• Why operational technology risk still slips past the boardroom

    From TechnologyDaily@1337:1/100 to All on Wednesday, July 22, 2026 10:15:22
    Why operational technology risk still slips past the boardroom

    Date:
    Wed, 22 Jul 2026 09:04:13 +0000

    Description:
    Boards need to start treating OT cyber risk as an issue of business continuity.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Across the UK, cybersecurity incidents have become a familiar feature of the business landscape.

    Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT). Latest Videos From Watch full video here: Louise Bulman Social Links Navigation

    Vice President International at Dragos. That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost data , affecting safety, revenue and in some cases an organization's ability to operate at all.

    For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped
    by experiences with data breaches or malware attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention. You may like Why our national sovereignty depends on cyber resilience Mythos shows why AI governance must catch up to the speed of risk discovery The
    cyber risk framework protecting your organization wasn't built for this adversary Why OT risk is routinely underestimated Much of todays operational infrastructure was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by
    equivalent security practices.

    The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or
    days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain
    abstract and under-prioritized. When cyber incidents stop operations Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships

    Similar lessons can be drawn from cyber incidents affecting the UKs water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. What to read next "$10.22 million and counting": US cyber breaches have become a boardroom issue The shocking
    reason 43% of UK businesses have been hit by cyber attacks last year Cyber resilience defines SME competitiveness

    Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade
    across an organization, and factoring in safety concerns and reputational risk. A risk landscape shaped by geopolitics Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade
    restrictions and supply chain uncertainty now influence how organizations
    plan and prioritize security investment.

    At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national
    infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance. Bringing direction and discipline to governance Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized
    and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.

    Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.

    Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites. A leadership obligation Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.

    Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide. We've ranked and reviewed the best antivirus software . This article was produced as part of TechRadar Pro Perspectives , our channel to feature the best and brightest minds in the technology industry today.

    The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit



    ======================================================================
    Link to news story: https://www.techradar.com/pro/why-operational-technology-risk-still-slips-past -the-boardroom


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)