The IT-risks which factory infrastructures are exposed to, require a common view of IT-security and operational technology (OT) protection. In this context, the measures from office IT can only be transferred to the production area and production control to a limited extent. The requirements and protection goals for the equipment used and the networking between these components are too different. An integrated approach and continuous management of IT security helps to identify and implement targeted measures in a concerted manner.