IT and OT teams aligning for improved resilience

Blog

April 17, 2026

Stronger operational resilience starts with IT and OT working together

Anyone working in and around operational technology (OT) knows the feeling. An issue comes up, people want to do the right thing, and yet progress slows because the teams involved are looking at the same problem from different angles. 

IT is focused on reducing risk. OT is focused on keeping systems safe and running. Both priorities are legitimate, but unless they come together in a practical way, resilience becomes much harder to build than it needs to be. 

This isn’t a “rip and replace” problem. In most environments, stronger resilience comes from making the day-to-day decisions easier: clearer ownership, cleaner handoffs, and fewer surprises when the pressure is on. 

Misalignment between IT and OT usually grows over time

This rarely starts with one obvious failure. More often, it grows through small gaps that seem manageable at first. 

A responsibility is assumed rather than clearly assigned. A workaround stays in place because it keeps things moving. A decision takes longer than it should because people are weighing different consequences and don’t yet have a shared way to work through them. 

At first, that can feel like business as usual. Then the strain starts to show. Decisions that should be straightforward begin to drag and ownership becomes less clear. The same issues resurface because no one’s fully worked through who’s responsible, what matters most, or how trade-offs should be handled. 

And when something more serious happens, that lack of alignment becomes much harder to ignore. Teams are still trying to solve the problem, but they’re working from different assumptions about risk, urgency and operational impact. That’s when response slows down and disruption becomes more likely. 

Clear roles make resilience easier to build

This is where clearer roles make a real difference, not because they tidy up the org chart, but because they make decisions easier to make. 

When people know who owns what, how decisions should move, and where accountability sits, work becomes easier to progress. Questions get answered faster because they’re going to the right place, and escalation becomes more useful because people understand why it’s happening and what needs to happen next. 

That kind of clarity doesn’t need a major restructure. In most environments, it comes from tightening up a few basics, so the environment is easier to govern and operate. 

Practical improvements often include: 

  • Defining decision rights for common scenarios (change, access, incidents) 
  • Agreeing who owns which systems and who approves what 
  • Putting shared reporting in place so IT and OT are working from the same picture 
  • Using joint playbooks so response doesn’t depend on who happens to be available 

The point isn’t to add process for the sake of it. It’s to reduce confusion and make good decisions easier under real operational constraints. 

Work through real situations together

One of the most useful ways to build alignment is to work through realistic scenarios together. 

That might be a security incident, a change that could affect production, or a response plan that sounds fine on paper but hasn’t been tested against operational reality. When teams talk through those situations together, assumptions surface quickly. Dependencies become clearer. It also becomes easier to see where a decision might stall, where context is missing, or where one team is holding information the other genuinely needs. 

This is also where a “common language” starts to form. IT gets a clearer sense of what operational disruption can mean in practice. OT gets more visibility into how cyber risk is being assessed and why certain controls matter. That shared understanding makes future decisions easier because teams aren’t starting from scratch each time. 

That’s what resilience looks like in practice. Not perfect alignment overnight, but a stronger ability to move together when the answer isn’t obvious.

Capability matters too

Even when the intent is there, alignment is harder when teams are stretched. 

That’s a common reality in operational environments. People are balancing production demands, vendor coordination, security expectations and day-to-day support, often without much room to spare. In that setting, collaboration can slip, not because anyone thinks it’s unimportant, but because there’s only so much time and attention available. 

That’s where the right support can add value. The most useful support brings technical depth and operational awareness together. It needs to understand the threat side of the problem, but it also needs to understand the environment well enough to know what’s workable and what’s likely to create friction. 

This is also where convergence literacy matters. Teams that understand both the operating environment and the threat landscape are better placed to design controls that are technically sound and operationally practical. 

Stronger resilience is built in small steps

Most operational environments have grown over time, with layers of process, responsibility and technology added as the business changed. That’s why resilience is rarely built through one big reset.  

More often, it grows through smaller improvements that build momentum. 

In practice, that often includes: 

  • Clarifying roles and expectations early, before issues force the conversation 
  • Running cross-functional exercises to test coordination and response 
  • Creating regular, lightweight check-ins between technical and operational teams 
  • Identifying capability gaps and bringing in trusted support where it adds value 
  • Keeping business priorities central, so security and operational constraints are weighed together 

These changes aren’t dramatic. That’s why they work: they’re practical, repeatable and easier to sustain. 

