Blog / OT security hiring: the NIS2 skills gap nobody staffed for

OT security hiring: the NIS2 skills gap nobody staffed for

    NIS2 now covers OT and IoT with no transition period. Here's why OT security hiring is suddenly urgent, and what profile actually closes the gap.

    NIS2 now explicitly covers OT and IoT, with no transition period to prepare. That means companies who never had to secure their PLCs, cameras, or building systems now need people who can. OT security hiring is suddenly a board-level priority, and there simply aren't enough qualified specialists to go around yet.


    You've probably got a security team. It's decent at IT. Firewalls, endpoint protection, identity management, all handled.


    But ask that same team who monitors the badge readers. Or the building management system. Or the PLCs running your production line.


    Silence.


    That silence used to be fine. Now it's a compliance gap with your name on it.

    Why OT and IoT became a compliance problem overnight

    OT and IoT fall under the same duty of care as your regular IT stack, and there's no grace period to fix the gap. If your industrial systems or connected devices aren't inventoried and monitored, you're already out of compliance, not heading toward it.


    For years, operational technology sat outside the security team's radar. Facilities managed the building systems. Engineering managed the plant floor. Nobody asked security to weigh in, because nobody framed it as a security problem.


    Dutch cybersecurity guidance now states plainly that the duty of care applies to the whole environment, not just the IT you already secure. That includes operational technology and the Internet of Things, the two categories most security programs still under-count.


    There's no phase-in. Risk-management measures had to be in place from day one under the Dutch Cyberbeveiligingswet, which took effect without a transition period.


    That's the part that changes hiring urgency. This isn't a two-year roadmap item anymore. It's a live gap, and someone above the CISO is now personally on the hook for it.

    Who actually needs to get hired for this

    Companies need people who understand industrial protocols and IoT device management, not generic IT security generalists. Think OT security engineers who can work with SCADA and PLC networks, and IoT specialists who handle asset discovery and firmware on connected devices. These are different skill sets from a typical SOC analyst.


    An OT security engineer needs to understand how a production line actually runs before they can secure it. Segmentation on an industrial network isn't the same exercise as segmentation in a corporate data center. You're dealing with legacy equipment that can't just get patched on a Tuesday night, because patching it wrong might stop a machine mid-cycle.


    IoT security specialists focus on a different problem: hundreds or thousands of small connected devices, cameras, sensors, access control systems, each with its own firmware, its own certificate lifecycle, its own blind spots. Nobody budgeted headcount for managing that inventory. Now they have to.


    Then there's the compliance layer. Cyber risk managers who can translate NIS2 obligations into actual controls and evidence are becoming just as scarce as the technical specialists. They're the ones who sit between the CISO, operations, facilities and legal, and make sure the whole thing is documented well enough to survive an audit.


    Roles like this show up more often now on our own information security analyst vacancies, where the OT and compliance angle has become a normal part of the brief instead of an edge case.

    Why this is harder to staff than a normal IT security role

    OT security hiring is harder because the group of people who combine industrial engineering knowledge with modern security skills is small, and most of them aren't actively job hunting. You're not competing on salary alone. You're competing for a profile that barely exists in the volume you need.


    A typical IT security hire has dozens of comparable candidates on the market. An OT security hire often has a handful, and half of them are already deep into a long-term contract at a utility or manufacturer that isn't letting go easily.


    Part of the problem is where these people come from. Some started as controls engineers and picked up security later. Others started in IT security and had to learn industrial systems from scratch. Neither path produces candidates in bulk.


    More than 8,000 Dutch organizations now fall under the strengthened obligations of the Cyberbeveiligingswet, according to KPMG's NIS2 market update.

    That's 8,000 organizations, many of them in energy, manufacturing, logistics and healthcare, all suddenly needing the same narrow skill set at roughly the same time. Basic supply and demand tells you what happens next: rates go up, timelines stretch, and the companies that already had a search running lose candidates to companies that started later but move faster.


    That's exactly where a rushed hiring process backfires. Cast too wide a net for a role this specific, and you burn weeks on interviews with people who don't actually have the industrial background the job needs.

