Cybersecurity has become an operational discipline
A cyber incident does not become operational when malware reaches a programmable logic controller. It becomes operational when production stops, quality deteriorates, safety is compromised or customer commitments cannot be met. By that measure, cybersecurity ceased to be solely an IT concern years ago, even if many manufacturers still organize it that way.
Factories now connect production equipment, enterprise applications, remote vendors and cloud services across environments that were once isolated. Yet responsibility remains divided between IT, engineering, operations and security teams. Dave Kang, Associate Principal Advisory Solutions Architect at industrial cybersecurity specialist Dragos, argues that this organizational gap has become a major source of operational exposure.
“Cybersecurity became an operational responsibility the moment a cyber event could stop production,” Kang says. “If a system can influence a physical process, it is an operational system, regardless of the operating system it runs on. An engineering workstation, HMI, historian or hypervisor may all run on Windows, but when one is compromised and logged only as an IT event, the operational exposure remains and the true cost stays hidden.”
Availability changes the security model
Manufacturers have legitimate reasons to distrust security controls designed for enterprise IT. An office laptop can often be scanned, patched and restarted with limited disruption, while a production asset may support a continuous process or validated environment. Intervening at the wrong moment can create safety, quality and financial consequences.
The conflict is not necessarily between security and uptime. It is between operational requirements and methods developed for a different environment. OT security must therefore begin with availability, using controls that reduce risk without introducing unnecessary disruption.
“The reason IT security tools can cause outages in plants is that they assume you can scan aggressively, patch on demand and reboot at will,” Kang explains. “OT-appropriate approaches start from the opposite premise. Passive network monitoring watches traffic without touching the process, so you gain visibility with essentially zero operational risk.”
Patching illustrates the difference. Manufacturers often receive long lists of vulnerabilities that appear urgent under generic severity scores, but only a small proportion may create an immediate operational risk. Treating every vulnerability as equally important can consume scarce downtime without materially improving resilience.
“Last year, only around two percent of OT-relevant vulnerabilities genuinely required immediate action, and about a quarter of published advisories had incorrect severity scores,” Kang says. “A plant that tries to patch everything is taking downtime for changes that may reduce no meaningful risk. Fix the few things that matter, mitigate or monitor the rest and schedule the work around production.”
Legacy equipment requires the same realism. Aging controllers and unsupported operating systems are normal in manufacturing, where assets can remain productive for decades and replacement is not always credible. Security therefore has to compensate through the surrounding architecture.
Segmentation can restrict movement between systems, monitored choke points can protect critical zones and secure remote access can reduce exposure created by supplier connections. Older devices may not support endpoint agents, but their communications can still be observed passively.
“Controllers running for 20 or 30 years are a feature of manufacturing, not a bug,” Kang adds. “If a device cannot protect itself, put a defensible architecture around it, monitor the network it lives on and control the pathways into it. None of that requires replacing the installed base.”
The operational perimeter is expanding
The factory is no longer defined by PLCs, distributed control systems and supervisory platforms. Robots, machine vision systems, manufacturing execution platforms, industrial sensors, automated guided vehicles and cloud applications now participate directly in production. Even peripheral assets can become operational dependencies if their failure prevents a product from being released or shipped.
This wider environment is often poorly represented in asset inventories. Manufacturers may understand core control systems while overlooking cameras, virtual machines and remote connections that provide an indirect route into production networks. Dragos has observed ransomware operators compromising IP cameras to bypass other protections.
AI will expand that perimeter further as it moves closer to the physical process. A model that recommends maintenance creates one dependency, while a system that automatically adjusts process parameters creates another. Manufacturers must consider malicious manipulation, model failure, undocumented changes, supplier instability and the possibility that a service may disappear.
“AI is moving from a supporting role into the control loop, with systems making autonomous decisions that touch the physical process,” Kang explains. “What happens to the line if an AI vendor fails, is acquired or its models disappear? As complexity increases, root-cause analysis becomes harder, whether the cause is an attack, a misconfiguration or a quality issue.”
