5 Actions to Take Now: Why OT Cybersecurity Should Be Every Organization’s Concern

Cybersecurity
May 14, 2025
Offshore oil rig platform lit up at sunset on calm ocean waters with a colorful sky.
Black and white portrait of a young man with short hair wearing a dark shirt against a dark background.

Operational technology (OT) is the hardware and software that monitors and controls physical processes — the programmable logic controllers (PLCs), SCADA systems, and human-machine interfaces (HMIs) behind power generation, water treatment, manufacturing lines, and railway signaling. Where IT manages data, OT acts on the physical world, which is exactly what makes its compromise so consequential.

In the last few years, operational technology (OT) has rapidly moved from the shadows to the front line of cyber risk. As industrial systems become increasingly connected, the line between IT and OT continues to blur, making OT environments prime targets for threat actors.

But here’s the twist: Most attacks that impact OT aren’t even OT-specific.

According to recent threat intelligence, 85% of attacks affecting OT environments originate as IT-focused attacks. And just 13% of attacks use OT-specific tactics, techniques, and procedures (TTPs)*. That means attackers often get in through known IT paths and then pivot toward industrial systems once inside, or the OT environment is affected by a loss of IT systems it relies upon.

This creates a massive exposure gap for organizations that haven’t extended their cyber strategy beyond traditional IT boundaries. So what are the main threats, what do they mean for your business, and most importantly, what can you do about it?

What Threats Face OT Systems Today?

Criminal Groups, Not Just Nation-States

There’s a perception that OT threats are mostly geopolitical or state-sponsored. While those threats are real, the data tells another story: 81% of attacks affecting OT are carried out by criminal groups, with 6% linked to nation states*. These actors are financially motivated, opportunistic, and increasingly well-resourced.

Ransomware Is Surging

Dragos tracked an 87% year-on-year increase in ransomware attacks targeting industrial organizations**, with 80 distinct ransomware groups active in 2024 – up from 50 in 2023**. Manufacturing remains the most targeted sector, bearing 58% of attacks, followed by Transport & Warehousing (17%) and Utilities (7%).*

These aren't just abstract threats. In 2021, Colonial Pipeline, which carries 45% of the East Coast's fuel supplies, was forced to shut down its entire 5,500-mile pipeline system after ransomware attacked its IT billing systems. Despite the OT systems themselves remaining uncompromised, the company had to halt operations for nearly a week, causing fuel shortages across multiple states and economic impacts in the billions. This high-profile case demonstrates how threat actors targeting conventional IT systems can force operational shutdowns even without directly breaching industrial controls.

Vulnerabilities Run Deep, and They’re Dangerous

OT vulnerabilities are not just common; they’re risky.

  • 70% of OT vulnerabilities reside deep within the network, making detection and mitigation more complex.**
  • 39% could lead to both a loss of view and loss of control – a worst-case scenario for any industrial operation.**
  • And 22% of CVSS advisories relate to perimeter-facing and network-exploitable systems – prime entry points for attackers.**

These statistics aren't merely theoretical concerns. The real-world impact of exploited OT vulnerabilities has been demonstrated repeatedly. In December 2015, attackers took down part of Ukraine’s power grid using the BlackEnergy malware, cutting electricity to roughly 230,000 people in the middle of winter. Crucially, they gained their initial foothold through spear-phishing emails on the IT network before pivoting into the OT systems that controlled substations — a textbook example of how the IT/OT security gap is exploited with serious real-world consequences.

The Cost of Inaction

  • Operational downtime: In sectors like manufacturing, shutdowns can result in millions in losses, not to mention supply chain ripple effects.
  • Health and safety: Industrial systems control real-world processes. Compromised systems can lead to dangerous or even life-threatening outcomes.
  • Regulatory pressure: Frameworks like NIS2, IEC 62443, and NIST SP 800-82 are raising the bar on compliance and accountability.
  • Loss of trust: From shareholders and partners to the public, one breach can severely damage long-term credibility.

5 Things You Can Do Now to Protect Your OT Environment

1. Prioritize Ot-Focused Cybersecurity Exercising

Let’s start with people. From phishing attacks to poor incident response, your teams’ cyber readiness can affect operations’ safety. Yet, most organizations don’t offer OT-specific exercising to help their employees prove and improve their understanding of the OT environment and risks. Immersive’s operational technology solution combines hands-on OT labs with team exercises so IT and OT staff build the same skills in a safe environment.

Upskilling helps bridge the gap between IT and OT teams, ensuring everyone understands the risks and how to respond. This is especially important with the convergence of both the environment and the impact IT now has on OT.

