The convergence of Information Technology (IT) and Operational Technology (OT) delivers significant efficiency gains for smart factories, but it also turns digital connections into potential pathways for risk. In high-availability environments, a cybersecurity incident is not limited to data loss within the IT department; it can also create a real risk of production-line disruption. To protect operational continuity, organizations need end-to-end monitoring that can detect and stop threats in the IT environment before they reach and disrupt OT systems.
The fact that manufacturing has become a leading target for cyberattacks. According to Black Kite's 2026 report, manufacturing remained the number one ransomware victim sector, accounting for 22% of 7,551 publicly disclosed cases. Notably, the number of incidents in the first half of 2026 increased by 34.2% year on year. In Southeast Asia, Kaspersky also reported that 23.21% of computers in industrial control system (ICS) environments detected malicious objects in Q1 2026, highlighting the level of exposure across industrial infrastructure.
IT-OT Convergence: How Expanding Connectivity Reshapes Risk
In a modern smart factory, data flows continuously between the two environments. IT coordinates management, orders and supply-chain processes, while OT directly controls equipment, conveyors and production processes. This convergence enables more precise quality control and better resource optimization, but it also fundamentally changes the scope that must be secured.
According to joint research published in 2026 by Palo Alto Networks, Siemens and Idaho National Laboratory (INL), the number of Internet-observable OT devices and services increased by 332% from 2023 to 2024, reaching approximately 19.6 million. This does not mean those devices had been compromised, but it does reflect the growing exposure of OT environments to external digital infrastructure.
When IT Disruption Becomes Production-Chain Business Loss
In September 2025, Jaguar Land Rover suspended operations across multiple production lines for several weeks following a cybersecurity incident. The impact extended beyond the factories themselves, with estimated losses of USD 2.5 billion and disruption affecting more than 5,000 organizations across the supply chain and dealer network. Around the same period, Japan's Asahi Group Holdings also faced a ransomware incident that forced order processing and delivery operations to switch to manual procedures. Although production resumed after one week, supporting logistics and customer service processes took several months to stabilize.
These cases show that risk does not have to originate directly from automation systems (OT). Even when mechanical equipment continues to operate normally, disruption to systems such as enterprise resource planning (ERP), distribution or logistics platforms in the IT environment can still create a domino effect that brings the wider production operation to a halt.
The Gap Lies in How Systems and Teams Coordinate
One of the biggest challenges today is how operational teams coordinate risk assessment. IT teams may detect abnormal traffic alerts without enough context to determine the potential impact on production lines. Conversely, OT teams may see unusual equipment parameters but prioritize mechanical troubleshooting before considering a cybersecurity issue. Dragos statistics for 2026 indicate that 81% of security assessments encountered challenges around IT-OT segmentation, while 82% of organizations had not established clear criteria for deciding when an operational anomaly should trigger a deeper security investigation.
To maintain resilient production operations, organizations should prepare in advance:
Identify critical dependency chains: Map the data flows, accounts and IT systems that could directly affect OT system availability.
Control convergence access points: Apply strict controls to remote access, privileged administrative accounts and, in particular, connection points used by external partners and suppliers.
Standardize escalation procedures: Clearly define the coordination model - who analyzes alerts, who has authority to isolate systems, and the recovery priorities required to keep the production line safe.
Built on the close integration of 03 pillars - people, process and technology - NetGuardX helps organizations maintain continuous 24/7 monitoring and reduce data gaps between teams. This allows businesses to shorten the path from alert intake to concrete action, contain risk proactively and maintain continuity across the entire production operation.
Hotline: 1900 1586
Email: marketing@netnam.vn
Website: https://netnam.com/netguardx
NETNAM CORPORATION – 30 years of trusted internet & managed IT solutions and services for businesses
Headquater: 2nd Floor, HITC Building, 239 Xuan Thuy Street, Cau Giay Ward, Hanoi
Ho Chi Minh City Branch: 7 Nguyen Thi Minh Khai Street, Sai Gon Ward, Ho Chi Minh City
Representative Office: 2 Quang Trung Street, Hai Chau Ward, Da Nang
Reference:
https://www.paloaltonetworks.com/resources/whitepapers/securing-ot-environments