How Ransomware Crosses the IT-OT Boundary (And How to Stop It)
Contributors
Ransomware operators understand manufacturing economics better than most security teams give them credit for. They know that a plant that cannot produce loses money by the hour. They know that operational technology (OT) systems are harder to restore than IT systems, that backups are often incomplete and that the pressure to pay comes faster when production is stopped. The IT-OT boundary is not an incidental target. It is a deliberate one. The numbers bear it out: Dragos tracked ransomware impacting 3,300 industrial organizations in 2025, and manufacturing accounted for more than two-thirds of the victims.
How Ransomware Crosses From IT Into OT
The path from a phishing email to a production shutdown follows a predictable pattern. An attacker gains an initial foothold in the IT environment, typically through a compromised credential or a phishing campaign targeting an employee with access to both IT and OT systems. From there, they move laterally, looking for systems that bridge the two environments.
Historian servers are among the most common pivot points. They are designed to collect process data from OT systems and make it available to IT applications. That functionality requires connectivity in both directions, which means a compromised historian server provides access to the OT network. Engineering workstations create the same exposure. They sit on the corporate network for remote access and email, and they connect to programmable logic controllers (PLCs) and human-machine interfaces (HMIs) for configuration and diagnostics.
Why the Boundary Fails
The IT-OT boundary fails most often not because of sophisticated attacks but because of accumulated operational decisions that each seemed reasonable at the time. A shared credential set up so the night shift supervisor could access both systems. A firewall rule opened for a vendor during a maintenance window and never closed. A demilitarized zone (DMZ) that routes traffic between IT and OT but does not actually inspect or restrict what passes through it.
These are not edge cases. In almost every OT environment that has undergone a security assessment, some version of these conditions exists. The boundary that appears robust in the architecture diagram is rarely as enforced as the documentation suggests. Ransomware operators, once they have access to the IT environment, are patient enough to find the gaps. They have the time: Dragos puts the industry-wide average dwell time for ransomware in OT environments at 42 days.
What Ransomware in OT Actually Costs
The cost of a ransomware incident that crosses into OT is not just the ransom demand. It is the production loss during the shutdown, which for a mid-size manufacturer can run to hundreds of thousands of dollars per day. It is the recovery cost for OT systems, which cannot simply be reimaged from a backup the way a laptop can. It is the time required to revalidate and restart process control systems safely. It is the reputational damage with customers who depend on your production output.
Colonial Pipeline is the most widely cited example, but the pattern repeats across manufacturing, food processing, pharmaceuticals and utilities. The May 2021 REvil ransomware attack on JBS halted cattle-slaughtering operations at 13 of its meat processing plants, and the company confirmed it paid the equivalent of $11 million in ransom. The attack does not need to target OT directly. It only needs to make enough of the environment inaccessible that operations leadership decides the cost of staying down exceeds the cost of paying.
What Penetration Testing Finds Before Ransomware Does
The value of an IT-OT penetration test is not that it simulates a ransomware attack. It is that it finds the same paths a ransomware operator would use to reach the OT environment, before they get there. That means testing lateral movement from the IT network toward OT systems. Validating whether segmentation controls actually enforce the boundaries they are supposed to. Checking whether historian servers and engineering workstations are accessible from the IT network in ways that could be exploited. IEC 62443 from the International Electrotechnical Commission defines those boundaries as zones and conduits, and Special Publication 800-82 from the National Institute of Standards and Technology (NIST) describes how to assess them.
The findings from these tests consistently cluster around the same categories: overly permissive firewall rules at the IT-OT boundary, shared credentials with access to both environments, and remote access paths that were set up for operational convenience and never hardened. Finding them in a controlled pen test is significantly less expensive than finding them during an incident response.
Knowing Your Exposure
The first step toward protecting the IT-OT boundary is understanding how exposed it currently is. That requires looking at the actual state of your network, not the intended architecture. Where can traffic cross between IT and OT? What credentials exist with access to both environments? Which systems at the boundary have not been assessed in the past 12 months?
A structured risk assessment focused on the IT-OT boundary gives you that picture. It identifies your most critical exposure points and maps them to the specific ways ransomware operators would exploit them. That is the foundation for a remediation plan that reduces real risk rather than checking compliance boxes.
