Walk through any large facility and start counting the connected devices. Building management systems, CCTV cameras, door controllers, industrial sensors, programmable logic controllers, lifts, air handling, metering, medical equipment. Most of them were installed by facilities teams, engineers or vendors over many years. Most of them are on the network. And in most organisations, nobody holds a complete list.
Meanwhile, the identity program has matured. People sign in with MFA, access is governed, joiners and leavers are automated, privileged accounts are vaulted. The humans are covered. The machines, largely, are not.
The estate nobody owns
Operational technology sits in an awkward gap. IT security teams often assume the operations or facilities side manages it, because they procured it and they run it. Operations teams assume IT security has it covered, because it is plugged into the network and security is IT's job. Vendors hold remote access for maintenance that nobody has reviewed since installation. The result is an estate that is connected, long-lived, rarely patched and unclear on ownership, which is precisely the combination attackers look for.
The question that exposes it is simple: if the board asked today who owns the risk in your OT and IoT environment, would the room have an answer?
Why this is landing on Australian boards now
Three forces are converging. The first is regulatory. For organisations operating assets captured by Australia's critical infrastructure regime, OT risk is no longer simply a technical concern. SOCI obligations, including risk management requirements for applicable entities, have pushed operational resilience and cyber risk firmly into executive and board oversight.
The second is the threat environment. As corporate IT defences have hardened, the least monitored path into an organisation has become the more attractive one. A building controller with a default password does not look like much until it is the foothold.
The third is data. The telemetry these devices produce is increasingly valuable, feeding reporting, automation and AI-driven insights into how sites and services actually run. That value only gets unlocked by connecting OT data to corporate platforms, and every connection is also a pathway that needs governing.
Devices have identities too
Every connected device has an identity problem, whether the organisation calls it identity or not. A shared service account created in 2019. A hardcoded credential the vendor set. A certificate nobody remembers issuing. A remote access tool the maintenance contractor uses. These are identities, and they deserve the same discipline your workforce identities now get.
The sharpest version of the question for a board is about the third parties: if you asked for a list of every vendor with remote access to your operational systems today, could anyone produce it?
OT and IoT security remains a specialist discipline, but many of its hardest access problems are fundamentally identity problems. What can connect to what. Which accounts hold privilege. How access is requested, approved, reviewed and revoked. How a device is onboarded when it arrives and retired when it leaves. Identity is the control point, for machines just as much as for people.
What good looks like
Organisations that get on top of this tend to build the same five things.
- Know what is connected. A current and honest register of the estate, because you cannot govern what you cannot see.
- Understand the risk. An assessment against recognised frameworks, with findings ranked by consequence rather than by noise.
- Control access. Segmentation between corporate and operational networks, privileged pathways brokered and monitored, and vendor access time-bound instead of permanent.
- Govern the lifecycle. Standards from procurement through configuration baselines to decommissioning.
- Use the data deliberately. Telemetry you are already paying to generate, put to work informing operational decisions.
The frameworks to anchor against are established: the Essential Eight and the Information Security Manual, ISO 27001, IEC 62443 for industrial environments, NIST SP 800-82, and the risk management program obligations under the SOCI Act. The work is aligning your environment to them in a sequence that reflects your actual risk.
Where to start
Not with a platform purchase. The organisations that handle this well start with a focused assessment: establish what is connected, how it authenticates, where the material risks sit, and what the prioritised uplift roadmap looks like. From there, the work is sequenced like any other well-run program, and some of it will turn out to be quick.
Three moments usually tell an organisation it is time. A SOCI obligation is approaching and the risk management program needs substance behind it. There has been an incident or a near miss, and the questions afterwards were uncomfortable. Or a site, plant or building upgrade is coming, and it would cost far less to build the controls in now than to retrofit them later.
At Move FWD we look at OT and IoT as part of the broader technology estate rather than a separate problem sitting in the corner. We bring together identity, security, architecture and transformation to understand the risk, shape the strategy and stay through delivery. If you are not sure what is connected, who has access to it, or who owns the risk, that is usually the place to start. Talk to us.