The Governance Gap That Nation-State Actors Have Already Found
For most organisations that operate physical infrastructure — energy, water, manufacturing, logistics, healthcare — the cyber risk governance framework covers IT systems comprehensively and operational technology (OT) systems almost not at all. Board risk registers acknowledge OT exposure in a line or two. Cyber insurance policies exclude physical damage caused by cyber events or cap OT-related losses at a sublimit that bears no relationship to the actual recovery cost. Security investments flow overwhelmingly into IT infrastructure, with OT budgets set separately and reviewed separately, usually by engineering rather than security leadership.
Nation-state actors have noticed. Volt Typhoon — the China-linked APT conducting systematic pre-positioning in Western critical infrastructure — operates almost exclusively in the OT-adjacent layer of utilities and energy operators. CISA and Five Eyes partner agencies have confirmed the group’s access to OT networks at US water, energy, and telecoms operators. The explicit intelligence assessment is that Volt Typhoon is not conducting intelligence collection; it is establishing access that could be activated to disrupt services in the event of a geopolitical crisis. The same pattern has been confirmed, with different actors, in European utility networks and manufacturing plants.
The operational question for boards is not whether OT cyber risk exists — it does, and at material scale — but whether their current governance structure is capable of managing it.
What OT Environments Look Like From a Security Perspective
Understanding the risk requires understanding why OT environments have not kept pace with IT security practices.
Age. Industrial control systems have operational lifespans measured in decades. A PLC that was installed in a manufacturing plant in 2008 may be controlling production in 2026 on the same firmware, because replacing it requires a production shutdown, capital expenditure, and re-validation of safety certifications. The same device that cannot be patched because patching was not part of its design is often directly connected to corporate IT networks for monitoring and data collection purposes.
Design assumptions. OT equipment was designed for availability, reliability, and safety — not for operating in an environment where adversaries are actively attempting to access it. Many industrial protocols (Modbus, DNP3, PROFINET) have no authentication. A device that speaks Modbus accepts commands from any device on the same network segment. These are not vulnerabilities that can be patched; they are architectural properties of the protocols.
Monitoring gaps. Standard endpoint detection agents — the tools that give SOC teams visibility into IT systems — cannot be installed on most PLCs, SCADA servers, or HMI workstations without voiding vendor support and potentially violating safety certifications. Many OT environments have no security monitoring at all; the first indication of a compromise is a process disruption or a physical event.
Convergence. The IT/OT boundary that was supposed to protect industrial systems has been steadily eroded by legitimate operational requirements. Remote monitoring, predictive maintenance using cloud analytics, supply chain integration, and COVID-era remote access for engineers have all created connectivity pathways that bypass the intended isolation. Many organisations do not have accurate documentation of what is connected to what.
Why Standard Governance Frameworks Fail Here
Most enterprise risk frameworks assess cyber risk through an IT security lens: data breaches, ransomware, regulatory fines, reputational damage. These are meaningful but incomplete risk categories for organisations with OT exposure. The OT risk categories that do not map cleanly to standard frameworks include:
Physical safety events. The Stuxnet attack on Iranian uranium enrichment centrifuges caused physical destruction. The TRITON/TRISIS malware attack on a Saudi petrochemical facility in 2017 targeted Safety Instrumented Systems — the devices that trigger emergency shutdowns to prevent industrial accidents. Cyber events that cause or prevent safety responses have consequences measured in human lives, not data records. No standard breach cost model applies.
Operational continuity losses. A ransomware attack on an IT network can be recovered from by reimaging workstations and restoring from backup. A ransomware attack that reaches an OT environment may require manual restart procedures across hundreds of physical assets, engineering validation of each, and extended production downtime while process safety is confirmed. The 2021 Colonial Pipeline attack — which was an IT ransomware event that caused the company to preemptively shut down its OT pipeline control systems — produced six days of fuel supply disruption across the US East Coast from a single organisation’s business decision.
Environmental and regulatory consequences. Process disruptions in water treatment, chemical processing, or waste management can cause environmental releases that trigger regulatory investigations, enforcement actions, and civil liability that dwells outside standard cyber incident response playbooks.
None of these consequences appear in a typical cyber insurance policy without careful, OT-specific negotiation. Many boards do not know this gap exists until they need to make a claim.
The Questions Boards Should Be Asking
Governance cannot close these gaps without asking the right questions. Boards that have substantive OT exposure should be asking:
What is our IT/OT boundary, and who owns the documentation of it? The answer to this question in many organisations is “we don’t know” or “the engineering team maintains a diagram that security has never reviewed.” The OT attack surface cannot be governed if it cannot be described.
Has our most recently completed cyber risk assessment included OT scope? Many cyber risk assessments — whether internal audits or third-party exercises — treat IT and OT as separate domains, often because the assessment vendor does not have OT expertise. The intersection is where the real risk lives.
What is our cyber insurance policy’s position on OT events? Ask specifically: does the policy cover loss of operational revenue from an OT disruption? Does it cover equipment replacement caused by a cyber event? Does it cover environmental remediation costs from a process disruption? The answers are often no, and boards should understand that exposure explicitly.
How would we know if a Volt Typhoon-style actor was pre-positioned in our OT network? The honest answer for most organisations is: we would not know until something happened. That answer should produce a specific remediation plan, not a risk acceptance.
What is our recovery time objective for an OT environment that has been compromised? IT environments have well-understood RTO frameworks. OT environments often do not — and the engineering-specific knowledge required to safely restart an industrial process is concentrated in a small number of people. Board-level continuity assurance requires understanding whether that knowledge is documented and whether it would survive an event that disrupted operations.
Practical Governance Steps
For boards and CISOs beginning to close this gap:
Commission an OT-specific risk assessment. Use a firm with genuine industrial experience, not a generalist IT security assessor. The assessment should enumerate OT assets, map IT/OT connectivity, identify remote access vectors, and assess monitoring capability.
Include OT scope in tabletop exercises. Simulate scenarios specific to your operational environment: ransomware reaching the SCADA layer, a logic bomb in a PLC, loss of HMI access during production. The response procedures for IT and OT events are different and require different stakeholders.
Review insurance coverage explicitly. Work with your broker to understand exactly what OT-related losses are covered and under what conditions. If the answer is unsatisfactory, negotiate an endorsement or consider supplemental coverage.
Establish a CISO/OT engineering governance bridge. In most organisations, the CISO and the chief engineer (or VP of Operations) do not have regular forums to discuss risk. Creating that forum is the structural change that enables everything else.
Prioritise network segmentation investment. Even where monitoring is impossible and devices cannot be patched, segmentation limits the blast radius of a compromise. Implementing unidirectional gateways (data diodes) between OT and IT networks, and removing unnecessary remote access pathways, are the highest-return OT security investments available.
The gap between OT cyber risk and OT governance is structural and widespread. The board’s role is to ensure the organisation knows what it cannot see, insures what it cannot protect, and has tested its response before it needs it.