Should you integrate your IT and OT teams for better OT security?
Traditionally, IT and OT systems have operated independently, with separate technology stacks, protocols, standards, and operating systems. As a result, OT security has developed differently from IT security.
Some vendors argue that tighter integration between IT and OT teams is both inevitable and beneficial, often citing gains in operational efficiency. What they often overlook is the fundamental cultural and technical divide between these teams. IT and OT professionals speak very different “languages,” which makes collaboration harder than it appears. And that’s just the beginning.
Implementing an IT/OT integration process:
- Requires significant time and planning
- Involves complex, resource-intensive projects
- Depends heavily on the cooperation of the OT team, who may not welcome IT’s involvement
- Can impact the production process directly
That last point is critical. Any disruption to production means downtime, and downtime creates chaos: it affects workforce scheduling, the supply chain, and the customer experience, and its financial impact is felt across the whole organisation.
Isolating a compromised OT device is rarely feasible without halting operations. Yet many of these devices are dangerously accessible, often protected by default or even no passwords at all. Once accessed, a single machine can become an entry point to the entire network, and attacks can resemble legitimate commands, which makes them hard to detect. On top of that, many industrial protocols are proprietary and incompatible with standard IT security tools, which complicates visibility and threat detection even further.
In short: breaking down IT/OT silos is difficult, time-consuming, and costly.
Approach Cyber’s answer: strengthen OT security without
disrupting operations
At Approach Cyber (the company formerly known as AXS Guard), we asked a different question: how can we strengthen OT security without causing disruptions, given the challenges above?
We’ve proven that CPS threat detection can be implemented without requiring the OT department to conform to IT department standards or processes. This is a game-changer for organisations that depend on uninterrupted industrial operations. To understand how this works, it helps to look at what CPS actually means.
What is CPS, and why does it matter for OT security?
Cyber-Physical Systems (CPS) are systems that integrate digital intelligence with physical processes. By combining sensors, data processing, control algorithms, and communication networks, CPS enables machines and systems to monitor, analyse, and control physical operations in real time. Advanced algorithms and real-time data allow CPS to make autonomous decisions, adapt to dynamic environments, and continuously optimise their performance.
Each CPS typically includes a combination of digital components (servers, software), communication infrastructure, control mechanisms, and the physical systems themselves, such as machinery or production lines.
Operational Technology (OT) and the Industrial Internet of Things (IIoT) are prime examples of CPS in action. These environments blend software and hardware to support critical processes in industries such as manufacturing, utilities, and logistics.
How does CPS threat detection work? Passive network sniffing explained
Approach Cyber uses advanced network sniffing and specialised tooling to strengthen OT security without disrupting production processes. This non-invasive threat detection approach is designed to preserve maximum uptime, a top priority for every OT department.
Network sniffing passively monitors and analyses network traffic. It lets organisations detect unusual activity, unauthorised access, or potential threats without interfering with system operations.
Key objectives: identify, protect, detect, respond
- Identify: gain complete visibility into the CPS environment (not to be confused with production performance monitoring), through passive network monitoring via TAP, SPAN, or PCAP files, and agentless OT asset monitoring using native protocols and APIs (OPC-UA, SNMP, MQTT, MODBUS, and others).
- Protect: secure critical OT systems by analysing real-time data from devices and machines, to maintain operational continuity without compromising security.
- Detect: use AI and machine learning to detect threats, classify anomalies, and recognise behavioural deviations within the network.
- Respond: react to emerging threats immediately, minimising potential damage, through an intelligent cascading system for alert correlation that delivers incident details within seconds to the team in charge or the Security Operations Center (SOC).
This is the least invasive approach to OT security available today, which is why OT stakeholders tend to favour it. But standardisation still plays a vital role: by gaining deep visibility into OT assets and network traffic flows, organisations can proactively identify vulnerabilities and respond to threats before they cause harm. You can’t protect what you don’t know exists. With the right tools, best practices, security procedures, and adherence to industry standards, companies can both maintain and strengthen the integrity of their OT networks.
