> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# From Cyber Warfare to the Factory Floor: What National Defense Gets Right (and Wrong) About OT Security
- URL: https://www.cybrsecmedia.com/from-cyber-warfare-to-the-factory-floor-what-national-defense-gets-right-and-wrong-about-ot-security/
- Published: 2026-04-21T13:04:43.000Z
- Updated: 2026-04-21T13:04:43.000Z
- Author: Lauren Andrus
- Tags: OT.SEC.CON. 2026, video, OT Security

**Presenter:**

[Anthony George](https://www.linkedin.com/in/anthonygeorgewichita/?ref=cybrsecmedia.com)

This talk argues that vulnerability management in OT is fundamentally broken because it’s still modeled after IT and that mismatch leads to wasted effort, poor prioritization, and persistent risk.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## **Key takeaways**

- **IT-style vulnerability management doesn’t translate to OT**
  - Scanning, patching, and CVSS scoring dominate the approach
  - But OT environments can’t always patch or reboot
  - What’s “critical” in IT isn’t always critical operationally
- **Volume isn’t the problem—context is**
  - Teams are flooded with vulnerability data
  - But lack understanding of which issues actually matter
  - Prioritization fails without operational context
- **Asset criticality is misunderstood**
  - Not all systems are equal
  - True risk depends on **process impact, safety, and uptime**
  - Without this lens, teams chase the wrong fixes
- **Patching is often unrealistic**
  - Downtime constraints limit maintenance windows
  - Vendor dependencies slow remediation
  - Some systems can’t be patched at all
- **Compensating controls are key**
  - Network segmentation
  - Access control
  - Monitoring and detection
  - Risk reduction often comes from mitigation—not remediation
- **Programs need to be risk-driven, not compliance-driven**
  - Stop chasing “all vulnerabilities”
  - Focus on what could actually disrupt operations
  - Align remediation with business impact

[![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/2026/02/Screenshot-2026-02-27-at-8.47.35---AM.png)](https://www.cybrsecmedia.com/conference/)