Today’s industry is facing a paradox. On the one hand, digitization and the interconnection of machines as part of Industry 4.0 are paving the way for unprecedented efficiency and analytics. On the other, every connected device becomes a potential entry point for a cyber attack. So the natural reflex of management is to instruct IT departments to extend their proven security mechanisms to the production floor. And this is where the problem begins. These projects often fail, facing a wall of misunderstanding and resistance from operational technology (OT) engineers.
This conflict is not due to ill will or lack of competence. Its source lies much deeper - in the fundamental differences between the IT world and the OT world. These are two different universes, governed by different laws of physics, having different priorities and using different languages. Trying to impose one model on the other without a thorough understanding of these differences is like trying to apply traffic rules to air traffic control. It can only lead to disaster. Building an effective cybersecurity strategy for the industry is only possible if we first build a bridge of understanding between the two cultures.
Shortcuts
- Why is the traditional approach to cyber security failing the industry?
- What exactly is information technology, or popular IT?
Why is the traditional approach to cyber security failing the industry?
Traditional cyber security, shaped over decades in corporate environments, has been built on one fundamental premise: its overriding goal is to protect data. All tools, procedures and policies in the IT world are designed to ensure the confidentiality, integrity and availability of information. This approach works well in protecting servers, databases and business systems, where data loss is the biggest threat.
The problem is that in an industrial environment, on the factory floor or in a power plant, data, while important, is not the overriding value. Here, physical processes are king. The most important thing is for a welding robot to move with millimeter precision, a wind turbine to turn at the right speed, and valves in a pipeline to open and close at the right time. Cyber security in this world must protect not bits and bytes, but people, machines and the environment.
Transferring a 1:1 IT methodology to the OT world fails because it ignores this different operational context. Automatically installing patches, which is standard in IT, in OT can suddenly bring a production line to a halt. Vulnerability scanning, which is routine in an office network, can disrupt sensitive controllers in an industrial network. That’s why the traditional approach is not only inefficient, but sometimes even dangerous to the stability and security of industrial operations.
📚 Read the complete guide: Ransomware: Ransomware - czym jest, jak się chronić, co robić po ataku
What exactly is information technology, or popular IT?
Information technology (IT) is a field that most of us are familiar with from our daily lives and office work. It encompasses the entire ecosystem of technologies used to manage electronic data. Its domain includes personal computers, servers, corporate networks, email systems, databases and business applications such as ERP (enterprise resource planning) and CRM (customer relationship management) systems.
The main task of IT is to ensure the smooth flow of information in an organization. These systems are the bloodstream of data that support decision-making, financial operations, communications and logistics. The IT world is dynamic by nature. Computer hardware is replaced every 3-5 years, software is updated regularly, and new technologies are implemented for optimization and innovation.
From a security perspective, the IT universe is focused on protecting digital assets. The priority is to prevent data theft, protect intellectual property, ensure customer and employee privacy, and maintain the availability of business services. An IT failure most often translates into financial losses, image problems or operational complications in the office sphere.
What, in turn, is operational technology, or the mysterious OT?
Operational technology (OT) is the world of machines, processes and physical interaction with the real world. It includes hardware and software systems designed to monitor and control industrial equipment. We’re talking about things like industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems and, at the lowest level, programmable logic controllers (PLCs), which are the brains of individual machines.
OT systems are the nervous system and muscle of any industrial operation. They are the ones that manage robots in a car factory, control chemical processes in a refinery, control water flow in a wastewater treatment plant and regulate turbines in a power plant. Unlike IT, the OT world is much more static. The life cycle of industrial equipment often exceeds 15 or even 20 years, and its operation must be extremely stable and predictable.
Security in OT has a completely different dimension. Its main purpose is not to protect data, but to ensure that physical processes run in a safe, reliable and uninterrupted manner. Failure of an OT system is not just a financial problem. It’s a direct threat to the life and health of employees, a risk of environmental disaster, damage to machinery worth millions, and an immediate halt to all production.
What is the fundamental conflict of priorities between IT and OT?
The conflict between IT and OT is most evident in the hierarchy of security priorities. In the IT world, the CIA triad of Confidentiality, Integrity and Availability reigns supreme. This means that the absolute priority is to protect data from unauthorized access (Confidentiality). In second place is ensuring that data is not altered in an uncontrolled manner (integrity). Availability, while important, comes in third place.
In the OT world, this hierarchy is reversed and expanded. Here, Safety and Availability are paramount. The number one priority is to ensure that systems operate in a way that is safe for people and the environment. Equally important is the continuous availability of the production process - every minute of downtime generates huge losses. Only in second place is data integrity (ensuring that commands sent to controllers are correct), and confidentiality is often the least important factor.
This fundamental difference in priorities is a source of constant friction. An action that to an IT specialist is standard procedure - like blocking a network port to isolate a threat - to an OT engineer can mean cutting off crucial communications and risking uncontrolled machine behavior. The IT specialist sees the risk of data leakage; the OT engineer sees the risk of an accident or production stoppage. Both are right, but they are looking at the same problem from completely different perspectives.
