The Current State of IT-OT Cybersecurity Convergence Programs

Introduction

Many Industrial companies are interested in converging (or integrating) their IT and OT cybersecurity programs. Some have limited objectives, like merging of security teams, while others are pursuing broad-based convergence of people, processes, and technologies to minimize overall cyber risks and reduce security costs.

The purpose of this ARC research study is to understand the current state of convergence programs across the industrial landscape. This includes what companies are doing and what they are learning about driving convergence of disparate security programs. Our methodology includes two data collection steps. First, we are asking users to complete this short on-line survey to give us a high level assessment of the current level of adoption and general goals. Second, we will conduct brief interviews with a select group of participants to gain deeper insight into the scope and objectives of their programs as well as the lessons they have learned that can help others in their IT-OT cybersecurity convergence journeys.

We are looking for participants who are end users involved in converging (or integrating) some part of their company's IT and OT cybersecurity programs. Participants that complete this survey and are willing to support a followup call will receive a complimentary copy of the research findings. We believe this report will benefit everyone involved in convergence efforts. Our findings will also benefit everyone who attends the workshop we have planned on this subject at the ARC Industry Forum in Orlando, FL on February 9-13, 2025.

Privacy: Your companies privacy and confidentiality is assured and your identity will not be released to others. Your responses will be combined with others and only appear as aggregated information in ARC reports on our findings from this research.

If you have questions about this survey, please contact Sid Snitkin at srsnitkin@arcweb.com. For information about ARC industrial cybersecurity services and the ARC Forum please contact ARC Client Director, Mark Luciw at MLuciw@ARCweb.com.
1.Which of the following best describes the the state of your IT-OT Cybersecurity convergence (integration) efforts? Please elaborate as needed in the Other field
2.How important are the following factors in your decision to converge (integrate) parts of your IT and OT cybersecurity programs? Please use Other to describe any factors not in our list.
The major factor
One of several major factors
Minor factor
Not a factor
Lack of OT people to maintain OT cybersecurity
Lack of OT people with cybersecurity expertise
Increased concern about OT cybersecurity risks
CISO wants consistency across IT and OT cybersecurity programs
Desire to use more advanced IT cybersecurity solutions in OT
3.Please use the free-form fields below to summarize the general scope and goals of your convergence efforts with respect to each of the indicated areas.
4.With respect to People, which of the following organizational models best describes the goal of your IT-OT cybersecurity efforts? Please elaborate as needed in the Other field
5.With respect to cybersecurity processes, which of the following best describes the goal of your cybersecurity convergence (integration) efforts. Please elaborate as needed in the Other field
6.With respect to cybersecurity technologies, which of the following goals do you have for your convergence (integration) efforts? Please select all that apply and elaborate as needed in the Other field
7.What IT technologies are included in your IT-OT cybersecurity convergence plan? Please select all that apply and elaborate as needed in the Other comment field.
8.Which of the following best describes your role in IT-OT cybersecurity convergence?
9.Which of the following best describes the principal industry of your organization?
10.In which Geographic Region do you work?
11.Please provide the following information to help us in aggregating your responses and contacting you for a brief followup call.(Required.)
12.Are you willing to support a brief interview with an ARC analyst to gain a deeper understanding of your convergence program and lessons learned?
13.Would you be interested in receiving information about ARC and our cybersecurity services?
14.Thank you for participating in this important research study. Please let us know if we have missed any important issues.