how is cybersecurity evolving in the industrial wo 1 0 45247
how is cybersecurity evolving in the industrial wo 1 0 45247

How Is Cybersecurity Evolving in the Industrial World?

Industry

The most revealing line in this year’s operational technology reporting is not a breach count. It is an accounting problem. Dragos notes in its 2026 OT/ICS Cybersecurity Year in Review, the ninth edition, covering activity through 2025, that when a Windows server running SCADA software or an engineering workstation gets compromised, the case is routinely filed as an IT incident. The plant learns nothing from it. Neither does the sector.

Industrial cybersecurity has stopped being a subset of corporate IT security. It now has its own tracked adversary groups, its own standards framework in ISA/IEC 62443, and, since 2026, its own regulatory calendar under NIS2 and the Cyber Resilience Act. What has not kept pace is visibility. Dragos found that only 46% of the organisations it assessed had adequate OT network monitoring deployed.

Key takeaways

  • 119 ransomware groups reached industrial organisations in 2025, against 80 in 2024.
  • Manufacturing made up more than two-thirds of industrial ransomware victims.
  • CRA vulnerability reporting starts 11 September 2026, full application 11 December 2027.
  • Only 3% of assessed ICS vulnerabilities warranted immediate action.

Three numbers that describe the shift better than any narrative

The evolution is easiest to read in volume, not in technique. Dragos tracked 119 ransomware groups with reach into industrial organisations during 2025, up from 80 the previous year, a 49% rise in the number of distinct groups. Those groups collectively touched roughly 3,300 industrial organisations, with attack volume up 64% year over year. More than two-thirds of the victims were manufacturers.

Dragos 2026 report, 2025 data Figure What it tells an operator
Ransomware groups reaching industrial targets 119, from 80 in 2024 The threat is crowded, not concentrated
Industrial organisations impacted About 3,300 Being unremarkable is no longer protective
Manufacturing share of victims More than two-thirds Discrete production is the default target
OT threat groups tracked 26 total, 11 active in 2025 State-adjacent activity sits alongside crime
Operational disruption in Dragos OT ransomware cases All cases responded to in 2025 Production stops even when OT is not the target

Three new groups appear in the 2026 edition, and the way they work says more than the count. AZURITE goes after engineering workstations and moves fast on publicly available proof-of-concept code. PYROXENE runs multi-year supply chain campaigns using fake recruiter profiles on LinkedIn. SYLVANITE behaves as an initial access provider, living off edge device vulnerabilities. Two established groups, KAMACITE and ELECTRUM, extended their operations into the United States and Europe during the year.

The bottleneck is detection, not adversary intent

What separates a contained event from a shutdown is rarely the sophistication of the attacker. It is whether anyone on site can tell that something odd is a security matter rather than a process quirk.

Dragos reports that 82% of organisations had no clear criteria for deciding when an operational anomaly deserves a security investigation, and that 88% of tabletop exercises exposed degraded detection capability. The consequence is measurable in time: the industry-wide average dwell time for ransomware in OT environments sits at 42 days, against an average of 5 days for organisations with comprehensive OT visibility.

An anomaly with no owner is not an incident. It is a maintenance ticket that quietly closes itself.

This is also where the misfiling problem does real damage. An engineering workstation compromise recorded as a laptop malware case never reaches the people who could tell you which control loop that workstation programmes. The same blind spot shows up in distributed architectures, which is why we keep returning to how edge computing changes industrial automation: every device that processes data locally is also a device someone has to watch.

Regulation stopped being advisory in 2026

For years the honest answer to “what are we legally required to do” was “not much, in most sectors”. That answer expired this year in the European Union, and two separate instruments now apply to two different roles.

NIS2 binds operators. The transposition deadline was 17 October 2024, and enforcement of the deadline itself has now reached the courts: on 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition, asking for a lump sum and daily penalties. For entities in scope, Article 34 of the directive sets fine ceilings of at least 10 million euros or 2% of worldwide annual turnover for essential entities, and 7 million euros or 1.4% for important entities, whichever is higher in each case.

