By Ann Marie van den Hurk, Mind The Gap Advisory
The Riskiest OT Systems Aren’t the Problem
The Inability to Act on Them Is.
The recent Riskiest Devices Report 2026 by Forescout highlights a familiar pattern: a small number of device types introduce outsized risk across enterprise environments.
Many of these assets share three characteristics:
- They are operationally critical
- They are difficult or impossible to patch quickly
- They sit across fragmented ownership boundaries
Healthcare systems, industrial environments, and network infrastructure are especially exposed.
Most organizations already know this.
Where they struggle is not identification.
It is decision.
Where Vulnerability Management Stops
Modern vulnerability management programs are effective at:
- identifying exposure
- prioritizing risk
- improving visibility
But they are not designed to answer a more urgent question:
What happens when a high-risk asset becomes an active incident?
At that moment, competing priorities surface immediately:
- Security pushes for containment
- Operations prioritizes continuity
- Legal evaluates regulatory exposure
- Communications anticipates external impact
Without pre-defined decision authority, escalation becomes negotiation.
And negotiation consumes time the organization does not have.
The First-Hour Failure Point
In high-velocity incidents, organizations do not fail because they lack data.
They fail because:
- decision ownership is unclear
- escalation thresholds are undefined
- authority is not aligned across functions
The result is predictable:
- delayed action
- inconsistent communication
- increased operational and reputational impact
This is not a tooling issue.
It is a governance issue.
What Needs to Be Designed in Advance
If certain devices are known to carry disproportionate risk, then the response to them must be equally defined.
That means:
- Named decision owners for critical asset classes
- Clear thresholds for action (contain, isolate, disclose)
- Pre-aligned authority across Security, Legal, Operations, and Communications
Not during the incident. Before it.
The Shift: From Risk Identification to Decision Readiness
The organizations that manage these scenarios well do one thing differently:
They do not rely on vulnerability data to drive decisions in real time.
They pre-design how decisions will be made when that data becomes urgent.
This is the difference between:
- knowing what is risky
and - being able to act on it under pressure
Where This Starts
Most teams don’t need another framework.
They need clarity on a simple question:
Will our decision structure hold in the first 20 minutes of a real incident?
That is where readiness begins.
If this gap exists in your environment, it will surface under pressure.
→ Explore how to structure decision authority for OT and industrial environments: ICS/OT Crisis Readiness
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
