Bridging the visibility gap: why manufacturers must rethink cyber resilience across IT and OT

Posted on 30 Apr 2026 by The Manufacturer
Company: Thales

Cyber risk is operational risk. That message was reinforced at CYBERUK 2026, where the UK’s National Cyber Security Centre (NCSC) warned of a ‘perfect storm’ of rising cyber threats, rapid advances in AI and growing geopolitical tension. For manufacturers and infrastructure operators, this isn’t a future concern, it’s already shaping how risk needs to be managed today. It should also span IT and OT operations and should not be confined purely to an IT problem. Mike Sewart CTO at Thales explains more. 

For a long time, cyber security has been treated as an IT issue, largely the domain of corporate networks, data centres and endpoints. But that way of thinking no longer reflects reality. As industrial environments become more connected, the boundary between IT and operational technology (OT) has blurred – and with it, the nature of cyber risk itself.

Key takeaways

  • Cyber risk is now operational, not just IT-related: Cyber security can no longer be treated as a standalone IT issue. As IT and operational technology (OT) environments converge, cyber risk directly affects physical operations, safety, and business continuity.
  • Complexity is increasing faster than security maturity: Manufacturers have rapidly adopted digital tools (cloud, IIoT, analytics), but security hasn’t kept pace. The result is fragmented systems, limited visibility, and a false sense of control despite having multiple security tools.
  • Threats are shifting from data theft to operational disruption: Attackers are increasingly targeting production downtime, system interference, and safety risks rather than just stealing data—making cyber incidents more immediate and damaging for manufacturers.
  • Lack of visibility is the biggest weakness: Many organisations don’t have a clear, unified view of their IT and OT environments, making it difficult to prioritise risks or understand potential real-world impacts on operations.
  • Integrated, operations-led security is essential: Moving forward requires breaking down IT/OT silos, adopting a unified view of risk, and implementing security approaches tailored to industrial environments – embedding resilience at both the operational and leadership level.

FAQs

  • Why is cyber risk no longer just an IT issue?
  • What is driving the increase in cyber risk for manufacturers?
  • Why are many organisations struggling with cyber security despite using multiple tools?
  • How are cyber threats changing in manufacturing environments?
  • What should manufacturers do to improve their cybersecurity posture?

Across manufacturing, energy and other critical sectors, organisations are now dealing with a different kind of exposure. The systems that keep our lights on, production lines running, control industrial processes and maintain safety are increasingly digital – and increasingly connected. Yet many organisations still don’t have a clear, joined-up view of risk across those environments.

Complexity is outpacing control

Over the past decade, manufacturers have embraced digital transformation at pace. Cloud services, remote access, Industrial Internet of Things (IIoT) devices and advanced analytics have all brought clear operational benefits – from predictive maintenance to improved efficiency and reduced downtime.

However, as these environments become more advanced, many organisations have not implemented the cyber security to keep up with the pace of change.

Many organisations now operate with a patchwork of security tools, introduced over time to address specific threats or compliance requirements. According to the 2026 Thales Data Threat Report, 81% of organisations are managing five or more security tools, while only 35% have full visibility of where their data resides.

That combination creates a problem. More tools don’t necessarily mean more control – in many cases, they create fragmentation.

Mike SewartThe threat landscape is shifting. Attackers are no longer focused solely on stealing data. Increasingly, they are targeting disruption – looking to halt production, interfere with operations or create safety risks. For manufacturers, the consequences can be immediate and tangible, from unplanned downtime to wider supply chain disruption. This shift is being reflected at a national level. The NCSC has reported that the number of nationally significant cyber incidents has increased, with many now linked directly or indirectly to nation-state activity.
Mike Sewart, CTO, Thales

Security teams may have strong visibility across IT systems, but far less insight into OT networks. These environments often rely on legacy equipment, specialised protocols and safety-critical processes, and in many cases were never designed to be online or with cyber security in mind. Now, they are being asked to operate in a far more hostile threat landscape.

The result is a gap between perception and reality – what organisations think they can see, and what is actually happening across their operational estate.

The changing nature of cyber threats

At the same time, the threat landscape is shifting. Attackers are no longer focused solely on stealing data. Increasingly, they are targeting disruption – looking to halt production, interfere with operations or create safety risks. For manufacturers, the consequences can be immediate and tangible, from unplanned downtime to wider supply chain disruption.

This shift is being reflected at a national level. The NCSC has reported that the number of nationally significant cyber incidents has increased, with many now linked directly or indirectly to nation-state activity.

