Turning operational technology cyber risk into operational resilience

Fortinet Australia Pty Ltd

Tuesday, 25 August, 2026


Turning operational technology cyber risk into operational resilience

Improving operational technology (OT) cybersecurity starts with visibility; however, knowing what is connected is only the first step. Organisations also need to understand how assets communicate, which systems are critical to operations, where vulnerabilities exist, and what controls can contain an incident without disrupting production or essential services.

This is increasingly important as industrial environments combine legacy operational assets with modern applications, remote connectivity, cloud services and artificial intelligence (AI). The resulting attack surface means that organisations should move beyond individual security products towards a coordinated approach to cyber resilience.

As noted by Michael Murphy, Director, Operational Technology and Critical Infrastructure, APAC, Fortinet, “OT cybersecurity must start with understanding the environment. Organisations can’t effectively protect or segment assets they don’t know exist. However, visibility only creates value when organisations use that information to make better decisions about access, segmentation, vulnerabilities and incident response.”

Industrial environments can contain programmable logic controllers (PLCs), human–machine interfaces (HMIs), engineering workstations, sensors, servers, networking equipment and other specialised systems. Some assets can remain operational for decades, creating environments where multiple generations of technology coexist.

Building and maintaining an accurate asset inventory is therefore an important first step. However, organisations need more than a list of devices. Security and operational teams need context around what each asset does, how important it is to the process, which systems it communicates with, and whether known vulnerabilities affect it.

This context lets teams prioritise security according to operational risk rather than treating every device and vulnerability equally.

“OT teams need to understand normal behaviour across the environment,” Murphy said. “Which devices should communicate? Which protocols should they use? Who should have access? Establishing that baseline gives organisations a stronger position for identifying unexpected activity and applying controls without unnecessarily affecting operations.”

Once organisations understand their assets and communications, segmentation becomes an important control for reducing exposure.

Flat networks can let an attacker or compromised device move between systems more easily. Segmentation and micro-segmentation can restrict communication according to operational requirements, creating boundaries between systems and helping limit lateral movement.

The challenge in OT is implementing those controls without interrupting processes that depend on reliable, predictable communication. Understanding existing traffic patterns helps organisations identify which communications are necessary before enforcing more restrictive policies.

“Access controls are equally important,” Murphy said. “Employees, contractors, vendors, original equipment manufacturers (OEMs) and service providers may require remote access to industrial environments. That access should be limited according to role and operational need, with activity appropriately controlled and monitored.”

Patching remains a fundamental cybersecurity practice, yet OT environments create practical constraints. Taking a critical industrial asset offline to apply a patch may not always be possible, and patches can require extensive testing to make sure they don’t affect sensitive processes or unsupported legacy technology.

Organisations therefore need compensating controls where immediate remediation isn’t practical.

Virtual patching can help protect vulnerable systems against known exploits at the network layer without directly changing the asset. This can provide additional protection while operators test, schedule or otherwise manage permanent remediation.

“The answer to an OT vulnerability can’t always be to patch immediately,” Murphy said. “Operational availability and safety requirements need to be considered. Security teams need options that help reduce exposure while giving operators the time required to manage remediation appropriately.”

Effective OT security also depends on understanding what attackers are doing and translating that information into controls relevant to industrial environments.

Threat intelligence can help organisations identify malicious activity, known vulnerabilities, suspicious communications and emerging attack techniques. Its value increases when that information is combined with knowledge of the organisation’s assets and operational priorities.

“Lessons from real incidents also reinforce the importance of fundamentals, including network segmentation, secure remote access, multifactor authentication, vulnerability management and visibility across the environment,” Murphy said. “These measures can help contain malicious activity before it spreads more broadly through an operational network.”

AI has a growing role in helping security teams manage complex environments. The role of AI isn’t to replace established security controls or human decision-making. Instead, AI can support teams by analysing large volumes of information, identifying unusual behaviour, helping investigate events, and bringing relevant security contexts together faster.

“AI is most useful when it strengthens the security practices organisations already need,” Murphy said. “Visibility, segmentation, access control, vulnerability management and incident response remain fundamental. AI can help teams work with that information faster and identify where attention is needed; however, it shouldn’t become a substitute for the underlying controls.”

No individual control can address every OT security challenge. Visibility without segmentation can make organisations aware of risk without giving them the controls needed to contain an incident. Segmentation without accurate asset information can create operational problems. Threat intelligence without environmental context can add noise rather than improve decisions.

An integrated approach can help connect asset visibility, network controls, secure access, threat intelligence, vulnerability management and security operations so teams can make decisions using a consistent view of the environment.

“Cyber resilience comes from layers,” Murphy said. “Organisations need to know what they have, understand how it communicates, restrict unnecessary access, protect vulnerable systems, and be prepared to respond when something goes wrong. Bringing those capabilities together helps turn visibility into practical risk reduction while maintaining the reliability OT environments demand.

“For critical infrastructure operators, the objective extends beyond preventing incidents. Organisations need to maintain essential operations when disruption occurs and be able to detect and contain incidents, recover from disruption, and protect operational availability. Combining visibility with layered controls, threat-informed defence and effective security operations provides a stronger foundation for doing so.”

Image credit: iStock.com/gorodenkoff

Related Articles

Chip‑scale laser array delivers faster connections indoors

UK researchers have developed a chip‑scale laser array with integrated beam shaping, enabling...

Safer skies: advancing mining drone operations

How Icom's airband communication system supports the BVLOS operations of a major Australian...

Futureproofing RNZ's infrastructure

Kordia recently helped Radio New Zealand replace two aging AM transmission masts in Henderson...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd