Field Note

OT/ICS cybersecurity is not IT cybersecurity with different hardware

The most common mistake in critical infrastructure cybersecurity is applying an IT security model to an OT/ICS environment and assuming the difference is just terminology.

Information technology security is built around a well-established priority order: confidentiality first, then integrity, then availability. Operational technology inverts that order. A control system for a water pump, a cooling loop, or a substation exists to keep a physical process running safely and continuously. Availability is not a secondary concern to be balanced against security. In many OT/ICS environments, an action that is standard IT practice, such as immediately isolating a compromised device from the network, can itself cause the unsafe outcome a security team is trying to prevent.

The convergence problem

Water, energy, and data center facilities increasingly run control systems that are IT-adjacent by necessity. Modern SCADA and building management systems use standard networking protocols, connect to vendor cloud platforms for monitoring, and are administered by staff who came up through facilities and engineering, not through a security operations center. This is IT/OT/ICS convergence, and it is not optional. It is what modern efficiency and remote monitoring require.

Convergence is also what erases the old assumption that OT/ICS systems were "air-gapped" and therefore safe by isolation. Air-gapping was never as complete as the term implied, and the remote monitoring and vendor access that make modern facilities efficient have closed whatever gap remained. The result is that a control system built on 1990s assumptions about isolation is now reachable through a 2026 network topology, administered by a team that was never resourced or trained as a cybersecurity function.

What this means for governance, not just technology

The technical fixes for OT/ICS cybersecurity, network segmentation, monitoring, patch management adapted to systems that cannot simply be rebooted, are well understood in the field. The harder problem is governance: who owns the risk when a facilities engineer, an IT security team, and an executive sponsor all have a legitimate claim on a control system, and none of them was resourced to own the whole picture.

For a data center or critical infrastructure investor, the diligence question is rarely "does a cybersecurity policy exist." It is whether OT/ICS risk has an actual owner with the authority and the budget to act on it, or whether it lives in the gap between departments where converged risk tends to collect.

Have a water, energy, or OT/ICS question about a data center site or investment?

Start a conversation