One of the clearest lessons I’ve seen in this field came from a mining operation that shut down a 15-kilometre conveyor in response to a perceived cyber threat. There was no real threat. What happened was an IT-style response applied to an OT environment, without anyone weighing what stopping that conveyor would mean for the operation.
A loaded conveyor can’t simply be switched back on. With thousands of tonnes of ore sitting along 15 kilometres of belt, there is far too much weight to start it from a standstill. Before the conveyor could run again, the ore had to be dug off the belt. That took six weeks.
Six weeks, not six hours. For an operation moving material at that scale, every day the conveyor sits idle is production that doesn’t come back. None of it was caused by an attacker.
The people who made the call weren’t careless. They followed a playbook built for IT, where isolating a system is cheap and reversible. What they didn’t have was the visibility to see that the threat wasn’t real, or an integrated IT and OT response that put the operational consequences of the off switch in front of them before anyone reached for it. In OT, stopping has physical consequences.
That is the argument of this piece. In asset-heavy industries, an IT-style response in an OT environment can do far more damage than the threat that triggered it, and far more than it would have cost to build converged security properly. Organisations that still treat OT/IT convergence as an IT problem are misreading the risk entirely.
Built for uptime, not for connection
Operational technology in mining and manufacturing was engineered to do one job extremely well: run a deterministic process, reliably, for years at a time. PLCs, SCADA systems, drives, sensors and safety systems were designed on the assumption that they would sit on isolated networks, talk to a small number of known devices and otherwise be left alone.
That design philosophy shows up everywhere once you look for it. Patching happens in planned shutdowns rather than on a monthly cycle, because updating a controller can mean stopping the process it controls. Many field devices have no meaningful authentication, because nothing untrusted was ever expected to reach them. Industrial protocols assume that anything talking on the network belongs there. None of this is negligence. These were sound engineering decisions for a closed system.
The system is no longer closed. The OT security principles published by ASD’s ACSC and its international partners put safety first and knowledge of the business second among six principles for OT cyber security (ASD’s ACSC, 2024). Both depend on knowing what your environment is and how it behaves. Unmanaged convergence erodes exactly that knowledge.
Convergence is already underway
I still meet leaders who talk about convergence as a programme they might start next financial year. In most large mining and manufacturing operations it started years ago. Vendors connect remotely to maintain equipment. Historian and SCADA data flows into cloud analytics. Sensors on fixed plant and mobile fleet feed maintenance and ERP systems. Private wireless networks carry traffic across sites that would once have been hard-wired.
Every one of those connections was made for a good operational reason. Taken together, they mean the boundary between plant and enterprise is now a set of pathways someone has to know about and manage. Where that hasn’t happened, the exposure shows. Claroty’s 2025 global survey of 1,100 security, OT engineering and plant operations professionals found that 46 percent had been breached through third-party access in the previous 12 months, and 54 percent discovered weaknesses in vendor contracts only after an incident (Claroty, 2025).
Australia is not on the sidelines. Nozomi Networks’ threat research covering the second half of 2025 found that manufacturing was the second most targeted sector across the year, and that Australia was one of the three countries generating the most alerts per organisation (Nozomi Networks, 2026). For mine sites that lean heavily on wireless, the same research found 68 percent of observed industrial wireless networks still operate without management frame protection (Nozomi Networks, 2026), which is reason enough to look closely at what is carrying operational traffic.
The choice facing mining and manufacturing leaders is not whether to converge. It is whether the convergence already happening on their sites is being managed.
Visibility is the first gap
Most OT environments I see have an incomplete asset inventory. Ask an operation what is on its OT network, what firmware those devices run and which of them can reach the internet, and the honest answer is usually partial. That gap is what turns a perceived threat into a real outage. If you can’t see what normal looks like, you can’t quickly establish that an alert is a false alarm, and the pressure to act on the worst case wins.
