Overview
Cybersecurity programs protecting traditional information technology (IT) systems have been well-established for decades. Often focused on data protection, such programs have naturally evolved since before such systems were connected to the Internet. More recently, there has been a growing realization that operational technology (OT) systems (e.g., process control, manufacturing operations, maintenance management, etc.) must also be protected by a comprehensive cybersecurity program. Although related and similar to those for IT cybersecurity, the nature and constraints associated with OT mean that some of the features of an OT cybersecurity program must be different. Many of the challenges faced in providing adequate protection for OT systems are similar across virtually all sectors, industries, and process types.
Planning and assembling an OT cybersecurity program begins with the understanding that risk is a function of threat, vulnerability, and consequence. Threats such as spear phishing, ransomware, information theft, and other types of malicious software are seldom limited to a specific type of system or installation. Similarly, using commonly available commercial technology (e.g., operating systems, networks, etc.) means that vulnerabilities are not generally situation specific. Thus, the potential consequences of an incident must be the primary focus in determining the most effective approach, often involving the application of general-purpose IT cybersecurity products in the OT environment. Acceptance of this began with tools such as anti-virus and has expanded to more sophisticated tools.
Suppliers of cybersecurity products and services have seen opportunities to provide them for use in the OT environment. Such opportunities may be difficult to pursue because of certain differences in this environment. Responsible organizations and roles may be different than those of the IT environment, and decision-making processes may also vary. It is essential to adapt the approach to respond to these differences.
Key findings of this report include:
- The cybersecurity needs of IT and OT systems are very similar, but the latter environment has specific characteristics that must be addressed.
- While there are established and accepted organizational models, they are general in nature and must be tailored to the specific environment.
- Addressing cybersecurity risks in OT involves several non-traditional roles that are critical to selection and implementation decisions.
- Suppliers who wish to propose solutions in the OT environment must adjust their proposals to meet specific characteristics and constraints.
The Cybersecurity Imperative
It has long been an imperative that information systems must be protected from security-related risks. Considering the reported and potential incidents in recent years, most experts agree that OT cybersecurity is of equal importance. Industry standards (e.g., ISA/IEC 62443) and frameworks (e.g., NIST CSF) make a strong case for this. However, awareness and acceptance are only the first steps. To make real progress it is also essential to fully understand the implications, beginning with certain realities.
Common Objectives for IT and OT
The first of these is that both IT and OT cybersecurity efforts have the common objective of mitigating or even avoiding the potential risks of a cyber incident. In OT environments the most serious of such incidents may take the form of compromise or loss of operation of the systems being protected, but less severe consequences can also be expensive and debilitating. Neither IT nor OT support organizations can achieve it on their own. An effective and sustainable program can only be successful through a meaningful partnership.
Differences Still Exist Between IT and OT Domains
While the basic objective may be common, there has been much discussion and debate over the years on the question of whether OT systems are sufficiently “different” to warrant a similarly different approach to protecting them against cyber threats. This question has often been presented as a choice of one over the other, but this is a false dichotomy. While there is little doubt that both domains share many characteristics, there are some differentiating factors, as summarized in the following table.

Table of Contents
- Executive Overview
- The Cybersecurity Imperative
- End User Program Implementation Approaches
- The Supplier Response
- Recommendations
ARC Advisory Group clients can view the complete report at the ARC Client Portal.
Contact Us if you would like to speak with the author.
Obtain more ARC In-depth Research Market Analysis.