Every industry believes its security challenges are unique. After implementing security across banking, government, insurance, and manufacturing, Ayo Akinsanya, CISSP, CC, believes they are partly right. However, while the threats and constraints differ, the methodology that works is more consistent than most practitioners realize.

Adapting Security Across Industries: A Practitioner's Perspective - Ayo Akinsanya, CISSP, CCDisclaimer: The views and opinions expressed in this article belong solely to the author and do not necessarily reflect those of ISC2.

Is the lesson here that security and system optimization are not competing priorities?

Earlier in my career, I led a security integration initiative that exposed a pattern I would encounter repeatedly across industries. In what was a highly regulated financial environment. the immediate challenge was access management. Permissions had accumulated over years, creating internal vulnerabilities that organizational inertia had prevented from being resolved. Addressing it required documentation of how the organization actually operated, mapping real access patterns against actual job functions and the redesign of controls around operational reality.

Results of this initiative confirmed the integrated approach: cybersecurity incidents dropped measurably within the first year, provisioning time shortened and onboarding bottlenecks – which had slowed the business for years – disappeared as a byproduct of the security work. The security improvement didn’t cost the organization operational performance. It returned it.

That early experience taught me a foundational principle that has carried me through every sector that followed: security frameworks fail when they are designed in isolation from the operational environment they’re meant to protect. When they are designed with that environment, they tend to improve it. The environments change, but the principle does not.

Working across public sector and insurance platforms reinforced this to me still further. Each environment forced the same adaptation: assessing assets by criticality, implement controls proportionate to operational risk, automate monitoring where limited personnel cannot provide manual coverage and never sacrifice operational continuity for security theater. In each case, technical debt was the common enemy. Consolidating redundant workflows reduced both attack surface and processing delays simultaneously.

What Operational Technology Taught Me That Other Sectors Couldn’t

By the time I transitioned to manufacturing, I had implemented security across four critical infrastructure environments. I assumed the new setting would be similar to those I had seen before. It was not.

The systems I was responsible for securing had never been designed with security in mind. Legacy operational technology operated on protocols decades old, now directly exposed to enterprise systems through the integrations that modern production management requires. The constraints were categorically different:

  • A production line cannot be taken offline for a security patch
  • Many OT systems run firmware that cannot be updated without halting production
  • A cyberattack on an OT system produces physical consequences: damaged equipment, halted production, endangered workers

Compensating controls replaced direct system hardening where legacy equipment couldn’t be modified. Network segmentation isolated vulnerable operational systems without requiring their replacement. Continuous monitoring detected anomalies that patching alone could not address. Zero trust principles transferred directly from financial services. Specific access control architectures did not.

The integration of security with system optimization produced results that were beyond security objectives. Standardizing data flows and eliminating redundant process steps reduced turnaround time on production orders. Security stopped being a cost center and instead became a contributor to operational performance.

This experience reflects a broader challenge across the manufacturing sector. The organizations most at risk are small and mid-sized manufacturers without dedicated security resources, facing enterprise-scale OT security challenges with a fraction of the budget available to large organizations. The sector most frequently targeted by cyberattacks is also the sector least equipped to defend itself.

What Cross-Sector Experience Has Actually Produced

Cross-sector experience has become my personal differentiator. I’m able to translate what worked in high-compliance financial environments into resource-constrained manufacturing settings, by:

  • Starting with constraints rather than controls
  • Separating what transfers from what must be rebuilt entirely
  • Quantifying security outcomes in the operational language the business already uses

Security stops being a cost center the moment its contribution to operational performance is visible to the people who fund it. Across every sector I’ve worked in, the security implementations that received sustained leadership support were the ones connected to measurable operational outcomes from the first review cycle.

If you are a cross-sector practitioner, know that you bring something a sector specialist cannot: the knowledge that the constraint in front of you has been solved before, in a different context, with a translatable methodology. The OT security gap is real, it is documented, and it is growing. The organizations most exposed are not large enterprises with dedicated security budgets. They are mid-sized manufacturers, utilities and infrastructure operators running legacy systems that were never designed to be defended. If you have built security programs elsewhere, that is exactly the gap your experience was preparing you to fill.

Ayokunle (Ayo) Akinsanya, CISSP, CC, has over 16 years of experience across financial services, healthcare technology, government, insurance and manufacturing. He has held technical, business analysis and project management roles, with direct responsibility for cybersecurity frameworks, ERP implementations and enterprise digital transformation. His cybersecurity work spans threat and risk assessments, data loss prevention, identity and access management, and compliance management across critical infrastructure environments.

Related Insights