The OT Disclosure Gap
Hillstrong Group Security ·
What Your 10-K Is Missing (And What Regulators Will Notice)
Most manufacturers’ annual risk factor disclosures describe OT risk in IT language. That gap is about to become visible to regulators, investors, and plaintiffs’ attorneys alike.
The Filing Nobody Reads Until It Matters
Every publicly traded company files an annual 10-K with the SEC. Buried inside that filing, usually in Item 1C (Cybersecurity), is a description of the company’s cybersecurity risk management, strategy, governance, and the board’s oversight of cybersecurity risk.
For most manufacturers, this section reads like it was written by a law firm that has never walked a factory floor. And in most cases, it was.
The language is careful, generic, and thoroughly IT-centric. You will find references to “information systems,” “data protection,” “network security,” and “business continuity.” You will find descriptions of CISOs reporting to audit committees, incident response plans tested through tabletop exercises, and third-party risk assessments conducted annually.
What you will almost never find is an honest description of what happens when a cyberattack compromises the systems that control physical manufacturing processes.
This is the OT disclosure gap. And it is not just an oversight. It is a material misrepresentation of the risk profile of every manufacturer with significant operational technology environments.
Last week, I wrote about why OT incidents break SEC materiality rules. This week, I want to focus on the quieter problem: the annual disclosures that are supposed to give investors a clear picture of cybersecurity risk but systematically exclude the most consequential attack surface in manufacturing.
What Regulators Actually Require
The SEC’s cybersecurity disclosure rules, adopted in July 2023, require registrants to disclose in their annual 10-K filings:
- Their processes for assessing, identifying, and managing material cybersecurity risks
- Whether any risks from cybersecurity threats have materially affected or are reasonably likely to materially affect the company
- The board of directors’ oversight of cybersecurity risks
- Management’s role in assessing and managing cybersecurity risks
Notice what the rule does not say. It does not say “IT cybersecurity risks.” It says “cybersecurity risks.” The SEC’s adopting release makes clear that “information systems” includes systems that control physical infrastructure. The rule is technology-agnostic in its scope.
But the disclosures are not.
I have reviewed the cybersecurity sections of 10-K filings from dozens of publicly traded manufacturers across chemicals, automotive, food and beverage, pharmaceuticals, and heavy industry. The pattern is remarkably consistent:
What they include: References to enterprise IT security programs, SOC capabilities, data protection measures, employee awareness training, third-party audits (usually ISO 27001 or SOC 2), and incident response plans.
What they leave out: Any specific mention of operational technology, industrial control systems, SCADA, PLCs, safety instrumented systems, or the unique risk characteristics of cyber-physical environments. Any acknowledgment that a cyberattack on their manufacturing systems could cause physical harm, environmental releases, or production losses that operate on a fundamentally different risk curve than IT system compromises.
The gap is not subtle. It is a chasm.
Why the Gap Exists
This is not a conspiracy. It is a structural problem with how cybersecurity disclosure gets produced.
The Disclosure Pipeline
At most publicly traded manufacturers, the 10-K cybersecurity section is drafted by outside counsel, reviewed by the CISO or VP of IT Security, approved by the disclosure committee, and signed off by the CFO. The process works on a tight timeline during annual reporting season. The drafters work from templates. The templates are built around IT security frameworks.
The OT security team, if one exists, is rarely in this pipeline. At many manufacturers, OT security reports through operations or engineering, not through the CISO. The people who understand the plant floor risk are organizationally disconnected from the people who draft SEC filings. Nobody is deliberately hiding OT risk. It simply does not enter the workflow.
The Knowledge Gap
Most securities lawyers have a working understanding of IT cybersecurity risk. They understand data breaches, ransomware, and business email compromise. They do not understand what a distributed control system does, why a compromised PLC is different from a compromised server, or what the consequence chain looks like when a safety instrumented system fails.
Ask a securities lawyer what happens when an attacker modifies a PLC program, and you will get a blank stare. Ask them what happens when a data breach exposes 10 million customer records, and they can give you a detailed cost analysis. The disclosure reflects the knowledge of the people writing it.
The Incentive Problem
There is also a quiet incentive to keep OT risk out of the disclosure. Describing specific OT vulnerabilities creates potential liability. If you disclose that your manufacturing control systems are vulnerable to cyberattack and then an incident occurs, plaintiffs’ attorneys will point to your own filing. If you keep the language generic, you have more room to argue that the specific incident was unforeseeable.
This logic is understandable but ultimately self-defeating. The SEC’s rules require disclosure of material cybersecurity risks. If your most consequential attack surface is your OT environment, and your disclosure does not mention it, you have not reduced your liability. You have created a different kind of liability: the failure to disclose a known risk.
What a Real OT Risk Disclosure Looks Like
Let me show you the difference between what most manufacturers file and what an honest OT-inclusive disclosure would look like.
Typical Disclosure (Paraphrased)
“We maintain a comprehensive cybersecurity program designed to protect our information systems and data. Our program includes network monitoring, access controls, employee training, and regular third-party assessments. Our CISO reports to the Audit Committee quarterly. We have not experienced a material cybersecurity incident in the reporting period.”
OT-Inclusive Disclosure (What It Should Say)
“Our operations rely on industrial control systems, including programmable logic controllers, distributed control systems, and safety instrumented systems, to manage manufacturing processes across [X] facilities. These operational technology systems present cybersecurity risks distinct from our enterprise IT environment, including the potential for production disruption, worker safety incidents, environmental releases, and equipment damage in the event of unauthorized access or manipulation.
