Utility OT Security Is Changing as Cloud Connectivity Grows
| Key Takeaways | ᐯ |
- IT/OT convergence expands the attack surface across OT, cloud, GIS, AI and enterprise systems.
- Security depends on segmentation, controlled data flows and tightly managed access.
- Cloud, APIs and AI agents require strong controls around identity, permissions and execution.
- Visibility across assets, users and communication patterns is essential for effective monitoring.
- Every new integration should be assessed for access, privilege, monitoring and potential blast radius.
A substation does not need to be directly exposed to the internet to become part of a cyber risk chain.
An engineer connects remotely. Operational data moves into a cloud analytics platform. A vendor gets temporary access to equipment. GIS data feeds another enterprise application. An API carries information between systems that were once separated.
Each connection serves an operational purpose, but together they create more potential paths into systems controlling physical infrastructure.
The threat environment is moving quickly too. Dragos reported that ransomware attacks against industrial organizations increased 64% year over year in 2025, affecting approximately 3,300 industrial organizations.
For utilities, the issue goes beyond ransomware. Every additional connection changes who or what can potentially reach operational systems.
That is where IT/OT convergence security becomes difficult.
SCADA systems, remote terminal units, programmable logic controllers and other operational assets have different lifecycles, availability requirements and consequences of failure. Many were designed when persistent connectivity to enterprise and cloud environments was never part of the architecture.
The question for utilities is how to keep adding useful connections without allowing the attack surface to grow unchecked.
Why the Utility Attack Surface Is Expanding
The business case for IT/OT convergence is strong.
Utilities want operational data available for outage analysis, predictive maintenance, asset management and performance optimization. Field teams need faster access to information. Cloud platforms provide scalable analytics and storage. GIS platforms increasingly connect asset location with operational context.
AI is adding another layer.
Utility teams can potentially combine asset records, geospatial information, maintenance history and operational data to give engineers better ways to retrieve and interpret information. The connection between GIS and AI becomes particularly important here. We explored this architecture in Spatial RAG: The Missing Layer Between GIS Data and LLMs.
The resulting technology chain can look something like this:
Field Assets → OT Systems → IT/OT Boundary → Enterprise Applications → Cloud → Data and AI Platforms
Each layer introduces identities, endpoints, APIs, credentials and data flows that have to be understood and protected.
This is why OT cybersecurity cannot begin and end with securing devices inside a substation or operational facility.
The security model has to account for the connected environment around them.
The Patch Cycle Cannot Keep Up With the Connection Cycle
A cloud service can be deployed quickly. An API can create another integration. A remote access account can open a new path into an environment.
OT assets operate on a different timeline.
Industrial equipment may remain in service for many years. Replacing or patching it can require testing, vendor approval, maintenance windows and coordination with operations. Some legacy equipment cannot support newer security controls.
This creates an important gap in operational technology security.
New connectivity can appear much faster than existing OT vulnerabilities can be remediated. Security therefore has to reduce exposure around those assets, not rely on patching alone.
Securing the Connections Between IT and OT
As IT and OT environments become more connected, security increasingly depends on how those connections are designed and controlled. The objective is not to block connectivity, but to ensure access between systems is deliberate, limited and monitored.
Three controls are especially important: segmentation, controlled data flows and remote access.
Segmentation helps separate critical OT assets according to function, dependency and risk, while restricting communication between zones to what operations genuinely require.
Controlled data flows ensure that applications receive the information they need without creating unnecessary routes into operational systems. For example, a cloud-based predictive maintenance platform may need equipment telemetry, but it does not necessarily need a direct connection back to the equipment. An intermediate layer can broker that data while limiting inbound access.
Remote access should follow the same principle. Employees, contractors and equipment vendors should receive access only to the systems required for a specific task, with verified identities, appropriate privileges, session logging and permissions that expire when no longer needed.
CISA also recommends maintaining separation between IT and OT networks and controlling approved remote-access solutions to help limit lateral movement. This aligns with Zero Trust for OT, where access decisions are based on identity, asset, task and required privilege rather than network location alone.
Together, these controls allow utilities to preserve necessary connectivity while limiting how far any single connection can reach.

Cloud and AI Are Extending the OT Security Boundary
Cloud platforms and AI systems are expanding the OT security boundary beyond the industrial network. APIs, cloud permissions, integration credentials, AI agents and machine-to-machine connections all become part of the attack surface.
A utility may have strong OT segmentation but still face exposure through insecure APIs, excessive permissions or poorly protected credentials. Cloud security for utilities therefore needs to include identity, encryption, secrets management, API security and logging.
AI adds another concern: what the system is allowed to do. Retrieving technical or asset information carries less risk than an AI agent that can query systems, create tickets or initiate actions. Utilities need clear boundaries between information access and operational execution.
As AI systems connect models with enterprise tools and data, protocols such as MCP also make machine-to-machine access part of the security model. Prompt injection, excessive permissions and unsafe tool access become more consequential when AI agents can interact with business or operational workflows.
Every API, credential, agent and automated interaction therefore needs the same deliberate access controls applied elsewhere in the IT/OT environment.
GIS Is Becoming Part of the Convergence Story
Utilities have always been spatial businesses.
Transmission lines, substations, pipelines, transformers, service territories and field crews all have a geographic dimension.
As GIS platforms become more deeply connected with enterprise data and AI, they become another important part of IT/OT convergence.
As agentic GeoAI brings AI agents into geospatial and enterprise workflows, GIS can become an active part of operational decision-making rather than simply a system of record.
For utilities, this creates possibilities around asset intelligence, inspection planning, outage response and field operations.
That also makes geospatial context part of the information security teams need to protect.
A system that knows where an asset is located, understands its maintenance history and can interact with enterprise workflows contains far more operational context than a standalone application.
Access to that context should be governed accordingly.
Visibility and Monitoring Across the IT/OT Boundary
Utilities cannot protect connections they cannot see. Effective OT security monitoring requires visibility across assets, identities, network traffic, cloud workloads, integrations and third-party access.
Asset inventories are only the starting point. Security teams also need to understand normal communication patterns, where operational data travels, who can access critical systems and which external services depend on OT data.
This context strengthens OT vulnerability management. A vulnerability on an isolated device presents a different level of risk from the same weakness on a system exposed through multiple access paths.
Monitoring should prioritize whether activity is expected, authorized and operationally normal rather than simply generating more alerts. Combining asset visibility, vulnerability context and anomaly detection helps teams focus on the alerts that matter most across the IT/OT boundary.
As AI enters these environments, monitoring will also need to track what agents access, which tools they invoke and whether their actions remain within approved boundaries.
What Secure IT/OT Convergence Looks Like
IT/OT convergence is giving utilities access to capabilities that isolated operational environments could never provide. Cloud analytics, intelligent GIS, remote operations and AI are bringing operational data into a much broader technology ecosystem.
Each new integration should therefore come with an explicit decision about access, privilege, monitoring and potential blast radius. Strong OT security increasingly means knowing which connections exist, controlling what can cross them and understanding how far an attacker could move if one is compromised.
The objective is not to restrict convergence. It is to make connectivity deliberate, visible and controlled.
This is where 12th Wonder can help. We support utilities across cloud, data, infrastructure, AI and digital engineering, helping modernize connected environments while accounting for the relationships between identity, integrations, monitoring and operational data.
The goal is to help utilities gain more value from connected technologies without allowing the attack surface to grow unchecked.
FAQ
Strengthen Security Across Your IT/OT Environment
Control access, integrations and data flows as utility systems become more connected.