The risk is not theoretical. Claroty Team82’s analysis of more than 940,000 OT devices across 270 organisations in manufacturing, natural resources and logistics found that more than 12 percent of industrial organisations had OT assets communicating with malicious domains (Claroty Team82, 2025). An organisation without visibility into its OT traffic has no way of knowing whether it sits in that group.
ASD’s ACSC treats this as foundational. Its asset inventory guidance for OT owners and operators positions an inventory and OT taxonomy as the basis for prioritising defences and managing incident response (ASD’s ACSC, 2025). The incident response point is the one that matters most here. An inventory isn’t a compliance artefact. It is what lets you make a fast, confident decision when something looks wrong.
That is why Orro starts converged security programmes with Digital Asset Discovery. Delivered as a managed service, it identifies and catalogues OT assets and their vulnerabilities and keeps that picture current, rather than treating discovery as a one-off project that is out of date within months. We looked at the compliance case for discovery in From Best Practice to Obligation: Why OT Asset Discovery Just Got More Urgent. The operational case is simpler: you can’t respond well to what you can’t see.
Why disconnection is the wrong reflex
When something suspicious shows up in an OT environment, the instinct is to pull the plug: isolate the network, stop the process and investigate from a position of safety. I understand the instinct, and in a genuine safety event stopping is the right call. As a reflex response to a suspected threat, though, disconnection can be operationally catastrophic, and the conveyor shows why. IT playbooks assume a system can be isolated and brought back once the all clear is given. Physical processes don’t work that way. A loaded conveyor, a flotation circuit or a production line stopped mid-batch can take days or weeks to recover from an unplanned stop, whether or not the threat was ever real.
The better approach is compensating controls: measures that contain a threat while the environment keeps running. In practice that means segmentation designed so a suspect zone can be isolated without taking down the whole operation, tightly governed remote access, monitoring that understands industrial protocols, and pre-agreed decision points that tell operators when to contain, when to keep running and when to stop. Australia’s Information Security Manual principles call for systems that can’t meet security requirements to be managed with compensating controls, and for remote access to OT to be authorised, controlled and monitored (ASD, 2026). Mature OT teams already apply that discipline to legacy equipment. It needs to extend to how they respond when something goes wrong.
Speed is where the difference shows up in dollars. IBM’s 2026 research found that Australian organisations taking more than 200 days to identify and contain a breach averaged AUD $5.17 million in costs, compared with AUD $3.26 million for those that did it in under 200 days (IBM, cited in SecurityBrief Australia, 2026). Those figures describe data breaches, not stopped production. In a mine or a plant the arithmetic is harsher, because the clock is measured in tonnes not moved and orders not shipped.
This is where Orro’s approach is different. Our OT Industry SOC and National Cyber Defence Centre monitor converged environments around the clock, with the goal of containing threats while production continues, rather than leaving an operator with a binary choice between running blind and shutting down. The same thinking underpins our view that air-gapping is no longer a realistic governance model for connected operations.
Where SOCI fits
For some operations this is also a regulatory question. The Security of Critical Infrastructure Act 2018 (SOCI Act) doesn’t treat mining or manufacturing as sectors in their own right, but many operations own or operate assets that can fall within captured asset classes, such as rail freight infrastructure, ports, energy assets or liquid fuel facilities. Where they do, Critical Infrastructure Risk Management Program (CIRMP) obligations apply, and those obligations have tightened. The Enhanced CIRMP Rules commenced on 10 June 2026, with 12 or 24 months to implement the uplifted requirements (Corrs Chambers Westgarth, 2026), and a second tranche of proposed reforms covering stronger governance, independent assurance and higher civil penalties went to consultation in July 2026 (Landers & Rogers, 2026). An OT environment you can’t see is very difficult to put in front of a board or an independent assessor. We unpacked the tranche two proposals in Beyond the Responsible Entity: What SOCI’s ‘Relevant Operator’ Concept Means for You.
SOCI applicability and obligations are specific to each organisation and each asset. Nothing in this article should be read as a view that the Act applies to your operation, and you should confirm your position with your legal advisers.
