
The latest OT cybersecurity trends and what to do about them in 2026.
Industrial environments are no longer isolated by nature.
Growing internet exposure, ransomware paralyzing production lines, AI accelerating offensive capabilities, regulation catching up with OT: 2026 is a turning point. Here is what CISOs, CIOs, and industrial site managers need to keep in mind.
Key takeaways
- Two thirds of OT systems are connected to the IT network, and direct internet exposure is growing by 50% per year.
- Nearly 20% of cyberattacks now target OT according to ENISA, up 43% year-on-year.
- 1 in 4 OT organizations experiences a confirmed incident per year, and 40% of those incidents result in a complete operational shutdown.
- AI will drive a surge in patches to be applied, both to OT systems and to the OT security solutions themselves: more software means more vulnerabilities. The patch race is unwinnable in OT. What is needed are software-free protection systems, immune to zero-days.
- NIS2 and other national regulations all converge on the same methodology: asset inventory, attack surface reduction, isolation of critical assets, continuous monitoring, isolated backups.
The evolving threat landscape: OT has become a target
OT is no longer isolated by design. Today, two thirds of industrial systems are connected to their organization’s IT network, and direct internet exposure of those systems is growing by nearly 50% per year. This reality was illustrated last May, in the midst of the Iranian conflict: PLCs on US water and energy industrial networks, directly reachable from the internet, were compromised by Iran-affiliated groups.
The potential impact goes far beyond data loss. An attack on an OT system can trigger production stoppages, damage to assets, harm to people, and environmental consequences. That is precisely what makes these environments such high-potential targets for attackers. According to ENISA, nearly 20% of cyberattacks now target OT, up 43% year-on-year.
For those who lived through IT security twenty years ago, the parallel is striking. The same false sense of security, the same conviction that attacks happen to others, that you are too small to be targeted and the same eventual consequences for those who fail to prepare. The difference is that we can learn from history. If OT accounts for 20% of attacks, it makes sense to allocate at least 20% of the cyber budget to it.
The AI factor: the exploitation window has collapsed
AI is set to intensify the pressure on vulnerability management even further. Anthropic’s Claude Mythos model has generated significant attention in recent weeks for its offensive cybersecurity capabilities, particularly autonomous vulnerability detection. Its performance led Anthropic to withhold public release and instead make it available first to around fifty organizations as part of Project Glasswing, with the goal of allowing them to identify their own weaknesses before the model reaches a wider audience. Access was subsequently extended to two hundred organizations.
The early results are striking: in just one month, more than 10,000 high or critical vulnerabilities were detected across the software of those first partner organizations. The rate of discovery has multiplied tenfold. Microsoft confirmed the effect on the patching side: its June Patch Tuesday set a record for vulnerabilities addressed, which it directly attributes to AI.
What this concretely changes for OT
As soon as a vulnerability is made public, attackers will be able to exploit it almost immediately. The window for planning updates disappears. In IT, this pressure is already difficult to absorb. In OT, it is structurally impossible to manage:– Legacy OT assets often cannot be patched, in some cases, not at all.
– AI will also generate patches for the solutions responsible for protecting OT environments themselves: firewalls, filtering routers, gateways. These devices will need to be patched even more frequently. Fortinet, Palo Alto, and Cisco already appear in ENISA’s top 10 vendors with the most exploited vulnerabilities.
– More software means more vulnerabilities to remediate. In OT, the patch race cannot be won on software terms alone. Software-free protection systems are the answer.
This dynamic places considerable pressure on vendors, who are forced to find and fix their vulnerabilities ever faster, and then on their customers, who must apply those patches within increasingly narrow maintenance windows. In OT, there is no viable solution to this equation if the approach remains purely software-based.
Tightening regulation: a lever as much as a constraint
Regulators have taken the measure of the risk. Critical infrastructure and OT environments are now subject to dedicated regulations in many countries. And that is good news: regulation is always a lever for moving security topics forward within an organization.
The trend is global and accelerating. Following NIS1 and then NIS2 in Europe, Japan and Australia published OT and critical infrastructure-specific requirements in 2025. The United Kingdom followed in January 2026. In France, ReCyF was published to help organizations prepare for NIS2. Canada acted in April, the United States and India in May.
These various regulations converge on a common methodology that can be applied right now.
How to respond: the methodology that has reached consensus
Regulations and field experience converge on the same sequence. This is not a compliance checklist, it is a structured approach designed around the real constraints of OT.
- Inventory assets and network flows
You cannot protect what you do not know. An inventory of OT assets and network flows is the essential starting point for any security initiative. Seclab Xplore offers unique mapping capabilities that facilitate collaboration between IT and OT teams.
Map all devices connected to the OT network, including legacy assets.
Document all existing network flows.
- Reduce the attack surface
Remove assets that are still on the network but no longer in use. Shut down or block flows that have become unnecessary, such as a legacy administration flow kept alive by inertia. Every unjustified connection is a potential attack vector.
Decommission unused assets still connected to the OT network.
Disable or block residual flows with no operational justification.
- Identify critical systems and physically isolate them
Critical systems are those whose proper operation directly conditions the operational process. Once identified, they must be isolated using physical mechanisms: complete disconnection, or hardware-based rather than software-based protection. This is the posture that breaks the patch cycle: software-free protection systems have no software vulnerabilities to remediate. This is precisely what Seclab Xchange and Seclab Xport deliver, with Electronic AirGap technology guaranteeing hardware-level isolation with no dependency on a patch cycle.
Identify OT assets whose failure directly impacts production or physical safety.
Protect those assets with hardware-based isolation mechanisms.
- Put the infrastructure under continuous monitoring
Detect deviations from baseline network behavior: new assets, new flows, anomalous activity. Continuous monitoring enables intrusion detection before it generates operational impact. Seclab Xplore addresses this continuous detection objective.
Deploy continuous monitoring of OT network flows.
Define an alert-handling process suited to OT teams.
- Secure backups
Backups accessible from the network can be encrypted by ransomware, making recovery impossible. OT backups must be tested regularly and physically isolated from the production network. Seclab Xchange enables this type of transfer to isolated environments, with full control over inbound and outbound flows.
Physically isolate OT backups from the production network.
Regularly test restoration procedures.
This is the end-to-end approach that Seclab has built into the Seclab Xcore platform: OT infrastructure visibility, AI-augmented threat detection, and sensitive asset protection for defense-in-depth.
What now?
The threat is real, and AI will drive it further. Organizations that prepare in time will be in a position to limit the damage. The methodology exists. The technologies built for industrial constraints exist. What is needed is the decision to start.
To learn more, watch this excerpt from our June 2026 webinar replay
French webinar with voices translated in English by AI.
FAQ
Why are OT environments harder to secure than IT?
They were designed for availability and long service life, not for cybersecurity. Legacy assets often cannot be patched. Some have no update mechanism built into their design at all. Standard IT remediation methods simply do not apply.
Is firewall-based segmentation enough to protect OT assets?
No. A firewall runs on software, which means it relies on components that are themselves vulnerable. In a context where AI is collapsing the exploitation window, keeping segmentation appliances up to date becomes a challenge in its own right. Hardware-based isolation mechanisms, with no attackable software stack, offer a structural guarantee that software alone cannot provide.
Where to start concretely?
With the inventory. Every regulation agrees on this first step: map OT assets and network flows. You cannot protect what you do not know.
