S&H Management Consultants · IT & OT Risk Advisory · Insight Series · June 2026
Persistent Vulnerabilities across the IT & OT Convergence in Energy, Manufacturing, and Extractive Industries
The most consequential IT and OT security incidents of the past two years did not originate from sophisticated exploits. They originated from conditions that had been present in the environment for months: ungoverned access, misclassified assets, and monitoring that stopped at the edge of one domain and did not extend into the other.
That is the operational consequence of inadequate IT and OT convergence governance. When those conditions go unaddressed long enough, an attacker does not need to breach a system. They follow the path that was already there.
01
OT Dwell Time: Classification Gaps and Undetected Access in Industrial Environments
In 2025, industrial organizations impacted by ransomware increased 95% year on year: from 1,693 to 3,300. Manufacturing accounted for more than two-thirds of all victims. The figure that carries the most operational weight is not the volume; it is the dwell time. Attackers spent an average of 42 days inside OT environments before detection.1
Forty-two days is not a monitoring oversight. It is a structural condition. Engineering workstations and HMIs running Windows were classified as IT assets; OT-specific hardening was never applied. IT monitoring covered the enterprise environment; OT monitoring covered the plant floor. The space between them, where those workstations actually sat, belonged to neither.
An attacker with 42 days in an OT environment has done more than persist undetected. They have mapped the architecture, identified the process, located the highest-consequence systems, and positioned for a disruption that, when it comes, will not look like a cyberattack. It will look like a production failure, an equipment fault, or an unexplained process anomaly. Fortinet FortiGuard Labs recorded over 36,000 automated reconnaissance scans per second in 2024; by the time dwell time is measured in weeks, the environment has already been mapped in detail.
02
Access Governance in OT Environments: A Persistent and Exploitable Vulnerability
In 2024, 76% of respondents in the extractive industry and materials sector reported that one or more cyberattacks originated from third-party supplier access to their cyber-physical systems.2 That figure points to a specific and widespread condition: vendor and contractor access into OT environments that is operationally necessary, routinely granted, and insufficiently governed.
The access management vulnerability in OT environments is not theoretical. Shared credentials on HMI workstations. Vendor remote access accounts that remain active long after the engagement is complete. Service accounts with broad privileges configured during commissioning and never reviewed since. Default credentials on PLCs and RTUs that have not been changed since installation.
These are the documented entry points, across incident after incident, in sector after sector. They persist not because organizations are careless, but because identity governance has not kept pace with the connectivity between IT and OT. In IT environments, privileged access management, multi-factor authentication, and credential lifecycle governance are established practice. In OT environments, the same discipline has not been applied with the same consistency; partly due to operational constraints, partly due to legacy system limitations, and partly because the accountability for governing access across both domains has not been clearly assigned.
The consequence of a compromised credential in OT is categorically different from a data breach. An attacker operating with valid credentials inside a control system environment is not extracting data. They are operating the plant, with the same access and the same apparent legitimacy as the engineer or vendor whose credentials they are using.
03
Data Integrity at the IT & OT Convergence: The Operational Safety Dimension
The SCADA operator trusts what the screen shows. That trust is not naïve; it is functional. The operator's job is to make real-time control decisions based on the data in front of them: open a valve, adjust a set point, trip a circuit breaker. The integrity of that data is the foundation of every decision they make.
When that data has been manipulated, delayed, falsified, or interrupted, the operator is not making a wrong decision. They are making a correct decision based on information that is no longer accurate. The distinction matters enormously when the physical consequence is equipment damage, a process upset, or a safety event.
In the Poland energy grid attack of December 2025, operators lost visibility between facilities and grid control at the worst possible moment: mid-winter, with nearly half a million people depending on those systems for heat.3 The wiper malware that corrupted OT firmware and destroyed HMI data did not just disrupt operations; it removed the operators' ability to know what was happening in the plant and respond accordingly.
This is the operational consequence that does not appear in most cybersecurity risk assessments, because most cybersecurity risk assessments are written from an IT perspective, where availability and integrity are important but rarely a matter of immediate physical safety. In OT environments, the priority hierarchy is reversed. Availability and integrity are not IT metrics; they are the conditions under which operators make decisions that affect equipment, processes, and people.
Final Remarks
Not every organization running OT will experience a Poland-scale event. But the underlying condition, monitoring that does not cross both domains, data integrity that is not verified across the IT & OT convergence, operators working from systems whose accuracy has not been validated end to end, is present in far more industrial environments than the incident statistics reflect.
None of these three conditions required a sophisticated attacker. None were caused by a failure of technology. Each one was a governance condition: accountability not defined, access not governed across both domains, visibility not maintained across the convergence.
IT and OT are different environments and they should remain so. The goal is not to make them the same; it is to make the interdependencies between them visible, owned, and maintained. That requires a pragmatic, iterative process built with the teams responsible for both environments, one they understand, own, and can sustain, not a framework handed down from outside.
Primary Sources
- Dragos, OT/ICS Cybersecurity Year in Review 2025, February 17, 2026. dragos.com
- Claroty, Global State of CPS Security 2024, Mining and Materials Sector, December 2024. claroty.com
- CERT Polska, Energy Sector Incident Report, 29 December 2025, January 30, 2026. cert.pl
- CISA, Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps, February 10, 2026. cisa.gov
- Fortinet FortiGuard Labs, Global Threat Landscape Report 2025. fortinet.com
An abridged version of this article was published on LinkedIn in the Cybersecurity Tips Newsletter.
© S&H Management Consultants Inc. 2026
