Creating a next-generation OT SOC is less about chasing the latest tools and more about reshaping security teams so that IT and OT (operational technology) systems are no longer islands. As OT systems increasingly connect to the corporate IT environment and other IIoT systems, cyber defenders will need integrated visibility and a shared data set to recognize patterns and complexities in threat intelligence and correlation. To do this, top industrial companies are shifting away from integrated teams and toward a single cyber team with integrated skills and abilities through convergence, delivering real value when it enables real-time analysis and automation, rather than noise and unnecessary information.
Automation today delivers value most clearly in routine tasks: inventorying assets that once took weeks to enumerate, correlating anomalies across thousands of sensors, and triggering automated containment for known-bad activity without interrupting safety-critical systems. It is not a substitute for human insight, either. In safety-critical environments, human judgment still applies for contextual decision-making since the stakes include physical process integrity and lives, hence why human-AI frameworks that balance autonomy with oversight gain momentum.
Redefining OT SOC (Security Operations Center) roles means blending traditional security analyst skills with industrial process knowledge-a tough cultural shift that often slows convergence. This creates unified models that struggle because of legacy mindsets and fragmented governance. Clear gains from next-generation OT SOC innovation emerge across real-world applications, such as OT-aware detection, AI-assisted triage, and distributed SOC models designed to reflect the day-to-day realities of operating critical infrastructure.
How IT/OT convergence is reshaping cyber teams and security
Table of Contents
- How IT/OT convergence is reshaping cyber teams and security
- Where automation delivers real value for OT SOCs today
- Redefining OT SOC roles in automation age
- Balancing automation and human judgment in safety-critical OT SOCs
- Why unified OT SOC models still struggle to take hold
- Where next-gen OT SOC innovations are delivering real value
Industrial Cyber spoke with industry experts to understand how the convergence of IT, OT, and increasingly interconnected systems is reconfiguring cybersecurity team structures, decision-making, and day-to-day operations across critical infrastructure. They also explore where convergence has moved beyond theory to deliver tangible improvements in OT security, operational reliability, and system resilience.
“IT risks are now OT risks and vice versa. Leveraging operational data inevitably demands the convergence of IT and OT, meaning corporate IT threats (malware, etc.) can directly affect OT systems,” Mark Ryan, team lead of DNV Cyber, told Industrial Cyber. “The line between what is OT and what is IT is blurred. Each customer, scenario, and request proposal shows a unique fingerprint of architectural, process, and industry-related concerns. Our OT SOC development program integrated industrial network sensors with enterprise SOC, enabling holistic monitoring of plants and offices together.”
He added that since these areas are no longer cleanly separated, the knowledge needed to serve and address these security concerns needs to work in synergy.
Ryan pointed out that awareness needs to be given on how to behave in IT response and OT response. The approach centers on looking to restructure teams and offer tangible gains. Convergence has driven the unification of previously siloed teams, with OT engineers embedded into SOC operations through a bespoke delivery team model. This allows 24/7 SOC analysts to draw on OT expertise for operational context when incidents arise.
“Day-to-day, IT and OT personnel now share tools and incident workflows, improving speed and consistency of response. This allows awareness of both concerns, but not a single type of response. Security concerns now stride between IT and OT, so our ability to build a body of knowledge and skills must do the same,” according to Ryan. “Industry challenges, coupled with converged knowledge, allow for a complete response to the challenges faced by our customers. Internally, the first hurdle we see is the cultural divide between IT security teams and OT engineering teams. They have historically operated separately, with different priorities (confidentiality vs. safety). This can breed mistrust or miscommunication.”
He also mentioned tangible gains and highlighted a recent internal recap that showed ‘measurable improvement in multi-site environments’ after aligning IT/OT security capabilities, allowing IT SOC services (like SIEM use cases) to extend into the OT network layer. “This convergence has yielded better anomaly detection and streamlined incident handling in our industrial facilities, increasing overall operational resilience.”

