Why OT cybersecurity needs its own roadmap

Why OT cybersecurity needs its own roadmap

The gap between legacy engineering and the modern threats is widening. Bridging it requires moving past IT-centric frameworks and building defence mechanisms specifically for the demands of operational technology

By: Valeriy Savinov, OT/ICS Cybersecurity Sales Lead, ABB 

Cybersecurity was never meant to be an afterthought. But for most industrial operators, that is exactly what it has become – not through negligence, but through circumstance.

The control systems running today’s power plants, water treatment facilities, and manufacturing sites were designed with one priority in mind: to keep things working and keep people safe. Encryption, network protection, access controls – these were not part of the original brief. The engineers who built these systems were not being reckless. They were solving the problem at hand. Security, at the time, was simply not that much of a problem. 

That has changed. And the gap between where operational technology (OT) was designed to go and where the threat landscape now sits leaves operators struggling.

While well-intentioned, the directives themselves are another challenge. Frameworks like NIS2 set out obligations in broad terms: protect your systems, manage your risks, demonstrate continuous improvement. What they do not tell you is how. 

NIS2 has also changed the game: C-level management executives are now personally accountable for their organization’s cybersecurity posture. Yet many of senior leaders remain unaware of this obligation. The work to close the gaps falls on those closest to the system – who already stretched thin. In smaller organisations, especially, you might find one automation engineer who is also expected to understand cybersecurity, interpret regulatory requirements and keep the plant running. These are not small asks; they require genuinely different skill sets, and conflating them into a single role does not make the problem more manageable. It just means the risk is less visible.

Adding to this pressure: management rarely provides additional budget to those responsible for closing these gaps. 

When organisations lack both OT cybersecurity expertise and resources, they often fall back on to build on the IT security tools and approaches they have. This is understandable – but it can lead to serious operation failures or safety incidents. 

The reason lies in a core difference: OT and IT security operate from fundamentally different starting points. IT systems are built around confidentiality first – protecting data. OT systems invert that order entirely: availability comes first, because a production system that goes offline, even briefly, has failed at its primary purpose.

This difference matters enormously in practice. To give a simple example, when an IT team detects suspicious activity on a node, they immediately isolate it for investigation. The same action in an OT environment could shut down manufacturing line or halt a power plant. The technology and tools might be similar; the methods and setup of the tools are not. Security measures that work flawlessly in IT environment can create operational or safety hazard in OT. 

This thinking is consistent with what has been observed more broadly – that people remain the biggest risk and challenge, precisely because they do not always understand that OT security requires a fundamentally different approach to IT security. The result is genuine confusion about where to start. Dedicated OT security teams need to drive them alongside their IT colleagues. 

Where most customers actually start

In my experience, customers rarely arrive with a comprehensive security strategy. They arrive with a specific problem. A particular system they are worried about, a regulation they have been told they need to comply with, or a gap that has been flagged in an audit. 

That instinct to fix the immediate problem is understandable, but it can work against them. OT environments are rarely made up of single-vendor systems. Most plants run equipment from multiple suppliers, built at different times, with different architectures and limited – if any – native security capabilities. Operators will know the game of whack-a-mole well, where as one hole is patched, another emerges. 

What we try to do is zoom out before we zoom in. When a customer comes to us with a specific request, we will address it, but we will also ask whether they have completed a formal cyber security risk assessment of their entire OT environment. Not a conversation about risk, but a comprehensive assessment, carried out according to established standards, that gives them a prioritised list of risks and a mitigation plan for addressing them. 

Source: ABB Ability™ Cyber Security Risk Assessment
Source: ABB Ability™ Cyber Security Risk Assessment
center

The mitigation plan matters more than any individual tool or fix – especially when budgets are constrained. It tells you where to start, where the highest-impact improvements are, and, critically, when you have done enough. The Center for Internet Security estimates that basic controls, systematically applied, can address up to 85% of cyber risks. That is not a trivial number, and it puts the foundational work within reach of most operators. Because there is no such thing as a perfectly secure system. There is only a system where the residual risk sits within a level your organisation can tolerate.

The cost calculation customers are not making

One of the biggest obstacles to investment in OT cybersecurity is that the return is invisible until something goes wrong. Organisations budget for motor replacements, for scheduled maintenance, and for the predictable costs of keeping a plant running. They do not always have a figure for what a cyberattack would cost them – and without that figure, it is hard to make the case for preventive investment.  

The calculation is not complicated. Take the estimated daily cost of a full system outage. Estimate the time it would realistically take to recover from a serious attack – days, not hours, in most cases. Apply a rough probability based on your current exposure. That number, even when conservatively modelled, tends to exceed the cost of implementing proper protections.

Source: IBM: Cost of a Data Breach Report 2026, IBM and Ponemon Institute
Source: IBM: Cost of a Data Breach Report 2026, IBM and Ponemon Institute
center

IBM’s Cost of a Data Breach Report 2026 puts the average cost of a data breach in energy sector at $5.2 million. Most operators have no equivalent figure on the prevention side of the ledger. That imbalance is where the conversation needs to start.

Making security manageable for the people doing the work

Even where organisations invest in the right tools, there is another challenge: knowing how to use them. A customer I worked with recently had implemented a substantial portion of security stack. They understood the value of each individual component. What they could not tell me was which dashboard to look at first thing in the morning.

That might sound like a minor operational question. But it isn’t. If the operative responsible for overseeing your cybersecurity posture does not have a clear, daily workflow – a way to quickly assess the status of the whole environment before getting on with everything else they are responsible for – then the tools are not doing their job, regardless of how good they are. 

This is something we are addressing in our portfolio through a more persona-based approach. We start with the person: their role, their background, their daily constraints. A dedicated cybersecurity analyst needs a different view of the same environment than an automation engineer who also carries cybersecurity responsibility. The technology is the same. The way the information presented is different. 

Another pattern we see repeatedly is that operators who conclude that their OT environment is very unique and that no standard solution will fit their environment and leads them to build their own. In almost every case, the result is something too complicated, too costly to maintain, and too difficult to scale. OEMs have already thought about it and developed solutions that fit the intended purpose. Starting from scratch rarely improves on that; it just shifts the ownership burden onto teams that are already stretched.

Source: ABB Ability™ Cyber Security Risk Reduction Roadmap
Source: ABB Ability™ Cyber Security Risk Reduction Roadmap
center

The shift being asked of industrial operators is not small. Systems that ran reliably for decades without any security consideration are now expected to meet modern threat standards. That means no downtime, no disruption, and, often, no additional headcount. That is a real constraint, and the industry needs to be honest about it.

What we can offer is a structured way through: Start with the assessment. Build the roadmap. Work through the priorities. And do not wait until the gap becomes a crisis.

To help identify where to start, ABB’s whitepaper shares practical steps for improving industrial performance, resilience and compliance without adding unnecessary complexity. 

For the full suite of ABB Cyber Security services see here

Links

Contact us

Downloads

Share this article

Facebook LinkedIn X WhatsApp