Yet better cybersecurity does not necessarily mean organisations understand every part of their operational environment.
Only 14% of respondents to Fortinet’s 2026 State of Operational Technology and Cybersecurity Report said they had full visibility of their operational technology (OT) environments. Almost a quarter could see only about half of their systems.
That does not necessarily mean organisations are unaware of the equipment they operate. They may know they have particular pumps, control systems, substations or other critical assets and understand their role in delivering a service.
The greater challenge is knowing what is happening across the operational network. Organisations need to understand how devices communicate, where operational systems connect with corporate IT networks and which systems depend on one another.
Many components in operational environments are pre-digital. They were designed to work in isolation and were never built with modern cyber threats in mind.
Over time, they have been connected to business networks, cloud services, remote monitoring systems and third-party suppliers. Retrofitting protection can be difficult and expensive, especially when essential services cannot simply be shut down while systems are upgraded.
Those connections are important. They can improve efficiency and make infrastructure easier to manage. They can also create new pathways for disruption.
Alcock says organisations can have a good understanding of their major assets while still lacking visibility into activity within the operational environment. “If you connect the traditionally isolated operational technology environment, which once had an air gap, you often don’t know what’s happening within these environments. A motivated threat actor can get inside and remain unnoticed for a considerable amount of time”.
That’s concerning, but operational technology security and resilience problems are not limited to deliberate cyber-attacks.
Indeed, keeping attackers out is only part of the challenge. As infrastructure becomes more connected, failures, technical errors and unexpected interactions can also spread beyond the systems where they begin. An organisation may have strong security controls but still struggle to respond if it does not understand how its operational systems fit together.
That is one of the key differences between conventional IT security and operational technology security.
Alcock says: “In IT, it’s about securing the data and securing the environment. That’s just stuff that supports the business.”
If those systems fail, the consequences can be serious. An organisation may still be able to function without email or other business applications for a period.
“With operational technology, the operational technology side of things is the business,” he explains. “If that goes down and you can’t make the widget or treat the water, then everything kind of goes haywire.”
For organisations operating critical infrastructure, that means the goal is not just about keeping attackers out. They also need to detect problems early, limit the damage and maintain essential services when an incident occurs.
Alcock describes this as a shift from designing purely for prevention to designing for resilience.
“It’s a question of how do we detect threats early, contain the damage fast and then recover without hopefully anyone noticing,” he says. “It’s about taking a hit and continuing to run, as opposed to take a hit and fall over.”
Alcock says New Zealand’s overall preparedness is mixed: “I think it’s a double-edged sword.”
Because New Zealand is small, critical infrastructure operators may not have the resources available to larger organisations overseas. At the same time, being small means the country can also be more agile, with a close-knit industry able to share information and respond quickly to new risks.
“There is a really good community when it comes to this sort of thing. They share a lot”.
Informal collaboration is one of New Zealand’s strengths. The country’s small cybersecurity sector means many specialists know one another and can share experience across industries.
Alcock helps bring those people together through Fortinet’s OT Security Exchange Forum, where operators and security specialists discuss emerging risks and lessons from other sectors.
Yet New Zealand’s size can also create vulnerabilities.
Some regional infrastructure operators have limited funding and only a small number of people with specialist knowledge. In some cases, critical operational knowledge may rest with one experienced employee.
Alcock says water infrastructure and systems operated by regional councils are particular concerns, not because organisations are ignoring the risks, but because they may have fewer resources available to address them.
“The biggest gap that I see right now is just the fact that we don’t have any actual requirement to do any of this stuff.”
Australia has introduced strong cybersecurity obligations for critical infrastructure operators. Alcock says Australia’s regulations have helped drive greater maturity because organisations must meet defined requirements rather than relying solely on voluntary action.
New Zealand does not have the same level of cyber regulation for critical infrastructure. That means organisations are left to improve their defences because they recognise the operational and business risks, rather than because they face a legal requirement.
Alcock says many are already adopting recognised practices and looking to Australian requirements for guidance. The challenge will be to develop an approach suited to New Zealand’s smaller scale, rather than simply copying overseas rules.
He says regulation could provide clearer direction and help ensure cybersecurity is treated more consistently across the sector. But it would need to recognise the different resources and capabilities of large national operators and smaller regional organisations.
“Whether or not we can scale it down properly to our sort of environment is another thing,” he says.
For Alcock, the most difficult risks are often the ones organisations have not yet identified.
“What we do know, we can identify as a risk and we can mitigate it. But it’s the stuff that we don’t know yet.”
New Zealand’s critical infrastructure sector is becoming more aware of cyber risk and better prepared to respond. But resilience depends on understanding not only the systems operators know about, but also the connections, dependencies and vulnerabilities that remain hidden.
Fortinet is a sponsor of the Herald’s Infrastructure report.