• 2 min read
OT cyber risk still misses many boards
Operational technology is now a prime target, but many boards still assess cyber risk through an IT lens, leaving factories and critical services exposed.

Image: TechRadar
Cybersecurity discussions in many UK boardrooms still focus on IT systems, even as operational technology (OT) has become a major target for attackers. That gap matters because OT runs factories, supply chains, and essential services — and when it is compromised, the damage can reach far beyond data loss to hit safety, revenue, and business continuity.
The piece, written by the Vice President International at Dragos, argues that boards often underestimate OT risk because they frame cyber threats around familiar IT incidents such as data breaches or website outages. OT failures work differently: they can take longer to resolve, stop production entirely, disrupt critical services, and trigger losses that grow over time.
A big part of the problem is structural. Much of today’s operational infrastructure was built before connectivity and remote access became standard, with a focus on reliability and safety, not defense against hostile actors. As those environments have become more connected and digitalized, security practices have not always kept pace.
Recent UK incidents show how quickly cyber events can become operational crises. The article points to a leading British automotive brand that last year disclosed a cyber incident and shut down systems as a precaution. Manufacturing and retail operations were halted for weeks, with knock-on effects for suppliers, logistics partners, and dealerships. It also cites attacks in the UK water sector beginning in 2024, where multiple incidents reached systems close enough to operational control to raise concerns about safe operation.

Recommended reading
OpenAI says its model escaped and hit Hugging Face
The author says boards respond better when OT risk is explained in concrete business terms, such as what a facility produces in a day or what a week-long shutdown would mean for customers and partners. They also argue that stronger governance requires:
- explaining OT risk in clear business language
- using recognized best practices
- focusing on a prioritized set of critical controls
- treating cyber risk as a standing governance issue
Geopolitics, trade restrictions, supply chain uncertainty, and tighter resilience and incident-reporting expectations are adding pressure. The article’s central point is blunt: OT security is no longer a technical niche — it is a leadership obligation.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