Which OT security standards matter: IEC 62264 vs IEC 62443
When it comes to securing industrial environments, two standards stand out: IEC 62264 and IEC 62443. Both are essential in industrial automation, but they serve very different purposes.
IEC 62264 (ISA-95): integrating IT and OT
Also known as ISA-95, IEC 62264 is an internationally recognised standard for Enterprise-Control System Integration. Its goal is to structure and standardise communication between business-level IT systems and plant-level OT systems. A typical use case is integrating ERP systems (like SAP) with MES or SCADA platforms.
ISA-95 defines models, roles, and data exchange frameworks to support integration efforts, particularly relevant for organisations embracing Industry 4.0 or undergoing digital transformation.
Key focus: integration and operational efficiency. If your organisation is moving toward greater IT/OT integration, adopting this framework is a smart, though not mandatory, step forward.
IEC 62443 (ISA-99): securing industrial systems
Previously known as ISA-99, IEC 62443 is the reference standard for Industrial Automation and Control Systems (IACS) security. It provides a comprehensive framework for protecting OT environments against cyber threats, built around defining security zones and conducting risk assessments, implementing access control and network segmentation, and establishing and maintaining security policies for industrial systems.
To build robust cybersecurity for industrial control systems, including SCADA, PLCs, HMIs, and DCS platforms, organisations are strongly encouraged to apply the principles and guidelines of IEC 62443.
Key focus: cybersecurity, system availability (uptime), and data integrity. Pursuing IEC 62443 alignment is recommended for manufacturers, operators, and vendors involved in industrial automation. You can think of it as the OT equivalent of ISO 27001 for IT environments. Approach Cyber is ISO 27001 and ISO 27701 certified, reflecting its commitment to information security at every level.
What does the NIS2 Directive change for OT security?
If your organisation falls under the scope of the NIS2 Directive, you are required to take steps to ensure the cybersecurity and resilience of your critical systems, and that includes both IT and OT environments.
Even if you work with an external cybersecurity partner, your organisation remains ultimately responsible for NIS2 compliance. The responsibility for implementing, maintaining, and demonstrating adequate cybersecurity cannot be fully outsourced. Whether your infrastructure is primarily IT, OT, or a mix of both, you cannot transfer NIS2 accountability to a third-party supplier.
Approach Cyber supports organisations across the NIS2 compliance journey for both IT and OT security domains, including:
- Risk management
- Incident management and reporting
- Monitoring and threat detection
- Supplier and third-party risk management
- Secure development and maintenance practices
- Employee awareness and training
- Coordination and communication with authorities
- Business continuity and resilience planning
- Compliance, governance, and documentation
FAQ: OT security and CPS threat detection
What is CPS threat detection?
CPS threat detection monitors the network traffic of Cyber-Physical Systems, such as OT and IIoT environments, using passive techniques like network sniffing. It identifies threats and anomalies without installing agents on OT devices or interrupting production.
Why is passive network monitoring often preferred to IT/OT integration for OT security?
Integrating IT and OT teams and standards is time-consuming, costly, and can disrupt production. Passive network monitoring gives visibility into OT assets and threats without requiring the OT department to change its processes or risk downtime.
Do IEC 62443 and NIS2 overlap for OT environments?
They address different layers. IEC 62443 is a technical framework for securing industrial control systems (zones, segmentation, access control), while NIS2 is a legal obligation that requires organisations, including their OT environments, to demonstrate adequate cybersecurity and resilience. Aligning with IEC 62443 helps support NIS2 compliance, but it does not replace the legal obligation itself.
Can NIS2 compliance for OT be fully outsourced to a partner?
No. Even when working with an external partner like Approach Cyber, the organisation itself remains ultimately accountable for NIS2 compliance. A partner can support risk management, monitoring, and incident response, but responsibility cannot be fully transferred to a third party.
Facing OT security challenges?
Talk to our team about strengthening your OT cybersecurity posture without disrupting production. We’ll help you assess where CPS threat detection and NIS2 compliance fit into your environment.