Xalient Holdings Ltd

05/07/2026 | Press release | Archived content

The Modern OT Challenge: Why Connectivity, Compliance, and Risk Have Collided

For decades, operational technology (OT) environments were designed with one primary goal: availability. Systems were built to run continuously, often for decades, in isolated environments where stability and safety mattered far more than connectivity or data exchange.

That reality has changed.

Today's OT environments must support remote operations, third-party access, multi-site connectivity, and cloud integration-while also meeting increasing regulatory expectations. The result is a collision between connectivity, compliance, and risk that many organizations are struggling to manage.

This shift is redefining the OT security landscape and exposing the limitations of traditional models that were never designed for today's operating conditions.

OT Was Built for Availability, Not Hyper-Connectivity

Most industrial environments still rely on systems that were designed 15 to 25 years ago. These systems were built to be resilient, predictable, and isolated. Security was achieved through separation, not continuous control.

Historically, many OT networks were described as "air-gapped." In reality, most are now partially connected to support operational monitoring, vendor maintenance, data analytics, or centralized oversight. What has changed is not just network architecture, but operational expectations.

OT teams are now expected to enable remote access, connect sites, support external partners, and exchange data with IT systems and cloud platforms-without disrupting production or increasing safety risk.

Xalient explores this shift in more detail in Securing Operational Technology for a Connected World.

Increased Connectivity Creates New Exposure Points

Every new connection into an OT environment introduces potential exposure.

Traditional controls such as static firewall rules or standing VPN access were designed for predictable traffic patterns-not modern, dynamic access requirements.

In today's OT environments:

  • Engineers and vendors connect from multiple locations
  • Access needs change based on role, task, and time
  • Cloud services and IT systems interact directly with OT assets
  • Active Directory identities used for IT now directly expose OT systems

These conditions create new opportunities for lateral movement, particularly from IT into OT. Once an identity or credential is compromised, attackers can move across previously segmented systems.

This is why OT risk is increasingly about identity and access, not just networks. The same challenge is explored in Xalient's work on identity-driven access in industrial environments.

Legacy Systems Meet Rising Regulatory Pressure

As connectivity increases, regulatory scrutiny is intensifying.

Frameworks such as NIS2, the NCSC Cyber Assessment Framework (CAF), and IEC 62443 all emphasize:

  • Least-privilege access
  • Third-party risk management
  • Accountability and audit evidence
  • Ongoing, continuous assurance

Many OT environments, however, rely on legacy operating systems, proprietary platforms, and vendor-certified solutions that cannot be easily patched or modified. Security teams must instead rely on compensating controls.

Audits increasingly reveal the same issues:

  • Shared or generic accounts
  • Standing vendor access
  • Poor visibility into non-human identities (service accounts, certificates, embedded credentials)
  • Manual, time-consuming evidence collection

These challenges are highlighted in Xalient's guidance on securing regulated OT environments.

The Operational Risk of IT-to-OT Lateral Movement

IT and OT convergence is no longer theoretical. It is already in place across most organizations.

Identity platforms, remote access tools, and centralized directories increasingly sit on the path between enterprise IT systems and industrial control systems. Without consistent governance, these become high-risk attack paths.

A compromise that reaches OT systems can:

  • Disrupt production or critical services
  • Delay recovery and maintenance operations
  • Increase safety risks to engineers and operators
  • Trigger regulatory reporting and reputational damage

These impacts are especially acute in critical infrastructure sectors, as outlined in Xalient's energy and utilities security insights.

Why Traditional Purdue-Based Models Struggle in 2026


The Purdue Model remains a useful structural reference for understanding OT environments. However, it was never designed to solve today's access and compliance challenges.

Traditional Purdue-based security models:

  • Focus on network segmentation rather than identity
  • Assume static, predictable access patterns
  • Lack lifecycle governance for users, machines, and services
  • Rely on manual processes for audits and reviews
  • Do not address non-human identities or modern attack paths

As OT cybersecurity requirements evolve, these limitations become increasingly visible. Static controls struggle to manage what is now fundamentally an identity and access problem.

The New Reality: More Capability, More Pressure

Today's OT leaders are being asked to deliver more than ever before:

  • Enable secure remote operations
  • Support external partners without increasing exposure
  • Connect environments across sites and cloud platforms
  • Demonstrate compliance with frameworks like NIS2 and IEC 62443
  • Reduce operational risk without impacting availability

This is driving increased demand for managed security services that can provide continuous monitoring, governance, and assurance.

Under traditional models, every step toward modernisation increases complexity and audit pressure. Without a different control approach, organisations are forced to choose between progress and risk.

What This Means for OT Security Leaders

The modern OT challenge is not about abandoning established models. It is about recognising that connectivity has changed the problem.

Security strategies must evolve to reflect:

  • Dynamic, identity-driven access
  • Governance across both human and non-human identities
  • Continuous visibility rather than periodic checks
  • Evidence that supports both operational and regulatory assurance

Ultimately, organisations need a more integrated approach to OT security, combining identity, access, and monitoring across converged IT/OT environments.

David (DJ) Morimanno, Field CTO at Xalient

David (DJ) Morimanno is the Field CTO at Xalient, where he helps organisations design and deliver identity-centric security strategies for complex, fast-evolving environments. With over 20 years of experience, he brings deep expertise across identity governance, privileged access, access management, and broader identity security programs. As a practitioner, advisor and strategist, he supports clients in translating identity into practical, scalable capabilities.

His work focuses on modern identity challenges, including non-human and machine identities, AI governance, cloud entitlements, identity threat detection and response, and Zero Trust. DJ advises senior leaders and Fortune 500 organisations across sectors such as energy, healthcare, manufacturing, and financial services, helping them turn emerging trends into clear operating models and measurable security outcomes.

Xalient Holdings Ltd published this content on May 07, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 07, 2026 at 09:34 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]