What it is
IT refers to the systems used to process, store, and communicate data: servers, workstations, cloud infrastructure, enterprise applications, and the networks connecting them. OT refers to the systems used to monitor and control physical processes: PLCs, RTUs, SCADA systems, distributed control systems, and the industrial networks they run on. Both categories involve computers and networks, but they were designed with different goals, different constraints, and very different definitions of what failure means.
Key points
- IT systems prioritize confidentiality and integrity. OT systems prioritize availability and physical safety above everything else.
- IT operates on refresh cycles measured in years. OT equipment runs for decades, often without updates or vendor support.
- IT security tools and methods were built for a different environment and can cause serious harm when applied to OT without adaptation.
- Convergence between IT and OT networks is growing, which transfers IT-world risk into environments that were never designed to handle it.
Concrete example
A security team responsible for both IT and OT at a manufacturing company decides to roll out endpoint detection software across the entire environment. In IT, this goes smoothly. When the same agent is deployed on an older Windows-based HMI in the production facility, the additional CPU load causes the interface to become unresponsive, triggering an unplanned line stop. The difference was not the tool. It was the environment the tool was deployed into.