Two months ago, I had a conversation with a CISO at a major UK energy provider that stuck with me. "We've had three OT security roles open since February," he told me. "At this point, I'd settle for someone who knows what a PLC is and has basic networking skills. We can teach the rest."
Whether they actually can, and who does the teaching, is the real question.
After seven years in a bank SOC before moving into recruitment, I've watched plenty of cybersecurity specialisms go through their hype cycle. After seven years in a bank SOC before moving into recruitment, I've watched plenty of cybersecurity specialisms go through their hype cycle. But what's happening with Operational Technology security in the UK right now is something else entirely.
What exactly is OT security?
For the uninitiated, Operational Technology (OT) refers to the hardware and software that monitors and controls physical devices and processes in industrial environments. Think manufacturing plants, power stations, water treatment facilities, transport systems. The systems that keep our critical national infrastructure running.
Historically, these systems were air-gapped from corporate networks, isolated and safe. That changed.
The convergence of IT and OT means that industrial control systems, SCADA networks, and PLCs (Programmable Logic Controllers) are increasingly connected to business networks and even the internet. The security implications are significant.
Almost nobody in the UK is training people specifically for this.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
The disconnect between university courses and market demand
I checked the cybersecurity course offerings at our top ten universities last month. Not one offers a dedicated module on industrial control systems security or OT protection. A few touch on it as part of broader critical infrastructure courses, but it's typically a single week at most.
Meanwhile, every manufacturing client I work with is desperately seeking OT security specialists. The demand skyrocketed after the 2025 attacks on European energy facilities, and the subsequent NCSC advisory warning UK organisations about targeted campaigns against industrial systems.
"We can't just deploy standard security tools in OT environments," an engineering director at a Midlands manufacturing firm told me recently. "You can't patch systems that need 99.999% uptime or run vulnerability scans on fragile legacy equipment from the 1990s."
This requires a completely different mindset. One that most traditional IT security people simply don't have.
The unicorn skill set nobody has
The ideal OT security engineer needs:
- Deep understanding of industrial protocols like Modbus, DNP3, IEC 61850
- Experience with major industrial control systems (Siemens, Rockwell, Honeywell, etc.)
- Knowledge of traditional IT security concepts and tools
- Understanding of engineering principles and physical processes
- Ability to communicate effectively with both IT and engineering teams
Finding one person with all five is nearly impossible.
I recently worked with a major utility company to fill an OT security role. After three months, we had exactly seven qualified applicants. Two were from outside the UK and couldn't get visas. Three were already employed in similar roles and wanted salary increases the client couldn't match. And the remaining two? They got multiple offers within days.
How people are actually getting into OT security
The career paths I've seen work typically fall into two categories:
- IT security professionals who deliberately cross-train in industrial systems
- Automation/control systems engineers who develop security expertise
The first path is more common in the UK, but it's not easy. Unlike traditional IT security - where you can set up a home lab with minimal investment - getting hands-on experience with industrial control systems is difficult and expensive.
Some companies like Siemens and Dragos offer training programmes, but they're typically aimed at organisations rather than individuals looking to break into the field. The SANS ICS security courses are excellent but cost thousands of pounds.
The alternative? Learning on the job. But that assumes you can get the job in the first place.
The salary situation
If you do manage to acquire this rare combination of skills, the financial rewards are substantial. I've placed OT security engineers at salaries ranging from £65,000 for junior roles to well over £120,000 for specialists with 5+ years of experience.
Contract rates have gone through the roof, with day rates commonly between £750-1,200 depending on clearance levels and specific industrial experience.
But is money enough to solve the problem?
What needs to change
The skills gap in OT security won't be solved by market forces alone. We need structural changes:
Academic curriculum development
Universities need to develop dedicated OT security modules within their cyber programmes. The University of Manchester has recently announced plans for an Industrial Cyber Security Centre opening in early 2027 - but that's still too little, too late.
Cross-training programmes
Organisations with both IT and OT environments should create internal pathways for IT security professionals to gain OT experience in a controlled environment.
Government intervention
The NCSC has recognised the problem, but we need more than guidance documents. Direct investment in training programmes, similar to the successful CyberFirst initiative but focused specifically on industrial systems, would make a huge difference.
Vendor responsibility
Industrial system vendors need to step up their game. Security can no longer be an afterthought in OT environments. Companies like Siemens and ABB have improved dramatically, but many smaller vendors are years behind.
How to break into the field
If you're interested in OT security (and looking at those salary figures, why wouldn't you be?), here's my practical advice:
Start with a solid foundation in either traditional IT security or industrial control systems. Don't try to learn both from scratch simultaneously.
Get certified. ISA/IEC 62443 is the gold standard for industrial automation and control systems security. GIAC's GICSP (Global Industrial Cyber Security Professional) is also highly regarded.
The OT security community in the UK is small and tight-knit. Getting to know people already in the field matters more than in broader cybersecurity specialisms.
Look for organisations undergoing IT/OT convergence projects. These often create opportunities for security professionals to get involved in OT environments.
I recently placed a former network security analyst with no direct OT experience into an OT security role. The key? He'd spent six months learning about industrial protocols in his spare time and completed a Siemens SIMATIC certification on his own dime. That demonstration of interest and initiative was enough to get him in the door.
OT security protects systems that control physical processes: systems where failure means danger to human life, not just data loss.
The UK's industrial base deserves better than the current ad-hoc approach to developing talent in this critical area. Until universities and training providers step up, we're going to continue seeing this painful skills gap widen.
For anyone looking for job security and a technically demanding challenge, few specialisms have a brighter future than OT security engineering.
