Most cyber security advice is written for corporate IT: patch your laptops, rotate your passwords, back up your files. None of it was written with a control room in mind.
If you run technology for a mine site, a processing plant, or an oil and gas facility, you are not just protecting data. You are protecting equipment that moves, heats, pressurises, and can hurt someone if it fails in the wrong way. That is operational technology (OT) security, and it needs a different starting point to IT security.
Why OT is not just “IT with bigger machines”
IT security is built around confidentiality, integrity, and availability, usually in that order. Protect the data first, keep it accurate, keep the lights on.
OT flips that priority. Availability comes first. A pump, a conveyor, or a safety interlock cannot go down for a patch cycle the way an email server can. Many OT systems run on old, unsupported software because the equipment they control is expensive to replace and was never designed to be updated. Passwords are often shared across shifts because a control room operator cannot afford to be locked out during an incident.
None of that is a mistake. It is a different set of constraints, and it means a straight copy-paste of your IT security policy will not work in the plant.
The risk is real and it is growing
Australia’s cyber threat environment has kept getting worse, not better. The Australian Signals Directorate’s Annual Cyber Threat Report for 2024 to 2025 recorded more than 1,200 cyber security incidents, an 11 per cent rise on the year before, with attacks on critical infrastructure up 111 per cent over the same period (cyber.gov.au).
Globally, the picture in energy and resources is sharper again. Ransomware attacks against oil and gas organisations surged 935 per cent between April 2024 and April 2025, and industrial-focused ransomware groups grew from around 80 to 119 in a single year (Dragos).
This is not a reason to panic. It is a reason to know exactly where you stand.
A practical starting point
You do not need to solve everything at once. Start here.
Separate what needs separating. Your OT network should not share a flat network with your corporate IT. If a laptop in the office gets compromised, that should not be a path into the control system.
Know what you actually have. You cannot protect equipment you have not documented. A basic asset inventory of OT devices, what they run, and who is responsible for them is the foundation everything else sits on.
Get eyes on the OT network specifically. Corporate security tools are built for IT traffic. They often cannot see, or do not understand, what normal looks like on an OT network. Purpose-built OT monitoring closes that gap.
Put someone’s name on it. OT security tends to fall into a gap between the IT team and the operations team, with each assuming the other owns it. Assign clear ownership, even if it is shared.
Test it, do not assume it. A basic risk assessment of your OT and ICS environment will tell you more in a few weeks than any policy document will tell you in a year.
Where to go from here
If you are not sure where your organisation sits against these basics, that is exactly what an OT cyber security assessment is for. Our team works specifically in mining, oil and gas, and other asset-intensive environments, so the recommendations we give are built around what is actually achievable on a working site, not a generic IT checklist.
Talk to our OT security team about where to start.