I sat down with Luis Luque, Managing Director and Global Cyber Physical Security Lead at Accenture, straight from the RSA conference floor, to talk about the intersection of operational technology, physical security, and cyber risk. And honestly, it was one of those conversations that changed how I think about the space.
A few things that stuck with me:
• Most executives still believe OT and IT are separate worlds. They are not. The convergence is already happening, and the companies that pretend otherwise are the ones leaving backdoors wide open.
• Boards are paying attention, but most still cannot answer a simple question: if an OT incident happened tomorrow, who is responsible? Not who should be notified. Who owns it end to end. The silence in that room is the real vulnerability.
• Supply chain risk goes all the way down to the electron microscope level. Some companies are still running critical manufacturing on Windows NT in 2026 because replacing it would cost tens of millions.
• The basics—immutable backups, visibility, and containment—are still the things most organizations get wrong.
Luis made a point that I keep coming back to: the most successful OT security programs are not funded as security projects. They are funded as business enablement. When you can show a plant manager that the right security investment will keep the line running and make their job easier, the conversation changes completely.
If your organization touches anything physical, from a factory floor to a hospital to a data center, this is worth 44 minutes of your time.