Back to News
    September 15, 2026· 2 min read

    OT security: what your customers are actually exposed to, and what to do about it

    OT security: what your customers are actually exposed to, and what to do about it

    Physical consequences change everything

    OT covers the programmable systems that monitor or control physical processes: industrial control systems, SCADA, PLCs, building automation, and the plant-floor computers running them. NIST's definition is broader than most people assume. Anything that can detect or cause a direct physical change, whether that's a production line, a substation, or a building's environmental controls, sits inside the OT boundary.

    That matters because the worst-case outcome is different. In IT, the worst credible scenario is usually data loss, encryption, or exposure. In OT, it can be an unsafe physical state: an overpressured vessel, a substation going dark, or a production batch that fails validation. This is why OT security prioritizes safety first, then availability, then integrity and confidentiality. IT security usually runs the other way around, starting with confidentiality. If a customer asks why you can't just apply their existing endpoint policy to the plant floor, this is the honest answer.

    It also changes what "downtime tolerance" means. A continuous-process plant that can't absorb an unplanned restart isn't behind on security, it's operating within the physics of the process. And a PLC configuration that's been qualified by the OEM often can't be patched on the same cadence as a laptop fleet without triggering recertification. Compensating controls and planned maintenance windows do the work that a patch cycle would do in IT.

    What's actually happening out there

    Two distinct patterns are driving most of the incidents customers are asking about, and they call for different defenses. The first is direct targeting of control environments. Dragos linked a coordinated attack on Polish combined-heat-and-power and renewable energy systems in late December 2025 to the ELECTRUM group, describing it as the first large-scale coordinated attack against distributed energy resources. A separate campaign against a Pakistani state power-transmission company in mid-2025 involved active searching for SCADA exploits and scanning of Modbus ports, the kind of reconnaissance that asset visibility and protocol-aware monitoring are built to catch.

    The second pattern is more common and, in some ways, more relevant to how most of our partners' customers actually get hit: IT incidents with operational fallout, without any confirmed compromise of a controller. Nucor halted parts of production as a precaution after unauthorized IT access. Masimo had to run manufacturing below normal capacity for weeks after a network intrusion. Jaguar Land Rover extended a production pause by more than a week after a September 2025 incident. Asahi's ransomware event in the same month knocked out ordering and shipment systems, with logistics not fully back to normal until February 2026. None of these were attacks on a controller. All of them stopped production because IT and OT are more entangled than most risk assessments assume.

    The numbers back this up. Dragos tracked 119 ransomware groups affecting industrial organizations in 2025, up from 80 the year before, hitting roughly 3,300 organizations, with manufacturing taking more than two-thirds of the hit. Siemens puts unplanned downtime at close to 1.4 trillion dollars a year across the world's 500 largest companies. What stands out in the SANS Institute's 2025 survey isn't detection, nearly half of incidents were caught within 24 hours, it's recovery: almost one in five took over a month to fix. Detection has gotten faster than restoration, and restoration is where the real cost sits.

    The framework your customers are actually measured against

    For most of your customers, NIS2 is what decides whether OT resilience is a legal obligation or just a nice-to-have. The directive doesn't create a separate OT regime, but it covers energy, transport, water, health, and manufacturing directly, and Article 21 spells out concrete requirements: incident handling, backup and disaster recovery, supply chain security, and access control. For a customer in those sectors, NIS2 compliance and OT resilience are the same conversation, not two separate ones.

    The most common gap among customers who say they're NIS2-ready is the same in practice: they have a backup routine, but it's never been tested against real hardware constraints, where the original device no longer exists and a like-for-like replacement isn't available. Backing up PLC logic, SCADA and DCS configurations, HMI files, and network device configs is one job. Actually demonstrating that you can restore them, which is what Article 21 requires evidence for, is a different one.

    Where this leaves your OT conversation with customers

    A defensible OT security setup needs asset visibility, segmentation, monitoring, and recovery working together, and no single vendor covers all four well. That's exactly where a distributor conversation is more useful to you than a single vendor's pitch: you can put together the combination that actually fits the customer's environment instead of stretching one product across four problems it wasn't built for.

    For the resilience piece specifically, backup and recovery for the PC-class assets that actually stop production when they go down, HMI workstations, SCADA servers, engineering workstations, historians, Acronis Cyber Protect for OT is built around image-based backup, recovery to dissimilar hardware, and support for the legacy Windows and Linux systems that dominate brownfield plants. It's designed around getting to a validated production state fast, not just around completing a backup job, and it works in air-gapped environments where cloud connectivity isn't an option. For the asset visibility and vulnerability side of the equation, Nanitor gives customers the inventory and exposure picture that NIS2's Article 21 obligations increasingly require documentation for.

    If a customer is asking about OT security, the useful next step usually isn't a single product demo, it's working out which of the four problems, visibility, segmentation, monitoring, or recovery, is actually the weak point in their setup today. Talk to our in-house specialist and Head of OT, Oscar Swanberg, and we'll help you figure out where that gap is and how Acronis closes it.