OT/IT Cybersecurity Survey
Abstract
The convergence of Operational Technology (OT) and Information Technology (IT) under Industry 4.0 has expanded the cyber-attack surface of critical infrastructure across manufacturing, energy, transportation, water, and healthcare. This survey synthesizes the state of OT/IT cybersecurity along four axes. First, we taxonomize attack vectors that traverse the ITOT boundary, distinguishing IT-side initial access (phishing, exploits, supply-chain compromise, exposed remote access) from OT-side propagation and impact (insecure protocols, weak authentication, firmware tampering, control-logic manipulation). Second, we review tools and defensive technologies rule- and signature-based intrusion detection, AI- and ML-driven anomaly detection, Zero Trust Architecture, blockchain-based event logging, digital twins, and OT-aware Security Operations Center toolingand identify the gaps that remain, including OT-specific patch management, dataset scarcity for ML, IoMT segmentation, and the absence of consistent resilience metrics. Third, we compile a cross-validated historical record of 69 high-impact incidents spanning 20102025, from Stuxnet through Jaguar Land Rover, and quantify their commercial effects sector by sector with concrete figures sourced from SEC filings, government post-incident reviews, and primary regulatory disclosures. Fourth, we map the regulatory landscape that governs OT cybersecurity: NIST Cybersecurity Framework 2.0 and SP 800-82 Rev. 3, IEC 62443, the EU NIS2 Directive, DORA, and the Cyber Resilience Act, NERC CIP, and healthcare-specific regimes (IEC 80001-1, FDA, NIST SP 1800-8). A sectoral deep-dive on healthcare illustrates the ITOT convergence threat model under high-consequence conditions. The goal is to give practitioners and researchers a single, source-traceable reference for understanding where OT/IT cybersecurity stands, what cost the historical record imposes on defenders who lag, and where investment yields the highest marginal return on resilience.