Conflict of priorities: Two worlds of security
IT World (Information)OT world (Physical process)1 Confidentiality: Protecting data from theft.1 Safety (Safety): Protection of people, machinery and the environment.2 Integrity: Protection of data from modification.2 Availability (Availability): Ensuring continuity of production.3 (Availability): Ensuring access to data and systems.3 Integrity: Ensuring correctness of control.
Why is data confidentiality the most important thing for IT - the CIA triad?
The CIA triad (Confidentiality, Integrity, Availability) is the cornerstone on which all modern IT and corporate cyber security is built. Its primacy stems directly from the nature of the resources that IT protects. In the knowledge economy, data has become the most valuable asset of many companies. They represent trade secrets, intellectual property, financial data and customer information.
Confidentiality comes first, as unauthorized disclosure of this data can have disastrous consequences: loss of competitive advantage, violation of data protection regulations (RODO) and the gigantic fines that come with it, as well as irreparable loss of customer trust. A leaked customer database is an apocalyptic scenario for an e-commerce company.
Integrity is second to none, as unauthorized modification of data can lead to erroneous business decisions, financial fraud or operational chaos. Imagine the consequences of silently changing bank account numbers in an invoicing system. Availability, while crucial to business continuity, comes in third place, as temporary system unavailability is often seen as the lesser of two evils compared to permanent loss of data confidentiality or integrity.
Why is physical security and process continuity a priority for OT?
In operational technology, the stakes are quite different. Here, not only information is at stake, but above all physical safety and real-time measurable production. That’s why the absolute priority is Safety - ensuring that industrial processes do not create a risk to the life and health of workers, cause an environmental catastrophe or physically destroy infrastructure.
Every action in an OT network must be evaluated through the prism of its impact on physical security. A cyber attack that causes an industrial robot to make uncontrolled movements, or that shuts down the cooling systems in a chemical reactor, are scenarios with unimaginable consequences. For this reason, OT engineers are extremely conservative and cautious about any changes to their systems.
Equally important is Availability, understood as the uninterrupted continuity of the production process. In a modern factory, every minute of downtime is a measurable, often huge financial loss. A production line that comes to a standstill because of a failed software update generates costs running into hundreds of thousands of euros per hour. For this reason, the OT philosophy is “if it works, don’t touch it.” Availability and reliability are synonymous with profitability here.
How can a simple system upgrade be routine in IT and a disaster in OT?
Consider a simple scenario: an operating system manufacturer publishes a critical security patch. For an IT administrator, the procedure is standard. He or she informs users that overnight, during a designated service window, servers will be rebooted to install the update. The process is automated, and the possible several minutes of service unavailability is an acceptable cost in exchange for patching a dangerous vulnerability. This is a routine, responsible action.
Now let’s bring the same scenario to the OT world. The computer that needs to be upgraded is a Human-Machine Interface (HMI) station overseeing the operation of a key reactor in a chemical plant. The process in the reactor must run continuously for weeks at a time. There is no “service window” in the middle of the night. Stopping and restarting the process is an extremely complex, costly and risky operation in itself.
Moreover, installing an untested patch on this critical system is a huge risk. What if the update proves incompatible with specialized SCADA software? What if it causes problems with communication controllers and loss of connectivity with PLCs? The potential consequences - from loss of process control to emergency shutdown of the entire plant - are disproportionately high relative to the risks associated with an unpatched vulnerability. That’s why in OT, updates are deployed extremely infrequently, during planned general overhauls, and only after weeks of testing on development systems.
How do IT and OT systems work in different environments?
The physical environment in which systems operate is another chasm separating IT and OT. IT systems are designed to operate in ideal, controlled conditions. The heart of IT is an air-conditioned, dust-free and physically secure server room. Office computers also function in comfortable, stable temperatures. The entire infrastructure is protected from extreme environmental conditions.
OT systems are the complete opposite. They are designed to operate in harsh and often hostile industrial environments. Controllers, sensors and operator panels must function reliably on production floors full of dust, vibration and electromagnetic interference. They must withstand extreme temperatures in steel mills, high humidity in paper mills or corrosive atmospheres in chemical plants.
This difference in operating conditions determines the design and robustness of the equipment. OT devices are much more rugged and specialized, but also less flexible than their IT counterparts. Their designers focus on reliability and longevity in harsh environments, often at the expense of computing power or modern, built-in security features that are standard in IT.
Why is the life cycle of IT and OT systems separated by a technological gap?
The technology life cycle is one of the most fundamental factors differentiating the two worlds. The IT world lives at the rhythm of constant change and innovation. The life cycle of hardware, such as laptops and servers, is typically 3 to 5 years. After that time, it is replaced with a newer, faster and more secure model. The same is true of software - operating systems and applications are regularly updated, with revolutionary new versions appearing every few years.
