Attacks On Operational Technology (OT) Expected to Ramp Up

CYRIN Newsletter

Attacks On Operational Technology (OT) Expected to Ramp Up

Cybersecurity experts predict a substantial uptick in malicious attacks on operational technology in 2026. In this month’s newsletter we discuss the unique vulnerabilities of OT, and what security teams can learn from existing IT protocols.

As industries digitize and integrate traditional OT systems with IT networks, the security of operational technology has become a top priority. Historically, OT systems were isolated from external networks. Now, devices are increasingly connected to the outside world by Industrial Internet of Things (IIoT) “devices, cloud services, and smart technologies. This convergence exposes OT to cyber threats such as ransomware, malware, and nation-state attacks.”

What is OT?

Operational Technology (OT) systems refer to the hardware and software that monitor and control physical devices, processes, and infrastructure. Devices like Programmable Logic Controllers (PLCs),  special-purpose computing devices for factories and infrastructure, are some of the most fundamental OT devices that monitor input signals from sensors or switches, execute custom user logic, and trigger output commands to control motors, valves, or lights. They’re built to handle heat and vibrations typically they are used in factories, water treatment plants, traffic lights, and elevators. They can connect to other devices to report data and provide centralized controls.

These legacy systems are now finding themselves bridged or connected to IT systems and attacks on these systems are potentially catastrophic as they impact manufacturing, energy grids, and water treatment plants. If an energy grid goes down or the water system is hacked and/or contaminated, the consequences could be fatal and widespread. An attack on critical infrastructure like a power grid can be apocalyptic. If the power grid goes dark, hospitals, transportation and climate control are impacted.

Writing in TechTarget, and referencing Google Cloud’s Cybersecurity Forecast 2026, researchers wrote “In 2026, we anticipate the primary disruptive threat to industrial control systems and OT will remain cybercrime." The article went on to say that expect to “see ransomware operations specifically designed to impact critical enterprise software, such as ERP systems, severely disrupting the supply chain of data essential for OT operations.” That works because the business layer can cripple the industrial environment, which will force “quick payments.” In the meantime, bad habits like “poor hygiene, and insecure remote access, will continue to allow common Windows malware to breach OT networks.”

Fortinet, in one of their 2026 blog posts, said that “traditionally, OT cyber security was not necessary because OT systems were not connected to the internet. As such, they were not exposed to outside threats. As digital innovation initiatives expanded and IT OT networks converged, organizations tended to bolt-on specific point solutions to address specific issues.”

Securing these environments is vital, because a malfunction in an OT system can result in physical damage or danger to human life. As an IBM think topic report noted, “OT systems often use legacy and proprietary protocols, which require specialized knowledge and solutions to protect against evolving security and cybersecurity risks. As a result, OT security must focus on maintaining system availability, understanding specific industrial protocols and protecting endpoints against threats that target outdated systems.”

OT security challenges

Internet connectivity has completely transformed the way organizations operate, often enabling seamless communication and providing opportunities for collaboration and easy access to comprehensive information. However, just like any system that relies on the internet, these advances have introduced significant cybersecurity threats.

According to the IBM X-Force Threat Intelligence Index 2026, “the manufacturing sector is the most attacked industry, representing 27.7% of all incidents within top industries.” More than 20% of businesses experienced an industrial cybersecurity incident in the past year, with four in 10 incidents disrupting operations. “Disruptions to OT-driven infrastructure can quickly cascade and affect large populations, so vigilant OT management must be a strategic priority for businesses looking to optimize and secure OT ecosystems.”

The IT/OT convergence

Before the widespread use of the internet, OT systems were isolated from corporate networks (called “air-gapping”), but as businesses and organizations increasingly use the internet to improve efficiency, the physical systems are connected to corporate IT networks, introducing the pros of increased productivity and information sharing and the cons of increased cybersecurity risks.

One of the core advantages of IT/OT convergence is increased efficiency. It facilitates the integration of different technologies to work as a single, cohesive system, reducing errors and enhancing workflows. This integration means that data from physical operations (OT) can be quickly analyzed and influenced by IT systems, allowing for more informed decision-making and autonomous operations which improves accuracy and uptime.”

While reliance on the Internet of Things (IoT) improves automated processes and easier maintenance, it also introduces significant risk into critical infrastructure.

Strategies and troubleshooting

How can organizations, business, companies and government sectors secure their OT systems? By taking a page from the book of IT security standards and protocols.

Simon Hodgkinson, the former Chief Information Security Officer (CISO) at BP and current Strategic Adviser at Semperis, writing in Cyber Magazine, said, “IT cybersecurity professionals focus on IT security first. They want to protect information from theft, prevent unauthorized access to IT systems, and stop phishing attacks on their users. OT engineers however are less concerned with these things. Instead, their focus is on controllers and sensors that affect physical processes and systems. As such, they're preoccupied with operational uptime, physical security and safety.”

