TL;DR: OT telemetry is increasingly a security priority because it captures the continuous signals that protect physical operations, yet legacy SIEMs were built for discrete logs and often cannot ingest this data at scale, according to DataBahn. The result is an architectural blind spot where enrichment, routing, and retention decisions increasingly determine whether teams detect interference before it becomes operational impact.
NHIMG editorial — based on content published by DataBahn: Why are Legacy SIEMs a problem?
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
Questions worth separating out
Q: What breaks when OT telemetry is treated like ordinary SIEM data?
A: The main failure is economic and operational.
Q: Why do OT environments need enrichment before ingestion?
A: Because context determines whether a signal deserves expensive retention or can be routed elsewhere.
Q: What do teams get wrong about OT telemetry visibility?
A: They assume more collection automatically means better security.
Practitioner guidance
- Define OT telemetry retention by security value Classify OT sources into high-value, medium-value, and operational-only streams before ingestion so the SIEM is reserved for data that can drive detection or investigation.
- Move enrichment into the collection pipeline Attach asset ownership, geolocation, threat intelligence, and identity context while telemetry is in motion so downstream routing can suppress low-value noise without losing forensic detail.
- Govern service accounts and routing identities Treat collectors, forwarders, and pipeline automation as identities with scoped access, rotation, and audit trails because they can expose or misroute the operational data they move.
What's in the full article
DataBahn's full article covers the operational detail this post intentionally leaves for the source:
- How the pipeline architecture handles high-volume OT collection at the edge without overwhelming central tools
- How enrichment and filtering are applied before SIEM ingestion to preserve context while reducing cost
- How AI-assisted parser generation supports new telemetry sources without manual re-engineering
- How policy-driven routing separates security-relevant data from operational telemetry for different consumers
👉 Read DataBahn's analysis of OT telemetry enrichment and SIEM blind spots →
OT telemetry enrichment: what it means for SOC and resilience teams?
Explore further
OT telemetry has become a governance problem, not just an observability problem. The issue is no longer simply that security teams lack data. The deeper problem is that the pipeline itself decides whether operational signals become security evidence, and that decision now shapes detection, retention, and response. For practitioners, this makes telemetry architecture part of control design, not an IT plumbing detail.
A question worth separating out:
Q: Who should be accountable when telemetry access exposes sensitive data?
A: Accountability should sit with the data and security owners who define classification, retention, masking, and access policy. If telemetry contains personal data, secrets, or regulated records, those controls need explicit ownership, not informal engineering discretion.
👉 Read our full editorial: OT telemetry enrichment is becoming a security control, not a cost line