By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Operational technology and industrial control systems were designed for reliability and uptime, not cybersecurity. As manufacturers connect production floor systems to corporate networks and the internet, attack paths that previously did not exist are now available to any attacker who can reach the corporate IT environment. OT and ICS security requires a different approach than enterprise IT security, built on frameworks like IEC 62443 and NIST CSF, and delivered by professionals who understand both domains.
Key Takeaways
- OT and ICS environments run on systems with long lifecycles, limited patching capability, and proprietary protocols that standard IT security tools do not support.
- IT-OT convergence has created network connections between corporate IT and production floor systems that expand the attack surface for threats originating in either environment.
- IEC 62443 is the international standard for industrial automation and control system security and provides the framework for structured OT security programmes.
- NIST CSF provides a complementary governance framework that spans both IT and OT environments and is widely adopted by North American manufacturers.
- OT security requires specialized assessment, monitoring, and incident response approaches that differ materially from enterprise IT security practices.
What Is the Difference Between IT and OT Security?
Information technology security and operational technology security share common principles but differ fundamentally in their priorities, constraints, and risk profiles. IT security prioritizes the confidentiality, integrity, and availability of data in roughly that order. OT security inverts this: availability is paramount because production must run, integrity of control signals matters for product quality and safety, and confidentiality is a secondary concern in most ICS environments.
The systems that OT security must protect reflect this difference. PLCs that control manufacturing processes run firmware that may be years or decades old, cannot be rebooted casually, and in many cases cannot be patched at all without disrupting production and voiding vendor support agreements. SCADA systems that monitor and control production processes often run Windows versions that are no longer supported by Microsoft but cannot be upgraded because OT vendors have not qualified newer operating systems with their software.
An IT security tool that quarantines a compromised endpoint has done its job correctly. The same action applied to a PLC controlling a production line may stop the line. An IT monitoring tool that generates network traffic to poll systems for status may interfere with the time-sensitive control signals that ICS networks depend on. The techniques and tools of IT security require adaptation before they can be applied to OT environments, and some cannot be applied at all.
What Has IT-OT Convergence Changed?
For most of the history of industrial manufacturing, OT networks were physically and logically separate from corporate IT networks. Air-gapped or minimally connected production environments had limited exposure to internet-based threats. A threat actor who wanted to reach a factory’s control systems had to physically access the facility or penetrate a deliberately isolated network.
IT-OT convergence has changed this at most manufacturing organizations. Enterprise resource planning systems that push production orders to manufacturing execution systems create data connections between business networks and production floor systems. Historians that aggregate production data for business intelligence create bridges between OT and IT. Remote monitoring and maintenance access that allows OT vendors to service equipment from offsite creates connections between the factory and external networks. Cloud connectivity for predictive maintenance and supply chain integration creates additional pathways.
Each of these connections provides business value. They also create attack paths. An attacker who compromises a corporate IT network through a phishing email can use a historian connection to reach the OT network. A vendor with remote access credentials to OT systems who is compromised externally becomes a vector into the production environment. The connectivity that enables modern manufacturing operations is the same connectivity that expands the OT attack surface.
What Are the Main OT-Specific Threats?
Ransomware Lateral Movement Into OT
The most common OT security incident in manufacturing is not a sophisticated ICS-targeted attack. It is conventional ransomware that spreads from corporate IT into OT-adjacent systems through network connections that should not exist or should be more tightly controlled. An IT ransomware payload that reaches a historian, an HMI workstation running Windows, or an engineering workstation connected to both environments can effectively halt OT operations without ever directly targeting PLCs or SCADA software.
ICS-Targeted Malware
A smaller number of incidents involve malware specifically designed to interact with industrial control systems. The Triton framework, which targeted safety instrumented systems, and EKANS, which targeted process-specific software in manufacturing environments, demonstrated that threat actors have invested in OT-specific capabilities. These attacks are typically associated with nation-state actors conducting espionage or pre-positioning for potential disruption of critical infrastructure, and they require significantly more expertise to execute than conventional ransomware.
Supply Chain and Remote Access Compromise
OT vendors, maintenance contractors, and engineering partners frequently have remote access to production systems for support and maintenance purposes. This access is necessary for operational reasons but creates a vector that is outside the manufacturer’s direct control. A vendor whose own network is compromised, or whose credentials are harvested through phishing, can become a pathway into the manufacturer’s OT environment through trusted remote access channels, which is why privileged access management with just-in-time, recorded sessions is the control that most directly reduces this exposure.
What Does IEC 62443 Require?
IEC 62443 is the international standard series for security of industrial automation and control systems. It addresses security from multiple perspectives: the asset owner who operates the industrial environment, the product supplier who manufactures OT equipment, and the system integrator who deploys and configures OT systems. For manufacturers, the asset owner requirements are most directly applicable.
IEC 62443 organizes OT security around security levels, from SL 1, which addresses protection against unintentional or coincidental violations, to SL 4, which addresses protection against sophisticated nation-state attacks. Most manufacturing environments target SL 2 or SL 3 depending on the criticality of their processes. The standard requires network zone and conduit design, access management appropriate to each security zone, monitoring and anomaly detection, and incident response capabilities.
