← All sectors / The AI transformation

055 · Operational technology security

Defending machines, not laptops

Curve position

Liftoff

Binding constraint

Downtime intolerance: you cannot patch a running production line.

Defending machines, not laptops

Industrial control systems run water treatment: power distribution, manufacturing, and pipelines. Most were designed before networked attacks existed, many cannot be patched without stopping production, and they are now connected to networks that reach the internet.

Historical context: operational technology and information technology were genuinely separate for decades, and the air gap was real security. Efficiency drove convergence, remote monitoring and analytics required connectivity, and the gap closed before the security model caught up.

The structural driver is a combination of demonstrated attacks on physical infrastructure and regulation responding to them. Critical infrastructure rules, incident reporting requirements, and insurance conditions are all converting security from optional to mandatory.

The technology layer spans passive network monitoring that does not disturb operations, asset discovery for equipment nobody documented, segmentation between operational and corporate networks, secure remote access for vendors, and anomaly detection tuned to industrial protocols.

Adoption economics are driven by downtime avoidance and regulatory compliance rather than efficiency. A day of stopped production dwarfs any security budget, which makes the business case straightforward once a board understands the exposure.

The beneficiaries include operational technology security specialists, industrial networking equipment makers, the automation vendors adding security to their own installed base, and the services firms doing assessments in environments generalist consultants cannot safely touch.

The value chain runs from industrial equipment through networking and monitoring to managed detection services. Domain expertise is the moat: securing a refinery is not the same job as securing an office network.

The overlooked layer includes industrial networking hardware suppliers, specialist assessment and integration firms, secure remote access vendors, and the automation companies quietly building security into controllers.

Competitive dynamics favor vendors with deep protocol knowledge and existing relationships with plant engineers, who are a fundamentally different buyer than corporate security officers.

Risks: industrial capital budgets are cyclical, sales cycles are long and conservative, general purpose security platforms are extending into this space, and adoption often waits for an incident rather than anticipating one.

What to watch: critical infrastructure regulation with mandatory controls, disclosed industrial incidents, security spend within manufacturing capital budgets, and partnerships between automation vendors and security specialists.