HOW IT/OT CONVERGENCE IS CHANGING OT CYBERSECURITY
For years, Operational Technology (OT) environments were designed around a simple principle: keep industrial control systems isolated from the outside world.
Industrial Control Systems (ICS), including SCADA systems, Distributed Control Systems (DCS), Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), Human-Machine Interfaces (HMIs), and engineering workstations, were traditionally separated from corporate IT networks and the internet.
That model is changing!
Modern industrial environments are increasingly connected to enterprise networks, remote access platforms, cloud services, centralized monitoring systems, engineering applications, third-party support infrastructure, and business systems. This connectivity brings significant operational benefits. It improves visibility, enables remote maintenance, supports data-driven decision-making, and allows organizations to manage geographically distributed assets more efficiently. But it also changes the cybersecurity equation.
The concern is no longer simply whether an attacker can directly reach an industrial control system.
The more important question is:
Can an attacker compromise something connected to the OT environment and use that trusted connection to move closer to the systems controlling the physical process?
This is where IT/OT convergence becomes a critical cybersecurity issue.
The convergence of IT and OT does not automatically create a security incident. The problem arises when connectivity creates poorly controlled paths between business systems and systems responsible for monitoring and controlling physical operations.
For critical infrastructure organizations, that distinction matters.
An attack that begins with a compromised IT account can potentially become an OT security incident. A compromised remote access system can become a pathway into an industrial network. A vulnerable engineering workstation can become a bridge toward controllers and process equipment.
And when cyber activity reaches OT, the consequences can extend far beyond data loss.
They can include production disruption, equipment damage, safety implications, environmental consequences, loss of availability, and interruption of essential services.
NIST emphasizes that OT security must account for the unique performance, reliability, and safety requirements of systems that interact directly with the physical environment.
That makes IT/OT convergence one of the most important considerations in modern OT cybersecurity and ICS security.
What Is IT/OT Convergence?
Before examining the cybersecurity risks, it is important to understand what IT/OT convergence actually means.
Information Technology (IT) generally supports information processing, business applications, communications, enterprise systems, identity management, data storage, and organizational decision-making.
Operational Technology (OT) is concerned with monitoring and controlling physical processes.
In an industrial environment, OT can include:
- Programmable Logic Controllers (PLCs)
- Distributed Control Systems (DCS)
- Supervisory Control and Data Acquisition (SCADA)
- Remote Terminal Units (RTUs)
- Human-Machine Interfaces (HMIs)
- Engineering Workstations
- Industrial Ethernet networks
- Safety Instrumented Systems (SIS)
- Historians
- Industrial servers
- Industrial firewalls
- Sensors and actuators
- Industrial communication protocols
These systems can be found across oil and gas facilities, power generation and distribution, water and wastewater plants, manufacturing facilities, transportation infrastructure, pipelines, substations, and other critical infrastructure.
Historically, OT networks were often isolated or operated with limited external connectivity.
Today, that separation is becoming more difficult to maintain.
Organizations need OT data for business analytics. Engineers need remote access for maintenance. Vendors need controlled access to support equipment. Security teams need centralized monitoring. Operations teams need real-time visibility across geographically distributed facilities.
IT/OT convergence is inevitable; the real risk comes from uncontrolled connections between enterprise and industrial environments.
Why IT/OT Convergence Changes the OT Attack Surface
Traditional cybersecurity often focuses on protecting individual systems. In an OT environment, however, security cannot stop at the device level. Organizations must also understand how systems connect, communicate, and provide access to one another.
A PLC may have no direct internet connection. A SCADA server may be protected behind several network layers. An engineering workstation may operate within a restricted control network. Yet these systems can still become reachable through trusted connections elsewhere in the environment.
For example, an attack may begin with a compromised IT endpoint and progress through stolen credentials, remote access infrastructure, and a jump server before reaching the OT network. From there, an attacker could potentially target an engineering workstation, SCADA or DCS systems, and ultimately the controllers responsible for the physical process.
