Automation Glossary • IT/OT Event Correlation

What Is Security Event Correlation Across IT and OT

Merobix Engineering • • 7 min read

Security event correlation across IT and OT is the practice of connecting events on the enterprise side with events on the control side to see an attack that spans both. Most real intrusions into industrial systems do not start in OT; they start with something ordinary in IT, like a phishing email, and then work their way toward the control network. If IT security and OT security are monitored in separate silos, each sees only half the story and neither recognizes the whole. Correlating across the boundary reconstructs the attacker's path, from the initial IT compromise to the first suspicious traffic appearing in OT, as a single timeline. This page explains how that cross-domain correlation catches lateral movement that a siloed setup would never assemble.

Back to Blog

IT/OT Event Correlation in one line: Security event correlation across IT and OT links events from the enterprise network with events from the control network so that an attack crossing between them becomes visible as one story. Because intrusions into OT usually begin in IT and then pivot inward, correlating a phishing hit or a compromised workstation with new or unusual traffic appearing in OT reconstructs the lateral-movement timeline. A siloed setup, monitoring IT and OT separately, sees only fragments and misses the boundary crossing that unified correlation reveals.

How Attacks Cross the IT/OT Boundary

An attack on an industrial target rarely begins with the control system. The attacker usually gains a foothold in the enterprise environment first, often through something mundane like a phishing email that compromises a user's workstation, because that is the softer, more exposed surface. From that foothold they explore, escalate privilege, and look for a path deeper into the network, and their goal in an industrial target is frequently to reach the OT environment where the physical process lives. The journey from that first IT compromise to the control network is lateral movement, the attacker pivoting from host to host toward their objective.

The boundary between IT and OT is meant to be a barrier, but it is rarely absolute. There are usually some legitimate connections across it, engineering workstations that touch both worlds, historians that pull data up from control to enterprise, remote-access paths for support, and it is these that an attacker seeks to abuse to cross over. Once across, their early activity in OT is often subtle: a new connection from a host that never talked to the control network before, an engineering tool used from an unexpected place, traffic that simply was not there yesterday.

The security significance of the crossing is enormous, because it is the moment a routine IT breach becomes a potential threat to a physical process. Catching the attacker at or just after that crossing, while they are establishing their first presence in OT and before they can manipulate anything, is far better than discovering them only once a process is disrupted. But catching them there requires seeing the IT origin and the OT arrival as connected, which is exactly what a boundary-spanning view is for and what a siloed one cannot do.

Why Silos Miss the Crossing

When IT and OT are monitored separately, each side sees only its own fragment of the attack. The IT security team sees a phishing hit and a compromised workstation, which is unfortunately common enough that it may be handled as a routine endpoint incident and not flagged as anything unusual. The OT monitoring, meanwhile, sees a new connection or some unfamiliar traffic appearing on the control network, which without context might look like a benign change, a new device, or noise not worth escalating. Each piece, viewed alone, is easy to dismiss.

The connection between them, that the compromised IT host is the source of the new OT traffic, is precisely the information neither silo has. IT does not watch OT traffic and would not notice that its compromised host then reached into the control network, and OT does not watch IT events and would not know that the source of the new connection was a machine that had just been phished. The single most diagnostic fact, the link across the boundary, falls into the gap between the two teams, and the attack proceeds because no one sees it whole.

Cross-domain correlation closes that gap by putting IT and OT events into one analysis. When the phishing hit, the workstation compromise, and the new OT traffic all land in the same correlation engine and can be joined by the shared host, the sequence assembles into a coherent story: this user was phished, their machine was compromised, and that same machine then began talking to the control network. The correlation raises the whole chain as one high-confidence incident, which is the boundary crossing made visible, and it does so precisely because it refused to look at IT and OT as separate problems.

Building a Unified Timeline for a Converged View

Reconstructing the crossing depends on assembling a unified timeline that spans both domains. That means bringing IT events, such as email security alerts and endpoint detections, together with OT events, such as new-connection and behavioral anomalies from passive monitoring, into one time-ordered sequence tied together by shared entities like the affected host and user. Laid out on a single timeline, the phishing, the compromise, the pivot, and the first OT activity read as the stages of one attack rather than as unrelated blips in two separate systems, which is what lets an analyst recognize lateral movement in progress.

This is the practical heart of a converged security operation, one that watches IT and OT together instead of as two disconnected responsibilities. The convergence is not merely organizational; it depends on the data from both sides actually reaching a common place where it can be correlated. The OT-specific monitoring tools, passive sensors, intrusion detection, and DPI, contribute the control-side events, while IT security tools contribute the enterprise-side ones, and correlation across them is what turns two streams into one understanding of an attacker's progression.

For organizations with distributed operations, the converged view has to reach across sites as well as across domains, and this is where a central platform is decisive. A cloud SCADA or security platform such as Merobix that ingests both OT monitoring events from many sites and the relevant IT security events can correlate a phishing incident on the enterprise side with new traffic appearing at a specific remote plant, reconstructing a lateral-movement timeline that no single site and no single team could have assembled alone. Seeing the attacker cross from IT into OT, as one continuous story on one timeline, is the whole reason to correlate across the boundary rather than guarding each side in isolation.

Frequently Asked Questions

Why do OT attacks usually start in IT?

Because the enterprise side is the softer, more exposed surface. Control networks are relatively isolated and hard to reach directly, while the IT environment is full of email, web access, and user workstations that an attacker can compromise with something as ordinary as a phishing message. From that foothold the attacker escalates and moves laterally toward the control network, abusing the legitimate connections that cross the IT/OT boundary, so the journey typically runs from an initial IT compromise inward to OT rather than starting in OT directly.

What does a siloed monitoring setup miss that correlation catches?

It misses the connection across the boundary. A siloed IT team sees a phishing hit and a compromised workstation and may treat it as routine, while a siloed OT team sees new or unfamiliar traffic and may dismiss it as a benign change, and neither knows that the compromised IT host is the source of the new OT traffic. Cross-domain correlation joins those events by the shared host and assembles them into one story of an attacker pivoting from IT into OT, which neither silo could see on its own.

What is needed to correlate events across IT and OT?

The events from both domains have to reach a common analysis point where they can be joined by shared entities like a host or user and laid out on one timeline. That means feeding IT security events, such as email and endpoint alerts, together with OT events, such as new-connection and behavioral anomalies from passive monitoring, into the same correlation engine. For distributed operations it also means a central platform that gathers both across many sites, so an IT incident can be linked to new traffic at a specific plant.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
OT Honeypot (Conpot)  •  OT Deception Grid  •  OT Alert Triage  •  SOAR Playbook  •  OT Threat Hunting  •  MITRE ATT&CK for ICS  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →