Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Tech Convergence is Minimizing IT Security Risk By Creating More Synergies Within Companies

Can a proper convergence strategy mitigate IT security risk? It is something all business stakeholders need to consider. In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes? As technological advancements evolve, the spectrum of security threats…

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By Carlos Rivera · Carlos RiveraCybersecurityInfo-tech Research GroupIt Security
Share

Key takeaways

01

Can a proper convergence strategy mitigate IT security risk?

02

It is something all business stakeholders need to consider.

03

In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes?

Get featured

Want to get featured in MarketScale Software & Technology?

Create a free MarketScale workspace and get your company's expertise featured across our Software & Technology coverage. No credit card, no demo required.

Start free

Can a proper convergence strategy mitigate IT security risk? It is something all business stakeholders need to consider.

In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes?

As technological advancements evolve, the spectrum of security threats extends beyond the digital sphere, encroaching on physical infrastructures and core organizational operations. Info-Tech Research Group emphasizes the necessity of a unified security architecture, merging physical security, cybersecurity, and other administrative realms like HR, legal, and compliance. Its most recent research and analysis, its “Integrate Physical Security and Information Security” blueprint, offers a structured three-phase approach to reduce IT security risk: Plan, Enhance, Monitor, and optimize to navigate this convergence. Though intricate due to proprietary and diverse technological landscapes, this integration heralds a robust defense against modern threats, embodying a modular, incremental, and repeatable process.

What initial steps should firms undertake to ensure a seamless transition towards this integrated security model? The path towards converging these diverse security networks presents challenges; how should firms adeptly navigate these to bolster their security posture?

Carlos Rivera, a Principal Research Advisor of Security and Privacy Practice at Info-Tech Research Group, provides insights into Info-Tech’s published research, expanding on the nuances of harmonizing digital and physical security infrastructures for an enhanced organizational defense mechanism.

Carlos’ Thoughts

“Our methodology basically goes into three primary steps, and it’s, you know, basically you plan, you make an assessment based on the output. You know, you should focus really on the outcomes more than a lot of people that focus on capabilities, but outcomes really are what you want to focus on. But after you plan and you do the assessment, it’s enhancing what you currently have, right? So, that is a kind of standard methodology. I know this sounds kind of boilerplate, but really, it’s taking a good look at what you have based on, you know, our methodology or a good control set, right? Using different models like Purdue, et cetera, to really gauge where you’re at and where you want to be at the end of the journey, right? So, you know, security is a never-ending journey, but this is a really good way to make an assessment and figure out what areas to focus on.”

How can firms ensure the highest levels of success and safety while converging their technology platforms?

“It’s all driven by risk, right? And definitely, in OT settings, you know, one variable that most organizations don’t have to worry about is safety, safety concerns. Another risk that I would say is with OT or IoT, as it were, things that could, you know, impact somebody’s life. They can have like medical devices, et cetera. This is really the value of the convergence, right? If you have a mindset of, I’m going to publish policies; I have a governance framework for my organization that really is extended to your OT infrastructure, right? And you’re holistically looking at a program from an organizational top-down perspective.

That’s really the value of convergence. It’s not really flattening, as some would think, the infrastructure and creating risk. It’s minimizing risk by building on the synergies that you probably already envision with your IT security program.”

What key challenges do you see from firms trying to do this, and how can they navigate them?

“One of the most common ones, to be honest with you, it’s probably a no-brainer, but it’s really just bringing all the key stakeholders to the table to have a conversation, right, about what the objectives are. That’s before you do any kind of technical evaluation. Come up with a charter about what the convergence is about. We have pretty good documentation methodology on getting you started and having the right conversation. We also have a list of stakeholders that we recommend having as part of that conversation, but then have a methodical phased approach on what you feel are the biggest risks and how you feel like you’re going to solve those risks.

Our methodology encourages you to use business language. That’s the best way to talk to stakeholders. You’re not going to drive this change from the bottom up. You’re going to drive it from the top down. And we recommend using something like COBIT and align your strategic goals for that convergence with business language like COBIT to make it really easy to understand what your mission is.”