Compromised IT Endpoint → Stolen Credentials → Remote Access → Jump Server → OT Network → Engineering Workstation → SCADA/DCS → PLC or Controller
This is what makes IT/OT convergence such an important consideration in modern OT cybersecurity. The attacker does not necessarily need to compromise a PLC directly. Instead, they may exploit the connections and trusted systems surrounding it.
Recent OT threat intelligence reinforces this concern. Dragos’ 2026 reporting highlights engineering workstations, identity systems, remote access infrastructure, and IT-to-OT pathways as important areas of concern. The broader lesson is clear: attackers can potentially reach critical OT assets by exploiting the systems and connections that provide access to them.
As a result, the OT attack surface should no longer be viewed simply as a collection of PLCs, SCADA servers, DCS systems, and HMIs.
It also includes every system, identity, connection, and access pathway that can reach, administer, monitor, authenticate to, or influence those assets.
Understanding these relationships is essential to building an effective OT cybersecurity strategy. Organizations need visibility not only into what assets exist, but also into how those assets are connected and where an attacker could move if one part of the environment is compromised.
The IT-to-OT Attack Path
One of the most important concepts in modern ICS cybersecurity is the attack path. Attackers do not always need to find a direct route to an industrial controller.
Instead, they can look for the easiest route through trusted connections. Consider a simplified industrial environment.
An organization may have:
Corporate IT Network
- Active Directory
- Employee endpoints
- Email.
- Enterprise applications.
- File servers.
↓
Industrial DMZ
- Jump servers.
- Remote access gateways.
- Data exchange systems.
- Historian replication.
↓
OT Network
- SCADA servers.
- Engineering workstations.
- HMIs.
- OT servers.
↓
Control Network
- PLCs.
- RTUs.
- DCS controllers.
↓
Physical Process
- Pumps.
- Valves.
- Motors.
- Compressors.
- Turbines.
- Breakers.
- Industrial equipment.
The security objective is not simply to prevent every connection.
It is to ensure that each connection is intentional, controlled, monitored, and limited to what is operationally necessary.
If an attacker compromises an IT endpoint, the question becomes:
How far can that compromise travel?
If the answer is:
“All the way to the engineering workstation”
the organization has a significant OT security problem.
If the answer is:
“The attacker cannot cross the controlled boundary, cannot authenticate to OT systems, and all permitted connections are monitored”
the organization has created meaningful resilience.
That is the difference between simply having network segmentation and actually managing an industrial attack path.
Why OT Is Different From IT
One of the biggest mistakes organizations can make is treating OT cybersecurity as simply another form of IT security. Although IT and OT environments are increasingly connected, they operate under very different requirements. Conventional IT security often places strong emphasis on confidentiality, data protection, user productivity, and keeping systems updated. In OT environments, however, availability, safety, reliability, deterministic behavior, and process integrity are often equally, or even more, critical.
This difference becomes particularly important when deploying cybersecurity controls. A security measure that is acceptable in a corporate IT environment may have unintended consequences in an industrial environment if it disrupts a control process. Restarting an employee’s laptop after a security update may be an inconvenience, but unexpectedly restarting an industrial controller, interrupting communication with a SCADA system, or affecting a critical control process can have serious operational consequences, including production disruption or safety risks.
For this reason, effective OT cybersecurity and ICS security cannot simply copy enterprise IT security practices. Security controls must be carefully evaluated and designed around the industrial process, the criticality of the assets, and the operational requirements of the facility. NIST’s OT security guidance emphasizes the unique performance, reliability, and safety requirements of operational technology, reinforcing the need for a security approach that protects industrial systems without compromising the processes they are designed to control.
The Major IT/OT Convergence Risks
1. Compromised Credentials
Identity has become one of the most important components of the IT/OT security boundary.
