link rel="stylesheet" href="https://unpkg.com/@phosphor-icons/web@2.1.1/src/regular/style.css"

OT Cybersecurity Myths

Six Beliefs That Quietly Increase Your Risk
Anthony Mondelli
Alaska OT/ICS Cybersecurity Lead
min. read
August 13, 2026
View on Original Source
min. read
"The most dangerous vulnerabilities in OT are not in the PLCs. They are in the assumptions."

Some of the biggest OT cybersecurity risks do not come from zero-day exploits or sophisticated adversaries. They come from assumptions, organizational beliefs that feel true, that often used to be true, but that no longer hold up when tested against reality.

"We're too small to be targeted." "We're air-gapped." "The vendor handles it." Each of these is a comfortable position that delays action and creates blind spots. And blind spots, in OT environments, have physical consequences.

Here are six myths we encounter consistently across OT assessments. For each one: why it persists, what reality usually looks like, and what to do about it.

Myth 1: 'We're Too Small to Be Targeted'

This myth persists because leaders imagine targeting as a precision operation, a sophisticated adversary selecting specific organizations for specific reasons. That is how some attacks work. It is not how most attacks work.

Most OT-relevant threats are opportunistic. Scanners do not care about your revenue. Ransomware groups do not look up your annual report before encrypting a historian. Exposed services, default credentials, and unpatched remote access interfaces are found and exploited because they are findable, not because the attacker knew who you were.

The corrective action is to inventory internet-exposed and vendor-reachable assets. That inventory is the list your attackers already have. The question is whether you have it too.

Read more: The Five Most Common Attack Paths in Operational Technology and How to Prevent Them

Myth 2: 'We're Air-Gapped, So We're Secure'

The air gap is a story, not a control. I say this directly because I have seen it believed as an absolute defense in environments where the air gap had effectively been crossed years ago.

Vendor tunnels, engineering laptops that connect to both networks, USB workflows for firmware updates, cloud connectors for SCADA dashboards, cellular modems for remote monitoring, folks, these are not exotic attack vectors. They are common operational realities that create IT-to-OT pathways the original air gap diagram never showed.

The corrective action is to validate the gap rather than assume it. Pull the firewall rules. Review VPN logs. Look at traffic data. Interview the engineers who actually work on the systems. Compare what the diagram says to what is actually happening on the network.

Read more: Exposing Invisible Links — The 6 IT-OT Bridges That Could Compromise Your Operations

Myth 3: 'IT Handles Our OT Cyber'

IT owns the security budget at most organizations. IT owns the enterprise tooling, the vulnerability management program, and many of the controls that govern access and identity. It is natural for that to expand into OT security.

The problem is that IT security controls applied unmodified to OT environments can break things. Aggressive vulnerability scanning can cause PLCs to behave erratically. Automated patch deployment without operational review can cause unexpected process behavior. IT-centric risk decisions — based on data confidentiality and system availability in IT terms — miss the safety and physical process dimensions that OT decisions require.

The corrective action is not to remove IT from OT security. It is to ensure that OT security has its own named owner with authority, that operations and engineering are at the table for OT risk decisions, and that IT and OT governance is jointly designed rather than IT governance being extended to cover OT by default.

Myth 4: 'The Vendor Handles Security for Their System'

This one is understandable. The system arrived as a black box with a support contract and a vendor who was confident about it. It is natural to assume that confidence includes security.

Vendor support contracts typically cover functional performance, the system does what it was designed to do. They do not typically cover your business risk posture. And vendor remote access — the path vendors use to provide that support — is itself one of the most consistently documented OT attack vectors. We have written specifically about how to move from always-on vendor tunnels to governed, time-bound access.

The corrective action is to treat vendor access as your responsibility to govern, not the vendor's. Broker the access. Time-bound the sessions. Record them. And put security terms into the next contract renewal.

Related: Vendor Risk Is Your Risk: The Harsh Reality and What to Do About It

Myth 5: 'We Passed the Audit, So We're Secure'

Compliance produces a document. Security produces nothing visible on a good day. Those are different things, and confusing them is expensive.

Audits sample the past. They look at a configuration or a policy or a control at a point in time, compare it to a standard, and document the result. Attackers probe the present. They look at what is actually reachable, what credentials are actually valid, and what changes have accumulated since the last review.

Compliance is the floor, not the ceiling. Organizations that treat a passing audit as evidence of adequate security tend to stop investing in the things audits cannot see: unknown access paths, undocumented changes, restore capability that has never been tested.

Related: Why OT Change Management Is Your Most Important Cyber Control

Myth 6: 'More Alerts Means Better Visibility'

This myth is easy to fall into because purchasing more tooling feels like progress. A monitoring platform deployed, an alert count increasing, a dashboard populating, long live more visibility!!!

What they often produce is noise. In OT environments especially, where operators are responsible for process safety and production in addition to monitoring security alerts, alert fatigue is a real and serious problem. When everything is an alert, operators learn to treat alerts as background noise. And then the one alert that actually matters gets treated the same way.

The corrective action is to build fewer, better detections. Ten to fifteen high-confidence detections tied to clear response steps that operators trust are worth more than hundreds of generic threshold alerts. This is a tuning discipline, not a purchasing decision.

Read more: OT Logging That Matters: Less Noise, More Signal

What These Myths Have in Common

Each of these myths outsources thinking to something outside the organization. Size. A diagram. An IT team. A vendor. An auditor. A tool. The common thread is that all of them defer the actual work of understanding and managing OT risk.

The antidote is consistent across all six: do the actual work. Inventory what is reachable. Validate the boundaries. Name the OT security owner. Govern vendor access. Measure what audits cannot see. Tune for signal, not volume. None of these require new tools. All of them require the organizational will to challenge comfortable assumptions.

30-Day 'Do This Now' Checklist

  1. Identify which of these six myths your leadership repeats most often.
  2. Gather evidence for or against it in your actual environment — not your diagrams, your actual network.
  3. Apply the corrective action for that myth first.
  4. Brief leadership in operational terms: what did we find, what did we fix, what does it mean for uptime and risk?

Retire One Myth, Then the Next

Focus beats fear in OT cybersecurity. Evidence beats assumption. You do not need to fix everything at once. Pick the myth your organization is most committed to, validate it against reality, and work from there. Do that consistently, and the security program improves without a single new tool.

More practical OT and IT cybersecurity guidance at The Catch.

About the resource
What you'll learn
Who is this resource for?
Download OT Cybersecurity Myths
Download Resource
Thank you and enjoy the resource
View Resource
Oops! Something went wrong while submitting the form.