As IT and OT increasingly converge, the opportunities grow for ransomware, remote access abuse and geopolitically motivated disruption. IoT botnets also increase the scale of DDoS attacks.
Typical signals
- Unknown remote tooling (RMM/RAS) on OT jump hosts
- Abnormal PLC/SCADA commands or config changes
- Unexplained segment-bridging between IT and OT
Current-state check
- Segmentation (zones/conduits), allowlisting, asset discovery
- Patch/compensating controls on legacy; monitor remote access strictly
- Exercise "safety" impact scenarios and recovery procedures