By Ann Marie van den Hurk, Mind The Gap Advisory

 

The Riskiest OT Systems Aren’t the Problem

The Inability to Act on Them Is.

The recent Riskiest Devices Report 2026 by Forescout highlights a familiar pattern: a small number of device types introduce outsized risk across enterprise environments.

Many of these assets share three characteristics:

  • They are operationally critical
  • They are difficult or impossible to patch quickly
  • They sit across fragmented ownership boundaries

Healthcare systems, industrial environments, and network infrastructure are especially exposed.

Most organizations already know this.

Where they struggle is not identification.
It is decision.

Where Vulnerability Management Stops

Modern vulnerability management programs are effective at:

  • identifying exposure
  • prioritizing risk
  • improving visibility

But they are not designed to answer a more urgent question:

What happens when a high-risk asset becomes an active incident?

At that moment, competing priorities surface immediately:

  • Security pushes for containment
  • Operations prioritizes continuity
  • Legal evaluates regulatory exposure
  • Communications anticipates external impact

Without pre-defined decision authority, escalation becomes negotiation.

And negotiation consumes time the organization does not have.

The First-Hour Failure Point

In high-velocity incidents, organizations do not fail because they lack data.

They fail because:

  • decision ownership is unclear
  • escalation thresholds are undefined
  • authority is not aligned across functions

The result is predictable:

  • delayed action
  • inconsistent communication
  • increased operational and reputational impact

This is not a tooling issue.

It is a governance issue.

What Needs to Be Designed in Advance

If certain devices are known to carry disproportionate risk, then the response to them must be equally defined.

That means:

  • Named decision owners for critical asset classes
  • Clear thresholds for action (contain, isolate, disclose)
  • Pre-aligned authority across Security, Legal, Operations, and Communications

Not during the incident. Before it.

The Shift: From Risk Identification to Decision Readiness

The organizations that manage these scenarios well do one thing differently:

They do not rely on vulnerability data to drive decisions in real time.

They pre-design how decisions will be made when that data becomes urgent.

This is the difference between:

  • knowing what is risky
    and
  • being able to act on it under pressure

Where This Starts

Most teams don’t need another framework.

They need clarity on a simple question:

Will our decision structure hold in the first 20 minutes of a real incident?

That is where readiness begins.

If this gap exists in your environment, it will surface under pressure.

→ Explore how to structure decision authority for OT and industrial environments: ICS/OT Crisis Readiness

Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com

Share This