OT Security Isn't the Same As IT Security: Here's What to Do About It

OT Security Isn't the Same As IT Security: Here's What to Do About It

🎙 Craig Duckworth and Dino Pusaki 👥 192 📅 February 25, 2026 ⏱ 26 min 👁 79 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT SOCasset visibilityincident responseIT-OT collaborationplant floor security

Summary

In this episode, Craig and Dino discuss the critical differences between IT and OT Security Operations Centers (SOCs), highlighting why traditional IT-centric SOCs often fail to protect manufacturing environments. They present a case study of a global beverage company that discovered it was only monitoring one-third of its OT assets, illustrating the common problem of poor asset visibility. The hosts explain that IT SOCs struggle because they lack operational context, such as line changeovers and PLC modifications, leading to false alarms and ignored alerts. They emphasize the need for OT-specific incident response protocols, where first responders are often operators, not IT personnel. The discussion covers challenges like asset inventory, remote access vulnerabilities, and the importance of localization—thinking globally but acting locally. They advocate for IT teams to embed themselves in plant operations, collaborate with OEMs and system integrators, and build relationships to bridge the IT-OT gap. They also touch on the need for standardization in greenfield projects and the slow progress in the industry. The hosts conclude that organizational accountability is crucial, as often no one takes responsibility for OT security, leaving gaping holes in the security posture.

188 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the practical challenges of OT security, drawing on real-world experiences and case studies. The hosts argue convincingly that IT-centric SOCs are inadequate for OT environments due to differences in asset management, operational context, and response priorities. They support their arguments with concrete examples, such as the beverage company case and the WannaCry response gap, which illustrate the consequences of neglecting OT-specific security. The discussion is well-structured, moving from problem identification to potential solutions, and emphasizes the importance of collaboration and localization. However, the argumentation relies heavily on anecdotal evidence and personal experience rather than formal research or data, which limits its scientific rigor. The hosts also acknowledge the slow progress in the industry, which adds a realistic perspective to their claims.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates a good understanding of the subject matter, but it lacks formal citations or references to external sources. The hosts mention industry partners like Rockwell and reference the WannaCry incident, but they do not provide specific URLs or studies. The title accurately reflects the content, which focuses on the differences between IT and OT security and offers practical advice. The discussion is based on the hosts’ professional experience, which adds credibility but also limits the generalizability of their claims. The video does not include any formal sources, and the lack of citations reduces its scientific rigor. However, the practical insights and real-world examples provide valuable context for professionals in the field.

255 words

Title / Content Match

The title accurately reflects the content, which focuses on the differences between IT and OT security and offers practical advice.

Quality & Reliability

7/10

The hosts are experienced practitioners in OT security, providing practical insights and real-world examples. However, the discussion is largely anecdotal and lacks formal citations or references to specific studies or standards.

Key Moments

Cited Sources

Concurring Sources

  • IEC 62443 — International standards for industrial automation and control systems security, aligning with the need for OT-specific security measures.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, providing guidelines for securing OT environments.

Dissenting Sources

  • No specific discordant sources — The video does not present any conflicting information or sources.

Contribution & Novelties

The video offers a practical perspective on the challenges of implementing OT SOCs, emphasizing the importance of operational context and localization. It provides real-world examples and actionable advice for bridging the IT-OT gap. The hosts stress the need for IT teams to embed themselves in plant operations and collaborate with OEMs and system integrators, which is a valuable insight for organizations struggling with OT security.

Pour aller plus loin :

  • IEC 62443 — International standards for industrial automation and control systems security, relevant to OT security frameworks.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, providing guidelines for securing OT environments.
  • MITRE ATT&CK for ICS — A knowledge base of adversary tactics and techniques specific to industrial control systems, useful for threat hunting in OT.

128 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the practical insights and real-world examples provided. The technical level is moderate, suitable for a professional audience, while the overall reliability is good but limited by the lack of formal citations.

Reliability 6/10

💬 No comments were provided for analysis.