Rethinking OT Security Ownership
Your security team might seem like the natural choice to protect operational technology. After all, OT systems involve computers and networks, and the CISO's team handles cyber risk. But this approach can fall short when attackers target your water treatment facility's PLCs, change administrator credentials, and force manual operations. Suddenly, your SOC analyst doesn't understand the chemical dosing system, your incident responder has never talked to the plant operator, and your business continuity plan didn't consider the physical plant going offline.
The Incomplete Picture
Recent analyses by the FBI, EPA, and CISA of municipal water facility attacks reveal a critical gap: while technical vulnerabilities like Internet-exposed devices and weak authentication are straightforward, the real issue is the lack of operational knowledge among cybersecurity professionals. OT security isn't just about IT; it's about ensuring continuous service delivery and public safety.
Your risk assessment should reflect this. While your IT risk register focuses on data breaches and regulatory penalties, your OT risk register should prioritize scenarios like contaminated water supplies and grid instability. With 85% of U.S. critical infrastructure owned by private companies, this is a shared responsibility that many haven't fully embraced.
Learning from Telecommunications
The telecommunications sector offers a model for handling this challenge. Communications networks are crucial because every sector relies on them. Successful organizations treat security as an enterprise-wide risk management function involving executives, engineers, and compliance officers. Security operations centers monitor threats, but they work with law enforcement, and access controls complement surveillance systems.
The Operational Technology Cybersecurity Coalition recommends Binding Operational Directives for OT security and expanded federal grants, focusing on modernizing industrial control systems. The emphasis isn't on hiring more cybersecurity analysts but on integrating operational tasks with cybersecurity awareness.
A New Approach
Acknowledge that your CISO can't own OT security alone. The chief operating officer, plant managers, and operational engineers must share ownership. This isn't about reporting structure; it's about recognizing the need for operational domain expertise.
Build your OT security program around three key capabilities:
Operational continuity planning. Assume control systems might fail while IT infrastructure remains intact. Can plant operators switch to manual mode? Do they know how to isolate compromised systems without shutting down critical processes?
Cross-functional threat response. Include operational personnel in your incident response structure. When attackers compromise PLCs, you need someone who knows what those controllers control and what safe shutdown procedures look like.
Integrated risk visibility. Map OT vulnerabilities to operational consequences. If you're tracking "unpatched SCADA system" as a finding, consider the real risk: "loss of real-time visibility into chemical dosing levels, requiring manual testing."
Train your security team in operational processes and your operational team in security. Run joint tabletop exercises and conduct vulnerability assessments with both network security specialists and process engineers.
Where Conventional Wisdom Applies
Your security team should lead the technical implementation of OT security controls. Network segmentation, access controls, and vulnerability management require cybersecurity expertise. CISA provides threat intelligence and incident response assistance that your security team is best positioned to use.
The conventional approach works for IT systems supporting operations but not directly controlling physical processes. Standard IT security practices apply to systems like enterprise resource planning and maintenance management databases.
The real challenge is ensuring that technical controls aren't the sole focus. Former CISA Director Jen Easterly pointed out that nation-state adversaries operate on a geopolitical level, while defense often rests with small municipal organizations. This imbalance requires integrated organizational capability where cybersecurity and operational expertise work together.
The question isn't whether your security team should be involved in OT protection. It's whether they're collaborating with the people who actually run the systems under attack.





