The air gap that once protected OT is mostly gone. Industry 4.0 and remote monitoring have wired the industrial network into everything else, and the attack surface has grown with every connection. In response, the market settled on a tidy promise: buy a SCADA scanner, point it at the plant, and the industrial side is covered. That promise is wrong.
The stakes are not hypothetical. In 2025, a cyber attack on Jaguar Land Rover that began in its corporate IT systems ended with vehicle production halted across its UK plants for five weeks, in what became the most economically damaging cyber event in UK history. An attack does not have to reach a PLC to stop a factory. When IT and OT share an environment, an intrusion on one side can bring the other to a standstill.
What is really inside a SCADA environment?
When people picture an OT environment, they see the field equipment: the PLCs, the RTUs, the sensors and valves and pumps. That is only the bottom layer. The supervisory layer that controls it is mostly software running on a normal operating system, which in practice means Windows. Engineering workstations, HMI stations, and SCADA servers are computers first and industrial systems second.
They do not sit alone. Alongside the control software you will find the same ordinary IT that exists everywhere else: Windows hosts, network switches, remote access tools, and almost always a handful of IP cameras. The industrial network and the office network are not two sealed worlds. They are one environment with industrial software layered into it.
This is why a SCADA-only scanner falls short. A tool built to fingerprint industrial protocols will identify the PLCs but say nothing about the Windows box beside them running the SCADA application, the camera shipping with default credentials, or the workstation two patches behind. Those are the systems an intruder would actually use to reach the industrial equipment.
The problem with separate IT and OT scanners
Rather than assessing the whole environment at once, IT and OT are typically covered by separate products: network scanning is one solution, SCADA scanning is another. For the buyer, that means two tools and two partial pictures. You scan the industrial protocols with one product and the surrounding IT with another, then try to stitch the results together.
An industrial-only view fails for another reason too: it strips away the context that tells you what to fix first. Consider two vulnerabilities. One is rated critical, but no one is exploiting it and no known attack path reaches it. The other is rated medium, but ransomware operators are actively using it right now. The medium-severity flaw is the one to fix first, because real-world exploitation, not the raw severity score, decides your true priority.
You can only make that call when you can see and compare risk across the whole environment. That is only possible when IT and OT are assessed together.
Assess IT and OT as one environment
The alternative is straightforward. Assess the whole environment as the single thing it is: industrial protocols and controllers, and the Windows hosts, network devices, and everything else around them, seen together and prioritized against each other rather than in two disconnected reports.
That is the difference between knowing you have a critical PLC vulnerability and knowing that the same vulnerability is reachable from an unpatched workstation that also carries a ransomware-associated flaw. The first is a data point. The second is the actual risk, and you can only see it when both halves are in one picture.
This is the approach Holm Security is built around. Assessing IT and OT through one platform means:
- One view of risk across IT, network, cloud, and OT, so industrial and IT exposure are seen and prioritized against each other rather than in separate reports.
- Prioritization driven by real-world exploitation, including whether a vulnerability is being used in ransomware attacks, not by severity score alone.
- Broad OT coverage, with tests spanning dozens of SCADA and industrial vendors and thousands of vulnerabilities.
- Full control over how the environment is assessed: tight scope, scheduling around maintenance windows, blackout windows, and the ability to stop instantly.
- No passive appliance to ship, install, and leave listening in the network, because assessment is done through active reconnaissance you control.
- A dedicated security research team continuously building and updating OT vulnerability tests as new threats appear.
Holm Security assesses IT and OT environments through one platform, so industrial and IT risk can be seen and prioritized together rather than in isolation. Learn more about our approach to OT security.
Frequently asked questions
Is a SCADA scanner enough for OT security?
No. A SCADA scanner inspects industrial protocols and controllers, but most of a SCADA environment is software running on Windows machines alongside ordinary IT such as network devices and IP cameras. Securing only the industrial protocols leaves most of the real attack surface uncovered.
Why do IT and OT need to be assessed together?
Because attackers do not respect the boundary. The path into an industrial system usually begins on the IT side, at an exposed workstation or a forgotten remote access service, and moves toward the field equipment. Industrial risk and IT risk regularly appear in the same environment at the same time, so seeing them together is the only way to understand the true path of an attack.
Does OT vulnerability management help with NIS2 compliance?
NIS2 expects entities to manage cyber security risk across their operations, including operational technology. Unified visibility across IT and OT is closer to what the regulation expects than a split, tool-by-tool view, though no single scanner delivers compliance on its own.