Defending Critical Infrastructure: Why OT Security Demands a Threat-Informed Approach

Operational technology (OT) has become one of the most critical areas of cyber risk management for enterprise security leaders. Manufacturing lines, power systems, transportation networks, healthcare infrastructure, energy operations, and other industrial environments rely on increasingly connected systems. That connectivity delivers operational advantages, but it also exposes OT environments that were not originally designed for today’s threat landscape.
For CISOs, this poses a difficult challenge. While OT environments are no longer isolated from enterprise risk, they also cannot be secured simply by extending traditional IT controls into industrial networks. The priorities, systems, and consequences of disruption are all different.
IT and OT Do Not Share the Same Priorities
In IT, the primary goals focus on protecting data, users, applications, and business systems. In OT, security must also address safety, uptime, physical processes, specialized equipment, legacy protocols, and operational continuity. A security control that makes sense in a corporate environment may pose unacceptable risk if it interrupts a production line, delays a safety process, or affects the availability of critical infrastructure.
That is why OT security requires a threat-informed approach. CISOs need to understand not only what assets exist but also which systems are most exposed, which threats are most relevant, how an attacker would move through the environment, and which controls can reduce risk without disrupting operations.

Start With the Environment, Not the Control Stack
Most OT environments were designed for reliability and availability long before they were ever connected to enterprise IT systems, cloud services, remote access platforms, and third-party support networks. As a result, they often include older systems that are difficult to patch, proprietary protocols that are hard to inspect, and operational requirements that restrict when and how changes can be made.
CISOs who approach OT as if it were simply another branch of the corporate network risk creating blind spots. They may overestimate the effectiveness of standard controls, underestimate the fragility of industrial processes, or overlook the specific ways adversaries target OT environments. A more effective model starts with the realities of the environment.
OT security must protect availability and safety while improving visibility, reducing exposure, and providing security teams with enough context to detect and respond to threats before they affect operations.
CISOs also cannot defend systems they cannot see. In many OT environments, the first challenge is mapping the full asset landscape, including industrial controllers, engineering workstations, HMIs, sensors, field devices, remote access points, and connections between OT and IT networks. Threat-informed defense depends on this context. The goal is not to treat every asset equally. The goal is to identify the systems most likely to be targeted, the pathways adversaries could use, and the controls that would make those pathways harder to exploit through compensating controls.
Segmentation and Shared Ownership
Once you understand your OT environment, segmentation is one of the most effective ways to reduce risk. Flat networks give adversaries room to move, and poorly controlled connections between IT and OT networks can allow a compromise in one area to spread to systems that support physical operations. IT and OT teams also often have different priorities, vocabularies, and definitions of acceptable risk. Both perspectives are valid, but neither is sufficient alone. When IT and OT teams work together, security decisions become more realistic. Incident response plans can account for safety and production requirements. Executive reporting can reflect both cyber exposure and operational impact.
The objective is not to make OT environments look like IT environments. The objective is to secure them in ways that protect both digital systems and physical operations.
Carl Windsor is Chief Information Security Officer at Fortinet, where he has worked for over 18 years across product security, strategy, the CTO office, system engineering, sales, and product management, including SD-WAN and SASE. He holds a Ph.D. in computational chemistry and quantum mechanics and a B.S. in computational chemistry from the University of Manchester. The views expressed are his own and do not necessarily represent those of Security Guys.


