惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
D
Docker
WordPress大学
WordPress大学
罗磊的独立博客
J
Java Code Geeks
博客园 - 【当耐特】
博客园 - 司徒正美
雷峰网
雷峰网
H
Help Net Security
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
T
Tailwind CSS Blog
Google DeepMind News
Google DeepMind News
M
MIT News - Artificial intelligence
Recent Announcements
Recent Announcements
B
Blog

Portfolio – Silicon Republic

Report: 60pc of large companies report mental health issues among IT workers China blocks Meta’s $2bn Manus acquisition Ireland’s solar sector hits 1GW of energy for first time After Amazon, Google commits up to $40bn in Anthropic Cohere buys Aleph Alpha to forge sovereign AI alternative to US Big Tech 4 easy ways to stay on top of cybersecurity in the workplace 15 companies you’ll see at NIBRT Careers in Biopharma 2026 Bloomberg: Bezos’ Project Prometheus bags $10bn at $38bn value Meta to lay off 10pc of its workforce amid an AI push China's DeepSeek unveils long-awaited V4 AI model Intel’s shares soar as Q1 results signal brighter future MongoDB to create 200 new jobs as it invests €74m into Irish operations Why it's full STEAM ahead for young people upskilling in Ireland's west Swedish legal-tech Legora buys AI legal research start-up Qura Belfast’s Cloudsmith eyes ‘massive growth’ with $72m raise France's Univity raises €27m to allow European telecoms to compete with Starlink AI race intensifies with Google's new agent management platform Government launches new AI initiative for greater access to essential skills Free and inexpensive cybersecurity courses to undertake in 2026 UL looking for ‘changemakers’ amid Research Week 2026 OpenAI taps Airbnb exec as first EMEA managing director EAM platform Blue Mountain acquires Cork’s CompuCal Calibration Solutions SpaceX agrees right to buy AI coding darling Cursor for $60bn Anthropic probing reported Mythos leak on Discord Professional job openings across Ireland increased in Q1, finds report Contract hiring evidence of a cautious jobs market, finds report Can you rely on AI chatbots for medical advice? €6.9m awarded to final four National Challenge Fund winners Amazon investing up to $25bn in Anthropic AI infrastructure deal Vodafone Ireland to invest €360m over the next four years
What’s the difference between IT and OT security?
silicon · 2026-05-06 · via Portfolio – Silicon Republic

Integrity360’s Matthew Olney explains the ins and outs of IT and OT security, and the importance of having both secured.

From manufacturing lines and water utilities to transport hubs and energy plants, operational technology (OT) is a prime target for cybercriminals and nation-state actors.

As the lines between information technology (IT) and OT blur, understanding the difference between them and securing both effectively has never been more critical.

IT v OT security

IT security is the practice of protecting an organisation’s IT assets, including computers, networks, and data, from unauthorised access, attacks and other malicious activity. It involves using a combination of technologies, processes and physical controls to ensure the confidentiality, integrity and availability of information. A key objective is to prevent threats like data breaches, malware and phishing.

OT security, on the other hand, protects the physical systems that keep operations running – machinery, control systems and critical infrastructure. Here, priorities shift: availability and safety come first, because downtime doesn’t just cost money; it can halt production or endanger lives.

Many industrial organisations still treat IT and OT as distinct domains – one governed by corporate IT teams, the other by engineering departments.

Historically, this separation made sense when OT systems operated in isolation. But that’s no longer the case.

Today, nearly 40pc of OT assets are connected to the internet without adequate security, and by 2025, 70pc of OT systems are expected to be integrated with IT networks.

With 72pc of industrial cybersecurity incidents originating in the IT environment before infiltrating OT systems, a unified, cross-functional approach to securing both realms is growing in importance.

Attackers exploit weak segmentation, unsecured remote access, and legacy systems that were never designed with cybersecurity in mind. Once inside, they can halt production, damage equipment, or even threaten human life or cause environmental damage.

The unique challenges of OT environments:

Legacy technology

Many systems run on outdated or unsupported software, sometimes decades old, that can’t easily be patched without interrupting operations.

Proprietary protocols

OT devices use vendor-specific communication methods not recognised by standard IT tools.

Availability over confidentiality

Shutting down a process for security reasons may be more damaging than the attack itself.

Human and safety impact

A compromised industrial controller could affect worker safety or public services.

Limited visibility

Without asset inventories or monitoring, intrusions can go unnoticed for months.

Common weaknesses found in OT networks

Integrity360’s experts regularly uncover recurring issues across industrial environments, including:

  • Poor network segmentation, allowing attackers to move from IT to OT.
  • Unpatched systems and default configurations left unchanged.
  • Weak or insecure remote access used by vendors and contractors.
  • Lack of asset inventory or real-time monitoring.
  • No endpoint protection against malware propagation.

These weaknesses make OT environments particularly attractive to threat actors seeking maximum disruption.

When operations depend on continuous uptime, a single breach can lead to production loss, safety risks, reputational damage and regulatory penalties.

By Matthew Olney

Olney is a cybersecurity content and communications specialist with extensive experience translating complex security topics into clear, engaging content for technical and executive audiences. As content marketing and social media lead at Integrity360, he works closely with Integrity360 experts to develop thought leadership, technical blogs, webinars and multi-channel campaigns that help organisations understand and respond to emerging cyberthreats.

A version of this article previously appeared on Integrity360’s website.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.