Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

OT Cybersecurity Is Maturing, But Visibility Is Still a Challenge

By Jordyn Alger, Managing Editor
Green planes reflected
Vishal Bansal via Unsplash
June 9, 2026

Operational technology (OT) security is growing into a board-level priority as industrial organizations increasingly rely on unified IT and OT environments to sustain production. The connectivity bolsters efficiency and resilience, however, it also expands the attack surface. 

The 2026 Fortinet State of Operational Technology and Cybersecurity Report reveals organizations are more alert about risks from ransomware groups, nation-state actors and other cybercriminals. Furthermore, they are realistic about OT cybersecurity maturity and are increasingly diligent about impending regulatory requirements. 

While visibility is also improving, gaps persist. The report found 23% of respondents have visibility into only half of their OT environment. Therefore, many security teams are defending these environments with inadequate information. 

Below, security leaders discuss concerns, trends and strategies for securing OT environments.  

Security Leaders Weigh In

Louis Eichenbaum, Federal CTO at ColorTokens:

Operational Technology (OT) environments rely heavily on Human Machine Interfaces (HMIs) and monitoring systems to give operators accurate situational awareness. If an adversary can compromise those systems and present false data, operators can be tricked into making dangerous decisions based on inaccurate information. In many OT environments such as water treatment facilities, pipelines, manufacturing plants, or energy infrastructure, false telemetry could have even more severe consequences ranging from environmental damage to safety incidents and operational outages.

The larger issue is that many of these OT systems were never designed with cybersecurity in mind. They were built for reliability and availability, not to withstand modern nation-state cyber threats. Unfortunately, many remain internet-facing, poorly segmented, and inadequately monitored. This is exactly why the cybersecurity conversation must move beyond prevention alone. We are never going to patch fast enough or prevent every intrusion. The focus now must be on resilience, assuming an adversary may gain access and ensuring they cannot move laterally or manipulate critical operations at scale.

Granular microsegmentation and zero trust principles are essential in OT environments because they help contain breaches, restrict unauthorized communications, and reduce the blast radius when a compromise occurs. The goal is not simply to stop every attack, but to ensure that a localized intrusion does not become a catastrophic operational event.

John Gallagher, Vice President at Viakoo:

Cybersecurity threats are always evolving, as are the skills needed to combat them. Clearly the shift by malicious hackers to target Operational Technology (OT) devices has brought new requirements to the lines of business, such as manufacturing, healthcare, physical security, facilities, etc. that are responsible for managing and securing such devices. Compared to traditional manufacturing or physical security workers, employers will pay a premium in these departments in their race to secure their non-IT devices. As threats become more cyber-physical in their impact, faster incident response and forensics will drive employers to recruit security professionals who can operate outside of the traditional IT space.  

I’d also like to touch upon the recent hype cycle around Mythos, which has been impressive, especially regarding its autonomous hacking capabilities. However, when we look past the theoretical zero-days in clean, standardized IT environments, the reality of securing OT and the Internet of Things (IoT) is the real cause for concern and urgent action because of Mythos. OT/IoT represents a larger attack surface than IT systems, and Mythos renders it into the most easily hacked part of infrastructure because it can overcome issues like non-standard operating systems and differences in network topology.  This directly accelerates existing trends like the shift of ransomware from data to OT systems, and the use of OT/IoT devices for initial infection and lateral movement. 

In the OT/IoT world, we are still managing device passwords on spreadsheets and manually rolling trucks to patch 10,000 cameras. If AI can discover and exploit a vulnerability in hours, yet it takes an organization six months of manual labor to patch their physical security systems, the math heavily favors the attacker. 

Nathaniel Jones, Vice President, Security & AI Strategy and Field CISO at Darktrace:

As Operational Technology (OT) becomes more integrated with IT systems, it presents more opportunities for attackers. OT security is strongest when supported by robust IT security, requiring coordination between IT and OT teams to defend the entire network. By adopting good cyber hygiene, proactively securing your digital estate, and addressing any vulnerabilities before they can be exploited, organizations will be much better equipped to defend their networks against increasingly resourceful threat actors.

Vincenzo Iozzo, CEO and Co-founder at SlashID:

Unfortunately, most Operational Technology (OT) systems were designed without security in mind. This includes the inability to patch them promptly or monitor them. Large Language Models (LLMs) are likely going to make attacks against OT systems more frequent as they further reduce the skill level required to launch these attacks. In the short term, the most effective approach we have to secure them is appropriate segmentation. Long term, these OT systems are some of the best candidates for architectural changes driven by LLMs. 

Vikesh Khanna, CTO & Co-Founder at Ambient.ai:

Legacy issues, such as air-gapped systems being compromised, weak authentication, and unpatched vulnerabilities persist, however, we’re seeing shifts toward more resilient architectures that incorporate physical security layers. For instance, unauthorized physical access to ICS assets — such as control panels or field devices — remains a major vector for breaches. With AI integration for real-time monitoring, anomaly detection, and proactive physical threat prevention, combined with stricter regulations, I expect meaningful improvements.

Recent trends include AI-driven anomaly detection, micro-segmentation, and zero-trust architectures, however a key innovation is agentic physical security for proactive threat prevention. Adaptive protections using ML for real-time encryption and threat response are game-changers, especially when layered with physical barriers and AI-verified access. 

Global, geopolitical conflicts are fueling a surge in Operational Technology (OT) attacks often exploiting physical vulnerabilities such as unsecured facilities or insider access. State-sponsored actors and hacktivists target critical infrastructure for disruption, as seen in DDoS campaigns, ransomware, and even physical sabotage attempts. This convergence of cyber warfare and geopolitics heightens risks, making robust agentic physical security essential to complement digital defenses and mitigate hybrid threats.

KEYWORDS: operational resilience operational security technology

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

Coding

What Security Leaders Say About the First AI-Developed Zero-Day Exploit

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

July 8, 2026

The 2026 Security Maturity Benchmark Report: Insights From Senior Security Leaders

In this webinar, speakers will share key insights from the report, including why today’s threat environment demands greater maturity and how to evaluate your organization’s current security posture.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Air Cargo Security Still a Challenge; Complex with Industry Fragmented

    See More
  • Responding to Cybersecurity Incidents Still a Major Challenge for Businesses

    See More
  • Three women sitting around a desk

    78% of MSPs state cybersecurity is a prominent IT challenge

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

  • security book.jpg

    Security Investigations: A Professional’s Guide

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing