As IT and operational technology converge, CISOs must extend their security strategies to the factory floor, where diverse systems, vendors and risks collide.

OT cybersecurity insights
- CISOs must now extend their cybersecurity responsibilities beyond IT systems to include manufacturing and OT environments.
- Building strong partnerships with system integrators, OEMs and plant teams is essential to understanding and securing complex industrial networks.
- Integrating cybersecurity into capital projects and piloting security efforts at select plants helps organizations manage costs and uncover hidden risks.
Chief information security officers (CISOs) are facing a tough new job. They’re being asked to secure not just information technology (IT) systems but also manufacturing equipment and industrial controls. This shift is happening fast, and many organizations aren’t ready for it.
The problem: it’s a whole new world
Manufacturing plants are complex. A single facility might work with dozens of different system integrators and equipment vendors. These companies install everything from industrial control systems applications, infrastructure, wireless, remote access and networks, to engineering workstations, HMIs, historians, etc. But here’s the catch: Most of them have little to no cybersecurity expertise.
Unlike IT departments, which have standardized around vendors like Microsoft, Dell, Fortinet, Palo Alto and Cisco, manufacturing environments are a mixed bag of technology and providers.
You’ll find hundreds of different devices from suppliers all over the world. Some equipment gets moved from plant to plant. Other times, teams may buy parts on eBay or from less known manufacturer, just to keep costs down or quickly solve a problem.
This creates a challenge for CISOs, who are used to having clear vendor relationships and security standards.
Know your players
The first step is identifying your top 10 system integrators and original equipment manufacturers (OEMs). These are the companies operating in your plants on a daily basis. CISOs need to build relationships with them, just like they do with their IT vendors.
But this requires teamwork. You’ll need to work closely with plant managers, operations, facilities/maintenance, production and engineering teams to understand who these integrators are, what technology they’re installing and how they operate and assist the plant with operations.
Many system integrators don’t have cybersecurity practices. The ones that do often partner with security companies like Claroty, Dragos, TXOne Networks or Cisco, for example. You need to find integrators who can demonstrate real cybersecurity experience and references versus taking the position of disinterested parties.
The budget challenge
Here’s where it gets tricky. Manufacturing teams often say they don’t have the budget for cybersecurity. But there’s a smart way around this: Build security into capital projects.
When you’re buying a $10 million piece of equipment, cybersecurity technologies and solutions can be included in that purchase. This is often easier than trying to get separate cybersecurity funding.
You’ll also need to pilot your approach. Start with one or two plants to understand what you’re dealing with. Most organizations severely underestimate how many assets they have. We regularly see companies miss their asset counts by 30% to 70%.
The technology decision
Don’t buy cybersecurity tools based on a single demo. Bring two or three options into your plant and run side-by-side comparisons. Get your operational technology (OT) teams involved in the decision. They know the manufacturing production and operational environment best.
Remember that licensing is usually based on the number of OT assets you have, not IT assets. Plant size matters, too. A large plant might have more than 5,000 assets, while smaller ones might have fewer than 1,000.
Remote access: a security nightmare
Most manufacturing sites have four to seven different remote access methods. Equipment vendors often install their own VPN connections as part of their work. This creates serious security vulnerabilities.
A basic VPN connection doesn’t tell you what vendors are doing once they’re inside your network. They could be accessing other systems, installing software or even stealing intellectual property.
You need remote access tools that provide visibility and control. Look for solutions that can record sessions, limit access to specific devices and prevent unauthorized file transfers.
Dealing with vendor pushback
Equipment manufacturers will sometimes threaten to void warranties if you install security tools within the machine centers. The key is starting these conversations early, before equipment is installed.
You need to show vendors that your security measures won’t disrupt their operations. Most modern security tools are passive and won’t interfere with equipment performance. It’s about changing the method they use to access systems, not blocking their access entirely.
Emergency response planning
Your incident response plan needs to include OT operators. They’re your first responders because they know how to safely shut down equipment without causing loss, damage or injuries.
But operators won’t shut down machines just because an IT person calls them. The shutdown order needs to come from plant management. Make sure your incident response plan reflects these realities.
The bottom line
CISOs taking on OT security responsibilities need to make new friends. You’ll have to build relationships with the system integrators and equipment vendors that your company spends millions of dollars with each year.
This isn’t a job you can do alone, especially if you’re starting from scratch. Partner with organizations that have industrial cybersecurity experience. They can help you navigate the unique challenges of manufacturing environments.
The key is to start now. Waiting a decade to secure your manufacturing operations isn’t an option. The bad actors are only getting more sophisticated.
Aligning yourself with an experienced system integrator who understands manufacturing plant and critical infrastructure equipment and environments, as well as industrial cybersecurity best practices, is a smart first step.
AUTHOR
Dino Busalachi, Director BW Design Group, has close to four decades of global experience across IT, engineering and industrial control system (ICS) with multiple global brands. His knowledge and understanding of ICS, OT, IIoT and technology solutions allows him to provide expert insight and solutions for digital safety and cybersecurity in the industrial space.
LEARNING OBJECTIVES
- Understand how the CISO role is expanding to include securing operational technology (OT) and manufacturing systems.
- Learn strategies for collaborating with system integrators, OEMs and plant teams to strengthen industrial cybersecurity.
- Identify practical ways to fund, pilot and implement cybersecurity measures within manufacturing operations and capital projects.
CONSIDER THIS
Is your organization truly prepared to secure its operational technology and manufacturing systems against today’s evolving cyber threats?