Skip to content
Commentary OT / ICSCritical Infrastructure

The OT/ICS Blind Spot: Why Your Cyber Risk Picture Is Missing Half the Picture

Ask a CISO at a utilities company to walk you through their cyber risk picture. You’ll get patch cadence, phishing resistance rates, EDR coverage, the last pentest findings. Solid IT security hygiene. Then ask specifically about the SCADA systems managing water pressure, the distributed control systems on the power distribution network, the historian servers logging plant data.

The answer changes character. Detection becomes “the engineers would notice.” Patching reveals Windows XP Embedded, unsupported PLCs, software stacks that haven’t seen a security update in years because updating them requires recertifying the industrial process they control. Segmentation is described in terms of physical access controls to the plant floor, not network architecture.

This isn’t a failure of individual CISOs. It’s a structural feature of how industrial environments were built, and it’s now one of the most consequential security exposures in the Western economy.

The Air Gap Was Demolished Years Ago

The traditional justification for lighter OT security controls was the air gap. Industrial systems were physically isolated from corporate networks and the internet. The attack vectors that threatened IT simply didn’t apply.

Approximately true in the 1990s. Increasingly less true with every passing year since.

The connectivity happened for legitimate business reasons. Real-time production monitoring. Remote access for vendor engineers who couldn’t afford to fly out for every maintenance window. Supply chain integration. Data analytics initiatives that promised to optimise industrial processes and delivered genuine value. Each connection made commercial sense in isolation. Collectively, they demolished the isolation that the entire OT security model was built on.

A typical manufacturing plant or utility operator today has dozens of pathways between its OT environment and the outside world, some documented, many not. Remote access for vendor support. Historian servers pulling data from plant systems into the corporate network. Engineering laptops that move between corporate WiFi and the OT environment. Industrial IoT sensors with direct internet connectivity, often installed without involving the security team. Jump servers sitting at the IT/OT boundary with authentication that hasn’t been reviewed in years.

The air gap is gone. The security model built on it remains in place. That gap is the exposure.

What State Actors Established a Long Time Ago

Stuxnet, 2010. Physical destruction of Iranian uranium centrifuges through software manipulation of Siemens PLCs. The proof of concept for industrial cyber operations, that software could cause real-world physical damage, was established fifteen years ago.

The 2015 and 2016 attacks on Ukraine’s power grid followed. Demonstrable, intentional outages affecting hundreds of thousands of people, caused by actors who understood the industrial environment well enough to time and sequence the attack for maximum disruption. The Triton/TRISIS attack on a Saudi petrochemical facility in 2017 was a different category: it targeted safety instrumented systems, the last barrier against catastrophic physical failure. The intention wasn’t disruption. It was to remove the mechanism that prevents a plant from destroying itself.

These techniques are documented. They’ve been analysed, published, and incorporated into multiple state actors’ toolkits. What was specialist nation-state capability in 2010 is now understood broadly enough that sophisticated criminal groups are beginning to probe OT environments. The attackers have been studying this for a decade. Most boards have not.

Five Questions Every Board Should Be Able to Answer

If you sit on the board, or in the C-suite, of an organisation operating industrial processes, utilities, transport systems, or physical infrastructure, these questions need answers. Substantive ones, with evidence, not “our team has that covered”:

Inventory: Can you produce a complete inventory of OT assets, their network connectivity, and current patch status? If that takes weeks to compile, the answer is already informative.

Segmentation: How are OT and IT networks separated? When did an independent party last test that separation?

Detection: Do you have the capability to detect anomalous behaviour on the OT network, not just IT network anomalies, but activity within the industrial environment itself? Who monitors it, and what does the response process look like?

Vendor access: Who has remote access into the OT environment? Under what controls? When was that list last reviewed against active need?

Resilience: If OT systems are unavailable for 72 hours (not a data breach, but a production stoppage), what is the operational and financial impact, and what is the recovery plan?

Every organisation that has answered these questions honestly has found gaps. Every one of them. The organisations that haven’t asked yet are the ones you read about afterwards.

The Ownership Gap Nobody Wants to Own

OT security consistently falls between organisational structures. The IT security team doesn’t own OT systems and usually lacks the engineering knowledge to assess them. OT engineers understand the industrial environment but weren’t hired to think in terms of threat actor TTPs. The CISO’s remit may technically include OT (it often does on paper), but the team has neither appropriate access nor tools configured for industrial protocols.

This isn’t a technology problem. No product solves it. It’s a governance problem, and the only people who can resolve it are the ones who own the board agenda and the budget: the executive team, and the board they report to. Assigning clear accountability, funding a baseline OT security assessment, and integrating OT risk into the enterprise risk picture alongside IT risk: those are deliberate governance decisions. They don’t happen by default.

The window for making them proactively is narrowing.