From Field Instrumentation to Cybersecurity: From ICS Engineering to OT Cybersecurity Leadership
How Can a Process Control Engineer Become an OT Cybersecurity Expert?
I hear this question often. After two decades in the field—from teaching ICS to undergraduates, to leading instrumentation and control systems at asset-owner sites, to supporting live control-system migrations and building industrial cybersecurity capabilities, and now leading InnovAKT's independent advisory—I can confidently say:
The transition from ICS engineer to OT cybersecurity expert isn’t just possible—it’s essential. And it’s a natural progression.
Let me explain.
Engineers Are Built for This Challenge
Engineers, especially those in critical infrastructure, are natural problem solvers. We thrive on complexity and continuous learning.
If you've worked in facilities that have been running since the 1970s—or earlier, long before many of us were born—you've already seen and adapted through major shifts:
- Pneumatic & Relay controls → Analog → Digital → DCS → SCADA → Full automation
- Standalone logic → Integrated networks → Distributed systems
- Manual operations → Full automation for operational excellence
That adaptability and systems thinking? It's exactly what cybersecurity in OT demands.
My Turning Point: From Migration to Motivation
I didn't begin my career in cybersecurity. Like many, my interest was sparked by Stuxnet. But what truly changed everything for me was the Shamoon attack against a major regional energy company.
At the time, I was leading control-system migration work at terminals and refineries in Saudi Arabia, moving live operations from legacy to modern DCS platforms. In parallel, I helped translate evolving cyber threats into actionable engineering guidance for industrial users as cybersecurity emerged as a critical OT concern.
Shamoon made it clear: cyber threats don't just affect IT—they can cripple operations. It was an operational crisis. A wake-up call for every engineer in OT.
The reality wasn’t that these systems were outdated—it’s that they weren’t designed with security in mind. That had to change.
ICS Engineers Already Know the Hard Part
In OT, cybersecurity doesn't begin with firewalls. It begins with understanding how the process works.
If you've ever:
- Migrated a DCS system while production continued
- Solved critical network issues blocking commissioning
- Integrated SIS, PLCs, SCADA, and historians across plants
- Connected wellhead units to centralized SCADA over radios, then integrated with a DCS
…then you already understand what truly needs to be protected, often better than many newcomers to cybersecurity.
The best OT cybersecurity professionals I've met and worked with, whether in my teams or in interactions, didn’t start in IT. They came from engineering, operations, commissioning, and field work. They've lived the process, experienced the risk, and know what's at stake.
My Advice to ICS Engineers Today
If you're working in the ICS sector today, critical infrastructure relies on you in the cybersecurity conversation. Here's how to start your journey:
- Understand OT networking. Study segmentation, industrial protocols, and visibility strategies.
- Get familiar with system security. Learn endpoint hardening, patching limitations, and backup planning.
- Advance to risk modeling. Map attack paths, asset interdependencies, and real-world scenarios.
- Keep your process knowledge central. Your operational expertise is your biggest strength—build on it.
It's much easier for a control engineer to learn cybersecurity than for an IT professional to learn process safety and control logic.
Final Thought: Ask for Help—and Be Specific
The OT cybersecurity community is generous and collaborative in nature. Don't hesitate to ask questions. Just be clear about your background and your goals.
You don't have to reinvent your career—you just have to expand your scope.
OT cybersecurity isn’t about the latest tech—it’s about protecting the systems that keep the world running. And for that, we need engineers like you.
🔗 Want to explore how InnovAKT helps critical infrastructure teams grow OT cybersecurity capabilities from within? Visit InnovAKT on LinkedIn or request a strategy call.