The response can cost more than the threat
Six weeks of digging ore off a belt is an expensive way to learn that OT is not IT. The operations that avoid that outcome are the ones that treated convergence as an engineering discipline before it became an incident. They know what is on their OT network, so they can tell a real threat from a false alarm. They have designed segmentation that lets them contain without shutting down. They have agreed in advance how IT and OT will respond together, and who weighs the operational consequences before anything is stopped.
None of that requires a rebuild before it can start. It starts with knowing what you have. If you’re responsible for an operation where the conveyor, the crusher or the production line can’t afford to stop, this is the conversation to have now, not in week two of an outage.
Get IT and OT responding as one team
The conveyor stopped because an IT playbook was applied to an OT problem. The IT vs. OT Playbook: A Guide to Productive Collaboration sets out shared governance, a common security language and unified incident response procedures, so the operational consequences are on the table before anyone reaches for the off switch. To discuss visibility, segmentation or OT incident response for your sites, talk to Orro’s Critical Infrastructure team.
Explore further: Mining & Resources · When the Factory Floor Meets the Network · The Convergence Risk: OT/IT Security Visibility Gap
Frequently asked questions
What does OT/IT convergence mean for mining and manufacturing?
It is the connection of operational technology, such as PLCs, SCADA systems and industrial sensors, to corporate IT networks, cloud platforms and remote access tools. In most large mining and manufacturing operations it is already happening through vendor remote access, cloud analytics and connected sensors. The practical question is whether those connections are known and managed.
Why is disconnecting OT systems a risky response to a cyber threat?
Stopping OT systems has physical consequences. A loaded conveyor or a production line stopped mid-process may not restart simply by switching it back on, and recovery can take weeks. In a genuine safety event stopping is the right call, but as a reflex response to a suspected threat it can cost far more than the threat itself.
What are compensating controls in OT security?
Compensating controls are measures that reduce risk when a system can’t be patched or disconnected. In OT they typically include segmentation that allows a suspect zone to be isolated without stopping the whole operation, tightly governed remote access, monitoring that understands industrial protocols, and pre-agreed decision points for containment.
Where should an OT security programme start?
With visibility. An accurate, current inventory of what is on the OT network is the basis for prioritising defences and making fast decisions during an incident. Orro’s Digital Asset Discovery service is designed as that starting point.
Does the SOCI Act apply to mining and manufacturing operations?
Mining and manufacturing are not SOCI Act sectors in their own right, but some operations own or operate assets that can fall within captured asset classes, such as rail freight infrastructure, ports or energy assets. Applicability is specific to each organisation and asset, so confirm your position with your legal advisers.
Sources & Further Reading
- Orro. (2026). When the Factory Floor Meets the Network: A Practical Look at OT/IT Convergence in Manufacturing.
- Orro. (2026). Beyond the Responsible Entity: What SOCI’s ‘Relevant Operator’ Concept Means for You.
- Orro. (2026). From Best Practice to Obligation: Why OT Asset Discovery Just Got More Urgent.
- Orro. (2026). The Convergence Risk: OT/IT Security Visibility Gap.
- Australian Signals Directorate. (2026). Information Security Manual: Cyber security principles.
- SecurityBrief Australia. (2026). Australia breach costs hit AUD $4.22 million, IBM says.
- IBM and Ponemon Institute. (2026). Cost of a Data Breach Report 2026.
- Corrs Chambers Westgarth. (2026). Security of Critical Infrastructure: enhanced CIRMP Rules now in force.
- Landers & Rogers. (2026). SOCI Act 2026 reforms: what responsible entities need to know.
- Nozomi Networks Labs. (2026). OT/IoT Cybersecurity Trends and Insights: 2025 2H Review.
- Claroty. (2025). The Global State of CPS Security 2025: Navigating Risk in an Uncertain Economic Landscape.
- Claroty Team82. (2025). State of CPS Security: OT Exposures 2025.
- ASD’s ACSC. (2025). Foundations for OT cybersecurity: Asset inventory guidance for owners and operators.
- ASD’s ACSC. (2024). Principles of operational technology cyber security.