ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Bridging the cultural divide between IT and OT  

industrial security
industrial security

Tony Atkins at Dragos explains how breaking down the silos between IT and OT will improve the security of industrial environments

 

In the last few years, cyber-security has become a top priority for critical national infrastructure (CNI) and industrial organisations. The heightened need to protect systems has not only been driven by an increase in cyber attacks, but also because of the digital transformation journeys many industrial organisations are currently undergoing.

 

In the contemporary digital-first age that we operate in, CEOs and board members are demanding that their institutions not just ensure the profitability of their industrial facilities, but also that they harness innovative technology to boost the productivity of their staff, improve operational efficiency and safety and maintain business continuity.

 

However, digital innovation and hyperconnectivity of the operational technology (OT) required to achieve these goals opens new avenues of cyber risks, exacerbates existing ones.

 

To minimise the risk exposure to critical business functions and progress safely, many industrial organisations are actively aiming to synchronise cyber-security with the innovation of OT environments.

 

Securing OT systems

When it comes to addressing industrial control systems (ICS)/OT security risks, many organisations are still unclear about the best approach. Security teams understand that the risks to OT are quite different to IT risks, but according to a recent study from the Ponemon Institute, many are still getting to grips with exactly what a mature OT cyber security posture should look like.

 

The Ponemon study examined the attitudes of 603 IT, IT security, and OT security practitioners at the managerial, director, and C-level to understand the current state of industrial cyber-security and what work needs to be done to address gaps.

 

Key findings from the study revealed that only 21 percent of respondents said their ICS/OT program activities have achieved full maturity, where emerging threats drive priority actions and C-level executives, and the board of directors are regularly informed about the state of their program.

 

The study by Ponemon highlighted the issue that nearly two-thirds (63%) of institutions had an ICS/OT cyber-security incident in the past two years. This took an average of 316 days to detect, investigate and remediate the incident, highlighting the fact that many OT systems may already be compromised with dormant risks.

 

The cultural divide

The research also uncovered a systemic cultural divide between IT and OT teams. This division is directly impacting the ability to secure both the IT and the ICS/OT environment.

 

Furthermore, only 43% of organisations have implemented cyber-security policies and procedures that are aligned with their ICS and OT security objectives, while only 39% have IT and OT teams that work together cohesively to achieve a mature security posture across both environments.

 

Just 35 percent of IT and OT teams have a unified security strategy that secures both the IT and OT environments, despite the need for different controls and priorities based on industry, hardware, and use-case.

 

Overall, the findings from the study highlight that many industrial organisations still have a lot to do to achieve a mature OT cyber-security posture. When building out cyber-security programs for OT environments there cannot be a copy and paste of an organisation’s existing cyber-security program.

 

ICS environments need cyber-security strategies and tools tailored specifically to the different missions, challenges and threats of the organisations. There are core differences between the pain points and objectives of a corporate IT environment—data, confidentiality, and security—and industrial environments, where human health and safety, loss of physical production, and facility shutdowns are real risks that could not only impact a businesses’ bottom line but have the potential to put employees at risk.

 

Breaking down security silos

Deep domain expertise as well as ICS/OT-specific technologies are both required to truly safeguard industrial systems, but with the current skills-gap there can be challenges finding the tools and tactics needed to properly secure OT environments.

 

However, this does not mean to say OT and IT teams should be siloed when building out their security programs. Instead, a unified approach where cross-functional teams of IT and OT SMEs collaborate to bridge the cultural divide provides the best security. While there is a need for different controls and priorities, organisations should have a unified security strategy that secures both the IT and OT environments.

 

A priority of these cross-functional teams should be to inform C-level executives and the board of directors about the efficiency, effectiveness and security of the ICS/OT cyber-security program, and the associated risks to the organisation. The cross-functional teams should also create an incident response plan for responding to a cyber-security incident and review the plan on a regular basis.

 

Cyber-security of industrial environments is becoming increasingly important as attacks increase, and digital transformation initiatives take place. While organisations are heading in the right direction, there is still a lot of work to be done to achieve cyber-security maturity.

 

Through cultural and technological collaboration between IT and OT, and by bringing the issue of cyber-security up to the board and executives regularly so they clearly understand the risks, organisations can significantly improve the effectiveness of their programs.

 


 

Tony Atkins is Account Manager, UK & EU for Dragos

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543