The techniques being used are also evolving. Credential theft remains one of the most common entry points, allowing attackers to gain access and then move laterally across systems. In an interconnected environment, that means a breach that starts in IT can quickly spread into OT.

AI is accelerating this further. As highlighted at CYBERUK, both attackers and defenders are now operating at a different pace, with AI enabling faster identification and exploitation of vulnerabilities. What once took days or weeks can now happen in a fraction of the time.

For manufacturers, this creates a difficult equation: more connected systems, more potential entry points and more capable adversaries.

Why visibility matters more than ever

In practice, the biggest challenge isn’t a lack of tools – it’s a lack of clarity.

Many manufacturers don’t have a complete picture of what’s running across their environments, how systems are connected or where their most significant vulnerabilities sit. Without that understanding, prioritising risk becomes far more difficult. Teams end up reacting to alerts rather than focusing on what actually matters to operations.

The real issue is impact. In a manufacturing environment, not all systems carry the same weight. A compromised office application might be disruptive; a compromised control system could stop a production line or introduce safety risks. That distinction is critical – and it’s often where visibility falls short.

Managing risk effectively isn’t just about identifying vulnerabilities; it’s about understanding how those vulnerabilities relate to real-world operations, and what the consequences could be if something goes wrong.

From siloed security to integrated resilience

To address this, manufacturers need to move beyond siloed approaches to cyber security and take a more integrated view of resilience.

Historically, IT and OT have been managed separately – often by different teams, with different priorities. IT teams focus on protecting data and systems, while OT teams are focused on safety and continuity of operations. Over time, that separation has led to gaps in visibility and coordination.

But in today’s environment, those gaps are harder to sustain. Organisations need to be able to see across both IT and OT, understand how they interact and manage risk accordingly. That requires not just new tools, but a shift in mindset – recognising that cyber security is not just a technical issue, but an operational one.

This is also being reflected at a policy level. At CYBERUK, government leaders called for cyber security to be treated as a board-level responsibility, reinforcing the idea that resilience needs to be embedded into how organisations are run, not just how systems are secured.

The role of operations-led approaches

One of the reasons this challenge persists is that OT environments are fundamentally different from IT.

Industrial systems rely on specialised protocols, legacy infrastructure and tightly controlled processes. Introducing new technology into those environments carries risk, particularly where safety and uptime are critical.

As a result, approaches designed for IT don’t always translate effectively. Instead, organisations need solutions that are grounded in operational and engineering expertise – ones that understand how industrial systems operate and how security can be applied without disrupting them.

This is where operations-led approaches come into play. By combining cyber security capabilities with a deeper understanding of operational environments, organisations can design and deploy solutions that work in practice, not just in theory.

That includes using passive monitoring techniques, aligning deployments with existing processes and focusing on the areas of highest operational risk.

Gaining a unified view of risk

A growing number of manufacturers are now looking at ways to bring together asset visibility, vulnerability intelligence and exposure analysis into a single view.

Often described as extended detection and response (XDR) for OT environments, these approaches aim to provide a clearer understanding of risk across both IT and OT systems.

By connecting data from different parts of the environment, organisations can begin to see how risks relate to each other – identifying potential attack paths and understanding how a threat might move through their systems.

This marks a shift from reactive to more proactive security. Rather than responding to isolated alerts, organisations can focus on reducing overall exposure, closing the gaps that attackers are most likely to exploit and strengthening resilience over time.

Beyond security: operational benefits

While the primary driver for these approaches is often security, the benefits go further.

Greater visibility into OT environments can also provide insight into how systems are performing. This might include identifying underused assets, spotting inefficiencies in network traffic or detecting early signs of equipment failure.

For manufacturers, that opens up opportunities to improve efficiency and reduce costs.

For example, understanding how assets are being used can inform investment decisions, while identifying anomalies in system behaviour can help prevent unplanned downtime. Visibility into third-party access can also support better management of external risk.

In that sense, improving security can also lead to better operational outcomes.

Preparing for a more connected future

The challenges facing manufacturers are unlikely to ease in the near term.

Digital transformation will continue to drive connectivity, while regulatory pressures – including frameworks such as NIS2 – will place greater emphasis on resilience. At the same time, geopolitical tensions and advances in AI will continue to shape the threat landscape.

As highlighted at CYBERUK 2026, the task now is not just to keep up with threats, but to rethink how resilience is built into increasingly connected systems.

For manufacturers, that means moving beyond fragmented visibility and siloed approaches, and developing a clearer understanding of risk across both digital and physical environments.

Closing that visibility gap will be a critical step – not just in protecting data, but in safeguarding the operations that keep industry moving.

For more articles like this, visit our Digital Transformation channel