    How Doghouse approaches an OT security search

    We treat OT and IoT security roles as a specialist search from the first conversation, not a rebranded IT security vacancy. That starts with a proper intake: what systems are actually in scope, what does the compliance officer need to see, and what does this person's Monday morning actually look like.


    We don't send you ten CVs and hope three stick. Our Delivery Sprint process means intake, sourcing and interviews happen in a structured sequence, so you know exactly where the search stands at every point, and candidates know exactly what to expect too.


    For a role like this, that structure matters more than usual. OT security engineers are used to being pitched jobs that sound like IT roles with a different label slapped on. They can tell within one conversation if the recruiter understands the difference between a SCADA network and a corporate LAN. If we don't understand it, we don't waste their time or yours pretending otherwise.


    We've seen this play out on searches adjacent to this space too, including roles like data platform engineer positions, where the client needed someone who could bridge infrastructure knowledge with a compliance-heavy environment. The skill of finding that bridge person doesn't change much between OT and data platforms. What changes is the vocabulary you need to speak fluently before a candidate takes you seriously.

    What hiring managers should do differently right now

    Start the search before the compliance deadline forces your hand, and be specific about which systems and protocols the role actually covers. A vague job description for "OT security" attracts the wrong candidates and scares off the right ones, because the right ones know exactly what they're good at and won't waste time on a role that isn't clearly scoped.


    Write the vacancy with the actual environment in mind. Name the protocols. Name the systems. If the role touches building management systems, say so. If it's purely industrial control systems on a factory floor, say that instead. Candidates in this niche read job descriptions the way engineers read code: they notice when something doesn't add up.


    Loop in whoever owns the compliance side early, even if they're not writing the job description. NIS2 obligations touch legal, operations and the board, and a hiring manager who can speak to that context in an interview closes stronger candidates faster than one who can only talk tech stack.


    Budget realistically for timeline. This isn't a role you fill in three weeks by posting on a job board. Treat it like the specialist search it is, and build in the time that takes.

    Veelgestelde vragen
    What does NIS2 mean for OT and IoT security?

    NIS2, implemented in the Netherlands through the Cyberbeveiligingswet, brings operational technology and IoT devices explicitly under the duty of care. Organizations must inventory, monitor and secure these systems just like regular IT, with no transition period to catch up.

    How do I find qualified OT security specialists?

    Look beyond generic IT security profiles. The strongest candidates usually have a background in industrial engineering or controls, plus security experience layered on top. A structured search with a clear intake on your actual systems finds them faster than a broad job posting.

    What skills should an OT security engineer have?

    Solid knowledge of industrial protocols like Modbus or OPC-UA, experience with network segmentation on legacy systems, and an understanding of how patching and monitoring differ on equipment that can't simply go offline for an update.

    Why is OT security harder to staff than IT security?

    The pool of people combining industrial systems knowledge with modern security skills is small, and most of them are already employed. Demand from thousands of newly regulated organizations has hit that small pool all at once, driving up competition and timelines.

    Conclusie

    OT and IoT security stopped being a technical afterthought the moment NIS2 removed the transition period. Companies now need people who can secure systems they never had to defend before, and the market for those people is thin.


    The organizations that move first on OT security hiring will fill their gaps before the candidate pool gets even tighter. The ones that wait will be competing with 8,000 other companies for the same handful of specialists.


    If you're staring down an OT or IoT security vacancy and not sure where to even start looking, that's a conversation worth having. We've been in enough of these searches to know what a realistic profile looks like, and we're happy to compare notes.

    Sources
    1. NIS2 (Cbw) Update - KPMG International
    2. NIS2 in the Netherlands: What the Cyberbeveiligingswet means ...
    3. Cybersecurity obligations for more companies in critical sectors (NIS2)
    4. Transposition in the Netherlands - NIS 2 Directive
    5. NIS2 in Netherlands — transposition and authority
    6. NIS2 Regulatory Timeline

    Written by our AI, read by a flesh-and-blood recruiter.