity increases and new vulnerabilities are discovered, organisations need to continuously adapt their security posture while managing operational constraints.

In what ways do companies fall short of proper OT security?

Most organisations do not fail because they ignore security completely. Usually, what we see is that security initiatives remain isolated, too much technology-focused or disconnected from operational realities.

Many organisations still struggle with basic visibility of OT assets, clear ownership between operations, engineering and cybersecurity teams, third-party access management and preparation for incidents that could impact production.

Another common challenge is moving from assessment to execution. Organisations often complete audits and assessments, but then struggle to prioritise, fund and implement the improvements that have been identified. Technology is important, but effective OT security also requires governance, operational ownership and long-term commitment.

Advertisement
What does a significant OT cybersecurity breach look like? Do you have any examples of a major incident?

A major OT cyber incident does not necessarily involve attackers taking direct control of industrial systems. In many cases, disrupting connected IT systems or remote access infrastructure is enough to affect industrial operations.

A recent example is the cyberattack that temporarily shut down a small power generation plant in the UK. According to public reporting, the incident is believed to be linked to Iranian actors and resulted in the facility being offline for several days. While there was no impact on the wider UK energy system, the event highlighted how cyberattacks can affect critical infrastructure operations without necessarily targeting industrial control systems directly.

This case illustrates that the challenge is not only to protect individual systems. It is to understand the dependencies between IT, OT and operational processes, and to make sure the organisation can continue operating and recover effectively when disruption occurs.

Is there a contrast between how organisations view IT security versus how they view OT security?

Historically, IT and OT security developed around different priorities. IT security has mainly focused on protecting information systems, while OT environments have traditionally prioritised safety, reliability and operational continuity. Today, the distinction is becoming less clear because IT and OT are increasingly connected, and OT is using progressively more common IT technologies.

Advertisement

The challenge is absolutely not to keep IT and OT security completely separated. It is neither to apply IT security practices to OT without adaptation. In practice, the most mature organisations combine both approaches. They use existing cybersecurity capabilities such as SOC, incident response and access management, while integrating OT expertise and operational context understanding.

Down the line, OT cybersecurity should be treated as a business and operational resilience challenge, not simply as an additional technical cybersecurity topic.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version