Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Tech Convergence is Minimizing IT Security Risk By Creating More Synergies Within Companies

Can a proper convergence strategy mitigate IT security risk? It is something all business stakeholders need to consider. In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes? As technological advancements evolve, the spectrum of security threats…

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By Carlos Rivera · Carlos RiveraCybersecurityInfo-tech Research GroupIt Security
Share

Key takeaways

01

Can a proper convergence strategy mitigate IT security risk?

02

It is something all business stakeholders need to consider.

03

In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes?

Can a proper convergence strategy mitigate IT security risk? It is something all business stakeholders need to consider.

In today’s world, where a single security breach could spell catastrophe, how prepared are organizations to combat the intertwined threats looming over their digital and physical landscapes?

As technological advancements evolve, the spectrum of security threats extends beyond the digital sphere, encroaching on physical infrastructures and core organizational operations. Info-Tech Research Group emphasizes the necessity of a unified security architecture, merging physical security, cybersecurity, and other administrative realms like HR, legal, and compliance. Its most recent research and analysis, its “Integrate Physical Security and Information Security” blueprint, offers a structured three-phase approach to reduce IT security risk: Plan, Enhance, Monitor, and optimize to navigate this convergence. Though intricate due to proprietary and diverse technological landscapes, this integration heralds a robust defense against modern threats, embodying a modular, incremental, and repeatable process.

What initial steps should firms undertake to ensure a seamless transition towards this integrated security model? The path towards converging these diverse security networks presents challenges; how should firms adeptly navigate these to bolster their security posture?

Carlos Rivera, a Principal Research Advisor of Security and Privacy Practice at Info-Tech Research Group, provides insights into Info-Tech’s published research, expanding on the nuances of harmonizing digital and physical security infrastructures for an enhanced organizational defense mechanism.

Carlos’ Thoughts

“Our methodology basically goes into three primary steps, and it’s, you know, basically you plan, you make an assessment based on the output. You know, you should focus really on the outcomes more than a lot of people that focus on capabilities, but outcomes really are what you want to focus on. But after you plan and you do the assessment, it’s enhancing what you currently have, right? So, that is a kind of standard methodology. I know this sounds kind of boilerplate, but really, it’s taking a good look at what you have based on, you know, our methodology or a good control set, right? Using different models like Purdue, et cetera, to really gauge where you’re at and where you want to be at the end of the journey, right? So, you know, security is a never-ending journey, but this is a really good way to make an assessment and figure out what areas to focus on.”

How can firms ensure the highest levels of success and safety while converging their technology platforms?

“It’s all driven by risk, right? And definitely, in OT settings, you know, one variable that most organizations don’t have to worry about is safety, safety concerns. Another risk that I would say is with OT or IoT, as it were, things that could, you know, impact somebody’s life. They can have like medical devices, et cetera. This is really the value of the convergence, right? If you have a mindset of, I’m going to publish policies; I have a governance framework for my organization that really is extended to your OT infrastructure, right? And you’re holistically looking at a program from an organizational top-down perspective.

That’s really the value of convergence. It’s not really flattening, as some would think, the infrastructure and creating risk. It’s minimizing risk by building on the synergies that you probably already envision with your IT security program.”

What key challenges do you see from firms trying to do this, and how can they navigate them?

“One of the most common ones, to be honest with you, it’s probably a no-brainer, but it’s really just bringing all the key stakeholders to the table to have a conversation, right, about what the objectives are. That’s before you do any kind of technical evaluation. Come up with a charter about what the convergence is about. We have pretty good documentation methodology on getting you started and having the right conversation. We also have a list of stakeholders that we recommend having as part of that conversation, but then have a methodical phased approach on what you feel are the biggest risks and how you feel like you’re going to solve those risks.

Our methodology encourages you to use business language. That’s the best way to talk to stakeholders. You’re not going to drive this change from the bottom up. You’re going to drive it from the top down. And we recommend using something like COBIT and align your strategic goals for that convergence with business language like COBIT to make it really easy to understand what your mission is.”

