Most GRC programs are built around IT assets — endpoints, servers, cloud environments, SaaS platforms. The risk register covers data breaches, ransomware, and regulatory compliance. That scope is appropriate for most of what the program governs. The problem is that a significant and growing category of risk sits outside that scope entirely: operational technology. And…