Why OT Security Demands Context, Not Just Controls
运营技术(OT)安全在关键基础设施保护中日益重要。与IT不同,OT涉及物理过程和老旧设备,配置错误或重启可能导致重大损失甚至安全隐患。将安全融入制造文化至关重要,需关注漏洞位置、资产重要性和现有保护措施。通过这种方法,企业可提升效率并实现可衡量的安全韧性。
2025-8-29 17:0:15
Author: securityboulevard.com(查看原文)
阅读量:11
收藏
Operational technology (OT) security is no longer a niche concern—it’s front and center in today’s cyber conversations. At Black Hat this year, OT had a real moment, signaling that protecting critical infrastructure has finally caught the broader security community’s attention. Rick Kaun, global director of cybersecurity services at Rockwell Automation, unpacks what makes OT security so different—and why “think global, act local” is more than a catchphrase.
Kahn traces his 25-year journey through the evolution of OT security, noting how IT-style controls don’t simply map onto industrial systems. A misconfigured patch or a routine reboot might be an inconvenience in IT, but in OT it can mean multimillion-dollar outages—or worse, safety risks. Unlike IT, OT environments run on decades-old equipment tied directly to physical processes, from pipelines to medical devices, where uptime and safety are paramount.
Security has to be embedded into the very culture of manufacturing, much like safety systems. That means moving past one-off fixes and focusing on contextual data—understanding not just what vulnerabilities exist, but where they sit, how critical the affected assets are, and what protections are already in place. With that lens, organizations can prioritize risks, streamline responses, and build global strategies that adapt to local realities.
The payoff is significant. Companies embracing this model are seeing major efficiency gains—turning what once took days of manual effort into hours—while giving boards and insurers the assurance that resiliency isn’t just an aspiration, but a measurable outcome.
For manufacturers and critical infrastructure operators, the message is clear: Cybersecurity isn’t just about defense. It’s about keeping the systems that keep society running safe, reliable, and resilient.

Alan Shimel
Throughout his career spanning over 25 years in the IT industry, Alan Shimel has been at the forefront of leading technology change. From hosting and infrastructure, to security and now DevOps, Shimel is an industry leader whose opinions and views are widely sought after.
Alan’s entrepreneurial ventures have seen him found or co-found several technology related companies including TriStar Web, StillSecure, The CISO Group, MediaOps, Inc., DevOps.com and the DevOps Institute. He has also helped several companies grow from startup to public entities and beyond. He has held a variety of executive roles around Business and Corporate Development, Sales, Marketing, Product and Strategy.
Alan is also the founder of the Security Bloggers Network, the Security Bloggers Meetups and awards which run at various Security conferences and Security Boulevard.
Most recently Shimel saw the impact that DevOps and related technologies were going to have on the Software Development Lifecycle and the entire IT stack. He founded DevOps.com and then the DevOps Institute. DevOps.com is the leading destination for all things DevOps, as well as the producers of multiple DevOps events called DevOps Connect. DevOps Connect produces DevSecOps and Rugged DevOps tracks and events at leading security conferences such as RSA Conference, InfoSec Europe and InfoSec World. The DevOps Institute is the leading provider of DevOps education, training and certification.
Alan has a BA in Government and Politics from St Johns University, a JD from New York Law School and a lifetime of business experience.
His legal education, long experience in the field, and New York street smarts combine to form a unique personality that is always in demand to appear at conferences and events.
alan has 107 posts and counting.See all posts by alan
文章来源: https://securityboulevard.com/2025/08/why-ot-security-demands-context-not-just-controls/?utm_source=rss&utm_medium=rss&utm_campaign=why-ot-security-demands-context-not-just-controls
如有侵权请联系:admin#unsafe.sh