Michael Cooney
Senior Editor

Cisco strengthens integrated IT/OT network and security controls

Feature
Sep 17, 20254 mins

Traditional attempts to merge IT/OT threat detection, network segmentation, and secure remote access are impractical in today’s world, Cisco exec says.

Security
Credit: Tapati Rinchumrus / Shutterstock

Cisco has plans to deliver the same network and security architecture it offers for IT infrastructure to the operational technology (OT) world of warehouses, distribution centers, utility substations, ports and factories. 

Melding IT and OT networking and security is not a new idea, but it’s one that has seen growing attention from Cisco. At Cisco Live 2025 in June, for example, the vendor rolled out new IE3500 rugged switches with modular, AI‑ready capacity for edge compute and analytics, and it announced the integration of its wireless backhaul technology and Wi-Fi technology for mobility and latency‑sensitive industrial IoT.

Cisco also added a new technology called AI-powered asset clustering to its Cyber Vision OT management suite. Cyber Vison keeps track of devices connected to an industrial network, builds a real-time map of how these devices talk to each other and to IT systems, and can detect abnormal behavior, vulnerabilities, or policy violations that could signal malware, misconfigurations, or insider threats, Cisco says.

The new AI clustering feature automatically groups devices into logical zones, making it faster and easier to set up segmentation, and it helps customers quickly keep threats contained, Vikas Butaney, Cisco’s senior vice president and general manager, Secure Routing and Industrial IoT told Network World

Cyber Vision can share its inventories with Cisco’s extended detection and response (XDR) platform to provide a combined inventory of both IT and OT assets, and that can make threat investigations easier and build remediation workflows, according to Butaney.

In addition, Cisco has integrated Cyber Vison with its remote access system, Secure Equipment Access (SEA), to let customers quickly detect suspicious activity such as remote logins from unusual locations or times. With Cisco’s AI Assistant on board, admins won’t need to sift through endless audit logs.

Another significant move that will help IT/OT integration is the planned integration of the management console for Cisco’s Catalyst and Meraki networks. That combination will allow IT and OT teams to see the same dashboard for industrial OT and IT enterprise/campus networks. Cyber Vision will feeds into the dashboard along with other Cisco management offerings such as ThousandEyes, which gives customers a shared inventory of assets, traffic flows and security.

“What we are focusing on is helping our customers have the secure networking foundation and architecture that lets IT teams and operational teams kind of have one fabric, one architecture, that goes from the carpeted spaces all the way to the far reaches of their OT network,” Butaney said. 

For too long, OT security has been thought of as a specific cybersecurity practice to be managed with point products, Butaney wrote in a blog post earlier this year: “As industrial organizations start deploying these, they realize that they need most of their IT cybersecurity tools to properly protect the OT environment, and that they also need to detect and remediate threats across domains.”

“Protecting industrial operations means profiling and monitoring tens of thousands of industrial assets, often installed in hard-to-reach locations. The traditional approach consisting of deploying dedicated appliances for OT visibility, threat detection, network segmentation, and secure remote access is proving too complex to deploy, too costly to scale, and in some cases just impractical,” Butaney wrote.

A recent report from IDC went even further, stating that 50% of OT assets are more than 10 years old, and their security posture needs to be assessed.

“Most OT networks remain unsegmented, leaving critical assets exposed and increasing the likelihood of lateral movement during attacks. Adaptive security policies and real-time segmentation are common in IT. These solutions can help minimize risks in OT without disrupting operations if they are integrated with OT visibility products,” wrote IDC’s Romain Fouchereau, senior research manager, European security.

“Managing OT security in isolation is no longer viable. Even when building a dedicated security operations center (SOC) for OT, effective threat detection requires telemetry from both the IT and OT domains,” Fouchereau wrote. “Unified threat detection enables organizations to correlate events across all domains and detect patterns and advanced threats that could otherwise go unnoticed. Detecting and responding to modern threats requires best-in-class IT security tools for each task of the security workflow. These tools need visibility and context to the industrial process.” 

Cisco is not alone in its efforts to meld IT and OT networking and security. Networking competitors such as HPE/Juniper and Extreme have integration plans. Security vendors such as Palo Alto, Fortinet and others have integration capabilities as well.