In this article

OT Threat Intelligence: Bridging the IT/OT Divide

IT and OT teams both read the risk correctly. The exposures live in the friction between them, and intelligence is the one input neither side has to fight.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Updated September 3, 2026

OT threat intelligence and the IT OT divide

Introduction

When an IT security team and an OT engineering team look at the same industrial network, they see two different machines.

The IT team sees unpatched systems, exposed remote access, and flat networks that a competent attacker could cross in an afternoon. The OT team sees physical infrastructure that has to run safely, for years, where an unplanned reboot can stop a production line, void a safety case, or in the wrong plant put people in danger.

Both are looking at the truth. That is the problem.

Most OT security advice fails not because it is wrong but because it is culturally illegible to the people who have to implement it. "Patch it now" is sound in a data center and reckless on a turbine controller with one maintenance window a year. "Just segment the network" assumes a greenfield that no operating plant has. The friction between these two worldviews is not a sign that one side is behind. It is the actual condition of industrial security, and increasingly it is the attack surface itself.

OT threat intelligence works because it asks nothing of either side's operating model. It does not require a reboot, a patch outside the window, or a re-litigation of the vendor's security claims. It tells you what to watch, not what to tear out.

Why the OT worldview is rational

Safety comes first in OT, and it is hard for an IT professional to overstate how completely this organizes everything else.

A failure in a corporate network costs money and reputation. A failure in a control system can cost a life or an ecosystem. The safety instrumented systems that sit beneath the process are not allowed to fail, full stop, and everything above them inherits that discipline.

The table below puts the two risk profiles side by side. It originates from a 2014 study of cyber risk in industrial control systems and has needed almost no revision since, which is itself the argument.

Risk Category

ICS or SCADA System

Corporate IT

Information Confidentiality

Low

High (Intellectual Property)

System Integrity

Very High

Low to Very High (Business Critical)

System Availability

Rebooting and momentary downtime unacceptable



Some operations are based on 99.99999% up time

Rebooting acceptable within specified time frames



Outages may be tolerated (determined by system impact)

Impact of System Failure

Regulatory non-compliance

Production interruptions

Supply chain affected

Reduced share price

Environmental damage

Personal injury or loss of life



Business operations

Market perception

Reduced share price

Customer confidence

Time Criticality

Response to human interaction and emergency situations is critical, see above.

System and service dependent

Performance

Must be real time

Latency and false positives are not acceptable

Moderate network throughput

Must be consistent

Latency and false positives are accepted as BAU

High network throughput



Priority of Risk Controls

Safety is primary

Process protection (integrity and availability)

Fault tolerance is critical

Protecting data confidentiality and integrity are primary

Fault Tolerance less critical

The availability math follows from this. Some industrial environments are specified to 99.99999 percent uptime, which allows a little over three seconds of downtime per year. A seasoned IT team works to 99.999 percent, roughly five minutes, and considers that demanding. The gap between three seconds and five minutes is the gap between the two professions. It is why a power station may hold a single annual shutdown window for every configuration change, patch included, while a corporate environment ships changes continuously.

In that light, "legacy" often means "proven." A controller running an operating system a decade past its corporate end-of-life is not necessarily negligence; it may be a system that has been validated against a physical process and left alone precisely because it works. The OT reflex to not touch what is running is not stubbornness. It is a rational response to an environment where the cost of being wrong is measured in more than dollars.

Why the IT worldview is also rational

The trouble is that the environment stopped holding still. The air gap that once justified leaving control systems untouched was always more aspiration than fact, and IT/OT convergence has erased most of what remained. Business demand for real-time production data, remote troubleshooting by vendors, and cloud-connected historians has quietly stitched OT networks to the wider internet, one convenient connection at a time.

Each of those connections is rational on its own terms. A small utility exposes a control interface so an engineer can respond at 2 a.m. without a two-hour drive. A vendor keeps a remote-access tool live so it can support the equipment it sold. None of these decisions is stupid. Together they produce an attack surface that expanded steadily while the OT instinct to leave things alone stayed constant. The IT worry is not that OT is careless. It is that the threat moved and the posture did not.

The friction is the risk

The exposures that actually get exploited live in the seams between these two rational worlds. They are rarely exotic.

Default credentials get left in place for the same reason the OT world does most things: continuity. A device that ships with a known username and password in firmware is a device an engineer can swap in at 3 a.m. and bring back online before the supply chain notices. The convenience is real and the risk is real, and no one owns the tradeoff because it falls between the teams.

