Cyber-Physical Convergence is Happening, But Not Fast Enough


A good starting point is for risk teams to have conversations about what threats they are focused on – taking time to understand each other’s monitoring requirements and identify those that are sacrosanct to all. Groups operating in silos often face overlapping risks. Cybersecurity teams, for example, are acutely aware of insider threats and what those pose to IT assets, data security, and intellectual property. But the same risk factors digital protectors seek are also on the radar of physical security and human resources teams.

By having inclusive discussions across departments, you should be able to develop a risk picture from a strategic, all-hazards perspective and start to drive a common operating language.

Look at the tools and data available within the enterprise. How can you map those to the organization’s risks? What data points collected by legal and compliance teams might be valuable in cybersecurity and physical security teams? Doing this will drive the concept of common operating information across groups that face and manage threats in the company’s structure.

If your organization can log that data, like those indicators of risk, into a single platform, it can be tracked when needed, and analysis will be accelerated across the organization, leading to fewer missed threats.

A common sentiment amongst risk professionals is that employees and institutions would be safer if their groups carried closer working relationships with other departments. Recent data suggests that this belief is widespread across organizations, not just those in physical security. 

Executives in cybersecurity, IT, human resources, physical security, and legal and compliance departments were surveyed as part of Ontic’s 2022 Mid-Year State of Protective Intelligence Report, with a majority suggesting that many threats that disrupted company continuity could have been avoided if teams were able to work in tandem, seeing and managing threats in a shared environment. This data echoes a report produced by the United States Cyber & Infrastructure Security Agency United States Cyber & Infrastructure Security Agency  (CISA), stating,

“When physical security and cybersecurity divisions operate in silos, they lack a holistic view of security threats targeting their enterprise.”  

CISA’s findings indicate that lack of joint security operations is more likely to result in “successful attacks” leading to “impacts such as compromise of sensitive or proprietary information, economic damage, disruption of National Critical Functions (NCFs), or loss of life.” However, Ontic’s data uncovered positive signs of cooperation and convergence as a majority (89%) of cybersecurity and IT executives agree their company is actively consolidating their multiple threat intelligence, data analysis, and reporting solutions.