When Patching Won’t Protect Your Factory
Hillstrong Group Security ·

Roger Hill
Why Smart OT Security Leaders Are Moving Beyond Vulnerability Metrics
Spend enough time in manufacturing cybersecurity and you’ll start to see a pattern.
Visit a major site, meet the OT security team, and someone will pull up a dashboard (or more than likely a spreadsheet). More often than not, the first thing they’ll show you is vulnerability data: total CVEs, patch progress, or trends over time.
It looks good. It feels like progress.
But here’s the uncomfortable truth: when production stops, it’s rarely because of an unpatched CVE. It’s almost always something no one tested.
Yet we’ve trained boards and CISOs to believe that patching equals protection. In OT, that thinking can quietly erode the very resilience those same leaders believe they’re building.
The Hidden Problem
Why is vulnerability management at the center of so many OT security programs?
Because it’s easy to measure. It’s easy to report. And it gives leadership a clean, ascending line on a graph.
Boards love that. CISOs love that. It provides an illusion of control in a domain full of uncertainty.
But that same comfort is part of the problem.
In most OT environments, patching every CVE is impossible. Some systems will never be patched – unsupported PLCs, vendor-locked appliances, or industrial protocols that were never designed for security.
And patching alone doesn’t correlate with production resilience. According to a recent analysis by the Hillstrong team, in more than 80% of recent OT-related disruptions we reviewed, the root cause was not an exploited CVE. It was an operational failure – a process gap, a fragile dependency, or an unvalidated system change.
Meanwhile, the real risks are multiplying:
- Change control breakdowns
- Legacy dependencies no one has validated in years
- Operational fragility created by human error
- Hidden interdependencies between fragile IT services and critical OT production systems
None of these risks appear on a vulnerability scan. But they are exactly what will bring your factory to a halt.
Real-World Flashpoint
I saw this first-hand with a global manufacturer running what most would call a “model” OT vulnerability management program.
Ninety-five percent mitigated vulnerability compliance across industrial endpoints (Note mitigated, not just remediated by patching). Detailed board reports. A well-resourced team.
And then it happened.
A routine patch to an IT service triggered authentication failures in several OT applications. MES systems were suddenly unreachable. Control engineers couldn’t log in. Production lines slowed, then stopped entirely at multiple sites.
No ransomware. No malware. No external threat.
Just an unvalidated change to a fragile dependency.
I remember speaking with one of their lead OT engineers during the incident.
“We thought we were protected,” he said. “We had the best patch numbers in the company. But no one had tested what would happen if the Production Active Directory went sideways.”
I also heard from a plant supervisor that day:
“All the dashboards said green. On the floor, we were red.”
The lesson was clear. The metrics that made leadership feel secure didn’t help when the real test came.
Strategic Pivot
The smartest companies I see are changing the conversation.
First, they acknowledge that patching is still necessary. Hygiene matters. But in OT, resilience has to lead.
They understand that even a perfectly patched environment can fail if the wrong system dependency breaks. And they no longer wait for perfect patch compliance to start building survivability.
They’re asking better questions:
- If this system fails, can we still produce safely?
- Where are our single points of operational failure?
- Which legacy dependencies create business-critical risk that no vulnerability scan will ever flag?
- Have we validated our recovery paths – or are we assuming they’ll work?
And they’re shifting what they show boards. Less about CVSS scores. More about operational consequences and business risk.
One global manufacturer I work with now leads its board discussions with a simple but powerful map: the company’s most critical production dependencies, with clear status indicators for each recovery path.
If a key system fails, they can show exactly how prepared they are to keep operating – and where the gaps remain.
That’s the kind of clarity boards need. And it’s the kind of resilience-focused framing that Hillstrong has been helping clients adopt for years.
Takeaway
If your OT security program is still celebrating patch progress as its primary measure of success, it’s time to reassess.
Patching has its place. But in the real-world disruptions I see, it’s rarely the deciding factor in whether a factory can keep running.
And waiting to achieve perfect patch compliance before building resilience is a dangerous trap. The best organizations develop survivability capabilities in parallel, not as a final phase.
The question to ask is this:
If one of your critical systems failed tomorrow, whether from a cyber event, human error, or an untested change, how confident are you that operations would continue safely?
That’s the battle worth fighting.
And it’s one that too many organizations still aren’t prepared for.
To think on…
Think back to the last major production disruption your company faced.
Was it caused by an unpatched CVE?
Or by something no one had validated?
If you haven’t mapped your top five operational dependency risks, start there.