KEYWORDS: it-sa Congress, OT Cybersecurity, Industrial Control Systems, NIS2 Directive, Zero Trust Network Security, Cyber Resilience Act, Managed Security Services, IEC 62443, Cybersecurity, Workflow Automation
Overview
The it-sa Expo & Congress in Nuremberg stands as Europe’s premier trade fair and congress dedicated to IT security, earning its reputation as the “Home of IT Security.” Each year, it-sa brings together a diverse community of providers, experts, government and regulatory bodies, practitioners, and customers from across industries. The event serves as a vital platform for sharing knowledge, showcasing innovations, exchanging best practices, and addressing emerging threats. Participants gain insights into the latest regulatory, technical, and strategic challenges facing the cybersecurity landscape.
A defining feature of it-sa is its commitment to bridge the gap between traditional IT security and the specialized field of industrial cybersecurity—commonly referred to as Operational Technology (OT) security. This focus has grown increasingly important in recent years, driven by the convergence of IT and OT environments within critical infrastructure and industrial sectors. As industrial control systems become more interconnected, the risks of cyber-physical attacks escalate, making robust OT security essential for safeguarding production, safety, and compliance.
Regulatory pressures such as the European NIS2 directive and international standards like IEC 62443 have further heightened the need for integrated security strategies. Organizations are now required to address not only IT threats but also vulnerabilities unique to industrial control systems and process automation. It-sa’s emphasis on OT cybersecurity reflects this shift, offering attendees practical solutions, expert guidance, and real-world demonstrations to help secure complex industrial environments against evolving cyber risks.
Challenges in Securing OT Control Systems
Securing Operational Technology (OT) control systems—such as those found in process- and factory-automation—presents a unique set of challenges that differ significantly from traditional IT environments. At the heart of these challenges is the need to protect the entire automation life cycle, which spans engineering, deployment, operations, and maintenance. Each phase introduces specific risks: from ensuring secure design and commissioning, to managing changes, applying patches, and updating firmware on PLCs and controllers. Unlike IT systems, many OT devices were not originally designed with cybersecurity in mind, making retrofitting security a complex task.
Network security is another critical concern. Industrial and control networks often require segmentation and isolation to prevent threats from spreading. The adoption of Zero Trust approaches—where every connection is authenticated and authorized—can significantly enhance security. However, implementing such models in OT must be done without compromising the safety or availability of critical processes, as downtime can have severe operational and financial consequences.
A persistent challenge is the limited visibility of OT assets. Many organizations struggle to maintain an up-to-date inventory of what is deployed, where it is located, and how vulnerable each asset might be. This lack of visibility hampers effective vulnerability management and prioritization of remediation efforts, especially since OT systems often have weak or outdated monitoring capabilities.
The convergence of IT and OT environments further complicates security. Integrating OT into broader enterprise cybersecurity architecture introduces new risks, as threats can move across domains. Managing these cross-domain threats requires a holistic approach that bridges organizational silos and aligns security policies across both IT and OT.
Regulatory compliance is an increasing area of focus. Frameworks such as IEC 62443 and the NIS2 Directive require robust governance, risk management, and documentation processes. Sustained compliance demands not only technical controls but also strong procedural discipline and continuous oversight.
The NIS2 Directive (EU 2022/2555) entered into force in January 2023, with Member States required to transpose it by October 2024. While this deadline has passed, enforcement will intensify through 2025 and 2026, and affected entities must ensure their cybersecurity governance, incident reporting, and supply-chain management practices are fully compliant and auditable.
The Cyber Resilience Act (CRA) establishes cybersecurity obligations for products with digital elements placed on the EU market. 2026 marks the transition from preparation to enforcement: conformity assessment bodies must be operational by June 2026, and vulnerability and incident reporting obligations take effect by September 2026. Harmonized standards for vulnerability handling are due by August 2026, with product-specific standards to follow in October 2026. Organizations should align their development, maintenance, and response processes with CRA requirements to ensure timely compliance.
Finally, increasing reliance on managed security services—such as Security Operations Centers (SOC), threat analytics, and monitoring—reflects the need for specialized expertise in OT environments. Demonstrations and real-world use cases, as shown at it-sa, are essential for illustrating how cybersecurity controls can be practically applied in complex industrial settings, helping organizations move from theory to effective implementation.
Secure Industry: Siemens Unveils Multi-Vendor OT Cyber Solutions
At it-sa, Siemens, a control systems leader, presented integrated OT-cybersecurity solutions to help organizations with limited resources protect their industrial operations effectively. Demonstrations were built around Siemens control equipment, illustrating state-of-the-art cybersecurity practices and how these solutions can be practically implemented across real industrial environments. However, Siemens emphasized that these initiatives are not limited to Siemens control architectures—most of the presented use cases were designed for multi-vendor control systems, highlighting the company’s commitment to interoperability and open, scalable cybersecurity concepts that can protect diverse industrial ecosystems.
SINEC Secure Connect introduces a Zero Trust networking platform tailored for OT environments. By virtualizing network structures and enabling secure machine-to-machine and remote connections without traditional VPNs, it simplifies segmentation and cell protection. This is crucial for legacy-heavy industrial networks, where isolating critical assets and preventing lateral movement are top priorities.
SINEC Security Guard is a cloud-based SaaS solution for vulnerability mapping and management. It automatically matches known vulnerabilities to production assets, prioritizes remediation, and integrates task management. For many industrial operators—especially SMBs—this provides much-needed visibility and actionable risk analysis, even when internal cybersecurity expertise is limited.
Managed IT/OT SOC, a joint offering from Siemens and Accenture, delivers unified monitoring and incident response across IT and OT domains. This service model is particularly valuable for SMBs, which often lack dedicated OT security teams. Outsourcing to a specialized provider ensures continuous threat detection, compliance alignment, and rapid response, helping organizations meet EU directives like NIS2 without building large in-house teams.
Partnerships and Use Cases, such as those with Actemium, NVIDIA, ServiceNow, SpiraTec, Palo Alto Networks, and others, bring these solutions to life through real-world demonstrations. Customers can see secure remote access, patch management, accelerated AI cybersecurity, workflow automation and network segmentation work in practice, building trust and facilitating adoption.
Conclusion: From Threats to Compliance - Strengthening IT and OT Defense
Cyber threats are becoming increasingly severe, with IT and OT systems often attacked simultaneously to gain unauthorized access to data or system control. This dual-domain landscape highlights the growing interdependence between information and operational technologies and the critical need for integrated protection strategies. At the same time, regulatory requirements for compliant cybersecurity solutions—driven by standards such as IEC 62443 and directives like NIS2—are steadily increasing. Failure to comply no longer affects only critical infrastructure; all operators face the risk of substantial financial penalties and reputational damage.
To ensure both security and compliance, organizations must now establish comprehensive cybersecurity concepts tailored to their operations. This begins with evaluating and strengthening internal expertise in industrial cybersecurity, followed by assessing the adequacy of existing hardware and software tools to provide sustainable protection throughout the system’s lifecycle. For those lacking sufficient in-house capabilities or tools, engaging in specialized external cybersecurity services is a strategic necessity. Only through such proactive, compliant, and well-structured approaches can organizations safeguard their operations and remain resilient against the evolving landscape of cyber threats. The urgency for comprehensive, compliant solutions has never been greater.
ARC Advisory Group clients can view the complete report at the ARC Client Portal.
Contact Us if you would like to speak with the author.
Obtain more ARC In-depth Research Market Analysis.