
For years, the conversation around IT and more recently operational technology (OT) has centered on networks, security and data. As factories, hospitals, utilities, warehouses and other operational environments become more connected, organizations have invested heavily in protecting the systems connecting these worlds.
There is another part of the architecture worth examining: the device sitting in front of the worker. Operator stations, shared workstations, clinical terminals and warehouse devices increasingly connect employees to cloud services, analytics platforms, virtual desktops and web applications. Yet many are still managed like conventional PCs, even when the requirements of the environment are anything but conventional.
The stakes are rising. Dragos reported that ransomware attacks against industrial organizations increased 64 percent in 2025, affecting more than 3,300 organizations, with manufacturing accounting for more than two-thirds of victims. The company also found an average ransomware dwell time of 42 days in OT environments. Those numbers make a strong case for looking not only at how organizations protect OT networks, but also at the endpoints through which users access operational systems.
OT Doesn't Always Need Another PC
A traditional enterprise PC is designed to do a lot. It runs applications locally, stores data, receives updates and can be customized extensively by its user. Those capabilities make sense for many knowledge workers, but they can become liabilities in an operational environment where a device may have one primary purpose and consistency matters more than flexibility.
Every locally installed application, operating system component and piece of stored data adds something else to secure, patch and recover. Device configurations can also drift over time, while older systems become increasingly difficult to maintain.
This is one reason thin client architecture deserves renewed attention as IT and OT converge. Applications and data can reside in a data center, cloud environment or other centralized infrastructure and be delivered through virtual desktops, published applications, DaaS or browser-based systems. The endpoint becomes primarily a secure access point rather than another distributed computing environment.
For operational environments, the principle is simple: make the endpoint responsible for less. Ideally, workers should have access only to the applications and resources required for their role. Reducing opportunities for general web browsing, unauthorized software installation or unnecessary local data storage simplifies management while also reducing the endpoint attack surface.
A lightweight, security-first operating system can reinforce this model. An immutable OS design can limit unauthorized changes to the underlying endpoint, while a minimal software footprint reduces the number of components that need to be maintained and protected.
Reduce the Consequences of an Endpoint Failure
Security discussions naturally focus on preventing compromise, but operational teams also have to consider what happens after something fails. If an operator workstation contains applications, data and a unique local configuration, replacing failed hardware may only be the beginning. IT may also have to recreate the environment before the employee can resume normal operations.
When applications and data reside elsewhere and endpoint configurations are standardized, the recovery equation changes. A replacement device can potentially reconnect the worker to the same environment without requiring IT to reconstruct everything locally. Organizations can establish standardized endpoint profiles for particular roles rather than maintaining many unique PC configurations.
That makes endpoint standardization a resilience strategy as much as a management strategy. Dragos found that 75 percent of the ransomware incidents it responded to in 2024 resulted in at least a partial shutdown of OT operations, while 25 percent resulted in a full OT shutdown. Reducing the dependencies that have to be restored at the endpoint can therefore become part of a broader operational recovery strategy.
Give IT More Control Without Giving OT More Disruption
IT/OT convergence has always involved competing priorities. IT teams are responsible for security, identity, compliance, patching and governance. OT teams are focused on uptime, predictable performance and operational continuity. A security improvement that creates frequent endpoint changes or unexpected downtime may not feel like an improvement to the people keeping production running.
The endpoint strategy has to accommodate both. Centralized thin client management can give IT the ability to apply configurations, policies and updates across distributed devices without treating every workstation as an individually managed PC. At the same time, OT can retain a consistent environment designed around a specific workflow.
That control also extends to identity and access. Operational environments frequently rely on shared workstations used by multiple employees across the same or successive shifts. Integrating endpoints with enterprise authentication technologies can allow workers to securely access their individual applications and sessions using smart cards, employee badges, MFA or other authentication methods. Organizations can maintain individual accountability without sacrificing the fast access required in production, clinical or warehouse environments.
Peripheral control is another part of the equation. Workers may legitimately need barcode scanners, printers, touchscreens or other specialized devices while having no reason to connect a USB storage drive. A centrally controlled endpoint can support approved peripherals while restricting unnecessary or unauthorized devices.
This does not eliminate the need for careful testing and change control in sensitive environments. It can, however, reduce the number of variables those processes have to accommodate.
The Windows 10 Problem Is Also an Opportunity
The end of Windows 10 support has forced many organizations to examine devices that have quietly remained in operational environments for years. The obvious response is a hardware refresh, and in some cases that will be necessary. But hardware age and hardware usefulness are not always the same thing.
If an existing device still performs its physical function reliably, organizations should ask whether it needs to be replaced or simply needs a different role. Compatible hardware can potentially be converted into a locked-down endpoint running a lightweight, immutable security-first operating system with a minimal footprint, while the applications employees need continue to run in an appropriate Windows environment elsewhere.
This approach can extend the useful life of hardware while simplifying the endpoint environment. It also allows organizations to modernize incrementally rather than forcing a large-scale replacement project into an operational setting where change itself carries risk.
Thin Clients Have Changed Along with the Workplace
The term "thin client" still evokes VDI for many IT professionals, but that description is increasingly incomplete. Modern operational environments may use virtual desktops, cloud desktops, SaaS applications, published Windows applications and browser-based tools simultaneously.
What matters is less whether everything runs inside a traditional VDI session and more whether the endpoint can provide secure, reliable access to the applications required for the job. That includes supporting the identity technologies and peripherals workers genuinely need while restricting the applications, devices and functionality they do not.
Nor does this mean every OT endpoint should become a thin client. Some workloads require substantial local processing, specialized peripherals or applications tightly coupled to a device. The better question is whether organizations should continue deploying and managing a full PC when a particular worker really needs secure access to a defined set of applications and services.
As IT and OT continue to converge, organizations need to consider how much complexity they want sitting at the edge. For many operational roles, adding more capability to the endpoint provides little business value while increasing the amount of technology that must be secured, updated, managed and eventually recovered.
A simpler architecture reverses that assumption. Keep applications and sensitive data centrally protected while limiting endpoint access and functionality to what each worker actually needs. Standardize devices, reduce local dependencies and make failed endpoints easier to replace. Where existing hardware remains viable, reuse it rather than assuming modernization requires replacement.
Thin clients will not be the right answer for every OT workload, but the architectural principle behind them is increasingly relevant. The less an operational endpoint has to do, and the less unnecessary functionality it exposes, the easier it can be to secure, manage and recover.
In environments where uptime is measured in production output, patient care, shipments or essential services, reducing complexity at the endpoint can become a meaningful part of operational resilience.





