The OT world operates on a completely different time scale. The life cycle of control systems and industrial machinery is designed for decades. Investing in a production line or a power plant control system is a decision for 15, 20 and sometimes even 30 years. Replacing these systems is a gigantic logistical and financial undertaking, requiring the entire factory to be shut down for weeks or months.
This gap in life cycles has huge security implications. It means that industrial networks are running devices on a daily basis that are prehistoric relics from an IT perspective. They run on long-unsupported operating systems, such as Windows XP or Windows NT, for which no security patches have been released for years. Securing such infrastructure requires a very different approach than in the IT world.
What are legacy systems and why are they such a challenge in OT?
“Legacy” systems (obsolete or legacy systems) are hardware and software infrastructures that are still in use, even though their technology is outdated and the manufacturer no longer provides technical support for them. They are ubiquitous in OT environments due to the aforementioned very long life cycle of industrial equipment. Many key controllers, HMIs or SCADA servers, installed 15 years ago, are still operating reliably and fulfilling their operational tasks.
From a cyber security perspective, legacy systems are a ticking bomb. First, they run on old operating systems that are full of known but unpatched vulnerabilities. Any novice hacker is able to find ready-made tools on the Internet to attack vulnerabilities in Windows XP. Second, these systems often lack the basic built-in security mechanisms that are standard today, such as encryption of communications or strong access control.
The biggest challenge is that these systems often cannot be replaced or upgraded. Replacement would mean gigantic costs and downtime. In turn, attempting to update software on older hardware would most likely result in failure or destabilization of the entire system. Organizations are thus forced to keep critical but extremely vulnerable systems alive.
How has IT/OT convergence shattered the myth of physical isolation of industrial networks?
For many years, the cornerstone of security in the OT world was the concept of the “air gap,” or the complete physical isolation of the industrial network from the corporate IT network and the Internet. There was a belief that if a network was not connected to anything, it was 100 percent secure. This may once have been true, but today it is just a dangerous myth.
A process called IT/OT convergence, driven by the need for real-time production data analysis, remote monitoring and optimization, has led to a massive merging of the two worlds. Data from sensors on the production line is sent to analytics systems in the cloud. Remote service technicians connect to machines via the Internet to diagnose problems. Production planning systems (ERP) on the IT network must communicate with manufacturing execution systems (MES) on the OT network.
These connections, often established ad hoc and without adequate security, have broken down the wall of isolation. OT networks became reachable from corporate networks, and by extension, from the Internet. This has opened up entirely new attack vectors. Malware that infects a computer in the accounting department can now potentially spread to production control systems, something that was unthinkable in the “air gap” era.
Where do the cultural differences between IT engineers and OT engineers come from?
Differences in technology and priority over the years have shaped two distinct, almost tribal organizational cultures. IT engineers come from the world of IT, where innovation, speed of change implementation and flexibility are valued. They are used to constant learning, dynamic projects and regular updates. Their work is largely virtual, and the risks they manage involve data.
OT engineers are usually specialists with a background in automation, mechanics or chemistry. Their world is a world of physics, where stability, predictability and reliability reign supreme. They value solutions that are proven and have worked for years. For them, any change is a potential threat to safety and process continuity. Their work is tangible, and the risks they manage are about real, physical consequences.
These cultural differences lead to communication problems. The IT team, when talking about “vulnerability management,” thinks in terms of scanning and patching. The OT team, hearing the same words, thinks in terms of “risk of production stoppage.” The lack of a common language and mutual understanding of each other’s priorities is one of the biggest barriers to building an effective enterprise-wide cyber security program.
How to build a bridge between IT and OT to effectively protect industrial infrastructure?
Effective protection of the modern industrial enterprise is not possible if IT and OT remain in their silos. The key to success is to build a “bridge” based on mutual understanding, cooperation and common goals. This is first and foremost a task for management, which must create the right organizational framework and promote a culture of cooperation.
The first step is to create a joint governance structure, such as a cross-functional cyber security steering committee with representatives from both worlds and business. Such a committee must develop a common security policy and a common risk management strategy that reconciles IT and OT priorities. It is also necessary to appoint a single person, such as a CISO, who will have overall responsibility for security in both domains.
”Soft” activities are also essential. Organizing joint training and workshops where teams can learn about each other’s work environments and challenges is invaluable. Temporary staff exchanges are also a good practice - sending an IT specialist to the shop floor for a few weeks and inviting an OT engineer to work on the SOC team. It is only through education, open communication and building personal relationships that existing barriers can be broken down and a single, unified team can be formed with the common goal of protecting the entire organization.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- Security Architecture — Security architecture is a comprehensive approach to designing, implementing,…
Learn More
Explore related articles in our knowledge base:
- Cyber security in public administration: How to protect citizens’ data and digital services?
- Cyber security in the health sector: How to protect patient data and critical infrastructure of hospitals?
- How to implement NIS2 and not go crazy? Use regulation as leverage to get a budget for OT security
- Blockchain in cyber security: Applications and benefits for companies
- Bug bounty programs: How can you leverage the global hacker community to strengthen your security?
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
