12 Plants, 12 Programs: Why Site-Level Risk Can’t Scale
Hillstrong Group Security ·

Enterprise OT resilience demands more than strong sites—it demands unified governance.
“You don’t need twelve programs. You need one model that flexes.”
Every plant has a story. However, not every plant should have its own program.
In OT security, site-level autonomy has its place. Operational nuances, local vendor ecosystems, and legacy constraints shape risk management.
But the problem is that every site manages cyber risk differently, and leadership loses the ability to compare, prioritize, or act.
Twelve plants. Twelve scorecards. Twelve definitions of “done.”
That isn’t “over” once. It’s fragmented when a risk event occurs; there’s no typical, escalation, or investment baseline.
What Fragmentation Looks Like in Practice
- One plant tags vulnerabilities by CVSS, another uses risk matrices, and a third uses a color-coded spreadsheet from 2018.
- Site A treats remote access as a business function, Site B treats it as an exception, and Site C has no idea who has access.
- Some sites log asset changes weekly as part of their management of change process (MOC), while others never do. One plant manually updates a Visio diagram after each project.
From HQ, the dashboard looks healthy. But underneath, it’s a patchwork of wits ‘ lows, standards, and assumptions.
Which means you can’t answer:
- Where was the greatest exposure?
- Which sites need help first?
- Where should we invest?
And if you can’t answer those questions, you’re not managing your risk. You’re reading plant-status reports.
Even worse, you’re implicitly telling your readership that there is no shared scale for risk across the business.
A Moment That Reframed the Problem
One manufacturing client told us:
“We had five plants in the same country reporting completely different OT maturity levels and the CISO had no idea who was right.”
The problem wasn’t dishonesty. It wasn’t consistent.
Each plant was graded against a different rubric. One had a local consultant, another had a checklist from an old audit, one site’s OT lead was a former IT manager, and another had no security resource at all.
So when it came time to justify a capital request for upgrades, no one could defend the prioritization.
The board asked, “Which sites are most at risk?” No one could answer.
That’s when the CISO realized that maturity doesn’t mean much without a unified lens for comparison. If every plant defines progress differently, there’s no credible way to defend investment, show improvement, or model enterprise risk.
The Cost of Inconsistency
A fragmented governance model carries real risk:
- Inefficient spending: Money goes to sites that advocate best, not those most at risk.
- Audit exposure: Without consistent documentation, global audits become site-by-site battles.
- Cyber insurance complexity: Underwriters struggle to evaluate program effectiveness without enterprise baselines.
- Incident response delays: Every incident is reinvented locally without standard escalation paths.
- Lost trust: When senior leaders realize that scorecards aren’t apples, they lose confidence in all of them.
Fragmentation creates a perception of maturity without the reality of coordination.
And when leadership starts questioning the data, OT risk becomes more challenging to fund, defend, and improve.
Why Site-by-Site Doesn’t Work
Running OT security as twelve independent programs might seem workable in the short term. Each plant has its own budget, its own preferences, its own way of doing things. But this approach doesn’t scale. It fragments oversight, fractures trust, and prevents the organization from gaining any cohesive understanding of enterprise-wide exposure. Over time, it creates:
- Redundant tooling
- Inconsistent controls
- Unverifiable claims
- No roll-up view of enterprise exposure
And when a centralized function (legal, finance, audit) asks for clarity, there’s no normalized way to provide it.
Worse, site-level independence creates hidden inequities:
- Sites with strong leaders get support.
- Sites with weak governance fly under the radar.
- Sites with low maturity avoid scrutiny by reporting success in local terms.
- Sites with unofficial tools and shadow-IT setups bypass standard protocols altogether, introducing risk that’s invisible to enterprise oversight.
Shadow-IT often starts with good intentions—a local engineering team solving a problem fast. But over time, these unapproved systems create data silos, inconsistent practices, and security gaps that can’t be seen, let alone managed. Without enterprise alignment, those gaps become permanent.
- Sites with strong leaders get support.
- Sites with weak governance fly under the radar.
- Sites with low maturity avoid scrutiny by reporting success in local terms.
That’s not a strategy. That’s organizational.
What Smart Organizations Are Doing Differently
The most mature organizations aren’t forcing uniformity. They’re defining a real model.
Here’s how it works:
- Here are the sites by criticality and risk
- Assign operating expectations by tier.
- Centralized assessment, decentralized action.
- Create an enterprise control plane.
- Use the same metrics everywhere.
- Provide support where it’s needed.
This is how governance scales—not by dictating every controversy but by harmonizing how risk is understood.
And that understanding enables strategic decisions:
- Where to invest
- What to defer
- Who to empower
What You Can Do This Week
If you’re your OT lead:
- Ask how your plant compares to others—are you speaking the same language?
- Push for shared definitions of risk, impact, and readiness.
- Volunteer your site for a pilot of the tiered governance model.
If you’re your enterprise risk lead:
- Inventory your governance models. How many different “programs” are you really running?
- Draft an OT site tiering model with 3–4 risk-based categories.
- Define core metrics every site must report, then validate with plant leads.
If you’re a COO, you’re for a unified view of OT risk across your facilities.
- Prioritize investment based on tier, not noise.
- Set a 12-month target to align all sites to a common reporting framework.
A Final Thought
Enterprise resilience isn’t about being perfect. It’s about the site being understood—and every risk being measurable, comparable, and actionable.
You don’t need programs. You need one framework that flexes.
Because if you can’t scale your model, you can’t scale your protection.
And if you can’t compare sites, you can’t protect them equally.
Your Turn
How many different OT security programs are you really running?
And what would it take to unify them without losing local control?
Thank you for reading! Follow us on LinkedIn for future blog, webinar and podcast releases!