Four Distinct Companies & One Critical Gap—The Ownership Crisis in OT Security

Four Distinct Companies & One Critical Gap—The Ownership Crisis in OT Security

🎙 Industrial Cybersecurity Insider 👥 192 📅 January 19, 2026 ⏱ 30 min 👁 35 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

ownershipOT securityIT/OT convergenceEDRcyber-informed engineering

Summary

This episode of Industrial Cybersecurity Insider brings together experts from four companies to discuss the critical gap in OT security: the lack of clear ownership and collaboration between IT and OT teams. The conversation highlights how traditional IT security approaches fail on the plant floor due to differences in priorities (safety, uptime) and the disruptive nature of IT tools like EDR. The experts use the cloud analogy to illustrate how IT security teams successfully adapted to cloud, but OT requires a different mindset. They emphasize the importance of involving all stakeholders—OEMs, plant operations, engineering, IT—in security planning from the start. The discussion covers the risks of deploying unqualified EDR solutions, the concept of cyber-informed engineering to build security into design, and the ‘have and have-not’ disparity in security investment across plants. They also introduce ’left of boom’ thinking, using security tools for operational visibility and predictive maintenance. The episode concludes with advice for IT leaders to understand capital plans, maintenance windows, and build relationships with plant teams to bridge the gap.

171 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in the practical, real-world insights from experts with hands-on experience in both IT and OT environments. They provide concrete examples of failures and successes, such as the collaborative design of a control room with separate OT and IT networks but shared hardware and drawings. The argumentation is solid, built on logical reasoning and analogies (cloud, aftermarket parts, farm-to-table) that make complex issues accessible. The experts consistently stress the importance of collaboration and understanding, rather than just technology, which is a valuable perspective. However, the discussion is largely anecdotal and lacks empirical data or references to specific incidents, which weakens the overall argumentative rigor.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the experts cite their own experiences and industry practices, but no formal sources or studies are referenced. The quality of sources is therefore limited to the credibility of the speakers, who appear knowledgeable. The title accurately reflects the content, focusing on the ownership crisis. The description mentions ‘four distinct companies’ and the discussion indeed features multiple experts, though their affiliations are not explicitly stated. The adéquation between title and content is strong, with the episode directly addressing the ownership gap and its consequences.

212 words

Title / Content Match

The title accurately reflects the core theme of ownership gaps in OT security, as discussed by experts from four companies.

Quality & Reliability

7/10

The discussion features multiple industry experts with practical experience, providing concrete examples and analogies. However, it lacks formal citations or references to specific studies or standards, and the claims are anecdotal rather than data-driven.

Key Moments

Cited Sources

  • Armis — Mentioned as an OT security platform for visibility and monitoring.
  • CrowdStrike — Mentioned as an example of EDR solutions that can be disruptive in OT environments.
  • SentinelOne — Mentioned as another EDR solution that can cause issues if deployed without vendor qualification.
  • S4 Conference — Mentioned as the event where the term 'cyber-informed engineering' was heard.

Concurring Sources

  • IEC 62443 — Standard for industrial cybersecurity that emphasizes the need for collaboration and risk-based approaches, aligning with the episode's themes.
  • NIST SP 800-82 — Guide to Industrial Control Systems Security, which discusses the differences between IT and OT and the importance of tailored security measures.

Dissenting Sources

  • Gartner's View on OT Security — Gartner often emphasizes technology solutions and market trends, which may contrast with the episode's focus on organizational and cultural challenges.

Contribution & Novelties

The episode provides a nuanced discussion of the ownership crisis in OT security, emphasizing the need for collaboration and understanding between IT and OT teams. It introduces practical concepts like ’left of boom’ and ‘cyber-informed engineering’ that are not widely covered in mainstream cybersecurity discourse. The experts share real-world examples of successful collaboration, such as the joint design of a control room, offering actionable insights for practitioners.

Pour aller plus loin :

  • Cyber-Informed Engineering — Official INL page on cyber-informed engineering, a key concept discussed.
  • IEC 62443 — International standard for industrial cybersecurity, relevant to the discussion of OT security.
  • MITRE ATT&CK for ICS — Framework for understanding adversarial behavior in industrial control systems, related to ’left of boom’ thinking.

120 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in information quantity and quality, reflecting the expert panel's depth of experience. The lower technical score indicates the content is accessible to a broad audience, while the reliability score is moderate due to the lack of formal citations.

Reliability 7/10

💬 No comments were provided for analysis.