Ολοκληρωμένη προσέγγιση ασφάλειας για την αρχιτεκτονική βιομηχανικών συστημάτων OT/IT
Integrated security approach for the architecture of industrial OT/IT systems

View/ Open
Abstract
The rapid convergence of Information Technology (IT) and Operational Technology (OT) has fundamentally reshaped the landscape of industrial production, introducing specialized security requirements and new risks for critical infrastructures. This thesis examines a comprehensive approach to the security of IT/OT architectures, analysing both the technological and organisational dimensions required for the effective protection of modern industrial systems. Particular emphasis is placed on international standards and best practices, such as ISO/IEC 27001 and ISO/IEC 27019 for information and energy systems, the NIST SP 800-82 framework for Industrial Control Systems (ICS), and the IEC 62443 series, which constitutes a key reference for OT cybersecurity.
Furthermore, the thesis explores critical concepts such as the Purdue model layering, defence-in-depth architectures, network segmentation mechanisms, and the importance of UAT/QA environments for the safe testing and validation of PLC, HMI and SCADA systems. Through a systematic literature review and evaluation of existing frameworks, the study highlights the challenges and opportunities arising from IT/OT convergence and proposes directions for holistic cyber risk management in industrial environments. The conclusions underscore the need for unified security policies, organisational maturity and technical mechanisms that address both information security requirements and operational safety.

