OT/IT Cybersecurity Survey

Arxiv pdf 2025-02-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

The convergence of Operational Technology (OT) and Information Technology (IT) under Industry 4.0 has expanded the cyber-attack surface of critical infrastructure across manufacturing, energy, transportation, water, and healthcare. This survey synthesizes the state of OT/IT cybersecurity along four axes. First, we taxonomize attack vectors that traverse the ITOT boundary, distinguishing IT-side initial access (phishing, exploits, supply-chain compromise, exposed remote access) from OT-side propagation and impact (insecure protocols, weak authentication, firmware tampering, control-logic manipulation). Second, we review tools and defensive technologies rule- and signature-based intrusion detection, AI- and ML-driven anomaly detection, Zero Trust Architecture, blockchain-based event logging, digital twins, and OT-aware Security Operations Center toolingand identify the gaps that remain, including OT-specific patch management, dataset scarcity for ML, IoMT segmentation, and the absence of consistent resilience metrics. Third, we compile a cross-validated historical record of 69 high-impact incidents spanning 20102025, from Stuxnet through Jaguar Land Rover, and quantify their commercial effects sector by sector with concrete figures sourced from SEC filings, government post-incident reviews, and primary regulatory disclosures. Fourth, we map the regulatory landscape that governs OT cybersecurity: NIST Cybersecurity Framework 2.0 and SP 800-82 Rev. 3, IEC 62443, the EU NIS2 Directive, DORA, and the Cyber Resilience Act, NERC CIP, and healthcare-specific regimes (IEC 80001-1, FDA, NIST SP 1800-8). A sectoral deep-dive on healthcare illustrates the ITOT convergence threat model under high-consequence conditions. The goal is to give practitioners and researchers a single, source-traceable reference for understanding where OT/IT cybersecurity stands, what cost the historical record imposes on defenders who lag, and where investment yields the highest marginal return on resilience.

Loading executive summary...

LINK COPIED TO CLIPBOARD