Most cyber attacks on OT environments do not start in OT. They start in IT, and then travel.
Recent industry research puts a hard number on this: 96 per cent of OT security incidents originate from an IT-level compromise (SANS Institute, cited via Industrial Cyber, 2025). The control system itself is rarely the weak point. The path in is.
That is the reality of IT/OT convergence, and it is why treating OT security as a bolt-on to your existing IT security program leaves a gap that is easy to walk through.
What convergence actually means
IT/OT convergence is the trend of operational technology becoming more connected to corporate IT systems, cloud platforms, and remote access tools. It happens for good reasons: better data for decision-making, remote monitoring of remote sites, easier vendor support.
The problem is that convergence often happens faster than the security model catches up. Networks that were designed to be air-gapped end up with a data historian talking to the cloud, a vendor’s remote access tool sitting on the OT network, or a shared identity system that was never designed with OT’s constraints in mind.
Why your existing IT security approach will not cover this
Traditional IT security tools are built to understand IT traffic: web requests, email, standard network protocols. Point the same tools at an OT network and they often cannot tell you what normal looks like, because OT protocols and traffic patterns are different, and the tools were never trained on them.
IT security also assumes you can patch quickly and restart systems as needed. Neither assumption holds in a live operational environment, where an unplanned restart can mean unplanned downtime, and a patch might break certified, safety-critical equipment.
And IT security policy generally prioritises confidentiality first. In an OT environment, availability and safety come first. A security control that protects data at the expense of uptime is solving the wrong problem on site.
Where the real exposure sits
Oil and gas organisations currently show the highest rate of malware protection and detection gaps of any sector, at 37 per cent of findings, alongside the worst vulnerability management gaps at 31 per cent (Fortinet, 2026 State of Operational Technology and Cybersecurity Report). Given that most incidents start on the IT side, these gaps are not just an OT problem, they are a converged-network problem.
The response from industry has been to spend more on OT-specific security: 88 per cent of organisations increased OT security spending by more than 10 per cent in 2025 (TXOne Networks). Spending without the right architecture behind it, though, does not close the gap on its own.
What a converged security approach actually looks like
Network segmentation between IT and OT, enforced technically, not just on paper. Separate identity and access management, so a compromised IT credential cannot walk into the OT environment. Monitoring tools that are built for, or tuned to, OT protocols specifically. And clear governance that puts one team, or a clearly shared arrangement, in charge of the boundary between the two environments.
None of this replaces good IT security. It sits alongside it, purpose-built for the point where the two environments meet.
Get the boundary right
If your IT and OT environments have converged faster than your security architecture has, our IT/OT engineering and advisory and OT cyber security teams can assess where the real exposure sits and what to fix first. Get in touch to talk it through.