Ransomware operators are already looking for your boundary gaps. Find them first. Request an IT-OT boundary risk assessment and get your most critical exposure points identified, ranked and mapped to a remediation plan.
Frequently Asked Questions
Ransomware operators target the IT-OT boundary because they understand manufacturing economics. A plant that cannot produce loses money by the hour, OT systems are harder to restore than IT systems, backups are often incomplete, and the pressure to pay comes faster when production stops. The IT-OT boundary is a deliberate target, not an incidental one. The scale bears it out: Dragos tracked 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024, collectively impacting 3,300 organizations, with manufacturing accounting for more than two-thirds of all victims.
Ransomware follows a predictable pattern to move from IT into OT. An attacker gains an initial foothold in the IT environment, usually through a compromised credential or a phishing campaign aimed at an employee with access to both IT and OT. From there they move laterally, looking for systems that bridge the two environments. Historian servers are among the most common pivot points, because their job of collecting OT process data for IT applications requires two-way connectivity, so a compromised historian provides a path into OT. Engineering workstations create the same exposure, sitting on the corporate network for email and remote access while connecting to PLCs and HMIs for configuration.
The IT-OT boundary fails because operational decisions break down what looks clean on paper. A shared credential for a night shift supervisor, a vendor firewall port never closed, or an uninspected DMZ cause more damage than sophisticated attacks. IT prioritizes patching and data protection, while OT prioritizes uptime and safety, since patching a live PLC can halt production or create a hazard. Equipment lifecycles widen the gap: IT hardware refreshes every 3 to 5 years, while OT equipment runs 15 to 25 years, leaving systems exposed between maintenance windows. Historian servers and engineering workstations need two-way connectivity to function, making them natural pivot points for attackers. IT and OT teams also report to different leaders with separate budgets, so no one owns the boundary. The average ransomware dwell time in OT environments is 42 days, though organizations with full OT visibility contain incidents in 5.
A ransomware incident that reaches OT averages between $4.5 million and $5.5 million, and the ransom payment itself accounts for only about 15% of that total. The other 85% comes from downtime, recovery work, and lost control. Downtime alone can cost $260,000 to over $1.9 million per hour in industrial settings, since idle machinery and delayed fulfillment add up fast. Recovery and remediation, separate from any ransom, typically runs $1.5 million to $2.7 million and covers forensics, re-imaging machines, and rebuilding OT systems. Attackers often encrypt engineering workstations or the virtualization layer rather than the controllers themselves, which forces a manual shutdown even when the physical equipment is untouched. OT incidents cost more than standard IT breaches because availability, not just data, is on the line. A stopped line hits revenue immediately, and prolonged outages ripple into supply chains, triggering contractual penalties and reputational damage with partners who depend on your output.
Penetration testing defends the IT-OT boundary by finding the same paths a ransomware operator would use to reach OT, before they get there. That means testing lateral movement from the IT network toward OT systems, validating whether segmentation controls actually enforce the boundaries they are supposed to, and checking whether historian servers and engineering workstations are reachable from the IT network in exploitable ways. IEC 62443 defines these boundaries as zones and conduits, and NIST Special Publication 800-82 describes how to assess them. Finding these gaps in a controlled test costs far less than finding them during incident response, especially given that 30% of Dragos incident response cases in 2025 began with operational staff reporting abnormal behavior rather than alerts or confirmed detection.
IT-OT penetration tests most commonly find the same recurring issues: overly permissive firewall rules at the IT-OT boundary, shared credentials with access to both environments, and remote access paths that were set up for operational convenience and never hardened. These are the exact weaknesses ransomware operators exploit to cross from IT into OT, and compromised VPN services and edge devices remain a common origin point for industrial intrusions.
Start by looking at the actual state of your network rather than the intended architecture: where traffic can cross between IT and OT, which credentials have access to both environments, and which boundary systems have not been assessed in the past 12 months. A structured risk assessment focused on the IT-OT boundary provides that picture, identifying your most critical exposure points and mapping them to the specific ways ransomware operators would exploit them. That assessment becomes the foundation for a remediation plan that reduces real risk rather than checking compliance boxes.
Other Popular Articles
In the digital age, businesses must adopt an ad
GRC is the capability, or integrated collection