Attackers are also using AI to accelerate their understanding of industrial environments. Kang says Dragos has observed an AI-assisted intrusion in which the system identified an adjacent operational environment, assessed it as valuable and began constructing an access path. The concern is not that every attacker has become an industrial specialist, but that the time required to learn and act is shrinking.
Visibility must support decisions
Asset discovery is frequently described as the foundation of OT security, but knowing what is connected does not create resilience by itself. Manufacturers also need to understand how assets interact, which dependencies can interrupt production and what abnormal behavior requires intervention.
Kang distinguishes between visibility and confidence. Visibility identifies what is present, while confidence means teams trust the information enough to act. A plant may have an extensive inventory and still lack the context to decide whether unusual traffic represents an attack, an engineering change or harmless process variation.
“Plenty of manufacturers have visibility without confidence, and the distinction matters,” he says. “Visibility is knowing what you have. Confidence is trusting what the data tells you enough to act on it, knowing whether today’s traffic means trouble and knowing what to do first.”
Poorly contextualized monitoring creates alert fatigue. An anomaly may show that something has changed without explaining whether it matters, and teams eventually stop trusting systems that repeatedly surface insignificant events. Effective detection must combine technical evidence with operational consequences.
The deeper weakness is often organizational. Kang regularly encounters flat networks, unmanaged vendor access and plants with little meaningful monitoring, but behind those gaps is uncertainty over ownership. OT security falls between IT and engineering, leaving critical decisions unresolved until an incident is underway.
“The root cause is almost always visibility, process and ownership,” Kang says. “A question such as whether you can isolate a machine may also mean stopping production. Who answers that? It is not simply a technology problem. It is an ownership and accountability problem.”
Preparation determines the disruption
Effective collaboration does not require IT and engineering to become a single department. It does require shared visibility, a common language for risk and an agreed decision process. Security teams bring knowledge of attackers, while engineers and operators understand the process, safety constraints and consequences of intervention.
“The teams need to decide before an incident who can isolate a cell, who talks to the vendor and who decides to stop the line,” Kang explains. “Where it works, security brings the threat knowledge, engineering brings the process knowledge and both groups collaborate. Plants that deliberately pair those skills will be measurably harder targets.”
No manufacturer can guarantee that an adversary will never enter an industrial environment. Operational resilience depends on how quickly the organization detects the intrusion, understands its scope and regains control. Kang says adversary dwell time in OT averaged around six weeks in Dragos data from last year, while organizations with strong visibility contained comparable incidents in approximately five days.
The difference is preparation undertaken before production is disrupted. An OT-specific response plan must address whether the plant can operate manually, which systems cannot be isolated without engineering approval and where known-good copies of controller logic are stored. Manufacturers also need forensic data to reconstruct events and restoration procedures tested under realistic conditions.
“An OT incident response plan is not the IT plan with the logo changed,” Kang says. “Without network monitoring already in place, you cannot scope the intrusion, so you either restore blindly or remain down while you investigate. Prevention reduces the frequency of bad days, but preparation determines their length, and length is what the business actually feels.”
This is why compliance cannot become the strategy. Regulation provides a minimum standard, but it cannot move as quickly as attackers, technology or industrial dependencies. Manufacturers that know their assets, monitor their networks, segment critical systems, control remote access and rehearse an OT response will be better prepared because those capabilities reflect how incidents unfold.
The manufacturers making the greatest progress will treat cyber risk as they treat safety and quality: as a condition of reliable production. They will reduce operational exposure, govern new technologies through change management and retain the ability to operate when a connected dependency fails.
“Operations must own cyber risk the way it owns safety and quality,” Kang concludes. “The knowledge, talent and technology to secure these environments already exist. What distinguishes the leaders is treating cybersecurity as a condition of reliable production. The reward is not only fewer incidents. It is a plant the organization understands better, and one that runs better because of it.”

