Breaking Down Silos: Why IT and OT Must Work Together for Cybersecurity Success
Hillstrong Group Security ·

Our LinkedIn: Hillstrong Group Security

Author’s LinkedIn: Chuck Tommey
Understanding IT/OT Dynamics and Shared Goals
For decades, Information Technology (IT) and Operational Technology (OT) have operated in separate domains, each focusing on different priorities. IT has been responsible for protecting data, ensuring network security, and maintaining compliance, while OT has been focused on keeping industrial processes running efficiently and safely.
But in today’s digital era, IT and OT systems are increasingly interconnected, and cyber threats now target industrial control systems (ICS) just as frequently as they target enterprise IT networks. This convergence presents both opportunities and risks.
The challenge? Merging IT and OT without disrupting operational resilience. The solution? True collaboration between IT and OT, built on a foundation of governance, risk management, and compliance (GRC) designed specifically for OT.
Cybersecurity in industrial environments must directly support the mission of the organization—whether that mission is producing pharmaceuticals, generating power, delivering clean water, or manufacturing critical infrastructure components. Every security initiative must enhance, not hinder, operational resilience.
Let’s explore how IT and OT can break down silos, align on common goals, and work together to build a cybersecurity strategy that strengthens the mission instead of impeding it.
The IT Perspective vs. The OT Perspective: Why the Divide Exists
To truly collaborate, IT and OT must first understand each other’s worldviews.
The IT Perspective: Securing Data and Networks
For most IT teams, cybersecurity is focused on data:
• Confidentiality – Protecting sensitive information from unauthorized access.
• Integrity – Ensuring that data isn’t altered maliciously.
• Availability – Keeping systems online and responsive to support business operations.
• Compliance – Meeting regulatory or standards requirements such as HIPPA, CFR 17 229.106 (SEC reporting requirements), ISO 27001, and/or CMMC.
Because IT networks are constantly under attack, IT professionals are accustomed to rapid software patching, multi-factor authentication, and strict access controls. IT views cybersecurity as a technical discipline governed by strict policies and regular updates.
The OT Perspective: Keeping Operations Running
In contrast, OT professionals prioritize operational resilience:
• Safety – Protecting human lives and preventing catastrophic failures.
• System Availability – Ensuring production and operational processes never stop unexpectedly.
• Reliability Over Change – IT may update systems weekly, but OT systems cannot tolerate frequent changes without risk to operations.
• Legacy Systems – Many OT assets have 20+ year lifespans and were not designed with cybersecurity in mind.
In OT, uptime is paramount. A well-intentioned IT security patch could shut down an assembly line just as completely as a mal-intentioned cyber attack. Either way, a shutdown could lead to millions in lost production, reputational damage, and possible safety hazards. This is why OT has historically resisted IT-driven security initiatives.
The Shared Goal: Safeguarding the Organization’s Mission
Despite their differences and whether they realize it or not, IT and OT are ultimately working toward the same overarching goal: Protecting the critical systems that enable the organization to fulfill its mission.
Whether it’s delivering power, treating water, producing goods, or enabling public safety, IT and OT must align their cybersecurity efforts with the organization’s core objectives.
A one-size-fits-all approach to cybersecurity does not work in OT environments—security initiatives must be tailored to industrial processes without sacrificing operational continuity.
A successful IT/OT collaboration strategy must:
Balance security and operational uptime.
Align cybersecurity with business and production goals.
Use an OT-specific GRC framework to guide collaboration for the long-term.
How an OT-Specific GRC Program Can Align IT and OT
Governance, risk management, and compliance (GRC) frameworks help establish clear roles, responsibilities, and procedures for both IT and OT. However, when attempts are made to apply traditional IT GRC models directly into OT environments, it often ends up alienating the OT teams. This has led to a lack of formal OT GRC programs in OT environments and even a lack of cooperation between IT and OT. When both teams feel the other has no idea what is important to get the job done, they don’t make time to resolve their differences.
This is where an OT-specific GRC program becomes essential. Frameworks like NIST CSF 2.0 can incorporate the structured guidance of OT-specific cybersecurity standards (e.g., NIST SP 800-82r3 and IEC 62443), moving the organization toward formally securing its industrial environments while maintaining operational integrity. When OT builds a GRC program, ideally with IT’s assistance, both teams can better understand how to work together.
The Role of OT-Specific GRC in IT/OT Collaboration:
Governance: Defines roles, responsibilities, and policies specific to OT security.
Risk Management: Assesses vulnerabilities in OT systems and aligns risk mitigation with operational requirements.
Compliance: Ensures cybersecurity efforts support regulatory needs without disrupting operations.
When properly implemented, an OT-focused GRC program serves as a bridge between IT and OT, creating a common framework for security initiatives.
Bridging the Gap: Steps to Align IT and OT
To move beyond IT/OT silos, organizations must intentionally foster collaboration between both teams.
Step 1: Establish a Shared Security Framework
Use NIST CSF 2.0, IEC 62443, and CMMI to create a common security language for IT and OT teams. NIST CSF encourages the creation of custom Organizational Profiles to better reflect the needs of highly diverse OT environments.
Step 2: Conduct Joint Risk Assessments
IT and OT must work together to:
Identify vulnerabilities in industrial systems.
Prioritize security fixes based on operational impact.
Implement layered security measures (such as network segmentation and access controls).
Step 3: Build a Culture of Trust and Communication
Encourage regular cross-team meetings where IT and OT can:
Discuss security concerns.
Align on security goals that support operations.
Share lessons learned from past incidents.
Step 4: Implement OT-Specific Security Policies
Standard IT policies often fail in OT environments. Instead, organizations should:
Use compensating controls for unpatchable systems.
Implement role-based access control (RBAC) specific to OT.
Ensure network segmentation to isolate critical OT assets from external threats.
By integrating these steps into a formal OT GRC program, organizations can harmonize IT/OT efforts without jeopardizing production.
Conclusion: A Call for Partnership
IT and OT cannot afford to work in isolation—the growing number of cyberattacks on industrial environments demands a collaborative, risk-based approach to security.
The goal is not just cybersecurity—it’s operational resilience.
Every security initiative must support the organization’s mission.
An OT-specific GRC program can serve as the foundation for a well-functioning IT/OT partnership.
By breaking down silos, building trust, and aligning security with operational goals, IT and OT can work together to protect the systems that drive the organization forward.