Human-machine interfaces get exposed to the internet for remote troubleshooting, then stay exposed long after the reason is forgotten. "We're segmented" is asserted more often than it is tested, and a firewall installed once is treated as a permanent fact rather than a control that decays. The manufacturer's assurance that a system is secure is taken at face value, because re-testing it means questioning both the vendor and the colleague who signed off on the deployment, which is its own kind of politics.

This is the part that has barely moved. A 2014 threat research study of cyber risk in industrial control systems cataloged exactly these patterns: default passwords, exposed interfaces, untested segmentation, unquestioned vendor claims. The surprising thing in 2026 is how little of that list is out of date. The technology changed. The seams did not.

What changed instead was who walks through them. Through 2024 and 2025, disrupting a small utility stopped requiring nation-state tradecraft. Both groups below still trace to state interests, which is the point rather than an objection to it: neither operation used capability a state had to supply, and the same doors are open to anyone who scans for them.

The Cyber Army of Russia Reborn, which Mandiant links to infrastructure operated by Sandworm, the GRU unit tracked as APT44, manipulated the human-machine interface at a municipal water tank in Muleshoe, Texas, in January 2024, overriding pump controls until the tank overflowed for roughly half an hour. The technique was not sophisticated. It was an exposed remote login and a control interface that trusted whoever reached it.

CyberAv3ngers, which CISA identifies as a persona used by cyber actors affiliated with Iran's Islamic Revolutionary Guard Corps, ran a broader campaign against internet-exposed programmable logic controllers in the water and wastewater sector, again leaning on default or absent passwords rather than any novel exploit.

The Colonial Pipeline shutdown in 2021 made the same point from the other direction. The ransomware never touched the OT network; it hit the business IT side, and as the company's CEO told the Senate Homeland Security Committee, operators shut the pipeline down themselves within an hour of discovering the intrusion, as a containment decision rather than a forced one. The physical disruption was a second-order effect of an IT incident, which is exactly the convergence the OT world worried about and the IT world underestimated.

Colonial was not an outlier. The SANS 2025 ICS/OT survey found that more than half of OT compromises originate in IT or external networks and pivot inward, which makes the IT boundary an OT problem whether or not the OT team owns it.

And then there is Oldsmar, useful precisely because it is contested. In 2021 an operator at a Florida water plant watched the sodium hydroxide setpoint move on a TeamViewer-connected workstation and reverted it within minutes. It was reported as an attempted poisoning. Two years later, as the Tampa Bay Times reported, the FBI stated it had not been able to confirm the incident was initiated by a targeted intrusion, and the city manager at the time described it as a nonevent that law enforcement and the media had run with. The Pinellas County Sheriff's Office case remained open. Whether it was an intruder or a mistaken click may never be settled, and for the security question it does not matter. A remote-access path that makes an accident and an attack indistinguishable is a governance failure either way. The friction produced the exposure regardless of who was on the other end.

The bridge

The teams that close these seams do it by translation, not conquest. Neither worldview wins.

It starts with framing risk in the language the OT side already uses. Confidentiality, the organizing principle of most IT security, ranks low in a control room where the process data is not the crown jewel. Integrity and availability rank at the top, because a manipulated setpoint or a halted process is the thing that hurts. Risk framed as a threat to safety and continuity gets heard. The same risk framed as a data-protection problem does not.

It runs the other way too. IT teams that succeed in OT treat the constraints, the patch window, the no-reboot rule, the validated configuration, as design inputs rather than obstacles to be overruled. A control that respects the maintenance calendar gets adopted. A control that demands the plant behave like a data center gets quietly ignored, and an ignored control is worse than none because it looks like coverage.

Where intelligence fits

There is one discipline both sides can adopt without either changing its operational reality, and it is threat intelligence. External intelligence does not require a reboot, a patch outside the window, or a re-litigation of the vendor's security claims. It tells you what to watch, not what to tear out.

For the OT operator, that means early warning that respects the maintenance calendar: knowing which actors are scanning for your protocols, which exposed-asset discussions name your sector, which newly disclosed vulnerability is about to be weaponized, in time to plan a response around the next window rather than scramble outside it. For the IT leader, it means the same picture in a shared language, so the conversation with the OT team starts from evidence rather than from a worst-case scenario that is easy to dismiss. Intelligence is the one input that makes the friction productive instead of dangerous, because for once both teams are reading from the same page.

Read the next blog now

Part two of this series moves from the friction to the actors exploiting it: the pro-Russian and pro-Palestinian groups now claiming operational disruption of water, energy, and building control systems, the tooling they sell to each other, and how much of what they claim survives inspection.

Carry on reading Part 2 here