Thought Leadership | Operational Technology (OT) Security | 8-minute read.
Recent incidents have highlighted just how quickly a cyber attack could escalate from an IT issue into a major OT and operational crisis.
£1,900,000,000.
One billion, nine hundred million pounds was the estimated loss by Jaguar Land Rover. It was the most economically damaging cyber event to hit the UK by the Cyber Monitoring Centre’s estimation.
In September 2025 JLR suffered a cyber incident. The immediate impact wasn’t limited to lost data or unavailable email. Production and retail were severely disrupted which led to a ripple effect throughout the supply chain. JLR was the primary victim with up to 2,700 UK organisations affected.
While this started as an IT attack at JLR, they took the necessary steps to shut down production as a precaution. The shut down lasted over a month, but it helped contain the affected area and prevented further loss and possible danger to life.
This was a wake up call to industrial leaders. An attacker doesn’t need bespoke malware or direct control of a PLC to create a crisis. Businesses have had to recognise that operational disruption poses the biggest cyber risk for most. The operational disruption for JLR generated almost all of the £1.9 billion financial loss.
State-Backed Threats and Supply Chain Risk
While this loss dwarfs other known data breaches, it is a signal for the future. Attack groups are becoming more sophisticated and have the financial backing from state actors. The NCSC said it managed more than 200 incidents affecting UK critical national infrastructure and the supporting ecosystem in the year to May 2026. Around 75% are believed to be linked to state actors.
The phrase “supporting ecosystem” will include a supplier, an MSP, an engineering contractor or a remote access provider. This is providing additional vulnerabilities for attackers to exploit and therefore making third party risk management one of the most important topics in cyber security right now.
Reconnaissance of Physical Processes
A growing concern for defenders is the reconnaissance of physical processes. Threat actors are increasingly specialising their operations. One group gains initial access and maps the environment, while another uses that intelligence to move deeper into operational systems.
For industrial organisations, this matters because it shortens the journey from initial compromise to operational disruption. Attackers no longer need deep knowledge of a plant from day one. They can acquire that knowledge after entry, identify where disruption will have the greatest impact, and retain access for future operations.
Strip away the threat actor names and the operating model is surprisingly consistent: compromise a trusted third party or exposed edge device, steal credentials, move through the IT/OT boundary, identify critical processes and retain access for future disruption.
This is not traditional data theft. It is reconnaissance of the physical business itself.
The High-Frequency Threat: Ransomware and Digital Dependencies
However, UK operators cannot assume that only advanced state group with bespoke ICS malware can cause operational harm.
While the patient reconnaissance is a real threat, most UK organisations don’t face it first. The high frequency risk is ransomware exploiting how dependent modern plants have become on shared digital infrastructure.
Dragos tracked 119 ransomware groups affecting more than 3,300 industrial organisations. With manufacturing representing more than two-thirds of observed victims. With increased targeting towards VMware ESXi systems hosting SCADA and engineering workloads. An attacker does not need to alter a PLC if encrypting the virtual infrastructure removes operator visibility or control.
This connects back to JLR. The Cyber Monitoring Centre (CMC) estimated that each week the loss was around £108 million in fixed costs and lost profit alone. This cascaded down through nearly a thousand tier 1 suppliers and thousands more beneath them. One case reported having to take out a personally backed loan in order to stay solvent.
The recommendation is blunt: boards need to stop thinking of cyber risk as solely data loss. Operational disruption is the biggest cyber risk the businesses are facing. They need to invest in specifically mapping and strengthening the boundary between IT and OT.
Identify the assets that are required to deliver business value. Challenge systems compromise scenarios and ensure that there are recovery plans in place to contain losses. Strengthening the IT/OT boundary is essential for limiting potential attack propagation.
UK Threat Landscape: Hacktivism, Edge Devices, and Router Exploits
Throughout 2026, the NCSC repeatedly warned about activity targeting UK organisations through internet-facing infrastructure such as VPN gateways, firewalls and routers.
While the actors varied from hacktivists to state-sponsored groups, the pattern remained consistent: exploit weak edge devices, steal credentials and use that access to move deeper into operational environments.
For industrial organisations, these devices have become a critical battleground. In many cases, operational disruption begins long before an attacker reaches an industrial control system.
Five Fatal Weaknesses Turning Access into Crisis
Across these diverse threat actors, the path to disruption relies on five recurring operational vulnerabilities that continuously turn access into crisis.