Attackers who obtain legitimate credentials may be able to access remote administration platforms, VPNs, jump servers, engineering environments, or other systems that provide pathways toward OT.
The danger is not simply the stolen password. The real problem is what that identity is authorized to reach.
If a compromised account has unnecessary access to industrial systems, an attacker may be able to move deeper into the environment while appearing to use legitimate authentication mechanisms.
Organizations should therefore consider:
- Multi-factor authentication
- Privileged access management
- Role-based access
- Least privilege
- Dedicated OT identities
- Credential monitoring
- Account lifecycle management
- Session monitoring
- Strong authentication for remote access
Identity security is increasingly becoming part of OT cybersecurity rather than remaining solely an IT responsibility.
2. Remote Access Into OT
Remote access is one of the most significant convergence points between IT and OT.
Remote connectivity can be essential for:
- Maintenance
- Troubleshooting
- Vendor support
- Engineering
- Emergency response
- Monitoring geographically distributed facilities
But every remote connection introduces another potential pathway into the industrial environment.
The question should not simply be: “Do we have secure VPN access?”
It should be:
Who can access OT remotely, from where, to which assets, using what authentication, for what purpose, and under what monitoring controls?
Remote access should be tightly controlled and ideally limited to specific assets, users, time periods, and approved activities.
Where appropriate, organizations should consider architectures involving:
- MFA
- Jump servers
- Privileged access management
- Session recording
- Time-limited access
- Vendor access controls
- Network segmentation
- Continuous monitoring
- Explicit authorization
Remote access should be treated as a controlled pathway into OT, not simply another IT service.
3. Weak IT/OT Segmentation
Segmentation remains one of the foundational controls for reducing IT/OT convergence risk.
However, segmentation is more than putting a firewall between two networks.
Effective segmentation should control:
Who can communicate with what, over which protocol, through which path, and for what operational purpose.
Industrial environments often use protocols such as:
- Modbus/TCP
- DNP3
- IEC 61850
- OPC
- EtherNet/IP
- PROFINET
- vendor-specific protocols
These protocols and communication relationships should be understood before security policies are designed.
A firewall rule that simply permits broad communication between IT and OT can create the appearance of segmentation without providing meaningful containment.
The objective should be controlled communication, not simply network separation.
4. Engineering Workstations as High-Value Targets
Engineering workstations deserve special attention.
They often have privileged access to industrial systems and may be used to:
- Configure PLCs
- Modify control logic
- Maintain DCS systems
- Configure SCADA
- Troubleshoot industrial equipment
- Upload or download controller programs
That makes them extremely valuable to attackers.
Recent 2026 OT threat reporting specifically identified engineering workstations as high-impact targets because of their ability to influence industrial control processes.
An attacker does not necessarily need to compromise a PLC directly.
Compromising the workstation used to administer that PLC may provide a more practical path.
This is why engineering workstation security should be treated as an important part of ICS cybersecurity architecture.
Controls can include:
- Application allowlisting
- Endpoint protection appropriate for OT
- Network restrictions
- Privileged access controls
- USB/device control
- Patch management
- Malware protection
- Secure configuration
- Monitoring
- Offline or protected engineering backups
5. Third-Party and Vendor Access
Industrial facilities frequently depend on vendors, system integrators, OEMs, contractors, and maintenance providers.
Third-party access can be essential to maintaining operations.
But from a cybersecurity perspective, every trusted third party represents another potential path toward OT.
Organizations should know:
- Which vendors have access
- Which systems they can access
- When access is permitted
- How they authenticate
- Whether sessions are monitored
- Whether credentials are shared
- Whether access remains enabled permanently
- Whether vendor connections can reach critical control networks
The objective is not to eliminate third-party access. It is to make third-party access controlled, observable, and temporary where possible.
6. Legacy OT Systems
Many industrial environments contain equipment that was designed decades ago. These systems may remain operational because replacing them can be expensive, disruptive, or operationally risky.
