e2e-assure has published new research highlighting that one-third of surveyed organizations are relying on IT cyber security processes and standards, despite operational technology (OT) requiring a specialist approach. The findings show that 32% of surveyed decision makers say that they are currently relying on detection platforms originally built for IT and ‘adapted’ for OT. This puts organizations at risk, says e2e-assure, because many are trying to secure industrial environments with tools that were not designed for the specific challenges of OT. This is particularly concerning given that 63% of decision makers also revealed that cyber incidents in the past 12 months resulted in direct operational downtime or impacted critical OT/ICS systems.
The research points to structural weaknesses in how incidents are managed across converged environments, as 28% of respondents still rely on manual or ad hoc coordination between their IT and OT security teams, while 37% of organizations have a shared platform for both IT and OT environments, but full technical integration still needs to become a priority.
Richard Groome, OT cyber security specialist spelling and casing to match master lexicon for industry terms at e2e-assure, commented: “Most adapted IT platforms struggle in OT because they’re still thinking like IT tools. They can identify anomalies, but they often have no understanding of the business impact they have. OT downtime isn’t just a network problem; it’s a process problem, and if you can’t interpret what an alert means for a running plant or production line, you’re not preventing downtime, you’re just creating noise.”
Methodology
The research was conducted by Censuswide, among a sample of 250 cyber security decision makers in businesses with 250-10,000 employees. The data was collected in January 2026.