Structured Defense: Implementing IEC 62443
To defend against these current threats, businesses are shifting away from ad hoc fixes toward structured engineering frameworks, most notably IEC 62443. As the recognized international standard for industrial automation and control systems, IEC 62443 gives organisations a blueprint to move away from reactive IT patching and establish formal security levels across their plant lifecycle.
In practice, companies are implementing IEC 62443 by establishing strict zone and conduit models. They group physical equipment and operational assets into distinct security zones based on criticality, then control and monitor every communication conduit passing between them. In the short term, this allows businesses to isolate high-risk HMIs and PLCs directly without breaking plant functionality. Over a longer horizon, organisations are using the framework to enforce multi-factor authentication on all vendor conduits, secure out-of-band offline backups for PLC logic, and deploy OT-native telemetry to monitor engineering workstation behaviour.
The result is a widening supply-and-demand gap. Regulatory expectations are increasing, threat activity is increasing, and transformation programmes are accelerating. Yet the number of professionals with proven OT security experience is growing far more slowly. Organisations are therefore competing for a limited pool of practitioners at the exact moment they need them most.
The Human Bottleneck in OT Security
However, executing an IEC 62443 roadmap has exposed a severe industry bottleneck: a critical shortage of personnel who possess genuine, hands-on framework experience. While many cyber security professionals understand standard IT frameworks like ISO 27001 or NIST, very few have the engineering depth required to apply IEC 62443 inside an active plant without risking operational downtime. Designing zones and conduits requires someone who understands both network architecture and physical process dependencies. The market is currently bottlenecked by a deficit of talent that can balance cyber risk against engineering safety, legacy hardware constraints, and continuous production demands.
The shortage exists because OT security sits at the intersection of three disciplines that have traditionally operated independently.
Cyber security professionals understand threat detection, identity management and security architecture. Control engineers understand industrial processes, safety systems and asset reliability. Operational leaders understand production risk, maintenance cycles and commercial priorities.
Effective OT security requires all three perspectives simultaneously. An engineer can understand a PLC but struggle to assess cyber risk. A security architect may understand segmentation but lack familiarity with process safety constraints. Gaining expertise in both areas typically takes years of experience across multiple environments, making the talent pool naturally limited.
The challenge is further compounded by legacy infrastructure. Many sites continue to operate systems that pre-date modern cyber security practices, requiring specialists who can improve security without introducing operational instability or downtime.
Regulatory Expectations Are Rising
This skills shortage directly impacts how quickly businesses can adapt to shifting regulatory expectations across Europe and the UK, which are moving from voluntary guidance to strict statutory enforcement. In Europe, the NIS2 Directive enforces stringent risk management and rapid incident notification requirements across essential sectors. In the UK, the Cyber Security and Resilience Bill expands regulatory oversight across Critical National Infrastructure, managed service providers, and industrial supply chains. Under this legislative framework, OT assets are explicitly treated as elements of national resilience, giving regulators enhanced powers to enforce compliance and penalize non-resilient operators. Compliance is no longer just an IT audit item, it is a legal prerequisite for doing business.
Addressing these risks is not a matter of buying another software tool or delegating OT security to an existing IT team. It requires specialists who can bridge three distinct cultures: cyber security, plant engineering, and executive leadership. Building a resilient OT capability depends entirely on finding talent with practical framework experience who can execute standards like IEC 62443 without sacrificing plant safety or operational availability.
Building True Resilience
Across the UK and Europe, the threat landscape has converged. Cyber criminals, state-backed actors, and hacktivists are exploiting the exact same stolen credentials, edge devices, and supply chain dependencies. An operational crisis rarely starts with bespoke PLC malware. It begins with an unmonitored VPN, a reused password, or a compromised engineering partner.
- The lesson from JLR, and from the wider threat landscape, is clear: the greatest cyber risk facing industrial organisations is operational disruption.
- Technology to reduce that risk already exists, the frameworks exist, the guidance exists.
- What remains scarce are the people capable of applying them in environments where downtime, safety and production all matter simultaneously.
- Organisations that close that capability gap first will be the ones best positioned to withstand the next major disruption.
InfoSec People is a boutique cyber security and IT recruitment consultancy, built by genuine experts.
We work with businesses in the cyber/tech arena, from start-ups and scale-ups to FTSE100 and central Government, many of whom are always looking for great people.
Call us directly on 01242 507 100 to discuss opportunities or email info@infosecpeople.co.uk.