Investigates socio-technical challenges impacting cybersecurity in operational technology organizations, highlighting improvement strategies.
Purpose Evidence suggests that the majority of cyberattacks have been made possible because of erroneous or noncompliant human behavior. Nevertheless, many organizations tend to focus their cybersecurity programs on technology, often overlooking the importance of socio-technical cybersecurity controls and practices. The reasons for this and processes to remedy it in organizations making use of IT have been examined in the literature. However, in organizations using integrated IT and operational technology (OT) systems, such as the digitalized manufacturing industry, cybersecurity is often treated with less rigor and attention. This paper aims to identify and analyze socio-technical challenges of cybersecurity in such organizations, with an eye toward improving their cybersecurity posture. Design/methodology/approach Two data sources have been used, namely, interviews and a survey, both with participants from the Norwegian Industry. The aim of both instruments was to investigate how cybersecurity is organized and how threats are mitigated, focusing on socio-technical aspects. The interviews investigated how organizations work with cybersecurity and what motivates cybersecurity-compliant behavior. The survey measured the usage and importance of the different security controls found in the NIST Special Publication SP800 - 82r3 “Guide to Operational Technology.” Findings The results show that organizations should include their OT personnel together with IT in the governance of OT cybersecurity. Communication between IT and OT is found to be a significant challenge. Communication barriers could stem from a lack of cybersecurity knowledge among personnel working with OT. Organizations should, therefore, invest more in specific OT cybersecurity training to bridge the communication gap. With increased efforts in specific training, it is expected that the extent of workarounds should decrease and that deviations found between best practices and the current usage of security controls should improve. By investing more in training, classified as a social element of the socio-technical system (STS), the needle will move toward a balance between the socio- and the technical dimensions of STS, which should yield the highest security outcome. Research limitations/implications This study does not give explicit advice nor does it uncover new in-depth knowledge regarding how organizations communicate internally and to what extent IT and OT cooperate; it only reports and discusses the views of the participants. The results of this study should be of interest to practitioners in both IT and OT cybersecurity. Future research should investigate, among others, how cybersecurity is organized and how communication is done within OT organizations. Originality/value This study uncovers new information as to how OT industry organizations organize and prioritize their cybersecurity efforts with a focus on socio-technical aspects; it examines if there are deviations between IT and OT systems cybersecurity and investigates how these affect the overall organizational goal of cybersecurity; and it reveals some of the challenges that such organizations face in achieving improved cybersecurity.
No takes yet. Share an insight, caveat, or question.
Kannelønning et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: