top of page
shield_bg_smaller_edited.jpg

Stay in the know with Sapphire's industry insights

background_edited_edited.jpg

Bridging the Gap: Why OT Cyber Risk Comes Back to IT/OT Integration

  • May 18
  • 5 min read

Updated: 4 days ago


If you spend time talking to organisations running industrial or operational environments, a pattern quickly emerges. The cyber risk isn’t just growing – it’s growing faster than their ability to see it, understand it, and respond to it. 

More often than not, the root cause isn’t just “OT is insecure” or “attackers are getting better”. It comes down to one thing: IT and OT still aren’t properly joined up. 

The Threat Is Real and It’s Accelerating 

The numbers coming out of recent OT security reports* are pretty stark: 

  • 87% increase in ransomware attacks against industrial organisations 

  • 69% of ransomware attacks targeting manufacturing 

  • 31% of organisations experiencing six or more intrusions 

  • 55% suffering operational outages as a result 

  • 73% seeing attacks that directly impact OT operations 

On top of that: 

  • 88% don’t have visibility into early-stage OT attacks 

  • 70% struggle with detection and response 

Those two stats are the most telling. It’s not just that organisations are being attacked more often. It’s that they don’t see it early enough, and when they do, they struggle to do anything meaningful about it. 

* Statistics borrowed from 2026, 2025 and 2024 OT Cybersecurity Year in Review’s by Dragos 

Why This Keeps Happening 

There are some obvious reasons why OT is an attractive target. A lot of the technology is old, wasn’t designed with security in mind, and now sits connected to modern IT networks. But that’s only part of the story – the bigger issue is structural. 

Most organisations still operate with a clear divide; IT teams manage corporate systems, identity, endpoints and cloud; OT teams manage plants, assets, control systems and safety. They have different priorities, different tooling, and often different reporting lines. 

We feel this Gartner® research highlights that communication and alignment between IT and operations teams are now one of the biggest barriers to integration.

So what you end up with is predictable; IT can’t see what’s happening in OT; OT isn’t architected in a way security teams understand; nobody has the full picture; and attackers take advantage of that gap. 

The Visibility Problem Is Bigger Than People Realise 

If you strip it back, most of the issues we see in OT security come down to visibility. Organisations often don’t have a complete inventory of OT assets, don’t understand how those assets communicate, and don’t have monitoring in place that makes sense of OT traffic 

In some cases, they don’t even know something is part of their OT estate until it breaks, and that’s why the stat that 88% lack visibility into early OT attacks matters so much. You cannot detect what you cannot see, and you definitely can’t respond to it. 

There’s also a misconception that if IT is well secured, OT will be too. That simply isn’t true. Gartner® found that security continues to be highly relevant for IT/OT integration planning with 5% of respondents experiencing a security incident that disabled OT systems but did not impact IT systems indicating direct attacks on OT systems. Which shows that attackers don’t need to go through traditional IT paths to cause damage (and that basic attacks which don’t impact your IT, will impact your insecure OT much more easily). So even if your IT SOC is world class, you can still be exposed. 

Convergence Is Increasing the Risk, Not Reducing It 

A lot of organisations are in the middle of IT/OT convergence programs. Industry 4.0, smart manufacturing, connected infrastructure. All positive from a business perspective, but there’s a significant trade-off. 

Systems that were once isolated are now connected. That isolation was never a security strategy, but it did act as a form of protection. Now, legacy OT systems are online, remote access is widespread and IT tooling is layered on top of environments it wasn’t designed for. 

Many of these systems are effectively insecure by design and decades old, so we’ve increased connectivity without fully solving the security model, and that’s why we’re seeing the spike in incidents. 

Why Detection and Response Break Down 

When an incident happens in a traditional IT environment, most organisations have a playbook. Logs, alerts, tooling, response teams. 

In OT, it’s very different; alerts may not exist or may not be meaningful, SOC teams often lack OT context, and OT teams prioritise keeping systems running. 

And at a broader level, there’s also a skills and capability gap. The UK NCSC has already pointed out that the capacity to respond to OT incidents is not where it needs to be, especially given how fragmented these environments are. So even when organisations know something is wrong, response is slower than it needs to be. 

What Actually Fixes This 

In my experience, trying to secure OT in isolation doesn’t work. Trying to extend IT controls into OT without adapting them doesn’t work either. 

The answer sits in the middle – you need to bring IT and OT security together operationally, not just architecturally. This is where an integrated IT/OT SOC becomes critical. 

Done properly, it gives you: 

A single view of what’s happening 

Not separate dashboards, not partial visibility, but a joined-up view across both domains. 

Context that matters 

Understanding how an alert in IT might relate to behaviour in OT, and vice versa. 

Faster detection and response 

Being able to spot an attack in progress and actually do something about it before it hits operations.  

Teams that understand both environments 

SOC analysts who aren’t just IT-focused, but understand OT protocols, risks, and constraints.  

This Only Works If You Get the Alignment Right 

One thing worth calling out, because it gets overlooked a lot. Integration is not the first step. 

Gartner® makes the point clearly: Alignment is the foundational process of synchronizing standards, governance and security risk management between IT and OT. Integration is the subsequent connecting of data flows and processes. Attempting integration before alignment will cause technology complications, risk exposure, cultural friction and failed results.

That means: 

  • Shared goals between IT and OT 

  • Agreed risk appetite 

  • Clear ownership of systems and data 

  • Communication that actually works 

If you skip that step, you end up with more technology but the same problems. 

Final Thought 

The cyber threat to OT isn’t just about legacy systems or sophisticated attackers. It’s about visibility, it’s about fragmentation, and it’s about organisations not having a joined-up way of seeing and responding to risk. 

Until IT and OT are brought together in a meaningful way, that gap will continue to be exploited. An integrated IT/OT SOC isn’t a nice-to-have anymore. It’s quickly becoming the only realistic way to manage cyber risk across modern operational environments.



Gartner®, How CIOs Are Approaching IT/OT Integration, Kristian Steenstrup, Jo-Ann Clynch, 13 April 2026


GARTNER is a trademark of Gartner, Inc. and/or its affiliates.


Sapphire title slide with teal and pink overlapping circles and text: Bridging the Gap: Why OT Cyber Risk Comes Back to IT/OT Integration

bottom of page