Bridging the Gap: Why OT Cyber Risk Comes Back to IT/OT Integration
- May 18
- 5 min read
Updated: 4 days ago
If you spend time talking to organisations running industrial or operational environments, a pattern quickly emerges. The cyber risk isn’t just growing – it’s growing faster than their ability to see it, understand it, and respond to it.
More often than not, the root cause isn’t just “OT is insecure” or “attackers are getting better”. It comes down to one thing: IT and OT still aren’t properly joined up.
The Threat Is Real and It’s Accelerating
The numbers coming out of recent OT security reports* are pretty stark:
87% increase in ransomware attacks against industrial organisations
69% of ransomware attacks targeting manufacturing
31% of organisations experiencing six or more intrusions
55% suffering operational outages as a result
73% seeing attacks that directly impact OT operations
On top of that:
88% don’t have visibility into early-stage OT attacks
70% struggle with detection and response
Those two stats are the most telling. It’s not just that organisations are being attacked more often. It’s that they don’t see it early enough, and when they do, they struggle to do anything meaningful about it.
* Statistics borrowed from 2026, 2025 and 2024 OT Cybersecurity Year in Review’s by Dragos
Why This Keeps Happening
There are some obvious reasons why OT is an attractive target. A lot of the technology is old, wasn’t designed with security in mind, and now sits connected to modern IT networks. But that’s only part of the story – the bigger issue is structural.
Most organisations still operate with a clear divide; IT teams manage corporate systems, identity, endpoints and cloud; OT teams manage plants, assets, control systems and safety. They have different priorities, different tooling, and often different reporting lines.
We feel this Gartner® research highlights that communication and alignment between IT and operations teams are now one of the biggest barriers to integration.
So what you end up with is predictable; IT can’t see what’s happening in OT; OT isn’t architected in a way security teams understand; nobody has the full picture; and attackers take advantage of that gap.
The Visibility Problem Is Bigger Than People Realise
If you strip it back, most of the issues we see in OT security come down to visibility. Organisations often don’t have a complete inventory of OT assets, don’t understand how those assets communicate, and don’t have monitoring in place that makes sense of OT traffic
In some cases, they don’t even know something is part of their OT estate until it breaks, and that’s why the stat that 88% lack visibility into early OT attacks matters so much. You cannot detect what you cannot see, and you definitely can’t respond to it.
There’s also a misconception that if IT is well secured, OT will be too. That simply isn’t true. Gartner® found that security continues to be highly relevant for IT/OT integration planning with 5% of respondents experiencing a security incident that disabled OT systems but did not impact IT systems indicating direct attacks on OT systems. Which shows that attackers don’t need to go through traditional IT paths to cause damage (and that basic attacks which don’t impact your IT, will impact your insecure OT much more easily). So even if your IT SOC is world class, you can still be exposed.
Convergence Is Increasing the Risk, Not Reducing It
A lot of organisations are in the middle of IT/OT convergence programs. Industry 4.0, smart manufacturing, connected infrastructure. All positive from a business perspective, but there’s a significant trade-off.
Systems that were once isolated are now connected. That isolation was never a security strategy, but it did act as a form of protection. Now, legacy OT systems are online, remote access is widespread and IT tooling is layered on top of environments it wasn’t designed for.
Many of these systems are effectively insecure by design and decades old, so we’ve increased connectivity without fully solving the security model, and that’s why we’re seeing the spike in incidents.
Why Detection and Response Break Down
When an incident happens in a traditional IT environment, most organisations have a playbook. Logs, alerts, tooling, response teams.
In OT, it’s very different; alerts may not exist or may not be meaningful, SOC teams often lack OT context, and OT teams prioritise keeping systems running.
And at a broader level, there’s also a skills and capability gap. The UK NCSC has already pointed out that the capacity to respond to OT incidents is not where it needs to be, especially given how fragmented these environments are. So even when organisations know something is wrong, response is slower than it needs to be.
What Actually Fixes This
In my experience, trying to secure OT in isolation doesn’t work. Trying to extend IT controls into OT without adapting them doesn’t work either.
The answer sits in the middle – you need to bring IT and OT security together operationally, not just architecturally. This is where an integrated IT/OT SOC becomes critical.
Done properly, it gives you:
A single view of what’s happening
Not separate dashboards, not partial visibility, but a joined-up view across both domains.
Context that matters
Understanding how an alert in IT might relate to behaviour in OT, and vice versa.
Faster detection and response
Being able to spot an attack in progress and actually do something about it before it hits operations.
Teams that understand both environments
SOC analysts who aren’t just IT-focused, but understand OT protocols, risks, and constraints.
This Only Works If You Get the Alignment Right
One thing worth calling out, because it gets overlooked a lot. Integration is not the first step.
Gartner® makes the point clearly: Alignment is the foundational process of synchronizing standards, governance and security risk management between IT and OT. Integration is the subsequent connecting of data flows and processes. Attempting integration before alignment will cause technology complications, risk exposure, cultural friction and failed results.
That means:
Shared goals between IT and OT
Agreed risk appetite
Clear ownership of systems and data
Communication that actually works
If you skip that step, you end up with more technology but the same problems.
Final Thought
The cyber threat to OT isn’t just about legacy systems or sophisticated attackers. It’s about visibility, it’s about fragmentation, and it’s about organisations not having a joined-up way of seeing and responding to risk.
Until IT and OT are brought together in a meaningful way, that gap will continue to be exploited. An integrated IT/OT SOC isn’t a nice-to-have anymore. It’s quickly becoming the only realistic way to manage cyber risk across modern operational environments.
Gartner®, How CIOs Are Approaching IT/OT Integration, Kristian Steenstrup, Jo-Ann Clynch, 13 April 2026
GARTNER is a trademark of Gartner, Inc. and/or its affiliates.