The zone and conduit model is the most distinctive aspect of IEC 62443. Rather than treating the OT network as a single flat environment, the standard requires segmentation into zones based on security level requirements, with conduits that control and monitor traffic between zones. This structure limits the blast radius of any single compromise and provides the monitoring points needed to detect lateral movement between environments.
How Does NIST CSF Apply to Manufacturing OT?
The NIST Cybersecurity Framework is a voluntary framework originally developed for critical infrastructure protection but widely adopted across manufacturing. The current version, CSF 2.0, organizes cybersecurity activities into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in 2024 to make governance and risk management explicit, and it sits at the centre of the other five. These functions apply to both IT and OT environments and provide a governance structure that spans the full manufacturing operation.
NIST has published specific guidance on applying the CSF to industrial control system and operational technology environments, and the CSF is the framework most commonly requested by large customers in US and Canadian manufacturing supply chains. A manufacturer that can demonstrate CSF alignment, with documented controls across all six functions for both IT and OT, satisfies the majority of customer security questionnaire requirements and provides the governance foundation for more specific standards like IEC 62443.
How Does Armour Approach OT Security for Manufacturers?
Armour Cybersecurity’s OT-focused manufacturing cybersecurity services begin with an assessment that maps the IT-OT architecture, identifies network connections between environments, inventories OT assets and their patch status, and evaluates current controls against IEC 62443 and NIST CSF requirements. The assessment produces a risk-prioritized remediation roadmap that sequences improvements by operational risk rather than technical complexity.
Penetration testing of OT environments follows rules of engagement designed for operational environments: passive observation and configuration review where active testing carries production risk, active testing during agreed change windows where operational teams have verified safety, and tabletop exercises that test response to OT-specific scenarios without touching live systems. The goal is accurate risk assessment, not operational disruption.
The vCISO service provides the governance leadership to maintain OT security as a programme rather than a one-time assessment. OT environments change as production processes evolve, new equipment is added, and vendor connections are established or modified. An ongoing governance function that reviews OT changes through a security lens, maintains the asset inventory, and monitors the threat landscape for OT-specific threats keeps the programme current.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the manufacturers with OT security worth the name are the ones who stopped pretending their production network was still air-gapped. They inventoried what was actually on the floor and what it was actually connected to, segmented IT from OT into real zones with monitored conduits instead of assumed separation, put OT vendor remote access behind on-demand privileged access instead of always-on VPNs, and assessed their control systems with techniques that do not knock a PLC offline, so convergence became a managed architecture rather than an invisible attack surface.
Frequently Asked Questions
Can we patch OT systems without disrupting production?
Patching in OT environments requires coordination with OT vendors, production scheduling, and change management processes that are more complex than IT patching. Many OT vendors qualify specific patch levels rather than the latest releases, meaning patches must be tested before deployment. Production schedules must identify windows when systems can be updated without halting production. For systems that cannot be patched due to vendor constraints or operational risk, compensating controls such as network segmentation, monitoring, and access restriction address the exposure without requiring a patch.
What is the difference between a SCADA assessment and an IT penetration test?
A standard IT penetration test uses active exploitation techniques against systems to identify vulnerabilities. In OT environments, many of these techniques carry operational risk: sending unexpected traffic to a PLC can cause it to fault, scanning a SCADA server with an IT tool can cause it to crash, and exploiting a vulnerability in a historian can interrupt data collection that operations depends on. An OT security assessment uses passive techniques, configuration review, network architecture analysis, and controlled active testing in isolated or test environments to assess security without creating operational risk.
How do we handle OT vendor remote access securely?
OT vendor remote access should be managed through a privileged access solution that provides just-in-time access, requires multi-factor authentication, records sessions, and allows the manufacturer to terminate access immediately. Always-on VPN connections to OT vendor networks represent a persistent exposure that does not reflect the actual access requirement for most vendor support scenarios. Access that is granted on demand, recorded, and revoked after the support session limits the exposure of a vendor credential compromise to the duration of active sessions.
What is the right starting point for an OT security programme?
An OT asset inventory and architecture review is the right starting point. Many manufacturers do not have a complete picture of what OT systems they operate, how those systems are connected to each other and to IT networks, and what remote access exists to those systems. The inventory and architecture review establishes the foundation that all subsequent security decisions require. Without knowing what is there and how it is connected, it is impossible to prioritize what to protect first.
The Bottom Line
OT and ICS security is not enterprise IT security applied to the factory floor. The priorities invert, availability first, because a stopped line is the loss; the systems are old, unpatchable, and easily disrupted by the very tools that protect IT; and IT-OT convergence has quietly wired the production environment to everything an attacker can already reach. The way through is structured, not improvised: inventory the OT estate and its real connections, segment it into IEC 62443 zones with monitored conduits, govern it under NIST CSF 2.0 across all six functions, and assess it with techniques that will not knock a PLC offline. Armour Cybersecurity helps manufacturers assess, protect, and monitor OT and ICS environments with manufacturing cybersecurity services built on IEC 62443 and NIST CSF, so the connectivity that runs a modern factory stops being the attack surface that takes it down.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



