Skip to content
The ATC
Ctrl K
Ctrl K
Log in
What we do
Our capabilities
AI & DataAutomationCloudConsulting & EngineeringData CenterDigitalImplementation ServicesIT Spend OptimizationLab HostingMobilityNetworkingSecurityStrategic ResourcingSupply Chain & Integration
Industries
EnergyFinancial ServicesGlobal Service ProviderHealthcareLife SciencesManufacturingMedia & GamingPublic SectorRetailSports & EntertainmentUtilities
Learn from us
Hands on
AI Proving GroundCyber RangeLabs & Learning
Insights
ArticlesBlogCase StudiesPodcastsResearchWWT Presents
Come together
CommunitiesEvents
Who we are
Our organization
About UsOur LeadershipSponsorshipsLocationsSustainabilityNewsroom
Join the team
All CareersCareers in AmericaAsia Pacific CareersEMEA CareersInternship Program
Our partners
Strategic partners
CiscoDell TechnologiesHewlett Packard EnterpriseNetAppF5IntelNVIDIAMicrosoftPalo Alto NetworksAWSGoogle CloudVMware
What we do
Our capabilities
AI & DataAutomationCloudConsulting & EngineeringData CenterDigitalImplementation ServicesIT Spend OptimizationLab HostingMobilityNetworkingSecurityStrategic ResourcingSupply Chain & Integration
Industries
EnergyFinancial ServicesGlobal Service ProviderHealthcareLife SciencesManufacturingMedia & GamingPublic SectorRetailSports & EntertainmentUtilities
Learn from us
Hands on
AI Proving GroundCyber RangeLabs & Learning
Insights
ArticlesBlogCase StudiesPodcastsResearchWWT Presents
Come together
CommunitiesEvents
Who we are
Our organization
About UsOur LeadershipSponsorshipsLocationsSustainabilityNewsroom
Join the team
All CareersCareers in AmericaAsia Pacific CareersEMEA CareersInternship Program
Our partners
Strategic partners
CiscoDell TechnologiesHewlett Packard EnterpriseNetAppF5IntelNVIDIAMicrosoftPalo Alto NetworksAWSGoogle CloudVMware
The ATC
OT SecurityATCManufacturingSecurity
WWT Research • Industry Insights
• September 21, 2026 • 6 minute read

Who Should Own OT Security? The Answer Is More Nuanced Than You'd Think

As IT and OT environments converge, the old model of siloed security teams is breaking down. Manufacturers are best served by a new approach, one that balances executive ownership with the realities of the plant floor.

In this report

  1. How most companies divide OT security
  2. Why traditional OT security models fall short
  3. A better option: one strategy, two playbooks 
  4. Four principles to drive OT/IT alignment 
  5. Where to start 
  6. How WWT can help 

Manufacturing continues to be a prime target for cyberattacks. In 2025, the sector accounted for 28% of all breaches, more than any other industry for the fifth year in a row, and ransomware campaigns targeting manufacturers jumped 56%. Now, AI is accelerating these attacks with frontier AI models finding and exploiting vulnerabilities at a rate that most manufacturers aren't ready for. 

This brings up a question that's been asked by manufacturing leadership for years: who should own the OT security strategy? IT, OT, both? The answer isn't as simple as choosing one side. 

How most companies divide OT security

There are two security governance models that show up repeatedly across manufacturing: 

Model 1: OT owns OT security. Plant engineering or leadership owns the security strategy. Cybersecurity is funded from the facility's budget and run by people who understand OT systems. 

This model has historically made sense because OT engineers know their environment inside out. OT also has different priorities than IT. The CIA triad that IT goes by—confidentiality, integrity and availability—is flipped in OT environments. Safety comes first, followed by availability, then integrity, then confidentiality. 

Model 2: IT and the CISO own security enterprise-wide; OT owns the floor. In this model, IT and the CISO own the security strategy, tooling and enterprise risk reporting. OT keeps control of how security is implemented on the plant floor. The two teams essentially operate in silos without a unified structure.

The logic behind this model is that IT is great when it comes to building consistent standards across sites, centralized vulnerability management and a unified risk picture for the board. This is hard to do when security lives plant by plant. 

Why traditional OT security models fall short

The reality is that OT security is no longer just an OT conversation. Air-gapped systems hardly ever exist like they used to. In fact, today 96% of OT security incidents come from IT. When security stays solely with the plant leaders, standards become inconsistent across sites. As a result, the CISO has no enterprise-wide picture to report against and security can end up funded like it's just another maintenance cost.

On the other hand, giving everything to IT without OT's partnership has its own problems. Plant realities like safety interlocks and zero tolerance for downtime don't map neatly onto a traditional business security model. Applying standard IT controls without understanding those constraints can cause serious issues. 

A better option: one strategy, two playbooks 

In contrast to these two models, WWT's manufacturing team recommends one enterprise-wide security strategy, executed through two distinct playbooks. IT is ultimately responsible for governance with accountability distributed between IT and OT. The strategy needs to be owned by IT, but OT also must be included as only they can provide first-hand knowledge and expertise on OT systems. The two teams work as partners while remaining experts in their own domains. 

