The integration of Information Technology (IT) and Operational Technology (OT) within Cyber-Physical Systems (CPS) is reshaping critical infrastructure, driving improvements in efficiency, automation, and agile decision-making. However, this integration introduces significant cybersecurity challenges due to fundamental differences in priorities, protocols, and governance models. While IT systems emphasize data confidentiality and rapid updates, OT systems prioritize availability, reliability, and safety—often relying on legacy infrastructure less-equipped to handle modern threats. This paper explores the multifaceted challenges in securing IT-OT convergence within CPS, with a particular focus on critical infrastructure sectors such as energy, water, transportation, and manufacturing. The policy and regulatory gaps that hinder unified security strategies are analysed. The architectural models that support secure interoperability are examined, and key implementation challenges including segmentation, legacy system integration, and threat modelling are identified. A literature review of contemporary frameworks and case studies reveals a fragmented approach to security, with a need for further standardization, governance harmonization, and real-time risk assessment tools. This paper outlines general guidelines and checkpoints aligned of existing frameworks for a layered, defense-in-depth strategy aligned with zero-trust principles, supported by policy recommendations and architectural guidelines tailored to critical infrastructure protection. The findings aim to assist policymakers, engineers, and security professionals in building resilient and adaptive CPS environments to mitigate evolving cyber threats.
Raich et al. (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: