Nearly 60% of critical infrastructure organizations experienced a significant cybersecurity incident in the past year, while widespread gaps in OT visibility, legacy infrastructure and IT/OT integration continue to complicate security, according to Palo Alto Networks’ new State of Critical Infrastructure Cybersecurity Report.
The report surveyed more than 1,600 security leaders across manufacturing, healthcare and life sciences, energy and utilities, transportation, and government and public sector organizations in 11 countries. Among the findings:
- 68% do not have complete, real-time visibility into all assets connected to their OT networks.
- An average of 23% of connected OT assets are unmanaged or difficult to monitor.
- 42% identify legacy, unpatchable OT assets as their biggest cybersecurity risk.
- 59% experienced a significant security breach in the past year, with one in five affected multiple times.
- Among organizations experiencing incidents, 50% cited safety concerns, 49% unplanned downtime, 46% production disruption and 46% financial losses.
- Unplanned downtime costs organizations an average of $288,563 per hour.
- 74% have not fully integrated their IT and OT security operations.
- Only 37% have comprehensive OT asset visibility, while 40% have virtual patching or other compensating controls for vulnerable assets.
- 95% are concerned about Frontier AI-powered attacks targeting critical infrastructure, while 91% expect AI-driven cybersecurity to play a role in defending against them.
- 84% expect 5G to be widely or extensively adopted within their organizations over the next two to three years.
The report also found that organizations use an average of seven disparate security systems and tools. Fifty-nine percent said multiple systems create operational complexity, 56% reported higher operating costs and 41% said tool sprawl contributes to delayed incident response.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Critical infrastructure security is constrained by assets that cannot be taken offline long enough to patch, while geopolitical tensions and expanding connectivity increase pressure on providers already working with limited resources.
“Palo Alto Networks’ 2026 State of Critical Infrastructure Cybersecurity Report connects that pressure to real operational consequences, including safety concerns, unplanned downtime, production disruption, and financial losses. The common thread is incomplete visibility across legacy systems, unmanaged devices, private 5G networks, and other connected assets. Separate IT and OT security teams, along with multiple disconnected tools, make the response slower and harder to coordinate.
“The burden is heavier for utilities, hospitals, manufacturers, transport operators, and government agencies because they cannot treat cybersecurity as a normal software-maintenance exercise. A security team may know that a programmable logic controller (PLC) is vulnerable, but still lack a reliable answer to the question that matters operationally, which pump, production step, or safety process does it control? Without that context, a vulnerability score cannot tell the team what to protect first.
“Time-to-protection is the meaningful measure for unpatchable OT. Passive asset discovery, network segmentation, strict remote access, and virtual patching can block exploitation while engineering teams test a vendor fix and schedule a safe maintenance window.
“AI will compress the attacker’s timeline while defenders are still establishing what a connected asset does, what it controls, and whether it can be safely changed. Constrained headcount makes that gap harder to close. AI can multiply a small team’s reach, but safe use still requires people who understand the model, the network, and the physical process. A facility without that technical talent could turn automation into another unmonitored dependency. For providers facing geopolitical pressure and constrained resources, connecting every alert to the physical process that asset controls is the priority.”
Damon Small, Board of Directors, Xcape, Inc.:
“Operational disruptions averaging nearly $290,000 per hour in downtime highlight the staggering financial risks of operational technology (OT) vulnerabilities. The convergence of OT and IT networks has been underway for nearly three decades, yielding tangible business efficiencies while simultaneously introducing severe cyber threats. Early examples of targeted OT attacks date back to the 2000s and have steadily escalated in frequency and sophistication. Today, legacy and unpatchable devices combined with fragmented security operations leave defenders blind to over two-thirds of their connected environments. Rather than chasing hype around emerging threat vectors, security leaders must prioritize foundational controls: continuous passive network monitoring to establish real-time asset inventories, strict network segmentation to isolate vulnerable systems, and unified identity enforcement across IT and OT boundaries.”
“Critical Takeaways:
- Unplanned downtime from OT security incidents costs organizations an average of $288,563 per hour.
- Decades of IT and OT convergence leave 68% of critical infrastructure security leaders without real-time visibility into connected assets.
- Effective defense requires prioritizing basic controls like network segmentation and passive monitoring over speculative AI threat vectors.
“Buying a seventh security tool will not fix the fact that nobody knows what is plugged into the OT network.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This is unfortunately what we should expect when we look at a lot of these organizations. What you’re seeing is technological spread. Organizations have a tremendous amount of legacy technology that can’t simply be ripped out and replaced. At the same time, newer and more secure technologies are being introduced, but that doesn’t mean they’re evenly distributed across the organization. There’s that great quote, ‘The future is already here. It’s just not evenly distributed.’ I think this story is a perfect example of that.
“What worries me even more is the coming age of AI, where people can create applications and SaaS services incredibly quickly without necessarily knowing how to code. I believe the technical complexity of these environments is going to increase, not decrease. And complexity is the enemy of computer security. Security teams are going to be dealing with new technologies being deployed incredibly quickly, legacy technologies that were never properly secured, and constant pressure to get things into production as fast as possible. All of those problems become even more pronounced when you get into SCADA, ICS, and OT environments.”
Critical infrastructure should be treated as critical. Which means that any and all measures should be taken to secure it 100% of the time. Otherwise adversaries will pwn it 100% of the time.
FBI, Secret Service warn FortiBleed campaign has compromised 86,000+ devices
Posted in Commentary with tags FBI, Secret Service on October 7, 2026 by itnerdThe FBI and U.S. Secret Service are warning that the ongoing FortiBleed credential-compromise campaign has affected more than 86,644 Fortinet devices across 194 countries, according to a new joint cybersecurity advisory.
The campaign targets internet-facing FortiGate firewalls and SSL VPN gateways, using credentials obtained from previous Fortinet leaks and infostealer logs along with password spraying and credential stuffing. Stolen password hashes are sent to a distributed GPU cluster where attackers attempt to crack them and convert the data into usable credentials.
After gaining access, attackers create new administrative accounts to maintain persistence and can move further into victim networks by enumerating Active Directory accounts and searching for privileged credentials. In some incidents, attackers have changed passwords or deleted legitimate accounts, locking organizations out of their own Fortinet devices and requiring remediation beyond standard patching and password resets.
The FBI and Secret Service said the operation ultimately packages and sells working VPN configurations and access to compromised networks to other threat actors. The FortiBleed attack chain has already been observed providing initial access to ransomware affiliates, including INC/Lynx and Payload ransomware.
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“FortiBleed is a good example of why organizations can’t treat perimeter security appliances as ‘set it and forget it’ infrastructure. Firewalls and VPN gateways are high-value targets because compromising one can give an attacker a trusted entry point into the network.
“What makes this campaign particularly concerning is that organizations may be dealing with more than a vulnerability that needs to be patched. If attackers have valid credentials or have already created new administrative accounts, applying an update and changing a password may not remove them from the environment. Defenders need to assume that previously exposed devices could already be compromised and investigate accordingly.
“Organizations should review administrative accounts, authentication logs and configuration changes, rotate potentially exposed credentials, enforce MFA wherever possible, restrict management interfaces from the public internet and look for evidence of lateral movement. If privileged credentials were accessible from the compromised environment, those credentials should also be considered potentially exposed.
“The ransomware connection also shows how mature the cybercrime ecosystem has become. The people gaining access don’t necessarily have to be the ones deploying ransomware. Initial access itself has value, and compromised VPN access can be packaged and sold to another criminal group that takes the attack from there.”
John Strand, Owner, Black Hills Information Security, Inc.:
“The most interesting thing to me about this particular attack is that some of these attackers are actually selling access to compromised networks to other threat actors. It’s basically malicious hacking as a service. And that concerns me because this isn’t necessarily a ransomware-style attack. You’re getting much closer to what we traditionally think of as an advanced persistent threat, and the persistence is what scares me. I’m not nearly as worried about an attacker who gets into an organization, locks everything down, and announces their presence. I’m terrified of the attacker who wants to quietly live inside that organization for as long as possible. This attack gives them exactly that kind of access.”
If you haven’t addressed FortiBleed, you should have an incentive to do it now. If you have addressed FortiBleed, congratulations. Now do again as it is better to be safe than sorry.
Leave a comment »