05/07/2026 | Press release | Archived content
For decades, operational technology (OT) environments were designed with one primary goal: availability. Systems were built to run continuously, often for decades, in isolated environments where stability and safety mattered far more than connectivity or data exchange.
That reality has changed.
Today's OT environments must support remote operations, third-party access, multi-site connectivity, and cloud integration-while also meeting increasing regulatory expectations. The result is a collision between connectivity, compliance, and risk that many organizations are struggling to manage.
This shift is redefining the OT security landscape and exposing the limitations of traditional models that were never designed for today's operating conditions.
Most industrial environments still rely on systems that were designed 15 to 25 years ago. These systems were built to be resilient, predictable, and isolated. Security was achieved through separation, not continuous control.
Historically, many OT networks were described as "air-gapped." In reality, most are now partially connected to support operational monitoring, vendor maintenance, data analytics, or centralized oversight. What has changed is not just network architecture, but operational expectations.
OT teams are now expected to enable remote access, connect sites, support external partners, and exchange data with IT systems and cloud platforms-without disrupting production or increasing safety risk.
Xalient explores this shift in more detail in Securing Operational Technology for a Connected World.
Every new connection into an OT environment introduces potential exposure.
Traditional controls such as static firewall rules or standing VPN access were designed for predictable traffic patterns-not modern, dynamic access requirements.
In today's OT environments:
These conditions create new opportunities for lateral movement, particularly from IT into OT. Once an identity or credential is compromised, attackers can move across previously segmented systems.
This is why OT risk is increasingly about identity and access, not just networks. The same challenge is explored in Xalient's work on identity-driven access in industrial environments.
As connectivity increases, regulatory scrutiny is intensifying.
Frameworks such as NIS2, the NCSC Cyber Assessment Framework (CAF), and IEC 62443 all emphasize:
Many OT environments, however, rely on legacy operating systems, proprietary platforms, and vendor-certified solutions that cannot be easily patched or modified. Security teams must instead rely on compensating controls.
Audits increasingly reveal the same issues:
These challenges are highlighted in Xalient's guidance on securing regulated OT environments.
IT and OT convergence is no longer theoretical. It is already in place across most organizations.
Identity platforms, remote access tools, and centralized directories increasingly sit on the path between enterprise IT systems and industrial control systems. Without consistent governance, these become high-risk attack paths.
A compromise that reaches OT systems can:
These impacts are especially acute in critical infrastructure sectors, as outlined in Xalient's energy and utilities security insights.
The Purdue Model remains a useful structural reference for understanding OT environments. However, it was never designed to solve today's access and compliance challenges.
Traditional Purdue-based security models:
As OT cybersecurity requirements evolve, these limitations become increasingly visible. Static controls struggle to manage what is now fundamentally an identity and access problem.
Today's OT leaders are being asked to deliver more than ever before:
This is driving increased demand for managed security services that can provide continuous monitoring, governance, and assurance.
Under traditional models, every step toward modernisation increases complexity and audit pressure. Without a different control approach, organisations are forced to choose between progress and risk.
The modern OT challenge is not about abandoning established models. It is about recognising that connectivity has changed the problem.
Security strategies must evolve to reflect:
Ultimately, organisations need a more integrated approach to OT security, combining identity, access, and monitoring across converged IT/OT environments.
David (DJ) Morimanno is the Field CTO at Xalient, where he helps organisations design and deliver identity-centric security strategies for complex, fast-evolving environments. With over 20 years of experience, he brings deep expertise across identity governance, privileged access, access management, and broader identity security programs. As a practitioner, advisor and strategist, he supports clients in translating identity into practical, scalable capabilities.
His work focuses on modern identity challenges, including non-human and machine identities, AI governance, cloud entitlements, identity threat detection and response, and Zero Trust. DJ advises senior leaders and Fortune 500 organisations across sectors such as energy, healthcare, manufacturing, and financial services, helping them turn emerging trends into clear operating models and measurable security outcomes.