In 2026, the US Cybersecurity and Infrastructure Security Agency published an alert urging a segment of critical infrastructure to remove all publicly exposed operational technology (OT) devices from the internet due to increased activity from threat actors.1 For more than a decade, the industry has discussed convergence and OT network vulnerabilities, yet decisions made along the way have led to another round of OT system compromises. To be fair, it is unlikely that many security practitioners will be surprised by the agency’s alert. After all, connecting any device to the internet makes it susceptible to compromise. But this risk is not new: in 2024, attackers targeted a major water utility in the United States.2 OT system compromise must be understood now to mitigate damage later.
To be clear—compromise is not solely tied to internet-enabled devices, and evidence of this is contained in a host of peer-reviewed literature on air-gapped compromise.3 However, internet-connected devices eliminate the physical proximity constraint, which increases the likelihood of attack.
The title of this article is drawn from the author’s prior career in the US Navy and is purposeful. Sailors train for a variety of events with “General Quarters” (GQ) being the most critical of all preparedness exercises.4 After all, sailors assigned to vessels are the emergency response many readers associate with 911, 112, or 999.5 Repeated training can create complacency so the words, “this is not a drill” is appended to signify a real threat. Plainly stated, leaders at all levels and all sectors have not made sufficient progress on a longstanding issue of this magnitude.
Acknowledgement is not action.
Convergence In Practice
The convergence of OT-IT is not new and yet little appears to have been done to shore up this front.
OT systems remain insecure and the reasons for why go well beyond technical flaws, pointing to human fallibility. Organizational decisions have consistently favored safety, uptime, and continuity over security hardening. In practice, system owners may delay patching, avoid reboots, or resist configuration changes because even minor disruptions can interrupt critical industrial processes, while managers may defer modernization because replacing legacy equipment is costly and operationally risky.6 These environments have long been plagued by a number of bad practices, such as shared credentials, default settings, removable media, and remote access exceptions—all of which expand the attack surface.7 Despite betterments in the number of CISOs or CSOs now involved, responsibility for OT security remains largely fragmented across engineers, IT staff, third-party vendors, and leadership,8 creating gaps in accountability, asset visibility, and incident response planning.9 As a result, OT insecurity is deeply shaped by routine human choices made under operational pressure, budget constraints, and competing institutional priorities, rather than by technology alone.10
Of course, this is not to say that the tides are not changing. There are many lessons that can be learned from prior incidents.11 Not to mention that International Electrotechnical Commission (IEC) 6244312 offers a standard for OT security, and a host of other regulations, standards, and best practices can also be applied to OT security at large.13 Despite it all, devices that are publicly exposed are practically begging to be exploited. Combing through relevant sources on this issue points to one primary conclusion: OT and IT security are still very much fragmented.
Conclusion
Many professionals still debate the differences between IT and OT security. Everything from objectives to impact to systems and downtime has been discussed but, looking at the modern digital ecosystem, convergence has softened those lines, if not erased them. The modern cybersecurity practitioner is now a key resource in protecting the modern digital environment. In developed countries, the line between cyber-physical systems technically exists, but is mostly blurry thanks in part to the rapid adoption of internet of things (IoT) devices on enterprise networks. Now more than ever the profession needs a unified picture of technical risk. Financial institutions, healthcare facilities, and critical infrastructure are all intertwined with information communications technology which heightens the criticality. Yes, assets and network protocols differ, but even the argument regarding systems availability is diminishing.14 Modern day reliance on internet connectivity demands that professionals be better at many things—most notably identifying and remediating discoverable devices. Beyond that, pushing for better security features for internet-enabled products should be a core focus of every cyberprofessional.
Endnotes
1 Lyngaas, S.; “Sweeping Cyberattack on Water Systems in Multiple States has US Officials on Edge” CNN, July 31, 2026; US Cybersecurity and Infrastructure Security Agency (CISA), “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” 30 July 2026
2 Rosenbaum, E.; “America’s Largest Water Utility Hit by Cyberattack at Time of Rising Threats Against U.S. Infrastructure,” CNBC, 8 October 2024
3 ISACA®, Industrial Control Systems: A Primer for the Rest of Us, USA, 2015
4 Military Times, “General Quarters, General Quarters!” YouTube, 1 February 2018
5 World Population Review, 911 by Country 2026
6 National Institute of Standards and Technology (NIST), Special Publication 800-82r3, Guide to Operational Technology (OT) Security, USA, September 2023
7 Pliatsios, D.; Sarigiannidis, P.; et al.; “A Survey on SCADA Systems: Secure Protocols, Incidents, Threats and Tactics,” IEEE Communications Surveys & Tutorials, vol. 22, iss. 3, 2020, p. 1942–1976
8 Mohammed, S.; “The OT CISO Series: Chapter Three Who Owns What?,” LinkedIn, 14 July 2025
9 Khalil, S.M.; Bahsi, H.; et al.; “Threat Modeling of Industrial Control Systems: A Systematic Literature Review,” Computers & Security, vol.138, 2024
10 NIST SP 800-82r3
11 Cybersec Magazine, “Case Study: Real-World OT Cyberattacks and Lessons Learned”
12 Herrera Lara, R.C.; “IEC 62443: The Definitive Cybersecurity Standard For Operational Technology,” LinkedIn, 13 September 2025
13 UV Enterprise, “Comprehensive List of OT (Operational Technology) Compliance Standards and Regulations,” LinkedIn, 25 July 2025
14 ISACA, Industrial Control Systems: A Primer for the Rest of Us
Jonathan Brandt, CISM, CDPSE, CCISO, CISSP, PMP
Is senior director of professional practices and innovation in ISACA®’s Content Development and Services department. In this role, he leads thought leadership initiatives relevant to ISACA constituents on audit, CMMI, GRC, emerging technology, information security, and privacy. He serves ISACA’s departments as subject matter expert on infosec and leads innovative workforce readiness enablers. Brandt is a highly accomplished US Navy veteran with 30 years of experience spanning multidisciplinary security, cyberoperations and technical workforce development. Formal education includes an MSED in Workforce Education and Development from Southern Illinois University and BS in Cybersecurity from Champlain College.