Bridging the IT/OT Divide: Why Security Is Also a Communications Challenge
By Ann Marie van den Hurk, MSc., APR – Founder, Mind The Gap Advisory
When Technology Fails, Language Fails Faster
When CISA, the FBI, and the UK’s National Cyber Security Centre released joint guidance urging organizations to align operational-technology (OT) security with ISA/IEC 62443 and ISO 27001, it marked a major step toward global consistency.
But let’s be honest: standards alone won’t save you if your teams can’t speak the same language during a crisis.
The Real Divide: Not Technical — Translational
Inside most organizations, IT and OT operate on parallel tracks.
IT teams speak in packets, protocols, and endpoints.
OT teams speak in uptime, reliability, and physical safety.
Executives speak in business continuity, shareholder confidence, and headlines.
During a cyber or operational incident, those languages collide — and confusion spreads faster than malware.
In the opening minutes of a crisis, clarity is everything. A missed translation between control-room engineers and cybersecurity analysts can delay containment, create conflicting updates, and trigger public statements that erode trust.
Why the New Guidance Matters
The CISA–FBI–NCSC advisory calls on organizations to:
Build a definitive record of OT assets
Document connectivity and third-party risk
Align controls with IEC 62443 and ISO 27001
That’s progress — but alignment is only half the equation. To turn compliance into resilience, organizations must also align language, expectations, and communication workflows.
From Frameworks to Fluency
Resilient organizations don’t just have patch management — they have message management.
They know who speaks when systems fail. They know which technical facts need translation before sharing with regulators or investors. And they know the difference between containment and communication silence.
That’s where CrisisOS5™ — Resilience at the Speed of Risk — comes in.
CrisisOS5™ is Mind The Gap Cyber Public Relations’ proprietary crisis-response system designed for the AI + cyber era. It helps industrial leaders bridge the IT/OT divide by connecting five critical disciplines that make resilience operational, not theoretical:
- Risk Intelligence – Detect cyber intrusions, AI anomalies, and synthetic threats before they escalate.
- Rapid Response – Deploy verified facts and actions within minutes to contain damage and preserve confidence.
- Crisis Communication – Own the first credible narrative in cyberattacks, data leaks, and AI-driven misinformation.
- Simulation Readiness – Stress-test teams until response becomes instinctive.
- Leadership Resilience – Equip executives to project calm authority through the chaos of AI-era crises.
Together, these disciplines form a repeatable system that helps enterprises detect faster, respond smarter, and protect trust when disruption strikes.
The Business Cost of Misalignment
In the recent cyberattack that disrupted airport check-in and boarding systems across Europe, operations at major hubs like Heathrow, Brussels, and Berlin were forced into manual mode — causing widespread flight delays and cancellations.
While exact costs were not disclosed, industry sources estimate that airport IT downtime can cost tens of thousands of dollars per hour in major hubs, even before factoring in penalties, passenger compensation, and reputational fallout.
The takeaway: it’s rarely the technical failure alone that drives losses — it’s the breakdown in coordination and communication that amplifies them.
IT understood the network impact.
OT understood the process impact.
But no one owned the narrative impact — and that’s where trust collapsed.
Misalignment doesn’t just break containment. It breaks confidence. Boards, regulators, and customers all judge leaders on response quality, not perfection.
The ROI of Resilience
When IT, OT, and communications teams operate from a shared playbook, organizations recover faster and communicate more consistently. Fewer missteps mean less downtime, lower regulatory exposure, and quicker recovery of stakeholder confidence. Aligning communication may be your highest-return cyber investment — because it protects the one asset you can’t insure: trust.
What Leaders Should Do Now
Even the best frameworks fail without clear execution. Leaders set the tone for how teams translate complexity into coordinated action.
To bridge the IT/OT gap before the next incident hits, start with these five moves:
- Run a language audit – Can your IT, OT, and communications teams describe the same incident the same way? If not, start there.
- Map technical assets to stakeholders – For every critical OT system, identify who speaks for it in a crisis.
- Train for translation – Include communications professionals in tabletop exercises, not just technical staff.
- Pre-write clarity – Prepare holding statements that explain technical events in plain English.
- Embed frameworks into narrative – IEC 62443 and ISO 27001 provide the structure; CrisisOS5™ turns that into action.
Because resilience isn’t built in the boardroom — it’s operationalized in the moments between detection and decision. That’s the space where CrisisOS5™ thrives: connecting technical precision with human clarity so organizations move from reaction to readiness — at the speed of risk.
Final Thought
The weakest link in your OT defense might not be a missing patch — it might be a missing conversation.
Bridging IT and OT isn’t just a security exercise; it’s a leadership mandate. Because when your teams can’t align internally, the world notices externally.
👉 Ready to assess your organization’s communication resilience? Learn more about OT / ICS Crisis Communications.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
Quick Q&A: IT/OT Crisis Readiness
Q1: What does the new CISA–FBI–NCSC guidance mean for OT leaders?
It signals a clear expectation: treat OT cybersecurity like IT cybersecurity — with standards, documentation, and accountability. The guidance specifically references IEC 62443 (the international standard for securing industrial automation and control systems) and ISO/IEC 27001 (the global benchmark for managing information-security risk). In practice, that means creating a detailed record of your OT assets, managing third-party exposure, and proving governance — not just having good firewalls. But the part often overlooked? You also need the ability to communicate that readiness clearly to boards, regulators, and the public.
Q2: Why is communication now a board-level OT issue?
The first story told about your incident shapes market confidence — and it rarely comes from you if your teams aren’t aligned. Boards and investors judge readiness not by whether you were breached, but by how transparently and competently you respond. Clear, confident communication is now part of operational resilience.
Q3: How does CrisisOS5™ help organizations bridge IT and OT?
CrisisOS5™ unites technical and non-technical disciplines under one repeatable system. It connects engineers, cybersecurity, legal, communications, and leadership through shared workflows and language — so that during a disruption, everyone moves in sync. The result: faster decisions, fewer errors, and preserved stakeholder trust when AI and cyber threats collide.
Q4: How quickly can an organization become crisis-ready?
With focused alignment workshops and pre-built playbooks, many leadership teams see measurable improvement within 30 days. The key is starting small — audit the language your teams use, clarify who speaks for which systems, and embed consistent messaging across IT, OT, and comms.
Q5: What’s the first step?
Start with a readiness conversation. Review how your current incident workflows handle communication — not just containment — then map those insights against CrisisOS5™ to identify your resilience gaps.
👉 Ready to assess your organization’s communication resilience? Let’s talk. Book time to speak with Ann Marie.
