The Patching Gap Putting Industrial Operations at Risk | IT vs OT

The Patching Gap Putting Industrial Operations at Risk | IT vs OT

🎙 Craig Duckworth and Dino Busilaki 👥 192 📅 January 28, 2026 ⏱ 26 min 👁 52 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT patchingIT vs OTvirtual patchinglegacy systemsOEM restrictions

Summary

In this episode of Industrial Cybersecurity Insider, hosts Craig Duckworth and Dino Bousilaki discuss the critical challenge of patching in operational technology (OT) environments compared to traditional IT. They highlight that while IT organizations patch frequently, OT environments often avoid patching due to concerns about downtime, OEM restrictions, and the complexity of legacy systems. The hosts explain that the cost of downtime on the plant floor is astronomical, making patching a risky business decision. They also discuss the role of OEMs, who may void warranties if systems are patched, and the challenges of managing decades-old equipment. The episode explores virtual patching as a solution to protect legacy control systems without traditional software updates. The hosts emphasize the need for collaboration between IT and OT, as well as with OEMs and system integrators, to develop effective patching strategies. They also touch on the consequences of not patching, including insurance requirements and regulatory pressures. The episode concludes with actionable insights for improving OT cybersecurity, such as asset inventory, continuous monitoring, and building a business case for patching investments.

176 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, real-world perspective on OT patching challenges. The hosts draw on their extensive experience in industrial cybersecurity to illustrate common obstacles, such as OEM restrictions, legacy system limitations, and the high cost of downtime. The argumentation is coherent and well-structured, moving from the problem to potential solutions like virtual patching and emphasizing the need for collaboration. However, the discussion is largely anecdotal, with no formal data or case studies to support claims. The hosts do not provide specific statistics or references, which weakens the scientific rigor. The argumentation is persuasive for practitioners but lacks empirical evidence.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The hosts are credible experts, but they do not cite specific sources or studies. They reference the CrowdStrike incident and mention Rockwell’s advisories, but without detailed analysis. The title accurately reflects the content, focusing on the patching gap and its risks. The discussion is relevant and timely, but the lack of formal citations and data limits its scientific value. The hosts do not provide a systematic review of the literature or empirical evidence, relying instead on personal experience and observations.

204 words

Title / Content Match

The title accurately reflects the core topic of the episode, which focuses on the patching gap between IT and OT environments and its operational risks.

Quality & Reliability

6/10

The hosts are experienced professionals in industrial cybersecurity, providing practical insights and real-world examples. However, the discussion is largely anecdotal and lacks formal citations or data. The mention of the CrowdStrike incident is timely but not deeply analyzed.

Chapters

Contribution & Novelties

The episode provides a practical overview of the patching gap between IT and OT, highlighting the unique challenges of OT environments. It introduces virtual patching as a viable solution for legacy systems, which is a valuable concept for practitioners. The hosts also emphasize the importance of collaboration between IT, OT, OEMs, and system integrators, offering a holistic approach to OT security.

Pour aller plus loin :

  • Virtual Patching — Provides a definition and context for virtual patching as a security measure.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, offering best practices for securing OT environments.
  • CrowdStrike Outage — Context on the CrowdStrike incident mentioned in the episode, illustrating the impact of EDR failures.

117 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher scores in quantity of information and technical level, reflecting the practical nature of the discussion. The lower score in reliability indicates the lack of formal citations and data.

Reliability 5/10