Michael Murphy - Fortinet

Turning Operational Technology Cyber Risk Into Operational Resilience

Improving OT cyber resilience starts with visibility. However, knowing what is connected is only the first step. Organisations also need to understand how assets communicate, which systems are critical to operations, where vulnerabilities exist, and which controls can contain an incident without disrupting production or essential services.

This challenge is becoming more important as industrial environments combine legacy operational technology (OT) with modern applications, remote connectivity, cloud services, and artificial intelligence (AI). As the attack surface expands, organisations need to move beyond individual security products and build a coordinated approach to OT cyber resilience.

Michael Murphy, Director, Operational Technology and Critical Infrastructure, APAC, Fortinet, said, “OT cybersecurity must start with understanding the environment. Organisations can’t effectively protect or segment assets they don’t know exist. However, visibility only creates value when organisations use that information to make better decisions about access, segmentation, vulnerabilities, and incident response.”

OT Cyber Resilience Starts With Asset Visibility

Industrial environments can contain programmable logic controllers (PLCs), human-machine interfaces (HMIs), engineering workstations, sensors, servers, networking equipment, and other specialised systems.

Some assets can remain operational for decades. As a result, multiple generations of technology often coexist within the same industrial environment.

Building and maintaining an accurate asset inventory is therefore an important first step towards OT cyber resilience. However, organisations need more than a list of devices.

Security and operational teams need context. They must understand what each asset does, how important it is to the operational process, which systems it communicates with, and whether known vulnerabilities affect it.

This context lets teams prioritise cybersecurity according to operational risk instead of treating every device and vulnerability equally.

Michael Murphy said, “OT teams need to understand normal behaviour across the environment. Which devices should communicate? Which protocols should they use? Who should have access? Establishing that baseline gives organisations a stronger position for identifying unexpected activity and applying controls without unnecessarily affecting operations.”

Segmentation Strengthens OT Cyber Resilience

Once organisations understand their assets and communications, segmentation becomes an important control for reducing exposure.

Flat networks can make it easier for an attacker or compromised device to move between systems. Segmentation and micro-segmentation can restrict communication according to operational requirements. These controls create boundaries between systems and help limit lateral movement.

However, OT environments present an additional challenge. Organisations must implement these controls without interrupting processes that depend on reliable and predictable communications.

Understanding existing traffic patterns helps security and operational teams identify which communications are necessary before they enforce more restrictive policies.

Michael Murphy said, “Access controls are equally important. Employees, contractors, vendors, original equipment manufacturers (OEMs), and service providers may require remote access to industrial environments. That access should be limited according to role and operational need, with activity appropriately controlled and monitored.”

Vulnerability Management Supports OT Cyber Resilience

Patching remains a fundamental cybersecurity practice, but OT environments create practical constraints.

Taking a critical industrial asset offline to apply a patch may not always be possible. Organisations may also need to extensively test patches to make sure they don’t affect sensitive processes or unsupported legacy technology.

As a result, organisations need compensating controls when immediate remediation isn’t practical.

Virtual patching can help protect vulnerable systems against known exploits at the network layer without directly changing the asset. This approach can provide additional protection while operators test, schedule, or otherwise manage permanent remediation.

Michael Murphy said, “The answer to an OT vulnerability can’t always be to patch immediately. Operational availability and safety requirements need to be considered. Security teams need options that help reduce exposure while giving operators the time required to manage remediation appropriately.”

Threat Intelligence Improves OT Cyber Resilience

Effective OT cybersecurity also depends on understanding attacker behaviour and translating that knowledge into controls that are relevant to industrial environments.

Threat intelligence can help organisations identify malicious activity, known vulnerabilities, suspicious communications, and emerging attack techniques.

Its value increases when organisations combine threat intelligence with knowledge of their assets, communications, and operational priorities. This approach can help teams distinguish meaningful threats from unnecessary noise.

Michael Murphy said, “Lessons from real incidents also reinforce the importance of fundamentals, including network segmentation, secure remote access, multifactor authentication, vulnerability management, and visibility across the environment. These measures can help contain malicious activity before it spreads more broadly through an operational network.”

How AI Can Support OT Cyber Resilience

AI has a growing role in helping security teams manage increasingly complex industrial environments.

However, AI should not replace established security controls or human decision-making. Instead, organisations can use AI to analyse large volumes of information, identify unusual behaviour, investigate events, and bring relevant security context together faster.

This capability can help security teams prioritise their attention without removing human oversight from critical operational decisions.

Michael Murphy said, “AI is most useful when it strengthens the security practices organisations already need. Visibility, segmentation, access control, vulnerability management, and incident response remain fundamental. AI can help teams work with that information faster and identify where attention is needed; however, it shouldn’t become a substitute for the underlying controls.”

OT Cyber Resilience Requires Integrated Security

No individual control can address every OT cybersecurity challenge.

Visibility without segmentation can make organisations aware of risk without giving them the controls needed to contain an incident. Segmentation without accurate asset information can create operational problems. Threat intelligence without environmental context can add noise rather than improve decisions.

An integrated approach can connect asset visibility, network controls, secure access, threat intelligence, vulnerability management, and security operations.

Bringing these capabilities together gives security and operational teams a consistent view of the environment. It also helps them make better decisions about cyber risk while protecting operational availability.

Michael Murphy said, “Cyber resilience comes from layers. Organisations need to know what they have, understand how it communicates, restrict unnecessary access, protect vulnerable systems, and be prepared to respond when something goes wrong. Bringing those capabilities together helps turn visibility into practical risk reduction while maintaining the reliability OT environments demand.

“For critical infrastructure operators, the objective extends beyond preventing incidents. Organisations need to maintain essential operations when disruption occurs and be able to detect and contain incidents, recover from disruption, and protect operational availability. Combining visibility with layered controls, threat-informed defence, and effective security operations provides a stronger foundation for doing so.”

Stay Informed With Cyber News Live

Cyber threats are constantly evolving, and staying informed is critical to protecting your organization.
Follow Cyber News Live for the latest cybersecurity news, threat intelligence, expert analysis, and practical guidance to help strengthen your cyber defenses.

Shopping Cart0

Cart

Login