Security leaders warned that extending IT-centric cybersecurity frameworks into operational technology (OT) and laboratory environments without adaptation can create hidden risk, because core IT assumptions (disposability, reversibility, and recoverability) often do not hold. Rich Kellen (CISO, IFF) emphasized that in labs “the system is the experiment,” where restoring from backups may not restore scientific validity; factors like calibration drift, temperature curves, and timing windows can invalidate results even if systems are brought back online, making “available but wrong” potentially more damaging than downtime.
In healthcare environments, Mohamed Waqas (CTO, Armis) described similar risk drivers arising from unclear ownership and accountability across IT, facilities/OT teams, and healthcare technology management for network-connected medical and facilities devices. He noted that devices are frequently deployed outside cybersecurity visibility, with an expectation that IT/security or vendors will respond only after incidents, while security teams may identify vulnerabilities without being positioned to remediate them—leaving asset owners responsible for fixes they may not be equipped to execute. Both accounts frame the issue as a safety and integrity problem (patient care and scientific outcomes), not just a compliance or “cyber exercise,” and stress governance and cross-functional collaboration to reduce operational risk.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
In a published interview, Armis CTO Mohamed Waqas said unclear ownership of medical device and OT security in healthcare organizations can leave vulnerabilities unremediated and create patient safety risks. He called for stronger governance, collaboration between cybersecurity and health technology teams, and framing cyber issues in terms of patient care, safety, and privacy to gain executive action.
In a published interview, IFF VP and CISO Rich Kellen said treating laboratory and OT environments like data centers creates hidden risk, including scientific integrity, safety, and regulatory consequences that traditional IT recovery models do not address. He described the need for OT-appropriate visibility, carefully managed compensating controls, and collaboration with scientists as stakeholders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.