Some legacy systems were never designed with modern cybersecurity requirements in mind.
They may have:
- Unsupported operating systems
- Weak authentication
- Legacy protocols
- Limited logging
- Infrequent patching
- Hard-coded credentials
- Limited endpoint protection
- Long replacement cycles
This creates an important OT cybersecurity reality:
You cannot always patch your way out of OT risk.
When patching is operationally difficult, organizations may need to compensate through:
- Network segmentation
- Firewalls
- Application allowlisting
- Monitoring
- Access control
- Virtual patching
- Isolation
- Secure remote access
- Compensating controls
This is one of the areas where OT security requires a fundamentally different risk-management approach from conventional IT.
7. Lack of OT Asset Visibility
You cannot protect what you cannot see.
This principle is particularly important in industrial environments.
Organizations may know they operate a certain number of PLCs, HMIs, servers, switches, and engineering workstations.
But do they know:
- Which devices are actually connected?
- Which firmware versions are running?
- Which systems communicate with each other?
- Which protocols are being used?
- Which assets are exposed?
- Which devices are critical to the process?
- Which assets are obsolete?
- Which systems have known vulnerabilities?
- Which engineering workstations can reach controllers?
Without accurate OT asset visibility, security teams may struggle to understand the real attack surface.
Current OT research continues to highlight asset visibility and reliable asset identification as major challenges. In 2026, Dragos also identified limited OT visibility as a major reason organizations struggle to detect threats before operational impact.
An effective OT asset inventory should therefore go beyond a simple list of IP addresses.
It should provide context.
What is the asset?
Where is it?
What does it control?
What communicates with it?
How critical is it?
What vulnerabilities affect it?
What is the consequence if it becomes unavailable or compromised?
That context turns asset inventory into a cybersecurity capability rather than simply an IT database.
8. Insufficient OT Network Monitoring
Traditional endpoint-based security can have limitations in industrial environments. Some OT devices cannot support conventional security agents.
Some legacy controllers cannot be modified without affecting operations. Some industrial protocols were not designed with modern security mechanisms.
This makes network visibility extremely important.
OT network monitoring can help organizations identify:
- Unexpected communications
- New devices
- Unauthorized protocols
- Abnormal traffic
- Suspicious remote connections
- Changes in communication patterns
- Potential command activity
- Lateral movement
- Indicators of compromise
In an OT environment, visibility should not focus solely on whether a device is online.
It should also consider:
Is this device behaving the way it normally behaves within the industrial process?
That distinction is fundamental to effective ICS monitoring.
When an IT Incident Becomes an OT Incident
One of the biggest misconceptions surrounding IT/OT convergence is that an IT compromise and an OT security incident are always separate events. In a connected industrial environment, a compromise that begins in the IT network can potentially develop into a much more serious OT incident when trusted connections provide a path toward industrial systems.
Consider a scenario where an attacker compromises an employee’s credentials and uses them to access a remote access platform. From there, the attacker reaches a jump server and identifies an engineering workstation with legitimate access to the OT environment. If that workstation is compromised, the attacker may be able to interact with systems connected to SCADA, DCS, or industrial controllers. What started as a conventional IT security incident has now crossed into the OT environment and potentially reached systems that influence physical operations.
This transition is what makes IT/OT convergence particularly important for critical infrastructure. Once an attacker moves beyond information systems and reaches systems responsible for monitoring or controlling an industrial process, the potential consequences change significantly. The incident may no longer be limited to stolen data, compromised accounts, or business disruption; it could potentially affect production, equipment, process availability, safety, and the continuity of essential operations.
A conventional IT compromise may result in:
- Data theft
- Account compromise
- Business disruption
- Financial losses
An OT compromise can additionally result in:
- Production interruption
- Loss of process visibility
- Loss of control
- Equipment damage
- Safety consequences
- Environmental impact
- Physical disruption
- Extended recovery periods
This is why OT cybersecurity must focus on operational consequences, not only technical compromise.
