BLOG

Date
22-09-2026

OT Cybersecurity

96% of OT Incidents Start in IT: Secure the Boundary That Actually Gets Crossed

A 2026 Frost and Sullivan survey of OT security decision-makers found that 60 percent of industrial organizations experienced an OT security incident during 2025, and that 96 percent of those incidents originated from an initial IT-level compromise.

That second figure deserves more attention than it gets. It means the overwhelming majority of OT incidents did not begin with a targeted attack on a controller, an exotic ICS exploit, or a nation-state operation against a safety system. They began with something ordinary happening on the corporate network, and then reaching further than it should have.

 

What the Number Actually Tells You

It reframes the budgeting question. Much OT security spending is directed at the deepest layers of the industrial network, which is where the highest-consequence assets sit and where the most alarming attack research is published. That work matters. But if 96 percent of real incidents arrive through the IT/OT boundary, then the boundary is where the marginal dollar buys the most risk reduction.

It also explains why so many organizations with mature Purdue Model architecture on paper still experience OT incidents. The architecture describes how the network should be layered. The incident data describes how attackers actually move, which is through the connections that were added operationally and never formally reviewed.

 

The Boundary Is Wider Than the Firewall

Most operators picture the IT/OT boundary as a firewall between the corporate network and the plant network. In practice the boundary has many more crossings than that, and several of them are not network connections at all.

 

Crossing

Why It Exists

How It Gets Exploited

Historian and data replication

Production reporting, analytics, ERP integration

Bidirectional path where a one-way flow was assumed

Vendor remote access

Maintenance and support for OT equipment

Compromised or shared credentials, persistent sessions

Engineering workstations

Programming controllers, holding project files

Phished IT account gives access to OT programming tools

Removable media

Firmware, project files, backups, patch delivery

Physical transfer bypassing every network control

Shared Active Directory

Convenience of single identity management

IT domain compromise extends directly into OT authentication

Cloud-connected OT assets

Vendor telemetry, IIoT, remote monitoring

Outbound connection becomes an inbound pathway

 

The crossing most often missed in architecture reviews

Shared Active Directory. It rarely appears on a network diagram as an IT/OT connection because it is an identity service rather than a data flow, yet it means an IT domain compromise can authenticate against OT systems directly. Organizations that have carefully segmented their networks frequently discover their identity infrastructure was never segmented at all.

 

What Actually Reduces the 96 Percent

An industrial DMZ, properly terminated

The single most effective structural control is a DMZ where no session traverses end to end from the corporate network to the control network. Connections terminate on both sides, and data is exchanged through the DMZ rather than passed through it. OT DMZ deployment is what converts a firewall rule into an architectural boundary.

Hardware-enforced one-way flow where it fits

For data that only needs to leave the OT network, such as historian replication and reporting, a unidirectional gateway removes the inbound path entirely as a matter of physics rather than configuration. Our comparison of data diodes and firewalls covers where each is appropriate, and the six proven deployment use cases cover the flows this typically applies to.

Identity separation

Separate authentication for OT systems, with no trust relationship that allows an IT domain compromise to authenticate into the control network. Zero Trust principles applied to OT address this directly, particularly for vendor and engineering access.

Vendor access governed by session, not by tunnel

Persistent vendor VPN connections are among the most consistently exploited pathways in OT incidents. Session-governed remote access with identity authentication, recording and prompt revocation closes it without disrupting the vendor relationship.

Control of the non-network crossing

Removable media bypasses every control above by not using the network at all. Removable media inspection at the physical boundary is the corresponding control.

 

Where to Start

The practical first step is an architecture review that maps every actual crossing rather than every documented one. In most environments the two lists differ substantially, and the difference is where incidents originate. An OT risk assessment produces that map, along with the evidence needed to prioritize which crossings to close first.

Prioritize by reachability and consequence together. A crossing that reaches a historian is a different problem from one that reaches an engineering workstation with programming access to safety-related controllers.

 

Why Choose Arista Cyber

Arista Cyber approaches the IT/OT boundary as an engineering problem rather than a firewall configuration. We map the crossings that exist rather than the ones on the diagram, design DMZ and segmentation architecture that terminates sessions properly, and deploy hardware-enforced isolation where the data flow justifies it.

Because we also work in functional safety, we account for what sits behind each crossing. A boundary protecting a safety instrumented system warrants different treatment from one protecting a reporting server, and that distinction is frequently absent from purely IT-led architecture work.

 

Next Steps

If your last IT/OT architecture review predates your most recent integration project, the documented boundary and the real one have probably diverged. Explore our OT cybersecurity services, read about network segmentation for industrial environments, or contact the Arista Cyber team.

 

Common Questions

If most incidents start in IT, is OT-specific security still necessary?

Yes, for two reasons. The origin of an incident and its consequence are different things: an incident that starts with a phished IT account can still end with a controller manipulated or a process halted, and only OT-specific controls limit that outcome. And the remaining minority of incidents that originate in OT directly tend to be the highest-consequence ones. The data argues for weighting the boundary more heavily, not for abandoning depth.

Does an air-gapped network avoid this problem?

It removes the network crossings and increases dependence on the physical ones. Air-gapped environments move firmware, project files, patches and backups on removable media, because there is no other path. That makes removable media control the primary boundary control rather than a supplementary one.

What is the difference between a DMZ and a data diode at the IT/OT boundary?

A DMZ terminates connections on both sides and allows controlled bidirectional exchange, which suits flows that genuinely need to move in both directions. A data diode enforces one-way flow in hardware, which suits data that only needs to leave OT. Most environments need both at different crossings. Our data diode and firewall comparison covers the selection criteria.

 

Do you know every crossing at your IT/OT boundary?

Arista Cyber maps the connections that actually exist, not the ones on the diagram, and designs the architecture to close them.

Book a Free Consultation

BOOK YOUR CONSULTATION