
IT/OT convergence is not a future state to plan for. In most critical infrastructure organisations, it already happened, incrementally, across a decade of efficiency projects. SCADA data feeds a corporate dashboard. A historian sits in the cloud. Vendors hold remote access into plant systems. Engineering workstations authenticate against the same directory as the finance team.
What has not caught up is how those environments get assessed. Many operators still run one cybersecurity assessment for IT and a separate one for OT, on different cycles, against different frameworks, reported to different people. The risk that matters most now sits in the space between them, and neither assessment is looking at it.
Convergence is rarely a deliberate architecture decision. It accumulates. A remote monitoring project needs a data path out of the control network. A vendor support contract needs a way in. A reporting obligation needs plant data in a corporate system. Each step is justifiable on its own, and each one adds a connection between environments that were once genuinely separate.
Threat activity has followed. ASD's Annual Cyber Threat Report 2024-25 records critical infrastructure in 13% of the incidents ASD responded to, with denial of service present in 31% of CI incidents, close to twice the rate across all incidents.
State-sponsored actors are also making heavier use of living off the land techniques, which work by blending into legitimate traffic. Those are hardest to spot at the boundary, where two teams each assume the other has visibility.
Three things fall through the gap between IT and OT consistently.
Separate assessments scope separate environments, so the connections between them belong to neither. Insecure data flows, flat segments behind a firewall configured years ago, and jump hosts nobody has reviewed, sit outside both scopes. Shared identity infrastructure is the clearest example. If a domain compromise on the corporate side grants access to engineering workstations, that is one attack path spanning two assessments, and it appears in neither report. The attack surface created by convergence is not the sum of two environments. It is both environments plus everything joining them.
Ransomware that lands in IT and forces an OT shutdown is the familiar pattern, and it is a useful test of whether your assessments are joined up. The IT assessment scores the initial access risk. The OT assessment scores the availability risk. Neither scores the path between them, nor the operational decision to halt production because you cannot prove the control network is clean. That decision, and the days of lost service behind it, is the actual risk.
IT and OT weigh security differently. IT protects confidentiality and integrity. OT protects availability and safety, and will refuse a control that introduces latency or an unplanned restart. Both positions are defensible. The problem arrives at the convergence zone, where each team assumes the other owns it, so it attracts neither team's budget. The same gap shows up during an incident, when two teams that have never assessed a shared scenario have to coordinate a response to one.
The regulator has already taken a position. A critical infrastructure risk management program under the SOCI Act must address hazards across four vectors, covering cyber and information security, personnel, supply chain, and physical and natural hazards, and it applies to the critical infrastructure asset as a whole. There is no provision for scoping out the operational technology the asset runs on.
AESCSF Version 2, released on 10 October 2023, moved in the same way. It expanded the framework from 282 to 354 practices and anti-patterns, placed considerably more weight on operational technology and supply chain security, and is recognised by CISC as compatible with CIRMP obligations.
ASD's CI Fortify guidance goes further, asking operators to be capable of isolating vital OT and enabling systems for three months. Demonstrating that capability requires knowing exactly what crosses the boundary, what depends on what, and what breaks when the link is cut. Our walkthrough of the six steps to isolate critical OT systems covers what that involves in practice. A siloed assessment will not produce that picture.
Overcyte runs assessments across IT and OT in a single platform, with built-in support for AESCSF, the Essential Eight, ISO 27001, NIST CSF and ISA/IEC 62443. Controls, evidence and scoring sit in one place regardless of which environment they relate to, so the boundary is inside the assessment rather than between two of them.
Dashboards show maturity and compliance posture across the full asset base, which is the view CIRMP reporting and board oversight both require. The platform was built by people with backgrounds in industrial control systems, which is why the framework coverage extends into OT rather than treating it as an annex to IT.
See how Overcyte gives critical infrastructure operators one view of cyber risk across IT and OT.
Book a demo with our team.