search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
TECHNOLOGY FOCUS Industrial cybersecurity


OVERCOMING THE OT/IT DIVIDE


©pexels Igor Passchier Rob Demain, CEO, e2e-assure, explains why we need to make resilience and recovery a priority in OT O


perational Technology (OT) is now fast being considered a sitting duck for nation state actors. The fact that the Volt


Typhoon cyber espionage group sat inside US national infrastructure for up to five years has focused hearts and minds on the need to improve OT system security, with our recent survey finding 64% of IT decision makers now fear nation-state sponsored attacks and 51% expect their systems to be subjected to a cyber attack of some kind over the coming year. OT is an attractive target for attackers because of its business-critical role. Compromise OT and you can cause widespread disruption with major incidents such as that experienced by Jaguar Land Rover, resulting in massive financial losses. But it’s often so difficult to secure these systems that they are only patched at scheduled intervals, if at all, with the predominant attitude being, why fix it when it isn’t broken? This results in a cultural divide between OT and IT teams, with the former concerned with availability and continuity while the latter prioritise network and data protection. However, both sides will need to


overcome their differences due to the increased convergence of IT and OT systems. The industrial internet of things (IIoT) and real-time data transfer are connecting OT systems to IT networks, enabling organisations to benefit from smarter and more efficient processing, but in so doing, those previously air-gapped systems are being made much more vulnerable to attack. Security, on the other hand, hasn’t kept


18 June 2026 | Automation


pace. The same survey found a substantial ‘remediation gap’ in many OT systems, with an average time of 52 days from compromise to detection while the breakout time – that is the time for an attacker to infiltrate and begin to move across the network – was just 30 seconds. What’s more, one in ten large organisations were found to have taken over a year to remediate a major incident. The greater attack surface presented by IT/OT convergence and the growing threat of attack due to rising geopolitical tensions therefore makes securing OT systems a national priority. In fact, there’s been a notable shift towards adopting a resilient stance i.e. one that prepares for attack and enables the organisation to withstand and recover from such an event. Key to this approach is monitoring for anomalous and suspicious activity but this too presents challenges. OT systems are often situated on plant floors or inaccessible locations which make them extremely difficult to physically monitor. Or they may be situated in remote or low-bandwidth areas that struggle with data transfer so that monitoring cannot deliver real-time insights. To overcome these issues, manufacturers need to be able to use sensors that have a minimal impact on operations but can collect and transfer metadata relevant to both OT and IT teams. Unlike physical sensors, software sensors can be deployed virtually and even locally in those environments where external connectivity is limited or not available and can report on status, vulnerabilities and threats. These software sensors can relay data to a Security Operations Centre (SOC) allowing the feed to be monitored 24x7 for indicators of compromise such as unauthorised access attempts, command changes or lateral


movement. The SOC team can correlate alert data with global intelligence to verify the attack and take the necessary mitigation steps, preventing escalation. Because the sensors operate on a continuous basis and effectively span both IT and OT networks, they can meet the needs of both teams and in so doing reduce the remediation gap. These shared datasets can also help meet compliance obligations, such as the risk assessment requirements of NIS2. Whether monitored over an in-house or


outsourced SOC, it’s important to note that events must be contextualised. Combining the data with threat intelligence helps to build out the case with all the details needed to carry out the investigation and the information can also be used for playbooks that facilitate more rapid response in the future. That then sees the organisation strengthen its defences and become more resilient.


It’s also advisable to perform testing and validation exercises based on the MITRE ATT&CK for ICS framework. These allow the SOC team to assess how attacks might unfold and to test how quickly they can respond. There are, however, differences in monitoring OT versus IT. IT is far noisier and generates higher alert volumes whereas OT will generate less frequent events but those detected are likely to pose a greater threat. Interestingly, our survey found that close to


a third of organisations (32%) have adapted and are using platforms built to monitor the IT estate, while only 28% are using OT-specific detection. Utilising OT-specific systems is much more likely to cater to the needs of the environment and ensure OT alerts aren’t missed. And it makes much more sense to deploy the right tools for the job to secure an attack surface.


e2e-assure e2e-assure.com


automationmagazine.co.uk


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40