The Role of Zero Trust in OT
Zero Trust is increasingly discussed in industrial cybersecurity, but applying Zero Trust to OT requires care. The objective is not to blindly apply enterprise IT security models to industrial control systems.
Instead, the principle should be adapted to the operational environment:
Never assume that a connection is trusted simply because it originates from an internal network.
Every access path should have a defined purpose.
Organizations should evaluate:
- Who is accessing the system?
- What device are they using?
- What asset are they accessing?
- Why do they need access?
- When should access be allowed?
- What protocols are required?
- What actions should be permitted?
- How should the session be monitored?
This approach complements traditional segmentation.
Segmentation establishes boundaries.
Zero Trust principles strengthen the controls governing access across those boundaries.
Why Segmentation and Visibility Must Work Together
A firewall alone cannot provide complete protection for an industrial environment. It can control and block network traffic, but effective security depends on understanding what assets exist, how they communicate, which connections are necessary, and which activities should be considered abnormal. Without this visibility, organizations may struggle to determine which traffic should be allowed, restricted, or investigated.
This is why OT asset visibility, network architecture, segmentation, security controls, and monitoring must work together as part of a coordinated OT cybersecurity strategy. The process begins with establishing an accurate inventory of industrial assets and understanding their role within the environment. Network mapping then provides visibility into communication flows and relationships between systems, helping organizations identify legitimate and unnecessary connections.
With this understanding, segmentation can be used to separate critical OT zones and control communication between them. Industrial firewalls and intrusion detection systems (IDS) can then enforce security policies and monitor permitted traffic, while security monitoring and SIEM solutions help correlate events across the environment and identify potentially suspicious activity. If a security incident occurs, incident response capabilities provide the processes needed to contain the threat, protect critical operations, and support recovery.
These capabilities should not be viewed as separate security products operating independently. Together, they form a layered OT cybersecurity architecture designed to provide visibility, control, detection, and resilience across the industrial environment.
How Organizations Can Reduce IT/OT Convergence Risk
There is no single technology that eliminates IT/OT convergence risk. A resilient OT security strategy should combine multiple controls.
1. Build an Accurate OT Asset Inventory
Identify devices, systems, communication relationships, vulnerabilities, ownership, and operational criticality.
2. Map the IT-to-OT Attack Paths
Understand every legitimate pathway from enterprise systems toward OT.
Do not only document network diagrams. Identify actual communication paths and administrative relationships.
3. Segment Critical OT Networks
Use appropriate zones and conduits to limit unnecessary communication.
Industrial segmentation should reflect the operational architecture and risk of each environment.
4. Secure Remote Access
Require strong authentication and tightly control remote connectivity.
Use dedicated access infrastructure where appropriate and monitor privileged sessions.
5. Protect Engineering Workstations
Engineering workstations should receive special security consideration because of their privileged relationship with controllers and industrial systems.
6. Monitor OT Networks
Deploy monitoring capable of understanding industrial communications and identifying abnormal behavior.
7. Apply Risk-Based Vulnerability Management
Not every vulnerability can or should be patched immediately in OT.
Prioritize based on:
- Asset criticality
- Exploitability
- Exposure
- Process impact
- Compensating controls
- Operational risk
8. Harden OT Systems
Reduce unnecessary services, accounts, protocols, applications, and communication paths.
9. Strengthen Backup and Recovery
Maintain protected backups of critical configurations, controller logic, engineering systems, SCADA infrastructure, and other essential OT assets.
10. Test the Response Plan
An organization should know what happens if an engineering workstation is compromised, a remote access platform is breached, or communication with a critical control system becomes unavailable.
Cybersecurity plans should be tested against realistic operational scenarios.
The Future of IT/OT Convergence
IT/OT convergence is not going away.
Industrial organizations will continue to connect systems because digitalization delivers real operational value.
