
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

For years, cybersecurity has been measured largely through an IT lens: protect data, prevent intrusions, and keep business systems available.
Summary
While that framework still matters, it does not fully account for the systems that keep physical operations resilient in the event of an incident. Operational environments rely on connected technologies that monitor, control, or support physical operations, including cyber-physical systems (CPS), operational technology (OT), the internet of things (IoT), the internet of medical things (IoMT), and building management systems (BMS). These assets are increasingly connected to enterprise networks, cloud platforms, remote-management tools, and third-party vendors.
While this connectivity helps organizations operate more efficiently, it also creates more pathways into systems that impose new risks on production, patient care, facility uptime, and service delivery. Understand the operational impact of cyber risk When the operational layer is compromised, the impact may not look like a typical breach. It can look like an outage, a safety hazard, or a process that can no longer run as expected – all of which have significant financial implications.
Claroty’s 2026 global survey reveals how often cyber incidents are already reaching operational environments. Fifty-eight percent of respondents said their organization experienced a cyberattack that affected operations in the past 12 months. The average incident caused three days of downtime and $1.04 million in financial losses.
Forty percent of respondents also reported a safety incident or hazard following a significant CPS-related incident. For a manufacturer, disruption could mean a production line stops, or product quality is affected. In healthcare, it could mean a connected device or supporting system is unavailable when care teams need it.
In a data center, it could mean problems with the power, cooling, or environmental systems that keep the facility online. Prioritize by operational impact, not just vulnerabilities That changes how organizations need to prioritize risk. A vulnerability on a system supporting a noncritical function is not the same as one affecting power distribution, cooling, production lines, or clinical operations.
Exposure management helps organizations prioritize devices and exposures based on their potential impact to the business, rather than treating every vulnerability equally. The challenge is that many organizations still lack the context to make that distinction. An asset inventory is important, but it is only a starting point.
Teams need to know not only which assets are in their environment but also what they connect to, who can access them, and which operational process they support. Vulnerability data and exposures should also be correlated with asset criticality, communication pathways, and other CPS context to help inform decision-makers on remediation and mitigation. Eliminating every risk is an impossible task.
Many operational systems have long lifecycles, proprietary or legacy protocols, and limited maintenance windows. Taking a system offline for a patch or upgrade may disrupt production or service delivery. In these cases, exposure management helps organizations assess the potential business impact of a compromise and determine how best to reduce risk while maintaining business continuity.
AI adds another layer to the operational risk equation, but it can also help teams manage growing complexity. Seventy percent of respondents said their organization is using AI to some degree across OT and CPS environments. AI can help teams make better use of asset data and focus attention where it matters most.
But 40% said it has also introduced new cybersecurity, compliance, or operational risks, underscoring the need to understand what these tools connect to and which business processes depend on them. Close the governance gap across IT and operations CIOs are increasingly responsible for bridging the gap between IT and operations, even when the systems themselves sit outside traditional IT ownership. In Claroty’s survey, 39% of respondents identified CIOs or IT organizations as primarily accountable for CPS security.
Yet only 16% said IT and operational security governance is fully integrated. That gap is where risk builds. IT, security, and operations each hold a different piece of the risk picture.
When they operate through separate processes and priorities, no one has a complete view. Third-party access is a clear example. Vendors often need remote access to maintain specialized equipment.
While that access may be necessary, it needs to be governed and monitored like any other connection into a critical environment. Three-quarters of survey respondents reported at least one operational incident related to third-party access, while 49% had only partial or no monitoring of third-party connections to operational assets. CIOs do not need to solve every problem at once.
The starting point is understanding which connected assets support critical operations, reducing unnecessary exposure and ensuring recovery plans account for the systems that keep their business running. When a cyber incident can stop production, affect care delivery, or take a facility offline, operational security is a business resilience issue. Explore Claroty’s latest global research for a closer look at how cyber threats are affecting physical operations and how organizations are evolving their cyber-physical systems security strategies in response.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
We've archived 154 other articles touching the same topic (security) , see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.