How to Build a Sustainable OT Vulnerability Management Program
Hillstrong Group Security ·

From project to practice: embedding VM in your OT security lifecycle
Author: Roger Hill
There’s no shortage of urgency when it comes to OT vulnerability management. The threat landscape keeps expanding. Regulatory pressure keeps mounting. And vendors keep promising solutions that will solve it all with one more sensor, scanner, or platform.
But if experience teaches one thing in this space, it’s that no technology can compensate for the absence of a sustainable program. Tools come and go. The real impact is created through governance, alignment, and consistent execution -especially in the high-stakes, high-friction environments that define industrial operations.
Building an OT vulnerability management program that lasts means accepting a few hard truths. First, you can’t fix everything. Second, some risks will persist for years. Third, success isn’t measured by how many vulnerabilities you close – it’s measured by how effectively you reduce risk without disrupting what the business is built to deliver.
From Scanning to Strategy
Most OT vulnerability efforts start with a scanning exercise. That’s fine—visibility matters. However, the gap between asset discovery and actual risk reduction is wide. If you don’t define what happens after the scan, you’ve just added noise.
What does a sustainable program look like? It has clear ownership, defined decision paths, and repeatable processes for triage, mitigation, and monitoring. It integrates with operations, not just IT. And it doesn’t fall apart when one SME leaves or one platform changes.
Think of it as an operating rhythm—not an incident response plan. It has to run monthly, quarterly, and annually across a fleet of sites, each with its own constraints.
Define Roles and RACI Early
One of the first cracks in most programs shows up around ownership. Who owns remediation? Who owns exception approval? Who determines whether a compensating control is adequate?
This is where RACI comes in—Responsible, Accountable, Consulted, and Informed. But in OT, the standard IT RACI often misses the mark. You need to account for:
-
Plant operations leadership
-
Controls engineering teams
-
EHS or quality stakeholders
-
IT security and GRC functions
Too often, decisions get bottlenecked because the wrong group is driving – or worse because no group is.
Establishing your RACI early prevents drift. It also builds clarity when sites push back on remediation due to production concerns. You’re not escalating the issue – you’re following the program.
Centralized Governance, Decentralized Execution
Industrial enterprises tend to be federated. That’s not going to change. Trying to enforce a monolithic vulnerability program across vastly different sites rarely works.
Instead, your goal should be to build a centralized governance model with site-level flexibility. That means:
-
Defining corporate standards and thresholds (e.g., max allowable time-to-mitigate for criticals)
-
Providing a shared playbook for triage and exception handling
-
Allowing sites to implement controls that match their unique systems and staffing
Your program must account for everything from legacy Windows 7 HMIs in one plant to air-gapped microcontrollers in another. This requires a uniform process and localized adaptation.
Make Risk Reporting Real
Executives don’t want vulnerability lists. They want decision context. That’s where the work you’ve done with RISE and QUICK becomes invaluable.
Instead of reporting “We have 374 open vulnerabilities,” report:
-
The percentage of OT assets with a risk-adjusted mitigation plan
-
The number of high-risk vulnerabilities mitigated this quarter
-
Sites with the highest risk density by asset function and business impact
You’re telling a risk story, not reciting technical inventory. That builds credibility with the board and with plant leadership.
Normalize Exceptions – But Track Them
In IT, the idea of permanent exceptions to patching feels uncomfortable. In OT, it’s often necessary. But that doesn’t mean it should be unmanaged.
Build an exception process that tracks:
-
Why remediation wasn’t feasible
-
What compensating controls were applied
-
When the exception will be reviewed again
A site that has 10 exceptions but full documentation and layered controls is in a much better place than one that claims perfect compliance but can’t explain its risk posture.
Invest in Repeatable Cycles
You don’t need a perfect program on Day 1. What you need is a cadence: monthly vulnerability review meetings, quarterly scorecard updates, and annual risk reclassification.
Over time, this rhythm does more than close gaps—it changes culture. It makes vulnerability management part of how you operate, not something that spikes before audits.
You’ll also start to see the benefits compound. The same asset classification that informs vulnerability prioritization can inform segmentation projects, procurement reviews, and detection rule tuning.
Security becomes embedded—not bolted on.
Don’t Let the Program Die on Paper
The final trap I’ve seen is beautiful policies and frameworks that live in SharePoint and never make it to the shop floor. Don’t mistake documentation for execution.
Go walk the line. Sit with the control engineers. Ask what works, what doesn’t, and what gets ignored. You’ll quickly find out where the gaps are—and where the real levers of change live.
A sustainable vulnerability management program is pragmatic, visible, and rooted in how people work. Anything less will collapse under the weight of operational complexity.
The Path Forward
You’ve now seen the pieces:
-
Why patching alone fails in OT
-
How to rethink CVSS in context
-
How to prioritize using RISE
-
How to understand asset value with QUICK
-
And how to build a program that brings it all together
The path to resilience isn’t paved with tools—it’s built through alignment, adaptation, and sustained effort. Vulnerability management in OT isn’t a sprint or a checkbox. It’s a commitment to protecting what matters in the ways that matter most.
This is the work. And it’s how we move the mission forward.
If you aren’t already, follow us on LinkedIn for upcoming OT Cyber eBooks, blogs and webinars!