A woman with glasses analyzing tech systems

3 steps to strengthen OT cybersecurity as attacks increase


EY ServiceNow logo

As operational technology (OT) converges with IT, AI and cloud, cyber threats continue to outpace defenses.


In brief
  • AI, cloud analytics and IT/OT convergence are reshaping industrial operations but also expanding the attack surface faster than most cyber programs can match.
  • Adversaries are systematically mapping industrial control loops and using commercial AI tools to accelerate pathways into OT.
  • Cyber leaders who pair a recognized OT framework with an operating model that unites IT, OT and safety leadership can unlock the value of OT digital transformation.

Digital transformation is no longer solely the concern of the enterprise IT function. Artificial intelligence, machine learning and industrial automation are spreading quickly from innovative pilot technologies into the core operations of manufacturing, energy, transportation and water – and impacting many parts of the business.

71%
71%
of surveyed organizations have experienced up to nine cyber attacks in the past year.

A 50% year-over-year increase, attributed largely to improved detection now catching what was previously invisible.1 Additional research recorded a 46% year-over-year rise in ransomware activity against industrial environments,2 while a separate OT threat report — which tracks only verified attacks with physical consequences — found that both nation-state and hacktivist attacks doubled year over year, with most targeting critical infrastructure.3

Despite rising attacks and an aggressive focus on updating OT, many cyber and operations leaders are seeing continued value in better integrating IT and OT environments for enhanced cyber protections for three reasons. Aligning production, equipment performance and supply chain data enables better visibility, decisions and supports just-in-time manufacturing, predictive maintenance and dynamic resource allocation. Unified monitoring reduces the need for on-site interventions in oil and gas, utilities and multisite manufacturing — improving safety, uptime and workforce productivity. And combining OT sensor data with enterprise systems fuels innovation in supply chain optimization, product quality, sustainability reporting and the customer experience. All are outcomes that are difficult to reach in siloed environments.

 

To begin this integration journey, organizations should consider three foundational steps to strengthen OT cybersecurity. Each of these aligns to National Institute of Standards and Technology Cybersecurity Framework 2.0 (NIST CSF 2.0) and, for organizations under regulatory scrutiny, to IEC 62443, a series of standards developed by the International Electrotechnical Commission (IEC).

EY point of view

Across manufacturing, energy and industrial organizations, programs that once appeared mature are now frequently missing foundational security: accurate asset inventory, validated network segmentation and tested OT-specific incident responses. Closing that gap is both essential and where value can be created.

As organizations strengthen OT cybersecurity programs, many are looking for ways to connect OT asset visibility, cybersecurity operations and service management processes. Platform-based approaches, including ServiceNow, can help create a more unified view of assets, incidents and operational risk across increasingly complex environments.

1. Build a comprehensive OT asset inventory (Identify)

You cannot protect what you cannot see. Only 12.6% of organizations report full visibility across the ICS Cyber Kill Chain, and visibility collapses at the lower Purdue Model levels — 19.7% at Level 3, 10% at Level 2 and lower still at Level 1, according to the SANS Institute.4 Legacy PLCs, unmanaged switches and vendor-installed remote access channels remain the largest blind spots.

Start with a passive-first asset discovery approach that respects fragile control systems, extend it to include remote and field sites, and feed the inventory into threat detection and response, vulnerability management and business continuity functions.

Regulators have also made this a baseline expectation. In August 2025, US agencies including the Cybersecurity & Infrastructure Security Agency, National Security Agency, Federal Bureau of Investigation and Environmental Protection Agency, together with international collaborators, jointly published Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators, establishing asset inventory and a supporting OT taxonomy as the foundation of a defensible OT architecture.5 Programs that align to this guidance now start from a stronger regulatory and audit position.

2. Understand how assets support critical processes (Identify/Protect)

Perimeter security alone is no longer sufficient. Organizations need to understand how each asset supports safety, production and revenue-generating workflows so that risk decisions are better anchored to operational consequences, not simply technical vulnerabilities.

This matters because convergence has already happened. According to 2026 industry threat research, adversaries systematically mapped industrial control loops end to end and increasingly used AI to accelerate their efforts.6,7 Risk assessments must now trace the full path from initial IT access to their impact on physical processes, meaning the classification of an asset must reflect its role in that path.

3. Strengthen control and monitoring across OT networks (Protect/Detect)

While network segmentation, secure remote access and OT-aware detection are now table stakes, half of all reported ICS and OT incidents in 2025 began with unauthorized remote access. And only 13% of organizations have fully implemented advanced remote-access controls such as session recording or OT-aware brokering, according to the SANS Institute.8 Detection is improving — nearly 49% of incidents are detected within 24 hours — but full remediation still stretches into weeks or longer.9

Organizations should prioritize segmentation between IT and OT (and between OT zones), replace flat vendor virtual private networks (VPNs) with brokered access and deploy OT-specific monitoring that integrates cleanly with the enterprise’s security information and event management (SIEM) and IT service management (ITSM) stack.

EY point of view

The organizations getting the most from OT monitoring investments are the ones that treat the OT security operations center not as a separate silo but as an integrated tier — with dedicated OT analysts, IT-/OT-aware playbooks and clear escalation paths into plant operations.

Many organizations are also looking for ways to connect OT monitoring with broader incident management, asset management and service management processes. Solutions such as ServiceNow can help provide greater visibility and coordination across cybersecurity and operational teams.

Tool selection matters less than the operating model wrapped around it.

