The Accountability Gap Nobody Wants to Talk About

Ask a mid-sized industrial company in Germany a simple question: “If one of your industrial control systems gets breached today, who’s responsible?”

The usual answer is a long pause. Then a name from IT. Then a different name from engineering or production. Then silence.

That silence is exactly what NIS2 is designed to end.

What NIS2 Is, and Why It Matters Right Now

The EU’s NIS2 Directive is no longer a theoretical discussion. Germany has transposed it into national law through the BSIG (Federal Office for Information Security Act), and the circle of companies now in scope has expanded dramatically. This time it’s not just banks and utility providers — manufacturers, supply chain companies, and a large number of mid-sized businesses that assumed “this doesn’t apply to us” are now squarely inside the perimeter.

Here’s the part that often gets missed: NIS2 doesn’t just target office networks (IT). Industrial control systems, production equipment, and operational infrastructure (OT) fall under the same obligations. And that’s exactly where the real problem starts.

Why IT and OT Don’t Talk to Each Other

In most industrial companies, two parallel worlds exist.

The IT team has spent years dealing with firewalls, security patches, and access management. Its language is cyber risk.

The OT team has spent years dealing with PLC operators, SCADA systems, and a production line that can’t afford a single second of downtime. Its language is operational safety and availability.

These two teams often sit under the same roof but report differently, prioritize differently, and — worse — carry separate budgets and separate accountability. The result is a gray zone that nobody formally owns. I call this the accountability gap, and in my consulting experience, it’s the most common root cause of serious vulnerabilities in industrial environments — not a technical weakness, but organizational ambiguity.

Why This Isn’t Just a Technical Problem

A lot of companies assume the fix is buying a new security tool for the OT network. But an expensive industrial firewall is just a sunk cost if nobody is clearly responsible for configuring, monitoring, and updating it.

The real fix is governance, not just technology:

Define roles explicitly. Who, at the management level, ultimately owns OT risk? This can’t be left to sit “between two chairs.”

Build a shared language. Translate risk in a way both IT and engineering actually understand — not raw technical jargon, but real impact on production and safety.

Use complementary standards, not just one. ISO/IEC 27001 gives you the general information security management framework, but industrial environments need something more specific — a standard like ISA/IEC 62443, which is built directly around OT realities such as the need for continuous system availability.

Run risk assessments jointly, not separately. When IT and OT hold their risk assessment meetings separately, the gap never closes — it just gets documented on two different spreadsheets.

A Realistic Starting Point

If your company still doesn’t have a clear map of where IT responsibility ends and OT responsibility begins, the first step doesn’t have to be complicated: a short gap assessment against NIS2/BSIG requirements and ISA/IEC 62443. This kind of assessment usually takes a few weeks and pinpoints exactly where the organization is most exposed — and more often than not, that weak point isn’t a server or a switch. It’s a decision that was never made.

Bottom Line: Ask Before the Regulator Does

NIS2 will eventually reach your company — either through a direct audit, or through pressure from customers who need assurance about a secure supply chain. Go back to the question at the start of this article and ask it again: if it happened today, do you actually know who’s responsible?

If the answer isn’t clear, it’s time to find that gap yourself — before an auditor or an attacker finds it for you.

DSG Solutions works with industrial and mid-sized German companies on information security and OT security governance — from gap assessments against NIS2/BSIG and ISA/IEC 62443, to designing the shared roles and governance processes that actually bridge IT and OT.

To talk through where your company stands on NIS2, get in touch via the DSG Solutions.

Share:

Add Your Comment

Your email address will not be published. Required fields are marked *

Subscribe to Our Newsletter for the daily Updates