
This article is sponsored by Fortinet. In this Voices interview, Control Engineering spoke with Aasef Iqbal, Senior Director, Product Management at Fortinet, about how industrial organizations can pursue IT/OT convergence without compromising safety, reliability or uptime. Aasef shared insights on the business drivers behind convergence, the challenges of introducing edge computing, analytics and AI into legacy OT environments, the role and limitations of cybersecurity frameworks, and the practical steps organizations can take to improve asset visibility, network segmentation, secure remote access and risk-based modernization.
Control Engineering: Please tell us about your background and your role at Fortinet.
Aasef Iqbal: I’m the Senior Director, Product Management at Fortinet, where I work with research and development teams to build operational technology (OT) security solutions and help industrial organizations integrate OT security into their broader cybersecurity strategies.
I have spent more than a decade addressing cybersecurity challenges in critical infrastructure sectors, with experience ranging from cybersecurity architecture, risk management, penetration testing, assurance and compliance across the energy, water, communications and critical manufacturing sectors. I hold CISSP and CISM certifications, the ISA/IEC 62443 Cybersecurity Expert designation, and the GICSP and GRID certifications from the SANS Institute.
Why is IT/OT convergence becoming a priority for industrial organizations, and what business outcomes are driving that shift?
Across the critical infrastructure sectors I work with, from energy and water to critical manufacturing, the same conversation is taking place. Plant leaders want to know what is running in their environment, how well each asset is performing and what is about to fail.
IT/OT convergence is being driven by the need for real-time operational visibility, predictive maintenance, remote operations and AI-driven decision-making. Organizations are looking to improve asset utilization, reduce downtime, optimize energy consumption and increase operational efficiency while enabling digital transformation initiatives. The business value comes from turning operational data into actionable insights that improve productivity and resilience.
A decade ago, operational data rarely left the plant floor. Today, executives expect the same visibility into production that they already have into finance or sales. Predictive maintenance shows why. When condition data from critical equipment feeds into an analytics platform, teams can spot developing failures weeks before an unplanned shutdown. Once an organization sees those results, convergence stops being a technology project and becomes a business strategy.
We have also seen customers require the consolidation of their technology and cybersecurity portfolios into an integrated technology infrastructure across IT and OT to achieve a better return on investment and reduce the total cost of ownership.
What challenges do organizations face when introducing technologies like edge computing, analytics and AI into OT environments?
An industrial automation and control system installed 25 years ago was built to run in isolation for decades. Many of these systems still depend on unsupported operating systems and industrial protocols with no built-in authentication or encryption, and they cannot simply be taken offline for an upgrade.
The biggest challenge is integrating modern technologies into environments that were never designed for connectivity. Legacy systems, proprietary protocols, limited maintenance windows and strict safety requirements make deployment complex. Organizations also need reliable asset and network visibility, high-quality operational data and strong cybersecurity controls to ensure these technologies enhance operations without introducing unacceptable operational or cyber risk.
There is a human dimension as well. IT and OT teams measure success differently. IT prioritizes data confidentiality, while OT prioritizes process safety and availability. Deployments stall when these two groups work toward different goals and have different views of the environment. The organizations doing this well form joint IT/OT teams early, agree on shared objectives and give both sides a common picture of assets and risk before any new technology arrives on the plant floor.
How can organizations balance innovation with the need to maintain safety, reliability and uptime in industrial operations?
Start with one principle: the process comes first. Nothing you introduce should be allowed to compromise safety or availability.
Innovation should be introduced incrementally using a risk-based approach rather than through the wholesale replacement of existing systems. New technologies should be validated, deployed in phases and protected with layered security controls while maintaining strict change management. Security should enable operations by minimizing risk without affecting process availability, safety or deterministic performance.
In practice, this means testing new technology in a staging environment, also known as a simulation or replica system, or during a scheduled maintenance window, then expanding the deployment as confidence grows. For legacy assets that you are unable to patch, apply compensating controls such as network segmentation and virtual patching at the network layer.
Standards help here. The zones and conduits model in IEC 62443 gives you a structured way to contain risk while modernizing one part of the environment at a time and introducing security controls gradually from the start e.g., secure-by-design approach. Change management matters as much as the technology itself. Document every modification, brief the operations team and have a rollback plan ready before anyone touches a live process.
What role do cybersecurity frameworks such as IEC 62443, NIST or NERC play in supporting secure convergence, and where do they fall short in practice?
I have worked with these standards, regulations and frameworks throughout my career and hold the ISA/IEC 62443 Cybersecurity Expert certification. I am also an active participant in several standards bodies, so I say this with real respect for what they accomplish.
These frameworks provide a structured foundation for securing industrial and critical infrastructure environments by defining best practices for architecture, risk management, access control and system lifecycle security. However, they are intentionally technology-agnostic and do not prescribe specific implementation methods. Organizations often struggle to translate framework requirements into practical controls, particularly in heterogeneous OT environments with legacy assets and limited visibility.
Take IEC 62443 as an example. The standard defines zones, conduits and security levels, which gives asset owners, integrators and product suppliers a common language for risk. NERC CIP adds regulatory accountability for the North American power sector. The NIST Cybersecurity Framework helps leadership organize and communicate the overall program.
Where organizations get stuck is the gap between the document and the plant floor. A framework tells you to segment your network. It does not tell you how to segment a running production line with equipment from five vendors and a maintenance window of only a few hours a year.
Compliance is also a point-in-time snapshot, while risk changes daily. Treat frameworks as the foundation of a continuous program, not the finish line. Likewise, security is a continuous practice, not a compliance checkbox. Security must not be reduced to a mere compliance exercise.
What practical steps should OT and engineering leaders take to modernize their environments while managing risk, particularly when it comes to segmentation, visibility and control?
You cannot protect what you have never seen, so begin with a complete asset inventory. Passive discovery allows you to build one without touching the process.
The first priority should be gaining complete visibility into OT assets, communications and vulnerabilities. From there, organizations should implement risk-based network segmentation aligned with industrial zones and conduits, enforce least-privilege access with secure remote connectivity and continuously monitor network activity for anomalies. Modernization is most successful when security is embedded into every stage of the digital transformation journey rather than added as an afterthought.
Secure remote access deserves special attention. Contractors and vendors often reach control systems through shared credentials and unmanaged VPN connections, and this remains one of the most common paths into an OT environment. Replace those connections with brokered, least-privilege access, session recording and time-bound approvals.
Then measure progress. Map your controls to the security levels defined in IEC 62443, set a target for each zone and review the gap on a regular cadence. Each step builds on the last, and each one delivers value on its own. Leaders sometimes ask where to start when resources are tight. Pick the zone with the highest consequence of failure, secure those assets first and use the win to build support for the next phase.
Secure your IT/OT convergence without compromising uptime — see how Fortinet’s ruggedized products can help at fortinet.com/products/rugged.