A Stark Warning: Cyber Threats Looming Over Cyber-Physical Systems
Recent research conducted by Claroty, a prominent player in cyber-physical systems (CPS) protection, has unveiled alarming statistics regarding the state of cybersecurity among CPS operators. The company's findings, published in the report titled "The Global State of Operational Security 2026 Protecting Operations Evolves as a Core Business Capability," reveal that
58% of CPS operators have faced a cyberattack affecting their operational environments in the preceding year. This statistic underscores a critical urgency as organizations increasingly rely on CPS technologies to maintain operational resilience, ensuring business continuity amidst escalating digital threats.
Disruptions Impacting Business Operations
According to the research, over one-third (37%) of executives cited operational risk and cyber threats as pivotal drivers for their cybersecurity investments. The urgency is echoed in the findings regarding operational incidents—
43% of respondents reported operational downtime as a significant impact of these cyber incidents, while
40% noted associated safety incidents and hazards. The financial ramifications are daunting, with the average loss from such incidents reaching approximately
$1.04 million. Notably, larger organizations with workforces exceeding 10,000 employees experienced even more severe losses, averaging
$2.25 million.
Unexpected downtimes can be detrimental, with the average incident length estimated at
three days. Alarmingly, nearly
10% of respondents acknowledged experiencing operational downtimes between eight and thirty days. Furthermore, issues stemming from third-party access were highlighted, with
75% of operators reporting incidents linked to this access and
49% indicating an insufficient level of monitoring for these connections. Despite the evident risks, the integration of IT and operational security remained low, with only
16% of organizations stating they had fully blended the two.
Navigating the Age of AI and Cybersecurity
With the rise of AI technologies, organizations are keenly aware of the dual-edged sword these tools represent—improving efficiencies while also presenting new security challenges. The survey showed that
70% of organizations utilize AI in their operations, with
30% acknowledging its role as critical for success in digital transformation efforts. The application of AI has yielded improved decision-making (46%) and operational efficiency (48%) among users. Yet, the shadow of AI-driven cyberattacks looms large, with
37% of respondents considering these threats to be a greater risk to operational integrity than ransomware and other attacks.
Compliance Challenges Looming Ahead
The regulatory landscape further complicates the cybersecurity landscape. Organizations face several hurdles in compliance management, including maintaining alignment between IT and OT operations (29%) and grappling with legacy system inefficiencies (26%). The report highlights that
38% of respondents regard the challenge of keeping up with evolving regulations as a pressing barrier. Proactively addressing these compliance issues can enhance operational resilience, as
82% of organizations with integrated IT/OT governance reported adopting structured compliance approaches.
Sean Tufts, Field CTO at Claroty, emphasized that cultivating operational resilience is vital for robust protection across critical infrastructure. He noted, "Organizations must transition from a mere asset-centric mindset to adopting an operational resilience-focused strategy, prioritizing risk reduction while enhancing recovery capabilities."
In today’s digital landscape, safeguarding CPS has become an imperative. The report serves as a clarion call for businesses, urging them to refine their cybersecurity strategies by establishing effective governance between IT and OT, enforcing rigorous third-party access controls, and modernizing business continuity plans.
To delve deeper into the research findings, download the complete report at
Claroty's website.