SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!

Bridging the OT/IT Gap to Achieve Smart & Secure Manufacturing

By Austen Byers
Austen Byers

Austen Byers

April 6, 2023

In recent years, there has been a great debate between information technology (IT) and operational technology (OT) departments about operational security. Each department has different priorities when it comes to operations and security, and meeting in the middle often doesn’t yield the best results. Sometimes the IT/OT breach impacts manufacturing and other industries where the stakes of system availability are at their highest, contributing to an acceleration in vulnerabilities in industrial control systems (ICS) and significant losses. 

Knowing that OT security is too often sacrificed to some degree in order to keep the operation running, further dialogue and organizational changes are needed to construct an adequate and practical security posture in the rise of the industrial Internet of Things (IIoT). 

An Evolving Mindset 

When system availability is the top concern, there is almost no motivation to upgrade the operating system (OS). In most cases, OT departments are cognizant of the need for cybersecurity; it’s just that they more highly prioritize guarding and utilizing their legacy assets up until the very end of their lifecycles. 

However, we’re starting to see an evolution. Endpoint security software on OT equipment is becoming the new norm among top-tier manufacturers, for dramatically reducing the oppressive threat of general malware attacks. 

Although the mindset of those in OT is changing, it doesn’t mean IT will follow suit. After all, the major goal is to eliminate any noise during operations. Not only is the malware itself noise, even the process to find malware — if too complex — is often considered noise, too. So, though OT departments want to upgrade their devices to include intelligent and advanced manufacturing features, most devices stay physically disconnected, or “air-gapped,” because of the high cost of cybersecurity in both human resources and dollars. As people advocate for smart manufacturing with Microsoft Azure Cloud, for example, it can be a deterrent that those assets might be equipped with Windows XP or another OS that Microsoft stopped supporting years ago. 

Proven Approaches 

To ensure that smart manufacturing is secure, OT and IT must share the same vision of a forward-looking methodology for cybersecurity using approaches that can function adequately at both ends with synergy: 

  • Relying Less on Air-Gapping — Air-gapping is proven in terms of security, but it runs counter to the smart manufacturing vision that most technology giants are proposing because inbound and outbound traffic alike are blocked. Actionable business intelligence is based on constant flows of a great amount of data, and the results rely on dynamic responses. Protection is achieved, but communication is sacrificed, making air-gapping a less appealing option to protect OT assets. Eventually, there will be a paradigm shift after more apps are adopted, and cloud-based implementations for OT cybersecurity will most likely become a major part of the process.   
  • Covering Every Device — There is also a hierarchy of needs in OT that must be respected and accounted for in any workable approach to cybersecurity — first, the smooth running of the operation, followed by a secured environment and, finally, upgrading to a smart environment. Fundamentally, every asset must be protected from at least one angle at every stage of its entire lifecycle — throughout onboarding, staging, production and maintenance. Multilayered protection is a general guideline. A mixture of agent-based and agentless implementations, plus hardware-based network security protection, should be applied to cover every single device in the OT space. One single vulnerable point becomes the vulnerability of the whole ecosystem. It’s mission critical to protect current assets the way they are. Therefore, for example, finding a Windows XP-compatible solution instead of forcing an OS upgrade is very important. 
  • Establishing Security Visibility Across OT/IT — There was a time when hackers didn’t care about OT/IT. They simply utilized whatever tool they possessed to maximize their success rate of hacking. However, they care now, after gaining millions of dollars in benefits from collateral IT-to-OT damage. Undoubtedly, they will seek out more OT-specific hacking techniques, such as manipulation of ICS protocols. As of today, most general-purpose security services are basically designed for IT but also work (less so) for OT. That needs to change. For example, endpoint detection and response (EDR) can continually monitor both IT and OT protocols throughout the entire site, with very manageable event logs and few false alerts.  

Shared Security Mindset 

Given the differing priorities between IT and OT departments when it comes to operational security, the success of OT/IT convergence depends on communication, collaboration and taking action with proven approaches. If it doesn’t happen organically, organizational changes may be necessary to achieve a shared security mindset to prevent financial (and other) losses. Sacrificing OT security was more acceptable in the past for the sake of availability, but as equipment evolves with the Industry 4.0 movement and becomes more connected, it should no longer be considered an option.

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

KEYWORDS: cybersecurity security integration

Share This Story

Austen byers small

As Technical Director, Americas at TXOne Networks, Austen Byers leads the company’s efforts in providing design, architecture and engineering technical direction and leadership. He is a sought-after thought leader in operational technology (OT) cybersecurity with more than 10 years in the cybersecurity space.

Blog Topics

SDM Editors

Industry Voices

Recent Comments

Wonderful Content! The way you describe the things...

amazing and very impressive dear check...

SOC Teams Protect Multi-Building Campuses

Smart Home Revolution

Benefits of Implementing 802.3bt

Blog Roll

Central Station Alarm Association

Electronic Security Association

Security Industry Association

Security-Net

Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing