Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Tech Convergence is Minimizing IT Security Risk By Creating More Synergies Within Companies

Can a proper convergence strategy mitigate IT security risk? It is something all business stakeholders need to consider. In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes? As technological advancements evolve, the spectrum of security threats…

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By Carlos Rivera · Carlos RiveraCybersecurityInfo-tech Research GroupIt Security
Share

Key takeaways

01

Can a proper convergence strategy mitigate IT security risk?

02

It is something all business stakeholders need to consider.

03

In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes?

Get featured

Want MarketScale to feature Software & Technology?

Book a 15-minute demo and we'll map your Software & Technology expertise to the content buyers are searching for.

Book a demo

Can a proper convergence strategy mitigate IT security risk? It is something all business stakeholders need to consider.

In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes?

As technological advancements evolve, the spectrum of security threats extends beyond the digital sphere, encroaching on physical infrastructures and core organizational operations. Info-Tech Research Group emphasizes the necessity of a unified security architecture, merging physical security, cybersecurity, and other administrative realms like HR, legal, and compliance. Its most recent research and analysis, its “Integrate Physical Security and Information Security” blueprint, offers a structured three-phase approach to reduce IT security risk: Plan, Enhance, Monitor, and optimize to navigate this convergence. Though intricate due to proprietary and diverse technological landscapes, this integration heralds a robust defense against modern threats, embodying a modular, incremental, and repeatable process.

What initial steps should firms undertake to ensure a seamless transition towards this integrated security model? The path towards converging these diverse security networks presents challenges; how should firms adeptly navigate these to bolster their security posture?

Carlos Rivera, a Principal Research Advisor of Security and Privacy Practice at Info-Tech Research Group, provides insights into Info-Tech’s published research, expanding on the nuances of harmonizing digital and physical security infrastructures for an enhanced organizational defense mechanism.

Carlos’ Thoughts

“Our methodology basically goes into three primary steps, and it’s, you know, basically you plan, you make an assessment based on the output. You know, you should focus really on the outcomes more than a lot of people that focus on capabilities, but outcomes really are what you want to focus on. But after you plan and you do the assessment, it’s enhancing what you currently have, right? So, that is a kind of standard methodology. I know this sounds kind of boilerplate, but really, it’s taking a good look at what you have based on, you know, our methodology or a good control set, right? Using different models like Purdue, et cetera, to really gauge where you’re at and where you want to be at the end of the journey, right? So, you know, security is a never-ending journey, but this is a really good way to make an assessment and figure out what areas to focus on.”

How can firms ensure the highest levels of success and safety while converging their technology platforms?

“It’s all driven by risk, right? And definitely, in OT settings, you know, one variable that most organizations don’t have to worry about is safety, safety concerns. Another risk that I would say is with OT or IoT, as it were, things that could, you know, impact somebody’s life. They can have like medical devices, et cetera. This is really the value of the convergence, right? If you have a mindset of, I’m going to publish policies; I have a governance framework for my organization that really is extended to your OT infrastructure, right? And you’re holistically looking at a program from an organizational top-down perspective.

That’s really the value of convergence. It’s not really flattening, as some would think, the infrastructure and creating risk. It’s minimizing risk by building on the synergies that you probably already envision with your IT security program.”

What key challenges do you see from firms trying to do this, and how can they navigate them?

“One of the most common ones, to be honest with you, it’s probably a no-brainer, but it’s really just bringing all the key stakeholders to the table to have a conversation, right, about what the objectives are. That’s before you do any kind of technical evaluation. Come up with a charter about what the convergence is about. We have pretty good documentation methodology on getting you started and having the right conversation. We also have a list of stakeholders that we recommend having as part of that conversation, but then have a methodical phased approach on what you feel are the biggest risks and how you feel like you’re going to solve those risks.

Our methodology encourages you to use business language. That’s the best way to talk to stakeholders. You’re not going to drive this change from the bottom up. You’re going to drive it from the top down. And we recommend using something like COBIT and align your strategic goals for that convergence with business language like COBIT to make it really easy to understand what your mission is.”

