惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
雷峰网
雷峰网
博客园_首页
小众软件
小众软件
美团技术团队
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
MyScale Blog
MyScale Blog
U
Unit 42
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Security Blog
Microsoft Security Blog
大猫的无限游戏
大猫的无限游戏
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 叶小钗

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
What’s the difference between IT and OT security?
silicon · 2026-05-06 · via Enterprise – Silicon Republic

Integrity360’s Matthew Olney explains the ins and outs of IT and OT security, and the importance of having both secured.

From manufacturing lines and water utilities to transport hubs and energy plants, operational technology (OT) is a prime target for cybercriminals and nation-state actors.

As the lines between information technology (IT) and OT blur, understanding the difference between them and securing both effectively has never been more critical.

IT v OT security

IT security is the practice of protecting an organisation’s IT assets, including computers, networks, and data, from unauthorised access, attacks and other malicious activity. It involves using a combination of technologies, processes and physical controls to ensure the confidentiality, integrity and availability of information. A key objective is to prevent threats like data breaches, malware and phishing.

OT security, on the other hand, protects the physical systems that keep operations running – machinery, control systems and critical infrastructure. Here, priorities shift: availability and safety come first, because downtime doesn’t just cost money; it can halt production or endanger lives.

Many industrial organisations still treat IT and OT as distinct domains – one governed by corporate IT teams, the other by engineering departments.

Historically, this separation made sense when OT systems operated in isolation. But that’s no longer the case.

Today, nearly 40pc of OT assets are connected to the internet without adequate security, and by 2025, 70pc of OT systems are expected to be integrated with IT networks.

With 72pc of industrial cybersecurity incidents originating in the IT environment before infiltrating OT systems, a unified, cross-functional approach to securing both realms is growing in importance.

Attackers exploit weak segmentation, unsecured remote access, and legacy systems that were never designed with cybersecurity in mind. Once inside, they can halt production, damage equipment, or even threaten human life or cause environmental damage.

The unique challenges of OT environments:

Legacy technology

Many systems run on outdated or unsupported software, sometimes decades old, that can’t easily be patched without interrupting operations.

Proprietary protocols

OT devices use vendor-specific communication methods not recognised by standard IT tools.

Availability over confidentiality

Shutting down a process for security reasons may be more damaging than the attack itself.

Human and safety impact

A compromised industrial controller could affect worker safety or public services.

Limited visibility

Without asset inventories or monitoring, intrusions can go unnoticed for months.

Common weaknesses found in OT networks

Integrity360’s experts regularly uncover recurring issues across industrial environments, including:

  • Poor network segmentation, allowing attackers to move from IT to OT.
  • Unpatched systems and default configurations left unchanged.
  • Weak or insecure remote access used by vendors and contractors.
  • Lack of asset inventory or real-time monitoring.
  • No endpoint protection against malware propagation.

These weaknesses make OT environments particularly attractive to threat actors seeking maximum disruption.

When operations depend on continuous uptime, a single breach can lead to production loss, safety risks, reputational damage and regulatory penalties.

By Matthew Olney

Olney is a cybersecurity content and communications specialist with extensive experience translating complex security topics into clear, engaging content for technical and executive audiences. As content marketing and social media lead at Integrity360, he works closely with Integrity360 experts to develop thought leadership, technical blogs, webinars and multi-channel campaigns that help organisations understand and respond to emerging cyberthreats.

A version of this article previously appeared on Integrity360’s website.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.