Oct 07 2026
Security

Why Flat Networks Are a Security Risk in IT and OT Convergence

As IT and operational technology converge, network segmentation can help organizations limit the blast radius of a cyberattack without disrupting critical operations.

Operational technology and corporate IT networks continue to converge. Manufacturers can remotely monitor equipment, building managers can control heating and cooling systems, and organizations can collect operational data without sending employees onto the production floor or into mechanical rooms.

But that connectivity creates a security challenge when OT devices simply get added to an existing corporate network. Instead of carefully separating production equipment, building automation systems and other connected devices from business-critical IT systems, organizations can end up with a “flat” network where everything shares the same environment.

That flat architecture can give attackers an opportunity to move laterally from a connected device that’s been compromised into systems containing sensitive data or supporting critical business operations. Network segmentation is therefore becoming an increasingly important part of securing IT/OT convergence.

Click the banner below to learn why cyber resilience is essential to enterprise success.

 

IT/OT Convergence Can Create Hidden Security Risks

I've seen firsthand how organizations can end up with flat networks without fully understanding the security implications.

Earlier in my career, I worked as an IT director for a nonprofit retirement community. We installed a building automation system, and I treated it like any other device that needed to connect to the network. I didn’t know then what I know now about the potential vulnerabilities that OT systems can introduce.

A big part of the problem is that IT teams don’t always think of systems such as ventilation controls, boilers or security cameras as potential cybersecurity concerns. When people hear “OT,” they often think about industrial control systems, human-machine interfaces, or supervisory control and data acquisition systems. They don’t necessarily think about the systems operating a building.

But those systems can have some of the same basic security weaknesses we see elsewhere: default administrator passwords, missing updates or unsupported software. Sometimes, an organization leaves a system alone because it works, and changing it could create operational problems.

I once encountered a security camera system that was still running Windows XP. It worked, so nobody touched it. But putting a legacy system like that onto a broader network can create a significant vulnerability.

Network Segmentation Can Limit Lateral Movement in OT Environments

The biggest concern with a flat network isn’t necessarily what happens if someone compromises an individual OT device. If an attacker takes control of a printer, for example, that’s a nuisance. If someone disrupts a ventilation system, the consequences could range from uncomfortable employees to an operational disruption.

What makes these scenarios so worrisome is when a compromised device is used as a pathway into accounting systems, business applications or sensitive data. That’s where IT/OT convergence can become a much bigger security problem.

DISCOVER: Here are five benefits of modernizing endpoint management.

I think of OT systems as needing a kind of “walled garden” within the broader network. Organizations don’t necessarily need to build an entirely separate physical network to achieve that. Virtual LANs, for example, can be used to create separate segments for building automation, cameras or other OT equipment while continuing to use the same underlying infrastructure.

But before making changes, organizations need to understand what they already have. A network assessment or penetration test can help identify connected assets, vulnerabilities and potential pathways between OT and IT systems.

This can be particularly difficult for small businesses. An IT team of one or two people may be responsible for hundreds of devices and simply not have the bandwidth to map the environment and determine how everything connects.

That’s where outside expertise can help. A technology partner or managed service provider can assess the existing environment and help develop a segmentation strategy without unnecessarily disrupting production or critical building systems.

Segmentation also shouldn’t be treated as a silver bullet. OT security requires a layered approach. Organizations can combine network segmentation with technologies and practices such as zero-trust network access, Secure Access Service Edge and multifactor authentication, along with appropriate monitoring and detection capabilities.

There is no single piece of equipment that will solve OT security. The goal is to build multiple layers of protection so that if an attacker does get through one layer, there are additional barriers preventing lateral movement.

As IT and OT continue to converge, that approach becomes increasingly important. Connecting operational systems can deliver significant efficiency and visibility benefits, but organizations need to understand what they’re connecting — and what those connections make accessible.

This article is part of BizTech's AgilITy blog series.

Agility_Logo_sized.jpg

Andriy Onufriyenko/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.