This website uses cookies

Read our Privacy policy and Terms of use for more information.

ITRADE works with STEM organizations to close Technology, Talent, & Security gaps. See how →

The ITRADE Dispatch Issue #4 · July 21, 2026
ITRADE
The Dispatch · Intelligence for STEM Leaders
Security · Week 4
The Hard Part Starts After You Connect the Network
More than 75% of OT environments have implemented convergence. Connectivity is the easy part. The hard work starts after: integrating legacy systems, securing the architecture, governing the data, and aligning teams that define success differently.
Security IT/OT Convergence ICS/SCADA
The Lead

Walk into any control room in 2026 and four people are talking past each other. The CTO wants real-time analytics. Operations wants reliability and predictive maintenance. The CISO wants to know why controls are reaching past trusted boundaries. The OT engineer wants one thing above all: keep the process safe, stable, and running.

More than 75% of OT environments have already implemented some level of IT/OT convergence. Connectivity is the easy part. The hard work starts after: integrating legacy systems, securing the architecture, governing the data, and aligning teams that define success differently.

Where it breaks.

Most stalled programs treated convergence as a networking project. Deploy a DMZ, add jump servers, segment a few networks, call it secure. Six months later a phished credential or a trusted remote session becomes the way in. Claroty's analysis of nearly one million OT assets found roughly 40% of organizations running internet-connected devices with known, actively exploited vulnerabilities. The ISA/IEC 62443 zones-and-conduits model addresses this, but a mature rollout runs 18 to 36 months. Compress it into one budget cycle and you get an architecture that looks finished on paper and buckles under a real threat.

What separates the organizations that scale.

They set governance before touching firewall policy, with ownership, decision rights, and risk tolerance defined first. They build a trusted data foundation before deploying AI or digital twins. They put IT and OT on shared KPIs instead of competing scorecards. They run security operations built for OT priorities, where safety and uptime outrank fast containment. And they treat change management as real work, engaging operators and engineers during design, long before the training deck.

The payoff is measurable. Fortinet reports that organizations at the highest cybersecurity maturity saw no successful intrusion 65% of the time, against 46% for the least mature. A unified IT/OT security strategy drove a 93% reduction in incidents.

Where to start.

See the environment. Passive OT asset discovery to inventory assets, communication paths, and vulnerabilities.

Set governance before technology. Ownership, authority, and lifecycle responsibility come first.

Stand up the DMZ. The highest-value boundary you can build, and the foundation for Zero Trust and 62443 later.

Governance, trusted data, shared objectives, OT-aware security, disciplined change. That is the operating model behind every convergence program that actually scales.

Signals · This Week in STEM
Technology
Enterprise AI investment reached $13.8 billion in Q1 2026, representing a 62% year-over-year increase, with AI emerging as the fastest-growing segment. Yet organizations continue to discover that AI cannot compensate for fragmented architectures and disconnected operational data. McKinsey's research shows that AI and analytics initiatives deployed on unconverged IT/OT environments rarely scale beyond pilot programs. The lesson is clear: AI readiness begins with IT/OT convergence, trusted data, and a secure digital foundation, not the AI platform itself.
Talent
The global cybersecurity workforce shortage now exceeds 4.8 million professionals, while demand for OT cybersecurity expertise outpaces available talent by nearly 3 to 1. According to the SANS ICS/OT Survey, the greatest obstacle during cyber incidents is not technology, it is unclear roles and responsibilities between operations, engineering, IT, and cybersecurity teams. Organizations that define governance, accountability, and cross-functional collaboration before an incident consistently respond faster and recover more effectively.
Security
Remote access remains the leading attack vector for control systems. Recent CISA guidance continues to identify remote connectivity as one of the highest-risk pathways into OT environments, while Claroty reports that approximately 40% of environments contain internet-exposed assets with known, actively exploited vulnerabilities. Every remote connection into an operational environment should be treated as privileged access, protected by multi-factor authentication (MFA), just-in-time access, least-privilege authorization, continuous monitoring, and complete session recording.
ONE STAT THAT MATTERS
93%
reduction in cyber incidents with unified IT/OT security platforms.
The OT environments scaling convergence successfully treat it as an operating model transformation - not a networking project.
The ITRADE Lens
The IT/OT Convergence Readiness Audit: Five Questions That Predict Enterprise Scale
1 Can your organization access operational data from three or more facilities through a single interface, without relying on manual reports or local support? If the answer is no, your data architecture is likely still fragmented. Enterprise AI, predictive analytics, and digital operations depend on a trusted, integrated data foundation that spans the entire organization.
2 Do you have an enterprise IT/OT reference architecture jointly approved by your CISO and operations engineering leadership? Technology alone does not create alignment. Successful organizations establish governance, clearly defined ownership, and shared architectural principles before implementing segmentation, DMZs, or Zero Trust initiatives.
3 Does your OT incident response plan differ from your enterprise IT incident response plan? It should. OT incident response prioritizes personnel safety, operational continuity, and process integrity, while IT focuses on protecting information assets, containing threats, and recovering business systems. Mature organizations coordinate both disciplines while maintaining distinct procedures, priorities, and decision-making processes.
4 When was the last time your IT and OT teams participated in a joint cyber incident tabletop exercise? Organizations that regularly rehearse cross-functional incident response are significantly better prepared to manage cyber events affecting operations. Quarterly tabletop exercises should be the objective. If your teams have never conducted one together, improving collaboration should become an immediate priority.
5 Is your AI or analytics initiative directly tied to a KPI that operations already measures and values? Successful organizations improve existing business outcomes rather than introducing new performance metrics alongside new technologies. Whether the objective is improving Overall Equipment Effectiveness (OEE), reducing downtime, lowering maintenance costs, or increasing production throughput, aligning AI initiatives with established operational KPIs accelerates adoption and delivers measurable business value.

Bottom Line: Organizations that consistently scale digital transformation don't begin with AI, they begin with governance, trusted data, secure architecture, operational alignment, and measurable business outcomes.

Bianca Diosdado
Founder & CEO, ITRADE Innovations · Education Programs Chair, SIM South Florida

Bianca architects the systems most leaders buy in pieces - talent, technology, and security, designed to work as one.

ITRADE
The Dispatch · Weekly Intelligence for STEM Leaders
Fort Lauderdale's founding STEM security circle.

Keep Reading