Article by James Kent

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

Carlos Rivera
Carlos RiveraPrincipal Research Advisor, Security & Privacy

Carlos Rivera is a Principal Research Advisor in the Security & Privacy practice. Carlos has 25 years of experience in IT and cybersecurity, primarily within the fintech industry. Prior to joining Info-Tech Research Group, Carlos spent 21 years as an information security officer for multi-billion-dollar business units dedicated to money movement in the P2P, B2C, and B2B space. Most recently, throughout his 21-year career with this Fortune 500 fintech, Carlos led global teams of security and network engineers, enterprise architects, risk managers and analysts that provided cybersecurity services to many global financial industry clients, and was responsible for information security governance, cyber risk management, vulnerability management, application security methodology and adoption focusing on shift-left fundamentals such as Static Analysis Security Testing (SAST), Dynamic Analysis Security Testing (DAST), Open Source Security Testing (OSST), and Manual Application Security Testing (MAST).

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Software & Technology Insights

Nvidia Says It Will Double Chip Sales Next Year. The Supply Chain Is Where That Gets Decided.

Nvidia Says It Will Double Chip Sales Next Year. The Supply Chain Is Where That Gets Decided.

Nvidia CEO Jensen Huang forecasted doubling chip sales next year, but the company's CFO frames this as the supply-unconstrained scenario, signaling that supply chain capacity, not demand, is the real constraint. Nvidia and Palantir launched a collaboration to apply AI to Nvidia's own supply chain operations to identify bottlenecks and allocate materials more effectively.

  • 01Nvidia's doubling forecast depends on supply chain throughput, not demand—the company itself is supply constrained according to CFO Colette Kress.
  • 02Nvidia and Palantir said their first sovereign AI deployment for Nvidia’s operations is designed to spot supply constraints earlier and improve how materials are allocated across production.
  • 03Enterprise buyers should plan for competitive allocation pressure, higher networking and infrastructure costs alongside GPU spending, and the emergence of on-premises architectures as first-class options.

Sep 20, 2026

Fifth Third, Priority and CSI deals put a premium on payments built into software

Fifth Third, Priority and CSI deals put a premium on payments built into software

Fifth Third led a strategic investment in Payload, Priority Commerce agreed to acquire IntelliPay, and CSI acquired Qolo in a series of summer transactions, PYMNTS reported. Together, the deals point to buyers valuing payments technology already integrated into the software customers use, not just standalone processing capacity. For operators, that means the entity holding payment data can change hands without the front-end software changing.

  • 01BCG puts software providers with integrated payments at 36% of small and midsize business acquiring revenue in 2024, heading to 45% by 2028, a benchmark for where merchant payment spend is shifting.
  • 02Finance and IT leaders at firms running property, practice management or utility billing software should check who actually owns the payment module in their contract, because that is the asset being bought.

Sep 19, 2026

System integrators decide whether factory tech pays off, Smart Industry argues

System integrators decide whether factory tech pays off, Smart Industry argues

Smart Industry’s Sept. 9, 2026 piece argues plant technology creates no business value until system integrators fit it into existing systems, operations and workflows. Related summer coverage highlights upskilling, institutional knowledge and technician demand alongside the same integration-and-deployment theme. The framing shifts attention from which platform to buy to who implements it and how the engagement is scoped.

  • 01Smart Industry's framing moves the buying question from which platform to license to who integrates it and how that engagement is scoped, which puts the system integrator line item at the center of the return rather than in implementation overhead.
  • 02Gartner figures cited by Quality Magazine show 24% of industrial enterprises using IoT have implemented digital twins and 42% plan to, suggesting most IoT-using plants still have digital twin integration work ahead.
  • 03The Deloitte and Manufacturing Institute report, as covered by Smart Industry, says AI can embed skills into workflows to address technician demand; the sharper question for a plant manager is whether that changes headcount or changes what each technician can cover.

Sep 18, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

Carlos Rivera
Carlos Rivera

Principal Research Advisor, Security & Privacy

Carlos Rivera is a Principal Research Advisor in the Security & Privacy practice. Carlos has 25 years of experience in IT and cybersecurity, primarily within the fintech industry. Prior to joining Info-Tech Research Group, Carlos spent 21 years as an information security officer for multi-billion-dollar business units dedicated to money movement in the P2P, B2C, and B2B space. Most recently, throughout his 21-year career with this Fortune 500 fintech, Carlos led global teams of security and network engineers, enterprise architects, risk managers and analysts that provided cybersecurity services to many global financial industry clients, and was responsible for information security governance, cyber risk management, vulnerability management, application security methodology and adoption focusing on shift-left fundamentals such as Static Analysis Security Testing (SAST), Dynamic Analysis Security Testing (DAST), Open Source Security Testing (OSST), and Manual Application Security Testing (MAST).

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512