Saltanat Mashirova, senior manager for OT cybersecurity at CPX, sees IT/OT convergence fundamentally reshaping cybersecurity teams from siloed IT and OT functions into a more collaborative, risk-driven operating model.
“In day-to-day operations, this means shared visibility, shared workflows, and much tighter collaboration between IT, OT engineers, and operations,” Mashirova told Industrial Cyber. “Risk is no longer discussed purely from a cyber perspective, but in terms of operational impact, safety, and reliability, which is more consequence-driven. When convergence is implemented securely, alerts are no longer investigated in isolation; identity, remote access activity, asset criticality, and process context are correlated together.”
She added, “I’ve seen this significantly improve OT security by reducing false positives, improving prioritization, and enabling faster and safer incident response, while also increasing reliability because decisions are made with real operational awareness rather than purely technical signals.”

“It’s more important than ever that teams are cross-functional, made up of ‘T-shaped’ members who are deeply skilled in their area of expertise, but also broad enough to understand and communicate with the ‘other side,’” David Formby, co-founder and CEO/CTO of Fortiphyd Logic, told Industrial Cyber. “Teams where IT has cross-trained on OT and OT cross-trained on IT are able to make more intelligent, consequence-driven decisions on triage and escalation of events.”

Zakhar Bernhardt, an OT/ICS cybersecurity consultant at German automation company anapur AG, told Industrial Cyber that OT environments are becoming more connected to IT systems and day-to-day business operations. “As a result, IT teams are increasingly involved in OT security and processes. For many organizations, OT directly supports core revenue, so protecting these environments is no longer optional.”
He added that convergence is mainly driven by the need to consume OT data for business applications, enable secure remote access and control, and monitor events across IT and OT from a single place. “This has pushed organizations toward unified SOC models, where IT and OT logs are analyzed together, improving visibility, response speed, and operational resilience.”
Where automation delivers real value for OT SOCs today
Automation is now a core component of modern OT SOCs. From a practical standpoint, the executives address where automation delivers clear operational value today, and where caution is still warranted given the safety, reliability, and process constraints of OT environments.
“Automation in our SOC is most valuable for data processing and first-line analysis. For example, our SOAR pipelines automatically enrich alerts by adding asset details, threat intel, and even auto-create incident tickets, so analysts spend time on investigation instead of paperwork,” Ryan identified. “Repetitive tasks like correlating logs or filtering false positives are handled at “Tier 0” (fully automated triage), which has significantly reduced noise and improved response times for common alerts. We limit automation in actions that could disrupt physical processes. Internal guidelines insist on human intervention for any high-impact OT response.”
For instance, he added that an automated system might isolate a suspected compromised OT workstation, but it will never shut down a running turbine without an operator’s approval. “OT environments have strict uptime and safety requirements. Unlike IT, a false move can halt production or endanger lives. Therefore, we apply automation primarily to detect and flag issues (or to handle IT-side malware cleanup), but in OT contexts, our automation is conservative, focusing on monitoring and advisories, with final decision-making left to skilled personnel.”
From a practical standpoint, Mashirova said that automation delivers the most operational value in enrichment, correlation, prioritization, and workflow orchestration. “Automating asset context, vulnerability risk prioritization with remediation recommendations, alert deduplication, and escalation logic dramatically improves analyst efficiency without directly impacting the industrial process. AI agents can act as SOC assistants by correlating large volumes of data and providing decision support to analysts.”
However, she added that organizations must be very cautious with automated response actions that could impact availability or safety, such as blocking traffic, isolating assets, or enforcing changes in live environments. “In OT, automation should prepare and recommend actions, but final decisions, especially near process control systems, must remain under human approval.”
Formby said that automation is great at quickly providing important contextual information for different events, but going much further requires significant testing and validation. “It may sound like a great idea to automatically shut down the process or cut the connection to IT if you are under attack, but the chances of false positives and potential production costs can be very high.”
He noted that it’s critical to thoroughly test the active response during a maintenance window or in a high-fidelity simulated environment and evaluate if it is worth the risk.