3 other considerations for OT cybersecurity leaders:

AI is accelerating attacks that require no prior OT expertise

The World Economic Forum’s Global Cybersecurity Outlook 2026 finds that 94% of surveyed leaders expect AI to be the most significant driver of change in cybersecurity in the year ahead. On each side, attackers are using generative AI to accelerate reconnaissance, phishing and payload development, and defenders are embedding AI into asset intelligence, anomaly detection and automated triage. As attack and defense lines are drawn, organizations can expect three effects: an expanded attack surface introduced by AI systems themselves, AI-augmented defense and AI-enhanced attacker tradecraft.10

The threat is no longer theoretical either. In late 2025 and early 2026, an unknown adversary used Anthropic’s Claude and OpenAI’s GPT models to compromise the enterprise IT of Servicios de Agua y Drenaje de Monterrey (SADM), map the internal environment, identify a vNode SCADA/Industrial Internet of Things (IIoT) gateway, classify it as a crown jewel asset and launch a password-spray attack against the IT–OT boundary.11 The breach attempt failed, but the adversary reached Stage 1 of the ICS Cyber Kill Chain with no prior OT expertise, proving that AI has made OT reachable to IT-only adversaries. For OT programs, prevention-only strategies (firewalls, segmentation, patching) are necessary but no longer sufficient. Visibility, detection and response are now baseline requirements.

Regulation is arriving faster than most OT programs can match

Recent research indicates that 89% of OT leaders now expect new regulation within five years, up from 66% in 2025.12 The NIS2 Directive in Europe, evolving Transportation Security Administration (TSA) security directives, the expanded North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) scope and emerging Automated Program Analysis for Cybersecurity (APAC) frameworks are pushing baseline capabilities. These include asset visibility, logging, change detection — and are moving from optional to mandatory. For organizations who are already compliant, the upside is clear: companies see around 50% fewer financial and safety impacts when incidents occur, according to the SANS Institute.13

Plant floor culture must be prepared for OT change

Even the best-designed OT security programs will stall or fail if the plant floor resists. Control room operators, plant engineers and maintenance technicians have spent their careers protecting availability and safety, and seen well-intentioned IT-driven changes disrupt production and, in some cases, endanger workers. Any security tool that scans a network, quarantines a device or forces a credential rotation is, from the plant's perspective, a potential source of unplanned downtime.

Yet the same workforce is essential to the program working. According to 2025 Sans Institute findings, organizations that include frontline plant staff in tabletop exercises are 1.7 times more likely to report strong readiness.14 Even so, additional shows that 95% of manufacturers have already invested or plan to invest in OT cybersecurity platforms within the next five years — meaning the tools are coming to the plant floor whether the culture is ready or not.15

To re-tool plant floor culture for coming OT cybersecurity changes think about:

  • Co-design, don’t impose: Bring plant operators and engineers into tool selection, deployment planning and playbook design early. A control system engineer who helps write the organization’s new response runbook will go on to defend it.
  • Frame security as availability: Present the value of segmentation, monitoring and incident response (IR) in the language of uptime, safety and mean time to recovery — not risk registers or Common Vulnerability Scoring System (CVSS) scores. Tie security KPIs to overall equipment effectiveness (OEE), unplanned downtime and audit-hour reduction so operations leaders can see the return.
  • Pilot on one line before scaling: Deploy a new capability on a single line, cell, unit or plant — with the local team’s active involvement — before scaling. Publish the results, including what went wrong. Credibility on the plant floor is earned in small wins, not enterprise mandates.
  • Build local champions: Identify respected plant engineers and control system specialists, invest in their OT security training and certification and empower them to lead in-plant awareness. Peer influence outperforms corporate mandates on a shift floor.
  • Sponsor from operations, not just security: A CISO memo alone will not shift a plant culture. Visible collaboration with the plant manager, VP of operations and head of environment, health and safety (EHS) signals that security is an operational priority, not an IT overlay.
  • Rewrite the safety-security narrative. Legacy playbooks that treat availability and security as competing goals reinforce the resistance. Update joint IT–OT–safety procedures so that security controls are designed to preserve availability and safety incidents that touch cyber are jointly investigated.

The bottom line

Operational technology is entering a new phase of digital maturity. The organizations that will lead the next decade are the ones treating OT cybersecurity not as an engineering afterthought but as a board-level operational risk to be addressed. This must be anchored to a framework (NIST CSF 2.0 or IEC 62443), integrated into a working operating model, sustained by a plant-floor culture that owns it, and matched to the pace of the adversary. And where in-house capabilities can’t scale to the pace of changing regulations and threats, managed service-driven acceleration may be a faster solution than building from scratch.

Organizations that delay will soon find the cost of catching up significantly compounds pain points — in more regulatory exposure, increased insurance premiums, costly operational downtime and lost competitive ground to peers that already embedded cybersecurity into transformation strategies.

EY OT Risk Visibility Analysis

A focused analysis can help organizations understand where operational risk exists across their OT environment, and potential impacts to safety, revenue/production and reliability. The engagement provides executives with a prioritized view of OT cyber risks and actionable recommendations to improve visibility, resilience, and informed investment decisions.


Summary 

As AI, cloud and IT/OT convergence reshape industrial operations, cyber risk is growing just as quickly. Organizations can unlock the value of digital transformation by strengthening OT cybersecurity foundations: building asset visibility, understanding operational dependencies and improving network controls. Success depends, in part, on aligning security, operations and safety around a common approach to managing risk.

About this article