惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Tenable Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threatpost
L
LINUX DO - 热门话题
C
Cyber Attacks, Cyber Crime and Cyber Security
W
WeLiveSecurity
P
Privacy & Cybersecurity Law Blog
H
Hacker News: Front Page
C
Cisco Blogs
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Martin Fowler
Martin Fowler
Help Net Security
Help Net Security
Scott Helme
Scott Helme
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Cyberwarzone
Cyberwarzone
Microsoft Security Blog
Microsoft Security Blog
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
Cloudbric
Cloudbric
Simon Willison's Weblog
Simon Willison's Weblog
A
Arctic Wolf
云风的 BLOG
云风的 BLOG
V
Vulnerabilities – Threatpost
Stack Overflow Blog
Stack Overflow Blog
T
Tor Project blog
O
OpenAI News
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
The Exploit Database - CXSecurity.com
MyScale Blog
MyScale Blog
罗磊的独立博客
美团技术团队
博客园 - 聂微东
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Apple Machine Learning Research
Apple Machine Learning Research
PCI Perspectives
PCI Perspectives
P
Privacy International News Feed
C
Cybersecurity and Infrastructure Security Agency CISA
Recorded Future
Recorded Future
Application and Cybersecurity Blog
Application and Cybersecurity Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - Franky
Security Archives - TechRepublic
Security Archives - TechRepublic
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Blog — PlanetScale
Blog — PlanetScale

Truesec

Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Russia Rolls Out Surveillance Through State-Backed “Super App” MAX Device Code Phishing via Fake File-Sharing Invitation Active Exploitation of PAN‑OS Authentication Portal RCE - Truesec Windows Client Security Baselines: When Assumptions Meet Incident Response Reality - Truesec Entra ID Password Protection: From “P@ssw0rd” to Protected GitHub Under Attack: How Small Exposures Snowball into Large‑Scale Compromises European Risks Linked to the U.S. – Iran Conflict Mythos: What It Actually Means and What It Does Not Russian Espionage Campaign Targets Home Routers How Nordic Organizations Must Adjust Their Cybersecurity to a Changing Operating Environment Critical Vulnerability in “Ninja Forms – File Upload” WordPress Plugin (CVE-2026-07409) Iranian APT Target US Critical Infrastructure Remote Access – Is VPN the Almighty Solution? Malicious Axios Packages Published to npm in New Supply Chain Compromise RCE Vulnerability in F5 BIG-IP APM (CVE-2025-53521) No Further Increase in Iranian Cyber Operations Malicious PyPI Package – LiteLLM Supply Chain Compromise Dutch Intelligence Warns of Russian Campaign Against Signal and Whatsapp Users Multiple Vulnerabilities, One Critical, in Ubiquiti UniFi Network Application
Securing IT, OT, and IoT When the Digital Meets the Physical
Hjalmar Desmond · 2026-05-19 · via Truesec

Many environments didn’t start with IT, OT, and IoT as distinct domains.

They started much simpler.

As I often put it:

“It all started with two guys and a welding machine.”

In the beginning, there was no IT department, no architecture, and no security model. There were just machines doing a job — computers running locally, controlling equipment, completely isolated because they had to be.

Then came networks, then came the internet, hen manufacturing, facilities, and operations were digitized step by step.

Over time, systems were connected for convenience, visibility, and remote access. What had once been isolated environments slowly turned into one large, flat network, where office IT, production systems, building automation, sensors, and embedded devices all lived side by side.

It worked — until it didn’t.

The Dangerous State Many Organizations Are in Today

This historical evolution explains why many organizations now find themselves in a risky position:

  • Legacy OT systems connected directly to corporate networks 
  • IoT devices sharing infrastructure with critical systems 
  • Minimal segmentation and unclear trust boundaries 
  • Little separation between users, systems, and operations 

This was rarely the result of bad decisions. It was the result of incremental change without an overarching architecture.

Now, security teams are asked to “secure IT/OT/IoT”, but what they are really facing is the task of re‑architecting something that grew organically for decades.

Why the Journey Feels Overwhelming

Moving from a flat, historically grown environment to a structured IT/OT/IoT architecture can feel overwhelming — especially when:

  • Production cannot be stopped 
  • Legacy systems cannot be replaced 
  • Documentation is incomplete or outdated 
  • Ownership is spread across multiple teams and vendors 

This is not about flipping a switch or deploying a product. It’s about introducing structure, segmentation, and trust boundaries into an environment that was never designed for it. 

That is why architecture, pragmatism, and an understanding of operational reality are so critical when securing these environments. 

A Changed Threat Landscape 

Traditional IT security models were built around systems where confidentiality was the primary concern. In OT and IoT environments, availability and safety are often even more critical. Downtime can stop production, disrupt logistics, or in some cases, put people at risk.

At the same time, many OT and IoT systems were never designed to be exposed:

  • Legacy devices with long lifecycles remain in use
  • Proprietary or outdated protocols lack basic security controls
  • Patching and scanning are often limited or impossible
  • Ownership is spread across IT, operations, facilities, and external vendors

Attackers are well aware of this. OT and IoT environments are increasingly targeted — not only to disrupt operations, but also as entry points into broader enterprise networks.

Why “Just Apply IT Security” Doesn’t Work

A common mistake is assuming that IT security controls can simply be copied into OT and IoT environments. In reality, this often leads to operational issues, blocked processes, or a false sense of security.

Securing these environments requires a different mindset:

  • Architecture before tools — design trust boundaries and communication paths first
  • Segmentation by design, not flat networks with exceptions
  • Controlled access for both users and systems
  • Visibility and monitoring that does not interfere with operations
  • Compensating controls where modern security features are not available

Most importantly, security must be adapted to how the environment actually works — not how we wish it worked.

From Frameworks to Real-World Design

Standards and frameworks provide valuable guidance, but they do not automatically translate into working solutions. Every environment has constraints: legacy systems, business requirements, vendor dependencies, and operational realities.

In practice, successful IT/OT/IoT security is about:

  • Reducing risk step by step
  • Accepting that not everything can be fixed immediately
  • Designing security that can evolve over time
  • Ensuring close collaboration between IT, security, and operations

This pragmatic approach is often the difference between a secure design that works — and one that looks good on paper but fails in production.

Learn More — Online and in Person

These topics are explored in depth in a longer, hands-on article that walks through real-world architecture patterns, common pitfalls, and practical design principles for securing converged environments.

For the full deep dive, read: Building a Secure IT/OT/IoT Infrastructure in the Real World (Deploymentbunny.com)

If you prefer an interactive format, these challenges and solutions will also be discussed during an upcoming conference session focused on IT/OT security in practice, where real-world experiences and lessons learned will be shared:

Event information: OT Security Day (Scanautomatic.se)

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights