The State of OT Defence – Part 4: Visibility Isn’t the Finish Line

Seeing more is useful. Knowing what to do with what you’re seeing is where it starts to make a difference. I see this regularly when organisations start sending OT security data into their Security Operations Centre (SOC). On paper, it makes perfect sense. More visibility. More monitoring. More alerts. Better coverage of the OT environment.…

The State of OT Defence – Part 3: Where Should Your Next £1 of OT Security Budget Go?

OT cybersecurity budgets are rarely unlimited. There is always something else that could be improved. Another system that needs attention. Another site. Another control. Another risk somebody wants addressed. So one of the most important questions isn’t: What should we buy next? It’s: Where will the next pound actually make a difference? That sounds obvious.…

The State of OT Defence – Part 2: You Don’t Need to Know Everything to Improve Something

One of the easiest ways to slow down an OT cybersecurity improvement is to get stuck deciding who owns it. I saw this with a food manufacturer that needed to introduce separation between its IT and OT networks. Everyone agreed a firewall was needed. What stalled progress was ownership. Engineering wanted authority over connectivity to…

Progress Beats Perfection in OT Cybersecurity

Progress Beats Perfection in OT Cybersecurity Reflections from an OT Cybersecurity Practitioner Across the previous parts of this series (Part 1, Part 2 & Part 3), I’ve reflected on recurring patterns that shape OT cybersecurity maturity far more than technology alone. Governance structures influence intent. Visibility determines the quality of decisions. Incentives quietly guide behaviour. Taken…

Actions Follow Incentives, Not Policies.

Actions Follow Incentives, Not Policies Reflections from an OT Cybersecurity Practitioner In Part 1 and Part 2 of this series, I reflected on how OT cybersecurity maturity is shaped more by governance, visibility, and decision-making than by technology. A third pattern that emerges repeatedly across OT environments is the role of incentives, particularly the gap…

OT cybersecurity strategy decisions are made far from where operational reality lives.

The Visibility Gap in OT Cybersecurity Reflections from an OT Cybersecurity Practitioner In Part 1 of this series, I reflected on why OT cybersecurity maturity is often constrained by governance behaviour, incentives, and decision-making rather than technology. One related theme that repeatedly surfaces in practice is the issue of management visibility, specifically, the gap between…

Operational risk doesn’t live where decisions are most comfortable.

Governance, Not Technology, Is Holding OT Cybersecurity Back Reflections from an OT Cybersecurity Practitioner After another year delivering OT cybersecurity services and solutions, one observation continues to surface, a pattern repeated consistently over time. While technology is often challenging, OT cybersecurity maturity is more often constrained by governance behaviour, organisational incentives, and how decisions are…