Martin Wegrostek, Cyber Security Portfolio Manager at cyber resilience company OryxAlign, argues organisations need a unified approach to manage the hidden risks of converged IT and OT systems.
Historically, IT systems managed corporate networks, applications and data, while OT ran the physical systems that kept operations moving, from building management platforms to industrial control systems and even control and automation systems.
IT security was built around confidentiality, rapid patching and centralised control, while OT environments prioritised safety, uptime and long equipment lifecycles, often running systems that were never designed to be connected to a corporate network. As organisations pursue increased efficiency built on access to accurate, real-time data, those boundaries have increasingly blurred.
This is particularly visible in data centres, where enterprise IT infrastructure now sits alongside power, cooling, physical security and building management systems on shared or interconnected networks. In these environments, disruptions are no longer confined to a single system as they can simultaneously impact multiple areas and cause more widespread damage than previously possible.
One incident, multiple failure points
Convergence brings real operational benefits, but it also means that a vulnerability in one domain can quickly become a problem in the other. Fortinet’s 2025 State of Operational Technology and Cybersecurity Report found โ50 per cent of organizations still reported experiencing one or more cybersecurity incidentsโ in the last year, with attackers increasingly exploiting the connectivity between industrial systems and enterprise networks.
Much of this risk stems from a mismatch in how IT and OT environments have historically been managed. OT systems often run on legacy technology with limited patching cycles and generally sit outside conventional IT asset registers, with a focus on functionality rather than security requirements. When these systems are connected to broader IT networks without adequate segmentation or oversight, they can become an entry point into the wider business, or a route for wider business risks to reach physical operations.
Guidance is catching upย ย
Governments and regulators are increasingly recognising this challenge. In January 2026, the UK’s National Cyber Security Centre (NCSC), working with the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI and international partners, published Secure Connectivity Principles for Operational Technology. This offers guidance to help organisations manage increasing demand for connectivity into OT environments without creating unnecessary risk. The NCSC has been clear that convergence itself is not the underlying problem. Its guidance on OT notes that the growing overlap between IT and OT increases the potential for system vulnerabilities, but that this can be addressed by applying consistent risk management principles across both environments.
It is unsurprising that the regulatory landscape is evolving in parallel with changing industry practice around IT and OT. For example, since their designation as Critical National Infrastructure, UK data centres are expected to come within scope of the new Cyber Security and Resilience Bill, which will bring qualifying data centre services into a regulatory framework historically reserved for sectors such as energy and utilities and finance. This signals to any organisation using converged systems that governance expectations around those systems are widening well beyond traditional IT security.
A unified approach
Many organisations still do not have a complete inventory of the operational systems connected to their networks, making it difficult to assess risk or respond quickly when something goes wrong. Establishing a shared asset inventory across both domains is often the fastest way to expose hidden dependencies and unsupported systems.
As IT and OT environments continue to converge across buildings, data centres and industrial sites, cyber risk can no longer be managed in isolation on either side. Organisations that build shared visibility, unified governance and consistent security principles across both domains will be well placed to prevent a single vulnerability from becoming a wider operational failure.
Visit www.oryxalign.com.




