Zero trust

The 2026 MSSP Blueprint: Scaling Zero Trust for IoT and OT Environments 

Guest blog courtesy of Palo Alto

The Reality of Modern Cyber-Physical Risk 

The convergence of Information Technology (IT), Enterprise Internet of Things (IoT), and Industrial Operational Technology (OT) has fundamentally reshaped modern enterprise infrastructure. While connecting factory equipment, building management systems, and smart sensors drives unprecedented operational efficiency, it also bridges once-isolated environments. 

Traditional security models relied heavily on static network perimeters and implicit trust. In those environments, anything inside the perimeter was assumed to be safe. Today, that implicit trust creates structural vulnerabilities across Cyber-Physical Systems (CPS). When an adversary gains access to a corporate network, flat network topologies allow them to pivot directly into critical operational zones. 

Managing this risk requires reframing cybersecurity. Rather than viewing security as an operational bottleneck, forward-looking organizations recognize it as a strategic business enabler. Transitioning to a Zero Trust architecture, built on continuous verification, explicit identity validation, and least-privilege access, supports operational continuity while protecting physical safety. 

Analyzing the Threat Vector: How Attacks Reach Operational Networks 

In connected enterprise environments, threat actors frequently target the human layer as their entry point. Palo Alto Networks Unit 42® incident response telemetry shows that social engineering remains the leading initial access vector, accounting for 36% of investigated incidents. Once inside corporate systems, adversaries exploit over-permissioned accounts and weak internal boundaries to expand their control. 

Crucially, attacks that impact operational technology rarely begin on industrial control devices themselves. Unit 42 research reveals that 70% of security incidents that cause OT operational disruptions originate within corporate IT networks. Attackers exploit flat network connections to move laterally from compromise-prone IT environments into human-machine interfaces (HMIs) and supervisory control systems. 

At the same time, the public attack surface facing industrial organizations has expanded rapidly. Between 2023 and 2024, Unit 42 observed a 332% surge in unique, internet-exposed OT devices and services, with nearly 20 million OT-related assets observable on public internet indexes. 

Once inside operational networks, threat actors often move with deliberate patience. Unit 42 telemetry indicates that 82.8% of adversary activity occurs during extended precursor phases, with attackers maintaining a presence in OT environments for an average dwell time of 185 days before initiating disruptive activity. During this multi-month window, adversaries map network topologies and identify critical assets. However, when active exfiltration or disruption begins, execution accelerates rapidly; in roughly 19% to 20% of fast-moving intrusions, exfiltration occurs within less than an hour of compromise. 

Closing Visibility Blind Spots and Managing Unencrypted Traffic 

Beyond heavy industrial equipment, enterprise facilities rely on thousands of connected IoT endpoints, including environmental sensors, smart badges, and security cameras. While these endpoints provide real-time operational data, they also present unique security challenges. 

Unit 42 research reveals that 98% of all IoT device traffic is unencrypted. Cleartext communication leaves sensitive credentials and operational telemetry vulnerable to network sniffing and payload interception. 

Compounding this challenge is the prevalence of basic security gaps. Unit 42 investigations show that in over 90% of breaches, preventable gaps, such as unmanaged assets, excessive identity permissions, or limited visibility, materially enabled the intrusion. When security teams lack visibility into connected devices, enforcing effective access controls becomes almost impossible. 

Industry analysts at Gartner note that business-led IoT and converged IT-OT initiatives have frequently underestimated safety and security risks. Gartner emphasizes that cyber-physical system security must focus on five essential operational tenets: safety, reliability, resilience, adaptability, and privacy. Establishing complete asset visibility through automated discovery platforms allows organizations to identify unmanaged endpoints, detect protocol anomalies, and monitor behavioral risks without risking operational downtime. 

Architectural Blueprint: Platformization and Zero-Trust Microsegmentation 

Securing converged environments requires moving away from fragmented point tools and adopting an integrated platform architecture. Deploying disparate security products across IT, IoT, and OT environments increases administrative overhead, creates coverage gaps, and delays incident response times. 

Gartner recommends evaluating dedicated CPS security platforms that automatically discover devices, map network topologies, and provide real-time threat detection and response. Furthermore, Gartner defines zero-trust network microsegmentation as the creation of granular, dynamic access boundaries that isolate network zones and restrict lateral movement. 

To align organizational strategy and policy enforcement, Gartner also suggests establishing a Zero-Trust Center of Excellence (ZTCE) to help ensure consistent application across all business units. 

In its market evaluation, Forrester named Palo Alto Networks a Leader in Industrial OT Security. The report highlighted technical innovation supported by more than 50 IoT- and OT-related patents. Forrester also cited the integration of 5G-Native Security within Next-Generation Firewalls, enabling consistent Zero Trust visibility and threat prevention across cellular-connected operational endpoints regardless of location. 

By adopting a platform approach, security teams can enforce least-privilege access and dynamic microsegmentation across every network layer. Rather than granting implicit trust based on physical location, access requests are evaluated dynamically using real-time user identity, device health, and context-aware risk scores. This multi-layered approach helps contain potential IT compromises before they can reach physical equipment, directly supporting operational uptime and physical safety. 

Strategic Summary: Taking the Next Step Toward Resilience 

Scaling Zero Trust across IoT and OT environments is an ongoing operational posture, not a single event. By replacing implicit network trust with continuous verification, organizations can significantly shrink their attack surface and mitigate operational risk. 

To strengthen your cyber-physical security posture, consider these foundational steps: 

  1. Conduct a Comprehensive Inventory: Fully assess all enterprise IoT and industrial OT assets across your infrastructure. 
  1. Implement Explicit Microsegmentation: Establish dynamic segmentation boundaries between corporate IT networks and physical control zones to prevent lateral threat movement. 
  1. Consolidate Security Management: Transition from fragmented point tools toward a unified security platform that provides real-time threat prevention and continuous trust verification. 

Protecting connected cyber-physical systems requires proactive, platform-driven security. Explore how Palo Alto Networks Zero Trust OT Security solutions can contribute to your organization’s security transformation and help safeguard critical operations. 

​ 

Tyler Murphy

Tyler Murphy is the Director of Palo Alto Networks’ MSSP Program.

Related Terms

Asymmetric Warfare

You can skip this ad in 5 seconds