According to Paul Evans, at Nozomi Networks, there are a few key steps that organizations should take in order to help the incident response team detect a threat and move quickly and effectively in response to it. “First, create a comprehensive inventory of all assets within the environment using a continuous monitoring tool,” he explains. “Second, deploy continuous monitoring for industrial networks to capture real-time data on traffic patterns and anomalies. Third, conduct regular vulnerability assessments to identify vulnerabilities in hardware, software, and configurations. Fourth, OT networks should be segmented from corporate networks, and remote access should be limited and or compensated by additional security measures like multifactor authentication and zero trust strategies.”

Looking at the big picture, Jayne Goble from KPMG UK in Cyber Magazine said: “OT should take a leaf out of IT’s book and import best practices from IT security. This will result in capturing the processes that are normal in the IT environment and harnessing them.”

Improving OT security

In a corporate blog post, CyberProof’s research team listed several realistic steps to address human and technical vulnerabilities. They noted that OT systems are contained within critical industries including manufacturing, energy, transportation, and utilities and while traditional IT systems have placed high importance on cybersecurity, OT systems are workhorses “designed with reliability and functionality as the primary focus. Many OT devices rely on legacy hardware and software, which lack even the most basic security measures.” This leaves them open to all the usual cybersecurity problems such as ransomware, infiltration by bad actors and insider threats.

To work on those threats, they list some specific responses including network segmentation. Network segmentation involves dividing a network “into smaller, isolated zones to limit the spread of cyber threats. In OT environments, this strategy is particularly effective in protecting critical systems by creating barriers between IT and OT networks.”

Another important step which is often overlooked is to implement real-time monitoring and incident response plans. Real-time monitoring provides “continuous visibility into your OT environment, allowing for the early detection and mitigation of threats. As industrial systems become more complex, real-time insights are critical to preventing small issues from escalating into major disruptions.” Another critical human element to this is employee training so employees get trained on the importance of “rapid reporting.”

Another technical fix is to regularly update and patch OT systems. “OT devices are designed for long-term use, often relying on legacy software that doesn’t support modern patching processes. Additionally, concerns about compatibility and potential downtime lead many organizations to delay updates, leaving vulnerabilities unaddressed.” One example is to test patches in a controlled environment, maybe like a digital twin, where patches are controlled and don’t affect ongoing operations.

There needs to be a hard focus on training employees. According to CyberProof, “Human error remains one of the leading causes of cybersecurity incidents. Employees who are unaware of OT-specific threats may inadvertently expose systems to risks, such as by clicking on phishing links or mismanaging sensitive information.”

As attacks on OT are expected to rise substantially in the coming years, cybersecurity professionals will need to keep their eye on their networks and implement tips and tactics for making sure that the systems that safeguard critical infrastructure remain safe and uncompromised.

How can CYRIN help?

We ended this article with a note about training. We live in an increasingly dangerous and dynamic world, and systems are under attack and there is a renewed emphasis on protecting critical infrastructure. At CYRIN we’ve been working for years on these problems, setting up realistic skills-based training to develop systems and answers to some of these vexing questions.

We implemented some of the industry’s first cyber training scenarios on OT systems, and we worked with industry partners to present the most effective and realistic scenarios in the marketplace. We understand that continuing innovation is needed as the marketplace continues to change. That’s why we stress continuing education and training, because the job is never done.

We continue to work with our industry partners to address major challenges and set up realistic scenarios that allow them to train their teams and prepare new hires for the threats they will face. Government agencies have been using CYRIN for years, training their front-line specialists on the real threats faced on their ever-expanding risk surface.

For educators, we consistently work with colleges and universities both large and small to create realistic training to meet the environment students will encounter when they graduate and enter the workforce. In an increasingly digitized world, training and experiential training are critical. A full-blown cyberattack is not something you can prepare for after it hits, no matter who the adversary.

Our training platform teaches fundamental solutions that integrate actual cyber tools from CYRIN’s labs that allow you to practice 24/7, in the cloud, no special software required. Our new programs, including our new “mini labs,” AI, and Digital Twins, can create real-world conditions for you to practice before you must act. Cyber is a team effort; to see what our team can do for you look at our course catalog, or better yet, contact us for further information and your personalized demonstration of CYRIN. Take a test drive and see for yourself!

< Read other CYRIN Newsletters

Contact Us for details or to Set Up a CYRIN Demo
+1-800-850-2170 sales@cyrintraining.com

Watch CYRIN: The Next-Generation Cyber Range

Learn More About How CYRIN Online Training Can Benefit You