Featured Articles

Strengthening Test System Security in IT and OT Networks

How Securing IT and OT Networks Boosts Test System Resilience and Performance

In the world of industrial research and manufacturing, the efficiency of your testing environment is crucial. While increased connectivity has revolutionized the speed of data collection, it has also turned test systems into high-risk gateways between Information Technology and Operational Technology (IT and OT) networks. Protecting the “digital heart” of your testing operations requires more than just standard firewalls. It demands a strategic commitment to securing every industrial control system against sophisticated and evolving control system cybersecurity risks. By adopting a proactive, multilayered defense and prioritizing industrial control systems protection, you can extend the life of your equipment and protect your data for a fraction of the cost of recovering from a breach.

In the article “Strengthening Test System Security in IT-OT Converged Environments,” published in Control Engineering, Dan Idzikowski, ACS Senior Staff Engineer, and Steve Summers, Security Lead for aerospace and defense customers at NI™, part of Emerson, explore how to strengthen the resilience of connected test ecosystems, highlighting several critical pillars:

  • Cohesion between IT and OT networks: Research shows that 72% of attacks originate in IT but migrate to operational areas. Organizations must bridge the friction between these teams, as an industrial control system often has different operational realities than standard office hardware. Aligning these departments ensures that security patches are applied without disrupting critical testing schedules.
  • Addressing supply chain and legacy risks: Many cybersecurity risks are inherited through third-party vendors or outdated legacy hardware. Because these systems often run on software that is no longer supported, they become easy targets. Implementing a Software Bill of Materials (SBOM) allows you to inventory components and identify vulnerabilities, making industrial control systems protection a standard part of your procurement process.
  • A culture of shared responsibility: Technical controls alone are insufficient if the human element is ignored. Strengthening IT and OT networks requires role-specific training and a “red teaming” approach to identify how an attacker might exploit human error or social engineering.

The real challenge lies in identifying exactly where your test environment is most vulnerable. You must prioritize control system cybersecurity when remote access points, such as 4G/5G or cloud connections, operate without full visibility from your security teams. These blind spots significantly increase cybersecurity risks, especially when combined with legacy devices that cannot be patched. As the European Union’s Cyber Resilience Act and U.S. Department of Defense mandates take effect, failing to secure your industrial control system will soon jeopardize not just your safety but your legal compliance and market access.

Modern IT and OT networks require a shift from a “one-and-done” checklist to a model of continuous resilience. This includes adopting zero-trust principles, where no device is implicitly trusted, and ensuring that any new integration includes long-term funding for industrial control systems protection. Without a plan to adapt to new threats, even the most advanced test systems will eventually become exposed.

Ultimately, securing your test systems is a strategic investment that provides a critical competitive advantage. It maximizes the reliability of your infrastructure by ensuring that your control system cybersecurity protocols are synchronized and defended. By addressing risks through a combination of technical rigor, cultural change, and lifecycle funding, you can ensure your industrial control system remains a robust asset rather than a liability.

Read the full article here.