The cyber-physical safety gap: Where cybersecurity can determine worker safety

In a connected workplace, a cyber event can turn a digital threat into a safety risk

Abiola Ayodele

The workplace has a digital nervous system 

The modern workplace may look physical, but much of what happens inside it is increasingly digital. Networks connect computers to operational technology (OT), while sensors collect information about equipment and environmental conditions. Programmable logic controllers (PLCs) translate digital instructions into physical actions, while human-machine interfaces (HMIs) allow operators to monitor and control processes. Access-control systems determine who enters a facility, building systems regulate ventilation and temperature, and connected devices continuously exchange information in the background.

These connections are designed to make workplaces more efficient, responsive, and safer. They can also create dependencies that are easy to overlook. A machine may depend on a network to receive instructions. An operator may depend on a digital display to understand what is happening inside a process. A safety system may depend on a sensor to detect a change in conditions. The technology may be invisible to the worker, but its influence on the work environment is not.

NIST describes OT as systems that monitor or directly control physical processes, including industrial control systems, building automation, transportation systems, physical access controls, and environmental monitoring systems. As these technologies become increasingly connected to enterprise networks and other digital systems, the traditional boundary between information technology and the physical workplace becomes less distinct.

That matters because connectivity creates dependency. The more a workplace relies on digital systems to operate, monitor conditions, and control physical processes, the more important it becomes to understand what happens when those systems are unavailable, compromised, or manipulated. For EHS professionals, this means the hazard assessment can no longer stop at what workers can see. Some of the systems influencing their exposure may exist behind a screen, inside a network, or within software that EHS may never directly interact with.

And that is where the relationship between cybersecurity and safety begins to take shape.

Cyber threat becomes a workplace hazard

The cyber-physical connection becomes clearer when you trace the threat to its potential safety consequences. A stolen credential may seem like an IT security problem. Still, if that credential provides access to an operational technology network, an attacker may gain a pathway to systems controlling physical processes. A ransomware attack that takes a monitoring system offline can leave workers without critical information. A manipulated temperature or pressure sensor can give operators a false picture of conditions. A disabled alarm can remove a warning that workers depend on to recognize danger. These are not simply technology failures. They can become hazard pathways.

The same principle applies across different workplaces. In manufacturing, interference with industrial controls could affect machine operation and create unexpected movement or hazardous energy exposure. In a water-treatment facility, disruption of control or monitoring systems could affect chemical processes and worker exposure. In a hospital, a cyberattack that disrupts connected buildings or medical systems can interfere with critical operations. In a smart building, compromised environmental controls could affect ventilation, temperature, or access to areas with hazards.

NIST's recent work on manufacturing cybersecurity recognizes this connection directly. Increasingly interconnected OT systems can expose factory operations, safety, and property to cyber threats.

The important point for EHS professionals is not to predict every possible cyberattack. It is to recognize which digital systems sit between a worker and a hazard. Once that connection is visible, cybersecurity becomes part of the safety conversation. The question shifts from “Can someone breach this system?” to “If this system is breached, what could happen to the people who depend on it?”

When IT risk becomes EHS risk

Cybersecurity risk should not enter the EHS conversation only after something fails. The stronger approach is to identify the connections before an incident occurs. That starts with mapping the systems that support critical safety controls. EHS can work with IT, Operations, Facilities, and Security to identify which digital systems influence worker protection and what could happen if each system becomes unavailable or unreliable.

Consider a facility with connected ventilation, gas detection, emergency notification, access control, and process-monitoring systems. IT may understand how those systems connect to a network. Operations may understand how they support production. EHS understands the hazards those systems help control. 

The risk appears when those pieces are considered separately.

If a network disruption takes environmental monitoring offline, for example, the issue is no longer simply system availability. Workers may be operating without information needed to recognize an unsafe condition. If a compromised control system changes how equipment operates, the concern is not merely unauthorized access. It may involve unexpected movement, hazardous energy, or exposure.

This is why EHS professionals can contribute an important perspective without becoming cybersecurity specialists.

They can ask:

  • Which safety controls depend on network connectivity?
  • Which sensors or digital displays do workers rely on to recognize hazards?
  • What happens if a critical system loses connectivity, availability, or integrity?
  • Is there a manual or independent backup?
  • How would workers know that a safety-critical system could no longer be trusted?
  • Has that failure scenario been included in emergency planning or drills?

These questions bring cybersecurity into familiar EHS territory: hazard identification, control effectiveness, emergency preparedness, and resilience.

Cybersecurity needs a safety lens

No organization can assume that cybersecurity controls will prevent every incident. NIST's guidance for manufacturing emphasizes the need not only to defend OT environments but also to prepare for response, recovery, and restoration when cyber incidents affect operations.

That principle matters for EHS because restoring a system is not the same as restoring safe conditions.

A system may come back online while a sensor remains unreliable. A control system may be restored before equipment has been verified to be operating as intended. Workers may return to an area before monitoring systems are fully functional. A cybersecurity team may declare a technical recovery while Operations and EHS still have unanswered questions about physical risk.

Recovery, therefore, needs a safety checkpoint.

Before a compromised system returns to service, organizations should consider whether the associated safety functions have been verified, whether affected equipment has been inspected, whether temporary controls are still necessary, and whether workers understand any changes to normal operating conditions.

This is not about adding another layer of bureaucracy. It is about recognizing that technical recovery and safe recovery are not always the same thing.

The future of workplace safety will increasingly depend on how well organizations understand this distinction.

Cybersecurity protects systems. Operations protect continuity. EHS protects people. In the cyber-physical workplace, those responsibilities can no longer be viewed as completely separate.

The question is no longer simply whether an organization can keep hackers out.

Can it keep workers safe when something gets through?

That is where cybersecurity becomes more than an IT concern. It becomes part of the safety system itself.