ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk:Navigating cloud transformation and IT/OT convergence in CNI

On 4 June 2026, teissTalk host Thom Langford was joined by Alex Holben, Strategy and Technology Officer, Fortinet; Amal Kotecha, Head of Technology, INEOS; and Sarah Clarke, Head of Information, Defence Medical Command, MOD.

Linked InXFacebook

Views on news


Iran-affiliated cyber actors are targeting internet-facing operational technology (OT) devices across critical infrastructures in the U.S., including programmable logic controllers (PLCs). "These attacks have led to diminished PLC functionality, manipulation of display data and, in some cases, operational disruption and financial loss," the U.S. Federal Bureau of Investigation (FBI) said in a post on X. The actors used leased, third-party hosted infrastructure with configuration software, such as Rockwell Automation’s Studio 5000 Logix Designer software, to create an accepted connection to the victim’s PLC. These are, however, not technologically sophisticated attacks but rather fundamental ones, which goes to show how important it is to get the cyber security basics right. The norm has shifted considerably in the past few years as these attacks have become almost acceptable. While originally the point of these attacks was to make operating inconvenience, now it’s to fiddle with the fundamentals of what CNI is doing. Hacking tanks, for example, can lead to fuel shortages and social disruption.  


Doing IT-OT convergence in the right way


OT moving to the cloud can be seen as a sign that IT pushes its patterns onto OT. But even for IT, moving to the cloud hasn’t been smooth sailing prior to CNAP. The question arises whether IT security is at a level that is sufficient for taking OT to the cloud. That said, collaboration between IT and OT will be key to the efficient configuration and security of OT systems in the cloud. 


One major step to convergence is the iterative and incremental application of Zero Trust to OT. To maintain the ability to isolate the OT system in times of incidents, all dependencies and connectivities must be mapped out and understood. Convergence is expected to speed up as vendors’ attitude to patching will need to change to comply with recent EU and UK legislation on cyber resilience and security by design. To avoid IT’s mistakes when it moved to the cloud, OT’s needs, criticalities, as well as the dependencies, vulnerabilities and risks introduced by the move must be rendered visible. Migration to the cloud must be done thoughtfully and at the right scope to optimise costs.


OT doesn’t necessarily have to connect to the internet to use the cloud – it can use private circuits (Express Route, Direct Connect) into cloud environments. The cookie cutter approach in OT will lead to overexposure. Meanwhile, security practitioners have a moral duty to ensure that no harm is done in the environments they work in. They should also see compliance as an opportunity to improve security and further reduce risk. 


The panel’s advice

  • IT and OT shouldn’t be separate entities but perceived as an integrated technology team.
  • When critical uptime is at stake, the cloud may be too far away. However, operating a local and a cloud environment can add a new level of complexity.
  • Successful OT migration to the cloud requires not just technological deployment but the adoption of cloud culture – DevSecOps, automation and the continuous improvement model.
  • Always take the safety first approach and validate safety with hard facts.
  • Find your crown jewels and protect those in case you have a limited budget.
  • Set aside ten minutes every day to reach out to someone in an adjacent team – IT to OT, security to networks team to build trust and understanding. 
Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543