• 09/29/2026
  • Interview

IT/OT Convergence: “Organisational Measures are Just as Important as Technical Ones”

The convergence of IT and industrial OT into the Industrial Internet of Things (IIoT) brings new challenges and responsibilities for ensuring cybersecurity. What are the implications of this convergence for industrial companies, and what technical and organisational safeguards are available? Six experts from six companies share their perspectives.

Written by Andreas Knoll

Portrait photos of six security experts in an image collage.
Six experts from Forescout, Fortinet, Infinigate, Paessler, Palo Alto Networks, and TXOne Networks share their views in this article.

it-sa 365: What exactly does the convergence of IT and OT mean, and what technical developments are driving this trend?

A more in-depth look at current threats and safeguards in this area is available on the topic page OT Security.

What fundamental differences between classic IT security and OT security make it difficult to bring the two worlds together?

What specific real-world examples illustrate how connecting production facilities with IT systems (e.g., through IIoT, cloud connection, or remote maintenance) affects a company's attack surface?

How remote access can be secured in converged IT/OT environments is shown by the session Cybersecurity for OT – Secure Remote Access in the Era of IT/OT Convergence at it-sa Expo & Congress 2025.

Which new threat scenarios arise specifically from the fact that attackers can access formerly isolated OT networks via IT?

How organisations can protect their endpoints against the growing ransomware-as-a-service threat is examined in the article Endpoint Security in the Age of RaaS. How attacks on the software supply chain can be detected and defended against is explained in the article From SBOM to PBOM: Defending Against Supply Chain Attacks.

To what extent does this convergence also change the collaboration between the IT department and production or automation engineering within a company?

Which technical measures – such as network segmentation, firewalls between IT and OT zones, or zero-trust approaches – have proven successful in practice for securing OT environments?

Which ten basic rules have proven effective when building a zero-trust architecture is shown in the article Zero Trust in Practice: The 10 Basic Rules for Protection That Promotes Resilience. How cybersecurity can already be factored into the procurement of OT products is shown by CISA Advises: 12 Recommendations for Selecting Secure OT Products.

How can effective attack detection (monitoring, anomaly detection, SIEM/SOC) be implemented in OT networks without endangering ongoing production operations?

What organisational measures – such as clear responsibilities, emergency plans, or regular risk analyses – are necessary to coordinate IT and OT security company-wide?

The concrete obligations and risks the directive creates for companies are explained in the article NIS2 Implementation: Obligations and Risks for Businesses.

What role do employee training and raising the awareness of production staff play for cyber risks which are traditionally associated more with the IT world?

How such an awareness campaign can succeed in practice is shown in the article How Does an Awareness Initiative Succeed in Cyclically Making Employees Aware of Cyber Risks?

Which standards or frameworks (e.g., IEC 62443, ISO 27001, NIS-2) do you recommend as a guide for industrial companies to structurally establish and verify their IT/OT security?

How IEC 62443 uses zones, conduits, and security levels to deliver precisely fitted protection in production is explored in the articleIEC 62443: Why Production Facilities Need Different Security Rules Than Office Networks.

How proactive rather than reactive cyber resilience can be built in practice is shown by the session The Cyber Resilience of Tomorrow: Proactive Instead of Reactive at it-sa Expo & Congress 2025. Watch the recording now!

Want to talk directly with OT security leaders and IEC 62443 experts? At it-sa EXPO & Congress you can expect live talks, hands-on use cases, and direct exchange with exhibitors on industrial cybersecurity. Visit now!

The questions were asked by Andreas Knoll.