Organisations increasingly depend on interconnected IT, OT and AI environments. Yet responsibility, risk information and security controls are often spread across different teams and tools. According to Stef de Graaf of Yellowtail Conclusion and Key Control Dashboard, this fragmentation is one of cybersecurity’s greatest blind spots.
A while ago, I was discussing information security with a government client when someone asked a deceptively simple question: “What actually counts as an asset? A bridge, a tunnel, a truck, ChatGPT, our people?”
The answer was straightforward: all of them. The harder question came next: “Who actually has a complete overview of everything we need to protect?”
Nobody answered. That silence captured one of the biggest cybersecurity challenges organisations face today.
The biggest risk today is fragmentation
When people talk about assets, they often think about IT: servers, laptops, applications and cloud environments. Most organisations have invested heavily in managing these assets.
However, the range of assets organisations need to protect is now much broader. Critical infrastructure increasingly depends on operational technology. Bridges, locks, pumping stations, traffic systems, production lines and vehicles all contain software that has become just as important as the physical hardware.
AI is also emerging as a new type of asset. It influences decisions, processes information and is increasingly becoming part of core business operations.
The problem is that these different assets are usually managed by separate teams, using different processes and tools. IT owns IT, operations owns OT and innovation owns AI. Everyone owns part of the puzzle, but very few organisations own the complete picture.
“Attackers only need one blind spot.”
Recent incidents continue to show the same pattern: ransomware moving from office environments into operational systems, attackers quietly positioning themselves inside critical infrastructure or organisations being brought to a standstill because a seemingly small weakness went unnoticed.
These may be different incidents, but the underlying issue is often the same: organisations do not fully know what they are protecting.
Regulation is forcing organisations to connect the dots
At the same time, the regulatory landscape is changing rapidly. NIS2, DORA, the AI Act and updated national frameworks all share a similar expectation.
Organisations must demonstrate that they understand their digital environment, know who owns what, manage risks consistently and can explain how their critical assets are protected.
This becomes difficult when IT, OT and AI are treated as separate worlds.
Almost every organisation now identifies AI as its newest challenge. However, many have not yet fully solved the existing challenge of creating a complete overview of assets, ownership and risks.
Prevention starts with knowing what you own
Before adding another security control, framework or tool, organisations should first make sure they understand what they are trying to protect.
The organisations making the greatest progress do not necessarily invest in the most technology. Instead, they create one governance view across IT, OT and AI, assign clear ownership and connect risks, controls and compliance rather than managing them separately.
Only then can prevention, detection and response begin to reinforce one another. Continuous monitoring becomes more meaningful because everyone works from the same picture. Incidents also become easier to manage because responsibilities have already been established before something goes wrong.
Trying to achieve this across hundreds of assets using spreadsheets may work temporarily. Eventually, however, that approach becomes difficult to maintain.
Why Cybersec Netherlands matters
Almost every meaningful improvement starts with a conversation. Not necessarily a conversation about technology, but about ownership.
Cybersec Netherlands brings together IT, OT, security, risk and AI specialists. Although they approach cybersecurity from different perspectives, they often face many of the same challenges.
Sharing practical experiences can help organisations make progress faster than another whitepaper or vendor presentation.
Stef de Graaf therefore leaves organisations with one important question:
“Do you really know everything you’re protecting?”
If the answer is “not completely”, you are certainly not alone. Creating one view across IT, OT and AI, with ownership, risks and compliance brought together in one place, is exactly what Yellowtail and Key Control Dashboard work on every day.
Meet Stef de Graaf and the team at stand 11.D068 during Cybersec Netherlands 2026.
About the author
Stef de Graaf
Head of Consultancy & AI Program Manager