Across the UK, cybersecurity incidents have become a familiar feature of the business landscape.
Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized.
Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).
Latest Videos From
Louise Bulman
Social Links Navigation
Vice President International at Dragos.
That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost data, affecting safety, revenue and in some cases an organization's ability to operate at all.
For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences with data breaches or malware attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.
Why OT risk is routinely underestimated
Much of today’s operational infrastructure was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent security practices.
The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.
When cyber incidents stop operations
Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships
Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation.
Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk.
A risk landscape shaped by geopolitics
Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment.
At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.
Bringing direction and discipline to governance
Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.
Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.
Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.
A leadership obligation
Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.
Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.
We've ranked and reviewed the best antivirus software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit