Fortinet

How OT Connectivity Is Changing the Cyber Risk Equation

OT connectivity cyber risk is growing as industrial organisations connect operational technology to IT networks, cloud platforms, applications, operators and third parties. Artificial intelligence could accelerate that shift by making those connections easier and cheaper to build.

The connections can deliver clear operational benefits. Organisations can use industrial data to improve decisions, optimise resources and identify problems faster. They can also reduce downtime and improve efficiency.

However, every new connection can create another potential route into an OT environment.

For security leaders, the answer isn’t to stop connectivity. Industrial organisations will keep connecting systems because the operational and commercial benefits matter. Instead, cybersecurity teams need to get involved earlier. They can then help build security into how organisations design, deploy and manage those connections.

Michael Murphy, Director, Operational Technology and Critical Infrastructure, APAC, Fortinet, said, “Connectivity is fundamental to modern industrial operations, and AI will accelerate how organisations connect systems and use operational data. The security conversation can’t start after new technology has been deployed. OT and cybersecurity teams need to be involved from the outset so organisations can capture the benefits of modernisation without introducing unnecessary operational risk.”

Michael Murphy at Fortinet

AI Could Increase OT Connectivity Cyber Risk

Industrial digital transformation has long relied on connecting systems, collecting data and turning that information into operational insights. AI could reduce the effort needed to bring information from different environments together.

For example, an AI-enabled industrial application could use information from several systems at once. These could include a manufacturing execution system, a supervisory control and data acquisition (SCADA) environment, a warehouse management system, a maintenance platform, a historian, and a shipping system.

Combining that information could help operators identify production problems and their likely causes faster. However, it also increases the scale of the security challenge.

The issue isn’t AI alone. The risk comes from the connections organisations create that let AI systems and agents access data and interact with operational applications.

As those connections become easier and cheaper to establish, organisations may pursue projects that were previously too expensive or complex.

Michael Murphy said, “AI changes the economics of connecting industrial data. Projects that previously required extensive integration work can become much easier to implement. This creates significant potential for OT operators, yet security teams need visibility of those connections, the data moving across them, and the permissions associated with them.”

Industrial Systems Are No Longer Isolated

This challenge builds on a transformation already underway.

Greater connectivity between IT and OT networks has reduced the isolation that once characterised many industrial environments. Remote operators, original equipment manufacturers (OEMs), service providers, cloud environments and other third parties can now form part of the operational ecosystem.

At the same time, many organisations still depend on legacy assets. Some have operated reliably for decades and weren’t designed for today’s level of connectivity or cyber risk.

Their importance to operations can also make them difficult to change. As a result, organisations may struggle to apply conventional security measures such as frequent patching.

Modern applications and new connectivity therefore increasingly operate alongside long-lived industrial assets.

Michael Murphy said, “Understanding connections is therefore as important as understanding individual devices. Organisations need to know what is communicating, why that communication is required, what information is moving, and what could happen if a connection is compromised.”

OT Cyber Risk Goes Beyond Data

An OT cyber incident can affect more than data or computer systems. It can disrupt production, service availability, equipment, supply chains and physical processes.

Organisations therefore need to assess cyber risk based on operational consequences, rather than relying only on technical severity.

For critical infrastructure operators, that means identifying the assets and processes required to maintain essential services. They also need to understand the dependencies between interconnected environments.

Michael Murphy said, “A vulnerability might look significant from a technical perspective, yet the business question is what it means for the operation. Conversely, an apparently minor system can be critical if other processes depend on it. Organisations need to connect cyber risk to operational consequences so leaders can make informed decisions about where resources and controls are most needed.”

Supply Chain Connections Extend OT Risk

Understanding dependencies also matters because modern supply chains rely heavily on interconnected systems.

Manufacturers, suppliers, logistics providers and infrastructure operators depend on automated systems and digital information flows. Those dependencies can extend well beyond a single industrial site.

As a result, disruption at one point can affect organisations and services elsewhere in the value chain.

Security teams also face a practical problem. Adding security controls after deployment becomes harder as the number and pace of connections increase.

Organisations therefore need to consider security during the design process. That includes assessing how systems will connect before deployment and limiting access to what operations actually require.

Teams should also establish appropriate segmentation, apply strong controls to remote and third-party access, and maintain visibility as environments change.

The objective isn’t to put cybersecurity in the way of modernisation. It’s to make modernisation more resilient.

Michael Murphy said, “OT environments will continue to become more connected because the operational case for connectivity is compelling. Security teams that engage early can help shape those projects rather than trying to retrofit controls later. The goal should be to support innovation while maintaining the availability and resilience that critical operations depend on.

“As AI and digital modernisation reshape industrial environments, connectivity itself needs to become a core part of OT risk management. Organisations that understand their connections, dependencies, and operational consequences will be better placed to adopt new technology while strengthening cyber resilience.”

Shopping Cart0

Cart

Login