What makes the difference over time

Operational resilience doesn’t come from waiting for perfect conditions. It comes from building better habits between the teams already responsible for keeping the environment secure and running. 

When IT and OT share context, define responsibilities clearly and make time to work through problems together, resilience becomes easier to strengthen. Not because the environment gets simpler, but because the people managing it are better aligned when it matters. 

That’s usually what makes the difference over time: better decisions, stronger coordination and more consistent ways of working. 

Want the broader context? Read the full Think Forward report for more practical insights on visibility, legacy risk and operational resilience in operational technology environments. 

If your team is working to strengthen operational resilience, RES. Business IT works with organisations to align IT and OT through clear roles, practical planning and security approaches that reflect operational reality. 

For a deeper look at applying security controls in live OT environments, read our guide on practical OT security for uptime-critical environments.


FrequentlyAsked Questions

What does operational resilience mean in an IT and OT environment?

Operational resilience is an organisation’s ability to keep essential systems and processes running, respond to disruption and recover effectively. Operational technology, or OT, includes the systems that monitor or control physical equipment and processes. Resilience improves when IT and OT teams share information, understand operational dependencies and make coordinated decisions about security, access, change and incident response.

Why do IT and OT teams sometimes approach risk differently?

IT and OT teams often approach risk differently because they are responsible for different outcomes. IT typically focuses on cybersecurity, data protection and reducing technical exposure, while OT prioritises safety, system stability and uninterrupted operations. Both perspectives are valid, but decisions can stall when teams do not understand each other’s priorities or have an agreed way to assess trade-offs.

How can poor alignment between IT and OT affect operational resilience?

Poor alignment can slow decisions, create unclear ownership and increase the likelihood of disruption during an incident. Teams may work from different assumptions about urgency, cyber risk and operational impact. When responsibilities and escalation paths are not agreed in advance, the same issues can reappear and responses may depend too heavily on whoever happens to be available.

Who should own cybersecurity decisions in an OT environment?

Cybersecurity decisions in an OT environment should have clearly assigned owners and agreed contributors. The appropriate owner may vary depending on whether the decision concerns system access, operational change, incident response or business risk. Defining decision rights, meaning who can decide, approve or escalate an issue, helps prevent responsibilities from being assumed or passed between teams.

What information should IT and OT teams share?

IT and OT teams should share information about system ownership, operational dependencies, security risks, planned changes and incident activity. Shared reporting helps both teams work from the same picture rather than relying on separate records or assumptions. The information should be practical enough to support decisions, including what may be affected, who needs to approve action and when escalation is required.

What is a joint IT and OT incident response playbook?

A joint IT and OT incident response playbook is a documented guide explaining how both teams will coordinate during a disruption. It should identify responsibilities, decision points, communication pathways and escalation procedures for realistic scenarios. A shared playbook reduces reliance on individual knowledge and gives teams a consistent starting point when they need to act under operational pressure.

Why should IT and OT teams run scenario-based exercises together?

Scenario-based exercises help IT and OT teams identify assumptions, missing information and unclear responsibilities before an actual incident occurs. Teams can work through situations such as a security event, remote access concern or change that may affect production. These discussions make system dependencies clearer and help participants understand how technical controls and operational consequences influence each decision.

What is convergence literacy in IT and OT security?

Convergence literacy is the ability to understand both cybersecurity risk and the practical realities of an operational environment. People with this understanding can consider threats, safety, uptime, equipment constraints and business priorities together. It supports security controls that are technically appropriate and workable in practice, rather than controls designed without enough knowledge of how the operation functions.

What practical steps can improve collaboration between IT and OT?

Practical improvements include defining system ownership, agreeing decision rights, creating shared reporting and running joint response exercises. Regular, focused check-ins can also help teams address small issues before they become larger problems. These steps do not require a major organisational restructure, but they do require consistent participation and clear expectations across technical, operational and business stakeholders.

How can RES. Business IT support IT and OT alignment?

RES. Business IT can help organisations align IT and OT through clearer roles, practical planning and security approaches that account for operational conditions. Support can focus on improving coordination, identifying capability gaps and establishing workable ways to manage access, change and incidents. The objective is to reduce confusion and strengthen resilience without treating cybersecurity and operational continuity as separate priorities.


Author

Share:

Recent Insights