Our cybersecurity program addresses both IT and OT environments, though OT security assessments and controls operate on different timelines and with different constraints than IT security due to the continuous operation requirements of our manufacturing processes and the limited patching availability for legacy control system components.
We have identified key person dependencies in our OT security program, with specialized control system expertise concentrated among a limited number of personnel. We maintain [specific measures] to mitigate this risk.
Our incident response plan includes procedures specific to OT environments, recognizing that forensic investigation of industrial control systems requires specialized capabilities and typically extends over longer timelines than IT incident investigation.”
The difference is not just specificity. It is honesty about the risk profile. The first version could describe any company in any industry. The second version tells an investor what it actually means to own stock in a company that runs chemical reactors, stamping presses, or pharmaceutical batch processes controlled by networked industrial systems.
The Counterargument and Why It Fails
I hear two common objections when I raise this with general counsel and disclosure committees.
“We don’t want to paint a target on our back.” The concern is that detailed OT risk disclosure tells attackers where to look. This argument does not hold up. Attackers already know that manufacturers run PLCs and DCS systems. The vulnerabilities are publicly documented. In 2025 alone, 2,451 new ICS vulnerabilities were disclosed across 152 vendors. Your 10-K disclosure is not providing attack intelligence. It is providing investor intelligence.
“The SEC hasn’t pushed back on our current disclosure, so it must be adequate.” This is the most dangerous assumption. The SEC’s cybersecurity rules are still in their early enforcement phase. The Commission has issued guidance, not enforcement actions, because it is building a baseline. That will not last. When the first major OT cyber incident at a publicly traded manufacturer causes production losses, safety events, or environmental damage, the SEC will look at the prior 10-K disclosures. If the disclosure described a generic IT security program and said nothing about OT risk, the company will face a securities fraud investigation on top of everything else.
The risk of inadequate disclosure is asymmetric. If you disclose OT risk honestly and manage it well, investors reward transparency. If you hide OT risk behind generic language and an incident reveals the gap, you face SEC enforcement, shareholder lawsuits, and a credibility collapse that compounds the operational damage.
What Investors Are Starting to Ask
The sophisticated institutional investors are ahead of the regulators on this. ESG and operational risk analysts at major funds are starting to ask questions that most manufacturers cannot answer:
- What percentage of your cybersecurity budget is allocated to OT versus IT?
- How many of your manufacturing facilities have been assessed for OT cybersecurity risk in the last 24 months?
- Do you have dedicated OT security personnel, or does IT security cover OT as a secondary responsibility?
- What is the mean time to detect a compromise in your OT environment versus your IT environment?
- Have you conducted consequence-based risk assessments for cyber events at your highest-criticality production facilities?
These questions are coming in investor calls, in proxy advisor reports, and in pre-investment due diligence. Manufacturers who cannot answer them are already at a disadvantage in capital markets. The 10-K disclosure gap is not just a regulatory issue. It is a capital markets credibility issue.
A Strategic Approach to Closing the Gap
I am not suggesting that manufacturers dump their entire OT vulnerability assessment into a public filing. That would be irresponsible. What I am suggesting is a principled approach to OT risk disclosure that satisfies the SEC’s requirements without creating unnecessary exposure.
Describe the risk category honestly. Acknowledge that your operations depend on industrial control systems and that these systems present cybersecurity risks with potential physical consequences. This is not proprietary information. It is an observable fact about every manufacturer.
Distinguish OT from IT in your risk management description. Explain that OT security requires different approaches, timelines, and expertise than IT security. This demonstrates sophistication, not weakness.
Disclose your governance model for OT risk. Who is responsible? How does OT risk information reach the board? If OT security reports through operations rather than IT, say so. The governance structure matters to investors.
Acknowledge the inherent challenges. Legacy systems, patching constraints, key-person dependencies, and forensic limitations are real. Disclosing them as managed risks is better than pretending they do not exist.
Quantify where you can. Number of facilities assessed, percentage of OT assets inventoried, investment in OT-specific security capabilities. Quantitative disclosures build investor confidence far more than qualitative assurances.
What You Can Do Before Your Next 10-K Filing
- Pull your current 10-K cybersecurity disclosure and red-team it. Have someone with OT operational knowledge read it and mark every statement that is either misleading or incomplete when applied to your OT environment. The markup will be extensive.
- Add your OT security lead to the 10-K review process. They do not need to draft language. They need to review it for accuracy and completeness regarding the operational technology environment.
- Build an OT risk fact sheet for your disclosure committee. A two-page document that describes your OT environment in business terms: what systems control what processes, what the consequences of compromise look like, and what your current security posture is. Update it annually.
- Benchmark against peers. A few manufacturers are starting to include OT-specific language in their disclosures. Find them. Use them as reference points for what your own disclosure should contain.
- Engage your outside counsel early. Do not wait for filing season. Have the OT disclosure conversation now, when there is time to get the language right without the pressure of a filing deadline.
What Comes Next
Next week, we tackle the hardest operational problem in this entire series: what happens when you need to investigate an OT incident on the SEC’s disclosure timeline, but the forensic realities of industrial control systems mean you cannot yet fully understand what happened. The manufacturing double bind between disclosure and forensics is where the SEC rules meet the physical world, and where most manufacturers are completely unprepared.
The 10-K is your first line of defense. Get it right, and you build credibility with investors, regulators, and your own board. Get it wrong, and you are writing your own plaintiff’s exhibit.
How does your organization handle OT risk in its public disclosures? Have you seen a 10-K that actually gets it right? I am genuinely curious because I have not found many.