“Today, automation brings the most value at the SOC Level 1 stage: handling alert intake, prioritization, and triage. This helps reduce analyst overload and ensures attention is focused on incidents that actually matter,” Bernhardt said. “At the same time, OT data must be properly prepared before any SOC or AI automation is applied.”
He added that data collection, filtering, aggregation, normalization, and contextualization are foundational steps, not SOC automation. “If this groundwork is weak, automation will simply scale noise and risk. Organizations should be careful not to automate analysis or decisions on raw or poorly contextualized OT data.”
Redefining OT SOC roles in automation age
As OT SOCs increasingly adopt automation and AI-assisted workflows, the executives examine how skill requirements for security teams are evolving. They also focus on which capabilities are becoming essential for analysts and engineers operating next-generation OT SOCs.
“Our internal hiring profiles show that ‘significant IT/OT experience’ is now expected of security staff,” according to Ryan. “Analysts must understand industrial control systems (ICS) protocols and safety processes alongside traditional IT security knowledge. For example, knowing Purdue model network segmentation or PLC behaviors can be as important as knowing Windows logs when investigating an OT incident.”
Mashirova said that as OT SOCs adopt automation and AI-assisted workflows, skill requirements are shifting away from manual, alert-by-alert triage toward supervision, validation, and informed decision-making.
“Analysts must understand OT environments deeply enough to validate AI outputs and recognize false correlations or hallucinations. Foundational knowledge of industrial protocols such as Modbus, DNP3, OPC UA, Profinet, etc., is becoming essential,” she added. “Rather than reacting to alerts, analysts need to assess whether AI-generated insights align with real process behavior, operational constraints, and safety logic. In parallel, detection engineering, workflow orchestration, prompt refinement, and hunting hypothesis development are becoming core skills.”
Moreover, she pointed out that analysts are evolving into conductors that guide AI, validate results, and translate technical findings into operationally relevant risk for engineers and leadership.
“Tools are only valuable if you know when and how to use them,” according to Formby. “As SOCs adopt more AI-assisted workflows and responses, it’s important for teams to have the skills to think about the potential physical consequences of false positives and work with the OT side to determine if the risk of false positive-induced harm is worth it. Then, it’s important to take time to practice with the tools in a safe environment to know what to do with them, and what not to do.”
Bernhardt identified that as automation removes repetitive tasks like filtering false positives and basic triage, the most important skill becomes understanding OT processes themselves. “Analysts and engineers need to explain what actually happened in the process, not just what an alert says. The ability to prepare meaningful, contextual OT data for AI-assisted SOCs is becoming a key competency.”
Balancing automation and human judgment in safety-critical OT SOCs
In environments where safety, availability, and process integrity are paramount, the executives look into how organizations should define the right balance between automated detection and response and human judgment within the OT SOC.
Ryan said that with more automation and AI, “we need people who can train, tune, and oversee these technologies. In fact, a forward-looking SOC skills assessment highlights adding data science and machine-learning proficiency on top of core cyber skills. Our next-gen SOC analysts are being trained in using AI-driven anomaly detection tools and in interpreting their output to avoid blindly trusting algorithms.”
In OT environments where safety, availability, and process integrity are paramount, the right balance between automation and human judgment should be defined by criticality. For events with no potential process impact, automation can be applied aggressively,” according to Mashirova. “For scenarios with possible operational impact, automation should provide recommendations and pre-approved containment options. For situations involving safety or availability risk, decisions must remain human-led, with engineering and safety sign-off supported by clear CONOPS (Concept of Operations) and SOPs. In this model, AI operates under strict human supervision, well-defined boundaries, and clear accountability.”
Formby said that when safety is involved, there must be a human in-the-loop and accountable for the decisions that are made. “In addition to the obvious ethical considerations, any root cause analysis or after-action report is going to need to explain the rationale behind the decisions that were made, and that can be difficult and unreliable with AI.”
“In OT environments, safety, availability, and process integrity come first. For that reason, AI-driven actions should remain passive,” according to Bernhardt. “Automated detection is valuable, but automatic responses that directly affect OT systems, such as stopping PLCs, can cause equipment damage or even human injury. Response decisions should always involve both security teams and automation/process engineers.”
