SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs

CVEM for Manufacturing and OT Environments: Securing the IT/OT Convergence Gap

Jul 27, 2026

Continuous vulnerability and exposure management (CVEM) secures manufacturing and OT environments by continuously finding and patching vulnerabilities across the IT-connected systems that sit closest to the plant floor, engineering workstations, HMI servers, and cloud-connected infrastructure, while flagging the legacy and vendor-locked systems that need compensating controls instead of direct patches. Manufacturing doesn't get breached through some exotic industrial exploit most of the time. It gets breached through an ordinary IT vulnerability that happens to sit one hop away from a production line.

Manufacturing has been the most attacked industry globally for four years running, absorbing a large share of all reported global cyberattacks, and ransomware activity against the sector jumped sharply again in 2025. A widely reported 2025 incident illustrates exactly how this plays out. Attackers compromised a third-party supplier's software, moved laterally into a major automaker's production systems, and deployed ransomware that halted manufacturing across multiple countries for roughly five weeks, with damage estimated well into the billions. It wasn't an ICS zero-day that caused it. It was an unpatched entry point on the IT side that had a direct path into production.

Why is IT/OT convergence such a big risk?

Factory floors used to be isolated. PLCs, SCADA systems, and production networks ran on their own, physically separated from the corporate network. That separation is mostly gone now. Engineering workstations, HMI dashboards, and SCADA data all connect to cloud analytics platforms, ERP systems, and vendor remote access tools, because that connectivity is what makes modern manufacturing efficient.

The problem is that connectivity cuts both ways. When attackers breach an ordinary IT system, an unpatched engineering workstation, a vendor VPN account, a poorly secured remote access tool, that breach now has a path into equipment that controls physical production. A vulnerability that would just mean a slow server anywhere else can mean a halted assembly line here.

What makes OT environments hard to patch?

Three things collide at once in most plants:

1. Legacy systems weren't built for this. Plenty of industrial control systems still in daily use were never designed to be internet-connected, and Industry 4.0 adoption bridged that gap faster than security controls kept up.

2. Vendor lock-in blocks direct patching. A PLC or SCADA controller often can't be updated without vendor certification, since an unapproved patch can void a warranty or, worse, disrupt a safety-critical process.

3. Downtime has a real cost attached. Patching a corporate laptop mid-shift is a minor inconvenience. Taking a production line offline to patch, even briefly, has a direct revenue and output cost that plant managers understandably resist.

This is exactly why vulnerability management in manufacturing can't be a single strategy applied uniformly. It needs one approach for the Windows-based systems, servers, and cloud infrastructure that can be patched directly, and a different approach, segmentation, compensating controls, vendor coordination, for the OT equipment that can't.

How does CVEM fit into an OT security strategy?

CVEM covers the layer of a manufacturing environment that's most often the actual entry point: the IT-connected systems sitting adjacent to OT. That includes:

• Continuous discovery and patching of engineering workstations, HMI servers, and Windows-based OT-adjacent systems that run standard operating systems and can be patched like any endpoint

• Risk-based prioritization that treats vulnerabilities on systems with a network path into production as higher priority than equivalent findings elsewhere

• Third-party and remote access visibility, since vendor and contractor access remains one of the most common ways attackers get into manufacturing networks

• Cloud posture monitoring for the analytics platforms, MES/ERP cloud integrations, and IoT data pipelines increasingly tied into plant operations

• Faster remediation on the systems that can be patched, closing the gap attackers rely on while segmentation and compensating controls handle the equipment that can't be

Direct PLC and SCADA firmware patching typically stays a vendor-managed process, CVEM's role there is flagging exposure and feeding it into your segmentation and access control strategy, not patching the controller itself.

IT security vs. OT security priorities

DimensionIT SecurityOT Security
Primary GoalConfidentialityAvailability and safety
Patch ToleranceRegular patch windows expectedDowntime often unacceptable
Typical FixDirect patchSegmentation, compensating controls, vendor coordination
Governing FrameworkGeneral compliance (SOC 2, PCI DSS, etc.)ISA/IEC 62443
Attack Path RiskData theft, service disruptionPhysical production disruption, safety risk

FAQ

Can CVEM directly patch PLCs and SCADA systems?

Generally no. Most PLCs and SCADA controllers run vendor-locked firmware that requires vendor certification before any update, since an unapproved patch can disrupt a safety-critical process. CVEM's role there is identifying the exposure and feeding it into segmentation and compensating control decisions, while it directly patches the Windows-based engineering workstations, HMI servers, and IT-connected systems that support the OT environment.

Why does manufacturing get breached through IT systems instead of ICS exploits?

Because it's usually easier and just as effective. Once IT and OT networks converge, attackers only need to find one unpatched IT system, a workstation, a vendor VPN account, a remote access tool, with a network path into production. That's a much lower bar than developing a purpose-built exploit against industrial control equipment.

What's the difference between CVEM and CTEM?

CVEM (continuous vulnerability and exposure management) is the operational process of continuously finding and remediating vulnerabilities and misconfigurations across endpoints and cloud infrastructure. It's distinct from broader exposure management frameworks that add extra validation layers on top of that ongoing remediation work.

Does IEC 62443 require continuous vulnerability management?

ISA/IEC 62443 emphasizes a security lifecycle approach, including ongoing risk assessment and patch management processes, rather than a one-time certification. Continuous vulnerability management on the IT-connected systems within an OT environment supports that lifecycle approach, though the standard's specific technical requirements should be reviewed directly for your zone and conduit design.

How much does third-party and vendor access contribute to manufacturing breaches?

It's a significant factor. A large share of manufacturers have experienced breaches tied to third-party vendor or contractor access, often through remote maintenance connections. Validating and limiting vendor access, alongside continuous monitoring of the systems those vendors touch, is one of the more effective ways to reduce this risk.

Conclusion

Manufacturing keeps getting breached through the same pattern: an ordinary IT vulnerability with a network path into production, not some exotic industrial exploit. Saner CVEM continuously discovers and patches the engineering workstations, servers, and cloud-connected systems sitting closest to the plant floor, closing the gap attackers actually use, while your segmentation and vendor controls handle the legacy OT equipment that can't be patched directly.


Featured Posts

Open What is a vulnerability? Types explained (CVE, CWE, CVSS)

What is a vulnerability? Types explained (CVE, CWE, CVSS)

Point of View

What is a vulnerability? Types explained (CVE, CWE, CVSS)

A vulnerability is a weakness that attackers can use to affect systems, data, or access. See how CVE, CWE, and CVSS describe specific flaws, weakness types, and technical severity.

Jul 28, 2026

Open What Is BYOD (Bring Your Own Device)?

What Is BYOD (Bring Your Own Device)?

Point of View

What Is BYOD (Bring Your Own Device)?

Jul 27, 2026

Open CVEM for Public Sector and Government: Meeting Federal and State Compliance Without Falling Behind

CVEM for Public Sector and Government: Meeting Federal and State Compliance Without Falling Behind

Point of View

CVEM for Public Sector and Government: Meeting Federal and State Compliance Without Falling Behind

Jul 27, 2026

Open CVEM for SaaS and Technology Companies: Closing the Gap Between Compliance and Attack Resistance

CVEM for SaaS and Technology Companies: Closing the Gap Between Compliance and Attack Resistance

Point of View

CVEM for SaaS and Technology Companies: Closing the Gap Between Compliance and Attack Resistance

Jul 24, 2026