Manufacturers are adding more digital connections to production environments. AI programs, remote monitoring, predictive maintenance, asset analytics, and cloud platforms all depend on some level of connectivity between OT, IT, and external systems.
That creates a practical question for manufacturers: how should the OT environment be built so one failure, one misconfiguration, or one compromised system does not spread into a larger operational problem?
This is where defensible OT architecture matters. A defensible architecture is not a single product or control. It is the way a manufacturing environment is designed so critical systems are harder to reach, harder to move through, and easier to protect when something goes wrong. During a session at IIoT World’s AI Manufacturing Day 2026, Itay Glick, Mark Toussaint, and James Turner Jr. of OPSWAT described how manufacturers should structure OT environments to support AI connectivity without creating excessive exposure.
Detection Alone Is Not Enough in OT
Many cybersecurity programs are built around detection. Detection matters, but in manufacturing it cannot be the only line of defense. OT environments often include legacy systems, old operating systems, specialized equipment, and production assets that cannot be patched or restarted on the same schedule as IT systems.
OT environments can include computers that are 8, 10, or 15 years old, including systems running older versions of Windows. Modern EDR tools may not be installable on some of these systems.
That reality changes the security strategy. If a manufacturer cannot easily patch, replace, or install modern endpoint protection on every OT asset, then the surrounding architecture becomes more important. The network must be designed to reduce exposure before an attacker or unsafe file reaches those systems.
AI Raises the Cost of Weak Architecture
AI changes the risk calculation because it can increase both connectivity and attacker capability. AI-enabled malware could become more autonomous inside an organization, moving through the environment, learning, adapting, and looking for ways to create damage.
For manufacturers, the deeper issue is that an attacker may use AI to move faster, understand unfamiliar industrial environments, and identify paths through weak segmentation.
A flat or loosely segmented OT network gives a compromised system more room to affect other systems. A stronger architecture limits that room.
Start With the OT Boundary
When CISOs ask where to get the biggest impact first, the OT boundary is often the recommended starting point. The boundary between OT and IT is where production systems connect to business systems, remote services, monitoring tools, analytics platforms, and other environments. If that boundary is protected, vulnerabilities inside OT become harder to reach from outside.
This does not eliminate the need to address internal weaknesses. But it gives manufacturers a strong first layer of protection. If a PLC, workstation, or legacy server cannot be patched immediately, reducing access to it becomes even more important.
For AI-connected manufacturing, the OT boundary should not be treated as a loose handoff between departments. It should be designed around the principle that production systems need controlled exposure, not broad connectivity.
Segmentation Limits the Blast Radius
Perimeter defense is only the first step. Manufacturers also need segmentation inside OT so a problem in one area does not move easily into another.
Defensible architecture combines segmentation, an understanding of data flows, and careful control over how traffic moves between zones. Industrial firewalls and other segmentation methods can help prevent lateral movement if a breach occurs in one part of the network.
This is especially important for manufacturers with multiple lines, cells, zones, or facilities. A packaging line, batch process, robotic cell, historian, and engineering workstation do not all need the same level of access to each other. Segmentation helps define what should communicate, what should not, and what requires stricter review.
Segmentation does not make production harder to run. It prevents unnecessary reach, so a compromised system stays contained.
Patch When Possible, Protect When Patching Is Hard
Patching remains important, but OT patching is not simple. Manufacturers often need scheduled downtime, vendor approval, testing, or maintenance windows before applying updates. Some systems may be too old or too sensitive to patch quickly.
Patching should still happen when it can be done safely, during planned downtime or scheduled outages.
This is the balance manufacturers need. Patching should not be ignored, but the architecture should not depend on perfect patching. A defensible OT environment assumes that some assets will remain vulnerable longer than anyone would like. It then uses segmentation, controlled access, monitored pathways, and boundary protections to reduce the chance that those weaknesses are easy to exploit.
In manufacturing, this is not a theoretical tradeoff. It reflects the reality of keeping production running while reducing cyber risk.
Business Continuity Belongs in the Architecture Discussion
Cybersecurity in manufacturing is also about limiting downtime and maintaining operations when something goes wrong.
Manufacturers need to look beyond individual controls and consider business continuity, incident response, data security, policies, and cybersecurity together.
This matters because many manufacturing disruptions do not begin with a direct compromise of PLCs or control systems. A disruption in enterprise systems, remote access, visibility, scheduling, ERP, or data exchange can still force production changes or shutdowns. A defensible architecture should account for these dependencies.
Manufacturers should ask how production would operate if a connected system became unavailable. They should also identify which systems are essential for safe operation, which are essential for production continuity, and which are important but not immediately critical.
That distinction helps prioritize protection and recovery.
AI Programs Should Build on a Defensible Foundation
AI can improve manufacturing operations, but it should not be added on top of weak architecture without review. If AI projects require more connections, more data movement, or more integration with enterprise and cloud systems, then the OT environment needs enough structure to support that safely. Modern manufacturing needs data, visibility, analytics, and in many cases AI. The goal is to connect with control.
Related from IIoT World
- 89% More Breaches: How Manufacturers Are Fighting Back
- Top 7 ICS/OT Cybersecurity Trends and Frameworks for 2026
- Securing Automation: Why the Specification Stage Is the Right Time to Embed OT Cybersecurity
This article is based on a panel discussion at IIoT World’s AI Manufacturing Day 2026, sponsored by OPSWAT. Speakers: Itay Glick, GM Hardware and OT Security; Mark Toussaint, Principal Product Manager; and James Turner Jr., Senior Solutions Engineer OT Cybersecurity, OPSWAT. Moderated by Tim Chase, Program Director, MFG-ISAC. AI tools were used to help summarize and organize the content. Reviewed and edited by the IIoT World editorial team.
Sponsored by OPSWAT. Editorially Independent.
FAQ
1. What is defensible OT architecture in manufacturing?
Defensible OT architecture is the way a manufacturing environment is designed so critical systems are harder to reach, harder to move through, and easier to protect when something goes wrong. It combines OT boundary protection, internal network segmentation, controlled data flows, managed access points, and patching strategies that account for legacy systems that cannot be updated on IT timelines.
2. How should manufacturers protect OT networks when scaling AI?
Manufacturers should start with OT perimeter defense, protecting the boundary where production systems connect to IT, cloud, and analytics environments. From there, internal segmentation limits lateral movement if a breach occurs. AI projects that require more connectivity should be reviewed for how they affect the OT architecture, including whether new data paths create routes back into critical systems.
3. Why is network segmentation important in manufacturing OT?
A flat or loosely segmented OT network allows a compromised system to affect other systems across the environment. Segmentation separates packaging lines, batch processes, robotic cells, historians, and engineering workstations so they do not all have the same level of access to each other. If one zone is breached, segmentation helps contain the incident and prevent it from becoming a plant-wide disruption.