
- 01Across 23 OT and utility engagements in 2025, patterns are remarkably consistent. The maturity gap between IT and OT cybersecurity is closing slowly; the engineering challenges of OT environments are not.
- 02What we consistently find: asset inventories 60-80% accurate at best, engineering workstations with internet access and no segmentation from control networks, remote vendor access via shared credentials and weak MFA, patch management with no risk-based cadence (everything waits for the annual outage), backups that exist but have not been restored in years.
- 03What works: passive asset discovery via tap or span ports rather than active scans, vendor remote access through a single hardened jump host with session recording, backup restoration drills as part of every annual outage. Baseline catching up to threat reality, not exotic.
- 04Where regulation helps: TSA pipeline directives, NERC CIP refinements, EU NIS2 transposition for critical infrastructure. Use the regulatory push to fund the program — and run the program for the operational benefit, not just the audit posture.
Across 23 OT and utility engagements in 2025, the patterns are remarkably consistent. The maturity gap between IT and OT cybersecurity is closing slowly; the engineering challenges of OT environments are not.
What we consistently find
- 01Asset inventories that are 60-80% accurate at best
- 02Engineering workstations with internet access and no segmentation from the control network
- 03Remote vendor access via shared credentials and weak MFA
- 04Patch management with no risk-based cadence; everything waits for the annual outage
- 05Backups that exist but have not been restored in years
What works in this environment
Passive asset discovery using tap or span ports rather than active scans. Vendor remote access through a single hardened jump host with session recording. Backup restoration drills as part of every annual outage. None of these are exotic — they are the baseline catching up to the threat reality.
Where regulatory motion helps
TSA pipeline directives, NERC CIP refinements, EU NIS2 transposition for critical infrastructure operators. The push from regulators is moving boards to fund OT cybersecurity work that was historically deferred. Use the regulatory push to fund the program — and run the program for the operational benefit, not just the audit posture.