The Cyber Resilience Act binds manufacturers of products with digital elements, which covers a large share of the equipment sold into plants. It entered into force on 10 December 2024. The notified body framework applied from 11 June 2026. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA Single Reporting Platform to their national CSIRT, with the information made available to ENISA: an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days of a corrective measure being available for a vulnerability, or within a month for a severe incident. Full application, including CE marking, follows on 11 December 2027.

Plenty of industrial firms sit on both sides of that line. They operate regulated infrastructure and they also sell connected equipment. Those are two compliance programmes, not one.

What ISA/IEC 62443 gives you that a corporate policy cannot

The technical vocabulary underneath both regimes is the ISA/IEC 62443 series, and its value is that it was written for control systems rather than adapted from office IT.

The series is organised in four groups: general concepts and terminology, policies and procedures for asset owners and service providers, system-level requirements, and component-level requirements for product suppliers. Its two most portable ideas are the security levels, SL 1 through SL 4, which grade protection by the capability of the attacker you are defending against rather than by a product feature list, and zones and conduits, which force a plant to declare which assets belong together and what is allowed to cross between them. IEC 62443-2-1, covering the asset owner’s security programme, was revised in August 2024.

The practical benefit is negotiating power. “We need better security” loses every budget argument. “This zone is specified at SL 2 and currently meets SL 1” is a gap with a price attached.

Patching everything is the wrong reflex

The instinct after a bad year of headlines is to chase every advisory. The data argues against it. Applying its own triage to ICS vulnerabilities, Dragos placed 3% in the “now” category requiring immediate action, 71% in “next”, addressable through compensating controls, and 27% in “never”, not worth remediation effort at all. Roughly a quarter of advisories arrived with no vendor patch, and only 4% were being actively exploited.

In an environment where a patch window means a production stop, that distribution is not a licence to relax. It is an argument for spending the scarce downtime on the 3%, and for buying visibility with the money that would otherwise go on chasing the rest.

Two questions worth settling before the budget meeting

Does an air gap still count as a control?

Rarely, and it is worth testing the claim rather than repeating it. Remote support tunnels, contractor laptops, USB-based updates and cellular modems in vendor-supplied skids all cross gaps that appear on the network diagram as absent. An air gap that has not been verified in the last twelve months should be treated as an assumption, not a control.

Should OT security report into the IT department?

Reporting lines matter less than who is accountable for the consequence. The pattern we see working is a shared programme where IT owns the tooling and identity, engineering owns the process risk and the decision to stop production, and both sign off on the criteria for escalating an anomaly. The 82% figure above is what happens when neither side owns that decision.

📈

Running plants with fewer people on site?

Remote oversight changes both the operating model and the attack surface, often at the same time.

See how remote industrial oversight is reshaping the factory floor

Sources: Dragos, 2026 OT/ICS Cybersecurity Year in Review (ninth annual edition, covering 2025), for the 119 ransomware groups impacting about 3,300 industrial organisations against 80 groups in 2024, the 64% year-over-year rise in attacks, manufacturing as more than two-thirds of victims, the three new threat groups AZURITE, PYROXENE and SYLVANITE, the 26 tracked groups with 11 active in 2025, the expansion of KAMACITE and ELECTRUM into the United States and Europe, operational disruption in all OT ransomware cases responded to in 2025, the misclassification of SCADA server and engineering workstation compromises as IT incidents, 82% of organisations without clear criteria for investigating operational anomalies, 88% of tabletop exercises revealing degraded detection, 46% with adequate OT network monitoring, dwell time of 42 days against 5 days with comprehensive visibility, and the 3% / 71% / 27% now-next-never vulnerability distribution with a quarter of advisories lacking a patch and 4% actively exploited. European Commission press release of 8 July 2026 on the referral of Ireland, Spain, France and the Netherlands to the Court of Justice over NIS2 transposition, and Directive (EU) 2022/2555 (NIS2), Article 34, for the fine ceilings. Regulation (EU) 2024/2847 (Cyber Resilience Act) and the European Commission’s CRA reporting guidance for the dates of 10 December 2024, 11 June 2026, 11 September 2026 and 11 December 2027, and the 24-hour, 72-hour, 14-day and one-month reporting steps via the Single Reporting Platform. ISA/IEC 62443 series for the four-group structure, security levels SL 1 to SL 4, the zones and conduits model, and the August 2024 revision of IEC 62443-2-1. Updated August 2026.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *