IT and OT Collaboration: The Key to Comprehensive OT Cybersecurity
Hillstrong Group Security ·

Our Linkedin: Hillstrong Group Security
Author: Chuck Tommey
In today’s interconnected landscape, organizations rely on seamless IT and OT integration for efficient operations. IT manages data and information systems, while OT oversees the physical processes and automation crucial to productivity. Although IT/OT convergence drives efficiency and innovation, it also introduces complex cybersecurity challenges.
After more than a decade of OT cybersecurity efforts, one lesson is clear: convergence is not enough—true collaboration is essential to secure operations and align cybersecurity efforts with the organizational mission. For organizations to ensure operational resilience and adopt advanced technologies safely, IT and OT teams must break down silos and work together.
Understanding IT/OT Dynamics and Shared Goals
Traditionally, IT and OT have operated in silos, each with distinct priorities and cultures. IT focuses on data confidentiality, integrity, and availability, while OT emphasizes safety, reliability, and the continuous operation of physical processes. These differences can lead to misunderstandings and gaps in security postures.
However, both domains share a fundamental objective: safeguarding the systems that enable the organization to achieve its mission. Recognizing and emphasizing this shared goal is the first step toward bridging the IT/OT divide. By fostering mutual understanding and respect, organizations can create a unified approach to cybersecurity that leverages the strengths of both teams.
One of the most significant areas where IT and OT can align their shared goals is in Governance, Risk, and Compliance (GRC), a critical yet often overlooked aspect of cybersecurity.
GRC: A Key Area for IT/OT Collaboration
Governance, Risk, and Compliance (GRC) is a cornerstone of effective cybersecurity, yet it is often underdeveloped in OT environments. This lack of GRC maturity is one of the main reasons for failed, stalled, or regressing OT cybersecurity initiatives.
On the other hand, IT teams often have well-established GRC programs with Board and C-level sponsorship, robust review processes, and deep institutional knowledge. By collaborating with their IT colleagues, OT teams can build comprehensive, OT-specific cyber GRC programs that are integrated into the broader organizational context from the outset.
For example, IT teams with experience in ISO 27001—a standard that outlines a risk-based, enterprise-level Information Security Management System (ISMS)—can provide valuable insights for OT teams pursuing NIST CSF, IEC 62443-2, or CMMC certifications. These IT frameworks often serve as a close analog to OT standards, and existing IT cyber policies and procedures can serve as a foundation for OT-specific documentation.
More importantly, IT’s institutional knowledge can help OT teams accelerate integration into organizational governance practices. This collaboration ensures that cybersecurity efforts not only meet technical requirements but are also aligned with enterprise risk management and compliance objectives.
Don’t Overlook the Role of Plant Safety
Another key partner for OT teams in cybersecurity efforts is the plant safety organization. Safety teams share OT’s focus on ensuring reliable and secure physical processes, making them natural allies in aligning cybersecurity initiatives with operational priorities.
By collaborating with safety teams, OT can incorporate cybersecurity measures into existing safety protocols and processes. This partnership ensures that risks are addressed holistically, accounting for safety and security concerns. For example, physical safety systems like emergency shutdown mechanisms can be reinforced with cybersecurity protections to guard against potential cyber-physical attacks. The safety organization is often structured similarly to a well-developed OT cyber organization, operating on a forward-looking, continuous improvement model. As such, the OT cyber team can quickly learn from the safety team how to build a critical oversight organization within the OT environment.
Through collaboration with IT and safety teams, OT can create a cybersecurity program that is not only technically robust but also operationally practical and aligned with the organization’s overall mission.
Conclusion: Breaking Down Silos to Build Resilience
In a rapidly evolving threat landscape, IT/OT collaboration is no longer optional—it’s a necessity. Organizations can strengthen their cybersecurity posture while driving operational resilience by aligning shared goals, leveraging IT’s expertise in GRC, and working with plant safety teams.
The key to success lies in fostering open communication and mutual respect between IT and OT teams. Each brings unique strengths to the table, and together, they can create a unified approach to cybersecurity that safeguards both digital and physical assets.
Whether you’re an IT or OT leader, now is the time to break down silos and start meaningful collaboration. Together, you can enable new and emergent technologies that drive efficiency and secure the critical systems that power your organization’s mission.