Every documented OT breach of the last three years shares one root cause. Not a novel exploit, not a zero-day, not a nation-state cryptographic breakthrough. An operational technology device that should never have been reachable from an IT network, or from the internet, was reachable. Convergence created the path. The attacker just walked it.

This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.

Why convergence is happening whether governance is ready or not

The Purdue Model, the reference architecture most industrial security programs still cite, was built on strict layering. Level 0 sensors and actuators, Level 1 controllers, Level 2 supervisory systems, Level 3 site operations, and only then, through a demilitarized zone, the Level 4 and 5 business network. The model worked because the layers were genuinely isolated. Data moved up in small, controlled amounts. Nothing moved down except engineering changes made by hand, on site.

That isolation is gone in most plants, grids, and utilities today, and it is gone by business decision, not by accident. Predictive maintenance needs vibration and thermal data from the plant floor in a cloud analytics platform. Remote support contracts require vendor access into control system networks. Executive dashboards want production data in near real time. Every one of these is a legitimate business case, and every one of them punches a hole through a model built on the assumption that no such hole would exist.

CISA's own guidance acknowledges this directly. Its 2022 infographic on layering network security through segmentation does not tell organizations to eliminate IT-OT connectivity. It tells them to control it, deliberately, at named points, with monitoring at each one. That is the realistic target. Full isolation stopped being achievable for most operators once the business case for OT data reached the C-suite.

What the real incidents actually show

In November 2023, a pro-Iran group calling itself CyberAv3ngers took control of a booster station's Unitronics PLC at the Municipal Water Authority of Aliquippa, Pennsylvania. The advisory that followed described the point of entry in blunt terms. The PLC was directly reachable from the internet, discoverable with a basic Shodan or Censys search, and still running its factory-default password. No sophisticated tradecraft was required. The attackers found an exposed device and used the credentials that shipped with it.

Compare that to what happened at American Water Works in October 2024. The company disclosed unauthorized activity on its networks and took some systems offline as a precaution. What it also stated, and what mattered most for anyone assessing the incident, was that operational and water treatment systems were not affected. The attacker reached IT. It did not reach OT. That is not luck. That is segmentation doing exactly what it is supposed to do, holding the line between a business network compromise and a process control compromise.

Then there is Volt Typhoon, the China-nexus actor CISA and its partners detailed in advisory AA24-038A. This is the case that should worry leadership and the board more than any ransomware headline. Volt Typhoon was not stealing data. It was pre-positioning, using compromised IT infrastructure to build lateral movement paths toward OT assets, in some cases maintaining footholds for at least five years before detection. CISA was explicit that this pattern is inconsistent with espionage and consistent with preparation for disruption in the event of geopolitical conflict. The convergence that makes an OT asset reachable from a compromised IT box is not a hypothetical risk here. It is the exact mechanism a state actor is reported to be exploiting, patiently, for exactly this reason.

Three incidents, three different lessons. Aliquippa is what happens when a device is exposed with no compensating control at all. American Water is what segmentation looks like when it works. Volt Typhoon is what a patient adversary does with the connectivity convergence provides, whether or not it is ever used.

The one-conduit rule

Most OT governance programs fail for a boring reason. They inventory devices, not data paths. A plant might have a reasonably current asset list and still have no idea how many distinct routes exist between its business network and its control network, because those routes accumulated one vendor request, one remote access tool, and one well-intentioned IT project at a time.

The fix is a rule, not a diagram. Every category of IT-OT data flow, whether it is predictive maintenance telemetry, vendor remote support, or executive reporting, gets exactly one inventoried, monitored, access-controlled conduit. Not a general-purpose VPN that happens to reach the OT network. A named, single-purpose path with its own logging, its own approval owner, and its own kill switch. If a new use case needs data from the plant floor, it does not get routed through an existing conduit built for something else. It gets its own, or it waits.

This matters because the alternative, in practice, is what causes incidents like Aliquippa. A single flexible access point gets reused for purposes it was never designed for, its scope creeps, and eventually someone forgets it exists. A one-conduit-per-purpose rule makes the access map something a CISO can actually recite in a board meeting, and something an auditor can actually verify against traffic logs.

Consider a mid-size manufacturer rolling out AI-driven predictive maintenance across three plants. The naive path is a site-wide VPN from the cloud analytics vendor into the plant network, justified because it is fast to stand up and the vendor asks for broad access to make troubleshooting easier. Under the one-conduit rule, the vendor gets a single data diode or unidirectional gateway pulling only the specific sensor tags the model needs, no inbound path back into the control network, and a review clause the moment the vendor requests write access for anything. The predictive maintenance use case still ships. It just cannot become the path an attacker later reuses for something else, because there is nothing else to reuse it for.

The honest counterargument

The strongest objection to all of this is that rigid segmentation backfires. Plant engineers facing a blocked official path do not stop needing the data. They route around governance instead, plugging in a cellular modem, sharing a laptop with dual network interfaces, or handing a vendor a password over the phone because the formal access request takes six weeks. Security teams that treat the Purdue Model as scripture, refusing every convergence request on principle, end up with more shadow connectivity than teams that never tried to enforce isolation at all, because they never account for the fact that shadow IT-OT convergence is nearly impossible to inventory once it exists.

This objection is correct, and it deserves to be taken seriously rather than argued past. A governance program that says no by default, with no fast lane for legitimate requests, will lose control of its own network within a year. Every operator who has actually run an OT security program has a story about the modem nobody knew was there.

The answer is not looser governance. It is faster, named governance. The one-conduit rule only works if requesting a conduit is genuinely easier than bypassing one. That means a standing intake process with a service-level target measured in days, not months, an engineer on the security team who understands plant operations well enough to approve a legitimate request without a six-person committee, and a default assumption that most new data needs are legitimate and should be served quickly through a controlled path. Segmentation programs that fail are not failing because they segment. They are failing because they are slow, and slow governance always loses to a modem from the hardware store.

Monday questions for leadership and the board

Ask for the current count of distinct data paths between IT and OT networks, by purpose, not by device. If nobody can produce that number in the meeting, that is the finding.

Ask how long a plant engineer or vendor has to wait for a new, legitimate OT data access request to be approved and provisioned. If the answer is measured in weeks, assume shadow connectivity exists somewhere in the fleet right now.

Ask which OT assets, if any, are directly reachable from the internet, and how that was verified rather than assumed.

Ask what the incident response plan actually does differently for an OT-adjacent intrusion versus a standard IT breach, and whether that plan has been tested against a scenario modeled on Volt Typhoon's pre-positioning pattern rather than a smash-and-grab ransomware scenario.

The line that matters

Convergence is not the mistake. An unmonitored, unnamed, forgotten path between the business network and the plant floor is the mistake, and it is the only one the incident record actually supports.