Article by James Kent

About the author

Carlos Rivera
Carlos RiveraPrincipal Research Advisor, Security & Privacy

Carlos Rivera is a Principal Research Advisor in the Security & Privacy practice. Carlos has 25 years of experience in IT and cybersecurity, primarily within the fintech industry. Prior to joining Info-Tech Research Group, Carlos spent 21 years as an information security officer for multi-billion-dollar business units dedicated to money movement in the P2P, B2C, and B2B space. Most recently, throughout his 21-year career with this Fortune 500 fintech, Carlos led global teams of security and network engineers, enterprise architects, risk managers and analysts that provided cybersecurity services to many global financial industry clients, and was responsible for information security governance, cyber risk management, vulnerability management, application security methodology and adoption focusing on shift-left fundamentals such as Static Analysis Security Testing (SAST), Dynamic Analysis Security Testing (DAST), Open Source Security Testing (OSST), and Manual Application Security Testing (MAST).

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one expert. Imagine publishing your whole team.

This article was produced through MarketScale. Create a free workspace and turn your own team's expertise into articles, video, and social posts. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

Southeast Asian enterprises cut vendor onboarding from 5 days to 4 hours with agentic AI

Southeast Asian enterprises cut vendor onboarding from 5 days to 4 hours with agentic AI

Southeast Asian enterprises have significantly reduced vendor onboarding time from five days to just four hours through the use of agentic AI. This multi-agent workflow showcases the advancements and effectiveness of enterprise AI solutions anticipated for 2026. The move marks a step beyond AI pilot programs, indicating a future trend in enterprise adoption of AI technologies.

  • 01Vendor onboarding reduced from five days to four hours with AI.
  • 02Multi-agent workflow signifies advancements in enterprise AI.
  • 03Shift beyond pilot programs indicates future AI adoption trends.

Jul 10, 2026

Enterprise AI spending hits a wall: companies ration tokens, redirect budgets

Enterprise AI spending hits a wall: companies ration tokens, redirect budgets

Major enterprises like Uber, Meta, and Salesforce are shifting their strategies for AI investments due to rising token costs impacting project budgets. These companies are now rationing access to AI resources and redirecting financial allocations. The changes indicate a critical reassessment of AI spending and resource management.

  • 01Enterprises are experiencing unexpected surges in AI token costs.
  • 02Companies are rationing AI access to maintain budget control.
  • 03Budgets are being redirected away from AI in certain organizations.

Jul 10, 2026

Logicalis earns Microsoft Frontier Partner status as enterprise AI deployments move past the pilot stage

Logicalis earns Microsoft Frontier Partner status as enterprise AI deployments move past the pilot stage

Logicalis has achieved Microsoft Frontier Partner status along with a Copilot specialization. This achievement indicates their readiness to support scaling enterprise AI deployments with integrated governance. These developments come as more enterprises move past pilot stages in AI deployment.

  • 01Logicalis earns Microsoft Frontier Partner status.
  • 02The company specializes in enterprise AI scaling with governance.
  • 03AI deployments are moving beyond pilot stages in enterprises.

Jul 10, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

Carlos Rivera
Carlos Rivera

Principal Research Advisor, Security & Privacy

Carlos Rivera is a Principal Research Advisor in the Security & Privacy practice. Carlos has 25 years of experience in IT and cybersecurity, primarily within the fintech industry. Prior to joining Info-Tech Research Group, Carlos spent 21 years as an information security officer for multi-billion-dollar business units dedicated to money movement in the P2P, B2C, and B2B space. Most recently, throughout his 21-year career with this Fortune 500 fintech, Carlos led global teams of security and network engineers, enterprise architects, risk managers and analysts that provided cybersecurity services to many global financial industry clients, and was responsible for information security governance, cyber risk management, vulnerability management, application security methodology and adoption focusing on shift-left fundamentals such as Static Analysis Security Testing (SAST), Dynamic Analysis Security Testing (DAST), Open Source Security Testing (OSST), and Manual Application Security Testing (MAST).