Remote operations, centralized monitoring, predictive maintenance, industrial analytics, cloud platforms, smart grids, digital transformation, and connected industrial assets all depend on greater connectivity.
At the same time, attackers are becoming more interested in the relationships between systems.
The 2026 OT threat landscape demonstrates this evolution. Threat actors are increasingly focused on understanding industrial environments and the systems that influence physical processes, rather than treating OT simply as another network to compromise.
Emerging technologies are adding another dimension.
Recent research has demonstrated that AI can assist with portions of the process of identifying and exploiting vulnerabilities in PLCs, although significant human expertise and resources may still be required.
The implication is not that every industrial facility will suddenly face autonomous AI-driven attacks.
The more important takeaway is that the barrier to certain reconnaissance, analysis, social engineering, and exploitation tasks may continue to decrease.
For OT defenders, this reinforces the importance of fundamentals:
Know your assets.
Understand your architecture.
Control access.
Segment critical systems.
Monitor industrial networks.
Protect engineering environments.
Prepare for recovery.
IT/OT Convergence Is an Architectural Challenge, Not Just a Cybersecurity Problem
Perhaps the most important lesson is that IT/OT convergence cannot be solved by adding another security product.
It requires organizations to understand how their industrial environments actually operate.
Cybersecurity teams need to work with:
- OT engineers
- Control engineers
- Network engineers
- Plant operators
- Maintenance teams
- IT teams
- System integrators
- Vendors
- Management
The goal is not to disconnect OT from everything.
The goal is to create secure, controlled, observable connectivity.
Industrial cybersecurity should enable digital transformation without allowing connectivity to become an uncontrolled pathway toward critical control systems.
Conclusion: The New OT Security Boundary
The traditional idea of the OT security perimeter is changing. In a connected industrial environment, it is no longer enough to ask, “Is the PLC protected?” Organizations also need to understand what systems can reach it, which identities can access those systems, which remote connections can enter the OT environment, and which engineering workstations have the ability to modify critical control systems. Just as importantly, they need to know what communication is permitted between IT and OT and whether abnormal activity can be detected before it affects the physical process.
This shifts the focus from protecting individual devices to understanding and controlling the attack paths that connect them. IT/OT convergence itself is not inherently dangerous. Connectivity can improve operational visibility, maintenance, efficiency, and overall performance. The risk arises when IT and OT environments become connected without sufficient visibility, segmentation, access controls, and monitoring.
For critical infrastructure, the goal should therefore not be to eliminate IT/OT convergence, but to control it securely. A resilient OT cybersecurity architecture combines asset visibility, network segmentation, secure remote access, industrial firewalls, intrusion detection, endpoint protection, security monitoring, vulnerability management, hardening, and reliable backup and recovery. These controls must also be designed around the operational and safety requirements of industrial environments.
Because once cybersecurity reaches OT, the question is no longer simply, “Can an attacker access the network?” The more important question is: “What can that access ultimately affect in the physical world?”
That is why IT/OT convergence has become a defining cybersecurity challenge for modern critical infrastructure. For organizations operating power, energy, water, manufacturing, transportation, and other industrial environments, securing the pathways between IT and OT is becoming just as important as securing the assets at either end of them.
Secure Your Convergence With Expert OT Cybersecurity Solutions.
At ATS, we help organizations secure critical infrastructure by identifying and controlling the attack paths between IT and OT. Our services include OT cybersecurity assessments, asset visibility, network mapping and segmentation, secure remote access, industrial firewalls and IDS, OT monitoring, and cybersecurity engineering.
Our experts help energy and critical infrastructure organizations strengthen cyber resilience, reduce IT-to-OT risk, and protect industrial operations without compromising reliability and safety.
Ready to secure your OT systems?
Contact our cybersecurity specialists today to assess vulnerabilities, strengthen defenses, and protect your critical infrastructure from evolving cyber threats.