Why unified OT SOC models still struggle to take hold
The executives examine the organizational, technical, and cultural barriers that most often slow or derail efforts to integrate IT/OT convergence, automation, and human expertise into a unified OT SOC operating model.
Ryan said that, in practice, detection and notification are automated, while any action that could affect operations or safety requires human approval. “We define clear criteria: if an automated response carries any risk to physical processes, it defaults to human control. For example, our email security gateway automatically quarantines malicious files across IT and OT, but our OT intrusion system will never automatically shut a plant’s network connection. It will alert an on-call engineer to decide the response. This balance is reviewed regularly by our SOC and OT operations leads.”
“One of the most common barriers to a unified OT SOC is attempting to build advanced SOC capabilities without foundational controls in place,” Mashirova said. “Without basic visibility, reliable telemetry, asset inventory, and proper network segmentation, an OT SOC cannot operate effectively. From a maturity perspective, organizations must first establish these fundamentals before moving toward convergence, automation, and advanced SOC models. Cultural gaps between IT, OT, and operations, unclear ownership of industrial cyber risk, and toolsets that are overly IT-centric further slow progress when not addressed early.”
In many organizations, there has been a history of IT imposing new security on OT, which then causes production problems, Formby said. “Understandably, this has led to a lack of trust and placed a heavy burden on the IT side to prove that their proposals, like automated responses, are not going to cause harm. It can be difficult to safely demonstrate this on the live plant, so high-fidelity labs can enable IT and OT to thoroughly and jointly evaluate the changes and possible failure modes to build confidence before deployment.”
“One of the biggest challenges is the cultural gap between security and automation teams,” Bernhardt said. “They often belong to different departments with different priorities: confidentiality versus safety. IT teams may lack hands-on exposure to real OT environments, while OT engineers may find it difficult to keep up with fast-moving security trends. Convergence only works when teams share common goals, education, and a clear, unified vision.”
Where next-gen OT SOC innovations are delivering real value
The executives assess how newer OT SOC innovations, such as OT-aware detection and response, engineering-driven telemetry, AI-supported triage and decision support, and distributed SOC models, are shaping the design and operation of next-generation OT SOCs, and where these approaches are delivering meaningful impact in practice.
“For engineers in an OT SOC, understanding the operational technology itself is essential. This includes familiarity with SCADA systems, PLCs, and safety instrumented systems. Internally, we have found value in cross-training IT security analysts on OT fundamentals and vice versa,” according to Ryan. “Capabilities like reading electrical one-line diagrams, knowing process control logic, or working with OT asset inventories have become critical. In short, the modern OT SOC team is multidisciplinary: cybersecurity analysts, industrial network engineers, and sometimes data analysts working side by side.”
Mashirova observed that newer OT SOC innovations are driving organizations toward more distributed and intelligence-driven operating models. “OT-aware detection and engineering-driven telemetry significantly improve signal quality and analyst confidence by adding operational context to security events. AI-supported triage and decision support are delivering immediate impact by reducing analyst workload and improving consistency in investigations. The most meaningful results occur when these capabilities are embedded into daily operations, not treated as standalone tools, and supported by strong human expertise at both the central SOC and site or plant level.”
Overall, Formby said that he sees “the biggest impact with AI is that it can help reduce the drudgery of digging through overwhelming false positive alerts. OT-aware detection and response is a promising step in the right direction for resiliency, but only if it is thoroughly tested in high-fidelity safe environments.”
“Innovations such as OT-aware detection, engineering-driven events, and AI-supported triage help address the shortage of OT security expertise,” according to Bernhardt. “They improve scalability and make it easier to bring IT and OT data together. At the same time, they can introduce new challenges, including vendor lock-in, higher operational complexity, and additional skill requirements.”
He concluded that their real value depends on teams that understand what data to collect, how to interpret it, and how to respond without disrupting industrial processes.
date: 2026-02-08 09:10:00