2. Conduct Asset Discovery and Risk Assessments

You can’t protect what you don’t know exists. Most OT networks have hidden assets or legacy systems that pose serious risks. A proper asset inventory and risk mapping exercise is a foundational step toward reducing exposure.

3. Implement Network Segmentation and Strong Access Controls

Flat, open networks make it far too easy for attackers to move laterally. Segmentation between IT and OT, combined with strict identity and access controls, drastically reduces blast radius.

4. Develop and Test OT Incident Response Plans

Most incident response plans are still IT-centric. OT requires a different playbook that considers the impact of physical processes, safety, and time-sensitive coordination. Simulate OT-specific incidents as part of your preparedness strategy — for example, through a cyber range exercise for technical teams and a leadership-focused crisis simulation.

5. Break Down Silos Between It and OT Teams

Security is a team sport. When IT and OT work together, you get faster detection, better response, and fewer blind spots. Create shared governance, joint threat exercises, or security champions across both domains.

OT Security Needs to Be Everyone’s Business

Attackers don’t care whether they’re entering through IT or OT. They’ll take the easiest path, often left open by poor collaboration, unclear responsibilities, or lack of awareness.

Your OT security journey doesn’t start with a patch. It starts with people.

“We can make our technology as secure as possible, but there will always be a risk of human error. We need to focus on building human resilience if we want a real culture of cybersecurity in operational technology — just as we have in IT.”

— Sam Maesschalck, Lead OT Cybersecurity Engineer, Immersive

That’s why cybersecurity can’t sit in silos. It’s not just a technical problem — it’s a people problem, a process problem, and a cultural one. Bridging the gap between IT and OT teams isn’t optional anymore; it’s foundational to any serious security strategy.

The good news? There are clear, practical steps every organization can take. Start by prioritizing exercises that bring OT into the cyber conversation. Build visibility into your assets. Segment networks to limit blast radius. Develop OT-specific incident response plans. Most importantly, the barriers between the IT and OT teams should be broken down so they can work together, not in parallel.

Immersive helps organizations prove and improve their cyber capabilities across IT and OT. Explore the Immersive operational technology solution, or see how Immersive One brings labs, cyber drills, and crisis simulations together to make your workforce ready.

Sources:

*Orange Cyberdefense 2025 Security Navigator

**Dragos 2025 OT Cybersecurity Report

***Fortinet 2025 State of Operational Technology and Cybersecurity Report

Frequently Asked Questions

What Is OT Cybersecurity?

OT cybersecurity is the practice of protecting operational technology — the hardware and software that monitors and controls physical processes, such as PLCs, SCADA systems, and HMIs in power, water, manufacturing, and transport. Unlike IT security, which protects data, OT security protects systems that act on the physical world, where a compromise can disrupt operations or threaten safety.

Why Is OT Cybersecurity Important?

Much of modern society — energy, water treatment, manufacturing, and transport — runs on operational technology, much of it built decades ago without security in mind. As these systems connect to IT networks, attacks can halt operations and create real-world consequences. In manufacturing, downtime can cost on the order of $50,000 per minute, according to Immersive’s Lead OT Cybersecurity Engineer, Sam Maesschalck.

What Percentage of OT Attacks Originate From It?

According to the Orange Cyberdefense 2025 Security Navigator, 85% of attacks affecting OT environments originate as IT-focused attacks, and only 13% use OT-specific tactics, techniques, and procedures. Attackers typically gain access through known IT paths, then pivot toward industrial systems.

What Are the Biggest Threats to OT Systems Today?

The leading OT threats are financially motivated criminal groups (81% of attacks affecting OT, versus 6% from nation states), surging ransomware (Dragos tracked an 87% year-on-year rise against industrial organizations, with manufacturing the most targeted sector at 58%), and deep, dangerous vulnerabilities — 70% reside deep within the network and 39% could cause both loss of view and loss of control.

Which Regulations Apply to OT Security?

Key frameworks raising the bar for OT and industrial cybersecurity include the EU NIS2 Directive, DORA for financial entities, the IEC 62443 series of standards for industrial automation and control systems, and NIST SP 800-82 guidance for OT security.

How Can Organizations Protect Their OT Environments?

Five practical actions: (1) prioritize OT-focused upskilling for both IT and OT teams; (2) conduct asset discovery and risk assessments; (3) implement network segmentation and strong access controls between IT and OT; (4) develop and test OT-specific incident response plans through simulations and drills; and (5) break down silos between IT and OT teams with shared governance and joint exercises.

Published:
May 14, 2025
Cybersecurity Training
Operational Technology

See how to prove readiness with one platform.

See how Immersive One helps technical teams and leaders prove readiness, close capability gaps, benchmark progress, and report cyber resilience with confidence.