Perspective
OT Is Not IT
Why the plant floor breaks every assumption the enterprise security playbook is built on.
Every enterprise security framework I have worked with assumes a few things that are simply not true on a plant floor.
It assumes you can patch. It assumes you can reboot. It assumes an asset inventory is achievable, that endpoints run a supported operating system, and that when you find something vulnerable you can take it offline while you fix it.
Now walk onto a manufacturing floor. There is equipment out there running control software that has not been updated since it was commissioned, because the vendor certified the machine as a unit and any change voids that certification. There are systems that cannot be rebooted without a controlled restart of the line. There is a controller nobody has logged into in nine years, doing its job perfectly, that would fail every scan you point at it.
None of that is negligence. It is what happens when capital equipment with a twenty-five year life meets an IT threat model with an eighteen month refresh cycle.
You cannot patch a machine that makes the product.
I audited the IT and OT boundary directly at a national food manufacturer, and the first real lesson was that the IT playbook does not port. Applied literally, it produces one of two outcomes. Either you break production, which ends your credibility permanently, or operations quietly routes around you, which is worse, because you now have an unmanaged environment and a false sense of coverage.
What does work starts from a different question. Not how do we bring these assets up to standard, but what would an attacker have to reach, and what stands between them and it.
That reframes the work toward segmentation, monitoring, and access rather than patching. You may not be able to update a controller, but you can control what is permitted to talk to it. You may not be able to run an agent on an HMI, but you can watch the traffic around it and know what normal looks like. You cannot make the equipment modern, but you can make it unreachable from the places attacks actually come from.
The industry has come around to this. In February 2025 Gartner published its first Magic Quadrant for Cyber-Physical Systems Protection Platforms, evaluating seventeen vendors in a category that had not previously existed as its own market. It has since run a second time. The creation of that category is itself the argument: the enterprise security market did not have a shelf these products fit on, because the assumptions underneath enterprise security do not hold on a plant floor. Gartner expects that by 2027, seventy-five percent of CPS-intensive organizations will obtain cybersecurity capabilities from a cyber-physical systems protection platform, accelerating the shift away from point solutions.
The other half is organizational, and it is the harder half. OT belongs to engineering and operations. IT belongs to IT. The boundary between them is exactly where the risk lives, and it is usually the one place nobody owns.
I have watched that gap produce the same conversation in more than one company. Security raises a finding on the plant network. Operations says the machine cannot be touched. Security says the risk is unacceptable. Operations says the downtime is unacceptable. Both are right, and because there is no shared owner, the finding gets logged and nothing changes. The register grows. The risk does not.
And when the answer is that the remediation will not be funded, the discipline is to make the acceptance explicit: written down, dated, and owned by the person who made it. An unfunded risk that nobody signed for is not a decision. It is a gap waiting to be found by someone else.
Which is the manufacturing version of an argument I have made elsewhere: the breach rarely happens in the gap between the threat and the control. It happens in the gap between the risk that was written down and the remediation that was funded. On a plant floor that gap has a second dimension, because the remediation is not only unfunded, it is unassigned.
The fix is not a technology decision. It is deciding, out loud, who owns the plant network, who is permitted to accept risk on it, and what happens when IT and operations disagree. Once that is named, the technical work is ordinary. Until it is named, no amount of tooling helps.
So when I say design it right, secure it, and sign your name to it, the OT side is where the third clause does the most work and gets the least attention. The signature is the whole problem, because at most manufacturers nobody has ever been asked to provide one.
Gartner, Magic Quadrant for CPS Protection Platforms, Katell Thielemann, Wam Voster, Ruggero Contu, 12 February 2025, ID G00808225. Gartner does not endorse any vendor, product or service depicted in its research publications. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact.
— Keith Formell
© 2026 Keith Formell · New Lenox, Illinois