This analysis draws on IBM and Fortinet 2026 data showing 44% of intrusions now start at exposed, internet-facing applications before migrating from IT into OT. It frames this as the defining shift for CISOs managing converged environments: the boundary between IT and OT is where attackers are actually operating, not deep inside either domain separately.
It also notes that OT security governance has shifted dramatically - over 95% of organizations have now elevated OT security to executive level, with CISO or C-suite ownership climbing to 52%, up from just 16% in 2022. That governance shift, the article argues, reflects how routine and business-like industrial attacks have become compared to a few years ago.
It also notes that OT security governance has shifted dramatically - over 95% of organizations have now elevated OT security to executive level, with CISO or C-suite ownership climbing to 52%, up from just 16% in 2022. That governance shift, the article argues, reflects how routine and business-like industrial attacks have become compared to a few years ago.
The piece argues NIS2's expansion to 18 sectors, including manufacturing alongside energy, water, health, and transport, makes securing the IT/OT boundary a boardroom issue rather than a purely technical one. Its recommendation for CISOs is to prioritize controlling who can reach operational systems and reducing internet-exposed assets, rather than investing further in internal-only monitoring tools.