Article by James Kent

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

Carlos Rivera
Carlos RiveraPrincipal Research Advisor, Security & Privacy

Carlos Rivera is a Principal Research Advisor in the Security & Privacy practice. Carlos has 25 years of experience in IT and cybersecurity, primarily within the fintech industry. Prior to joining Info-Tech Research Group, Carlos spent 21 years as an information security officer for multi-billion-dollar business units dedicated to money movement in the P2P, B2C, and B2B space. Most recently, throughout his 21-year career with this Fortune 500 fintech, Carlos led global teams of security and network engineers, enterprise architects, risk managers and analysts that provided cybersecurity services to many global financial industry clients, and was responsible for information security governance, cyber risk management, vulnerability management, application security methodology and adoption focusing on shift-left fundamentals such as Static Analysis Security Testing (SAST), Dynamic Analysis Security Testing (DAST), Open Source Security Testing (OSST), and Manual Application Security Testing (MAST).

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

Etched’s $21 billion valuation forces AI inference buyers to treat racks as contracts, not chips

Etched’s $21 billion valuation forces AI inference buyers to treat racks as contracts, not chips

With a $21 billion valuation, Etched is prompting a shift in how AI inference buyers approach procurement, focusing on racks rather than individual chips. Etched's significant valuation, fueled by a $700 million funding round, underscores the evolving economics of AI inference. This approach emphasizes the importance for enterprises to consider racks as long-term infrastructure investments.

  • 01Etched's $700 million funding round has propelled its valuation to $21 billion.
  • 02AI inference buyers should treat racks as enduring contracts, not just individual components.
  • 03The economics of AI inference are evolving, necessitating changes in procurement strategies.

Aug 19, 2026

Groq’s $350M neocloud push and Relay’s shutdown put more pressure on enterprise AI runbooks than on model choice

Groq’s $350M neocloud push and Relay’s shutdown put more pressure on enterprise AI runbooks than on model choice

Groq's significant investment in neocloud capacity and the shutdown of Relay with its integration into Google's Chrome team highlight operational challenges in maintaining continuity and control in AI automation. This landscape shift pressures enterprise AI runbooks rather than the choice of AI models. Companies must adapt to these transitions to ensure operational stability and strategic advantage in the AI sector.

  • 01Groq has invested $350 million in expanding its neocloud capabilities.
  • 02Relay has been shut down and integrated into Google's Chrome team.
  • 03Enterprise AI runbooks are under pressure due to changes in continuity and control.

Aug 19, 2026

Alphabet’s $5.9B Q2 cash burn is turning AI infrastructure into a CFO-led capex fight in 2026

Alphabet’s $5.9B Q2 cash burn is turning AI infrastructure into a CFO-led capex fight in 2026

Alphabet's recent financial report indicated a $5.9 billion cash burn in Q2 and an increase of $15 billion in the 2026 spending outlook. This financial adjustment is influencing enterprises to re-evaluate the return on investment for GPU and data center purchases. The changes are transforming AI infrastructure investments into a capital expenditure challenge led by CFOs.

  • 01Alphabet reported a $5.9 billion cash burn in Q2.
  • 02The 2026 spending outlook is increased by $15 billion.
  • 03Enterprises are facing tougher ROI thresholds for AI infrastructure investments.

Aug 19, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

Carlos Rivera
Carlos Rivera

Principal Research Advisor, Security & Privacy

Carlos Rivera is a Principal Research Advisor in the Security & Privacy practice. Carlos has 25 years of experience in IT and cybersecurity, primarily within the fintech industry. Prior to joining Info-Tech Research Group, Carlos spent 21 years as an information security officer for multi-billion-dollar business units dedicated to money movement in the P2P, B2C, and B2B space. Most recently, throughout his 21-year career with this Fortune 500 fintech, Carlos led global teams of security and network engineers, enterprise architects, risk managers and analysts that provided cybersecurity services to many global financial industry clients, and was responsible for information security governance, cyber risk management, vulnerability management, application security methodology and adoption focusing on shift-left fundamentals such as Static Analysis Security Testing (SAST), Dynamic Analysis Security Testing (DAST), Open Source Security Testing (OSST), and Manual Application Security Testing (MAST).

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512