OT Cyber Security, from technical effort to assured business risk

Operational technology underpins the delivery of modern industrial and critical services. These systems control physical processes that, if they fail, can have immediate consequences for safety, the environment, service availability, and financial performance. Despite this, OT cyber security is still frequently framed as a technical issue rather than a material business risk.

This framing is the root of the problem.

Across industry, capable OT and cyber specialists are actively addressing real risk. However, without structured, evidence-based assurance, it is difficult to know whether all relevant risks are consistently identified, prioritised, and controlled. OT cyber risk is therefore not failing due to a lack of effort or expertise. It is failing because assurance and reporting are not consistently elevated to board or leadership level.

When OT cyber risk is not assured and reported at board level, it is not treated as part of the enterprise cyber strategy. As a result, IT underweights its importance and operational teams are left to manage risk without strategic backing.

Without structured assurance, boards cannot distinguish between effort and effectiveness.

The threat landscape – evidence of exposure and impact

Increased connectivity has expanded exposure across OT environments. Cyber risk increasingly manifests through disruption to physical processes rather than loss of information.

Research published in August 2025 by Cornell University identified nearly 70,000 OT devices globally directly accessible from the public internet, including exposed HMIs and SCADA interfaces supporting live operations.

Industry research from Waterfall Security Solutions shows a marked increase in OT cyber incidents resulting in physical consequences, often exploiting known weaknesses such as unmanaged remote access and insufficient separation between IT and OT environments.

These findings demonstrate both exposure and impact. OT cyber risk is measurable and increasingly linked to operational and safety consequences.

Implications for resilience and safety

From a resilience perspective, OT cyber incidents increase the likelihood of unplanned outages and extended recovery. From a safety perspective, they offer credible pathways to circumvent systems designed to prevent harm.

The Health and Safety Executive recognises cybersecurity as a potential trigger for major accident scenarios. The National Cyber Security Centre continues to emphasise resilience and disruption affecting essential services.

Evidence-based assurance as the enabler

Evidence-based assurance links board oversight to operational delivery, drawing on the Cyber Assessment Framework, OG86 operational guidance, and IEC 62443 as the recognised international standard for securing industrial control systems.

Owning the assurance process

An independent review has value. However, relying solely on periodic external assessment does not create resilience. Effective governance requires organisations to maintain their own authoritative, current view of OT cyber risk.

Structured self-assessment, aligned with recognised frameworks and standards, enables organisations to continuously refine and strengthen their programmes. It allows teams to evidence control effectiveness, identify emerging gaps, and report risk in business terms.

When supported by appropriate assurance systems, this process becomes disciplined and repeatable. Boards gain visibility based on evidence rather than assumptions.

Conclusion

OT cyber risk does not fail for lack of effort. It fails when assurance is absent and risk is not visible at board level. Organisations that elevate OT cyber assurance to board and leadership level move from fragmented effort to informed governance, strengthening resilience, safety, and operational confidence.

Useful links

ncsc.gov.uk/collection/cyber-assessment-framework
hse.gov.uk/eci/cyber-security.htm