A playbook for IT and OT jointly owning security strategy.

For most manufacturers, this doesn't mean building something from scratch. It's more about extending IT's security strategy to also cover OT.

For example, one manufacturer we worked with had successfully piloted OT security capabilities at a single site, but scaling that approach across the organization proved difficult. By standardizing governance at the enterprise level while allowing individual facilities to adapt execution to local operational requirements, the company was able to expand the program across multiple locations without disrupting production.

Four principles to drive OT/IT alignment 

In practice, this model rests on four principles: 

  1. Executive ownership. The CISO owns OT cyber risk while having support from operations leadership. IT doesn't run the plant but someone at the executive level is accountable for security across the organization.
  2. Shared responsibility. An OT security council brings together members from IT security, OT engineering, plant operations, manufacturing leadership and the business. Clear roles across IT, OT and operations keep the group accountable.
  3. IT-led governance with OT-led execution. IT owns strategy and governance; plant teams own how that strategy gets executed. Neither operates without the other.
  4. Build the program in the right sequence. An OT security program starts by defining the most critical assets and their blast radius. Then it moves into segmentation, secure remote access and monitoring for those systems.
OT and IT expertise and processes inform an enterprise-wide security strategy.

Where to start 

A unified security strategy is a destination, not a first step. WWT's manufacturing team typically recommends a crawl/walk/run approach so manufacturers can make real progress in phases. 

Crawl: define blast radius. Determine what must keep running and what can safely be taken offline. Then map how those systems depend on and communicate with each other. Name an executive sponsor and establish a joint IT/OT governance charter with a formal RACI. The typical outcome of this phase is a 90-day baseline that identifies which assets matter most and who is accountable for them.

Walk: unify and alert. The walk phase focuses on unifying detection and alerting. Segmentation is in place, there's a shared SOC and both teams rehearse a joint incident response playbook. This phase normally plays out over 6 to 12 months. 

Run: predict and scale. In the run phase, threat intelligence is fully unified across IT and OT. Risk for both teams is reported at the board level and AI-assisted anomaly detection becomes part of the strategy.

WWT's crawl, walk, run approach to a unified security strategy for manufacturers.

Most of our clients begin in the crawl phase. Starting at one or two plants with a blast-radius and containment assessment gives manufacturers a strong foundation to build from before expanding across the network.

For example, in our work with one of our global manufacturing clients, it was clear that alignment was the first challenge they needed to overcome, not technology. Individual plants understood their operational risks, but there was no consistent way to assess, prioritize or communicate OT cyber risk across the business. Before implementing new controls, the company established a joint governance model that gave both IT and OT a clear role in decision-making.

How WWT can help 

WWT works with manufacturers across food and beverage, industrial equipment, pharmaceutical, mining and life sciences to help them align IT and OT under one security strategy. Most engagements start with a Manufacturing Digital Transformation Workshop which helps leadership align on priorities and define the right starting point. From there, next steps can include: 

  • OT cybersecurity risk assessments across multi-plant environments, covering network visibility gaps and phased remediation planning.
  • OT network visibility briefings addressing control-system segmentation and secure vendor remote access.
  • IT/OT convergence governance design and RACI development for manufacturers standing up a joint security charter.

Wherever your organization is on the path to unified IT/OT security governance, WWT's manufacturing and OT security teams are here to help you move forward. 

WWT Research
Insights powered by the ATC

This report may not be copied, reproduced, distributed, republished, downloaded, displayed, posted or transmitted in any form or by any means, including, but not limited to, electronic, mechanical, photocopying, recording, or otherwise, without the prior express written permission of WWT Research.


This report is compiled from surveys WWT Research conducts with clients and internal experts; conversations and engagements with current and prospective clients, partners and original equipment manufacturers (OEMs); and knowledge acquired through lab work in the Advanced Technology Center and real-world client project experience. WWT provides this report "AS-IS" and disclaims all warranties as to the accuracy, completeness or adequacy of the information.

Contributors

Shane Kehoe
Practice Manager, GES
Jadyn Koenes
Global Solutions & Architecture Intern
Owen Skoler
Sr Content Marketing Mgr

Contributors

Shane Kehoe
Practice Manager, GES
Jadyn Koenes
Global Solutions & Architecture Intern
Owen Skoler
Sr Content Marketing Mgr

In this report

  1. How most companies divide OT security
  2. Why traditional OT security models fall short
  3. A better option: one strategy, two playbooks 
  4. Four principles to drive OT/IT alignment 
  5. Where to start 
  6. How WWT can help 
WWT
  • About
  • Careers
  • Locations
  • Help Center
  • Sustainability
  • Blog
  • News
  • Press Kit
  • Contact Us
© 2026 World Wide Technology. All Rights Reserved
  • Privacy Policy
  • Acceptable Use Policy
  • Information Security
  • Supplier Management
  • Quality
  • Accessibility
  • Cookies