A fundamental shift is happening among technology and business leaders when it comes to cybersecurity: as digital transformation has taken hold, there’s a reprioritization happening that elevates the protection of operations as a core business capability.
Claroty sought to learn more about how chief information officers (CIOs), chief operating officers (COOs), and security leaders are bridging the gap between digital and physical environments. We surveyed 2,000 globally, and today we’re publishing an extensive report that explains the trends supporting these key business initiatives. The report includes insights on:
The adoption of artificial intelligence and its use in protecting operations
How operational security maintains business continuity
Where operational security supports ongoing digital transformation efforts
How operational security helps meet compliance and insurability requirements
For CIOs, COOs, and CISOs, the security of operational environments is essential to operational resilience. Cyberattacks are now consequential operational events that can impact physical processes, patient care, worker safety, and overall financial performance for an impacted enterprise. Technology and business leaders face a definitive shift when it comes to defending operations; security is now more than just about attack prevention; it’s transforming into a business continuity and rapid recovery practice.
Cyberattacks are targeting operational technology (OT), the internet-of-things (IoT), connected medical devices, and smart commercial environments with increased frequency. Claroty Team82 research published earlier this year warned of the risks of unprotected internet-facing operational assets, and the survey results bear this out by demonstrating real consequences to businesses worldwide.
58% of respondents experienced cyberattacks that impacted operations
Downtime, safety incidents, financial loss were the top three impacts noted by respondents
Large organizations with at least 5,000 employees suffered an average financial loss of $1.6M; that average grows to $2.25M for companies of 10,000 or more employees.
On average, downtime from an attack impacting operations was three days
9% of respondents reported downtime between 8 days and 30 days.
Third-access poses tangible risks to operations
75% of respondents suffered at least one incident impacting operations related to third-party access
49% of respondents said they had only partial or no monitoring of third-party connections
Respondents recognized AI’s role in digital transformation and procurement, with 70% citing at least limited use of AI in OT/CPS environments. More than 30% said AI, autonomous actions, and advanced analytics were critical to the success of digital transformation initiatives. Operational environments are an area where AI’s ability to deliver context to threat and vulnerability information, and carry out predictive analytics, maintenance, and optimization are invaluable.
It’s showing already for the business leaders among the respondents; 71% said AI’s ability to enable and inform automation and analytics were baseline cybersecurity procurement requirements.
AI is a strategic issue moving forward where adoption has to be considered against risk. Survey respondents weighed in on AI usage and impact with mixed results. The majority of respondents report positive impacts, but concede to new risks.
Close to half of respondents said AI has improved efficiency and productivity, while 40% cautioned that AI has also introduced new operational, security, or compliance risks. Another 33% said AI implementations are creating operational challenges or disruptions that must be managed.
Respondents were clear that strong operational security and risk management was the top success factor driving digital transformation projects. Effective use of AI via automation and advanced analytics and high-quality data and data governance were also highly cited as success factors. But there are areas where fragmentation presents challenges such as in IT and operational security governance, accountability over operational security, and control of security budgets.
The integration of IT and OT security and risk management under one domain is noted as a key driver of digital transformation, yet only 16% of respondents said IT and operational security governance is fully integrated inside their organizations. Structural problems also remain around operations that include accountability and budget control over operational protection. 84% of accountability is split between the CIO/IT office (39%), the CISO and security teams (28%), and operations (17%), while a similar split (75%) is noted regarding budget control.
For CIOs and COOs increasingly tasked with operational protection, resilience may soon sit alongside compliance as the guiding force of a security program. Operational resilience ensures that critical assets withstand the impacts of ongoing cyberattacks, and therefore continue to support key business goals, even in the event of compromise.
Three-quarters of our respondents indicated that mature compliance programs have been established, yet to reach full operational resilience, there are barriers. CIOs, operations, and security teams require visibility and asset inventories in order to reduce the risks from exposures (unpatched vulnerabilities, weak configurations, excessive remote access, legacy technology and protocols), and segment critical assets to limit the blast radius of attacks. This is enhanced resilience and quicker recovery in the event of an incident is achieved.
In unison, as cyber insurance emerges as a key business initiative, its focus on resilience is being noted in our results. The extensive rigor established by cyber insurance underwriters to determine the insurability of an organization is guided by a checklist of controls and processes in place emphasizing operational resilience—and determining coverage.
CIOs, COOs, and CISOs are re-orienting programmatic protection of operational assets toward measurable resilience. Operational security must proceed under the assumption that compromise is inevitable, and assets must be protected, segmented, and governed in order to withstand and rapidly recover in the event of a disruptive incident.
As leaders reach the start of 2027 budget planning cycles, here are four recommendations based on the trends surfaced from the results of this survey:
Establish a unified IT and operational governance model co-owned by the CIO, COO, and CISO that united accountability and budget control under one office.
Third-party access is a major vulnerability, driving an average of three operational cyber incidents per enterprise; securing vendor access provides immediate exposure reduction and satisfies critical cyber insurance underwriting requirements.
Transition business continuity and disaster recovery frameworks from traditional IT failover to cyber-physical restoration. Incidents still cause an average of three days of downtime and more than $1M in financial losses.
Establish proactive AI risk frameworks to safely scale modern operational capabilities. AI adoption is accelerating; integrating robust guardrails and security baselines allows leadership to capture digital transformation efficiency without increasing exposure.
Interested in learning about Claroty's Cybersecurity Solutions?
Life, uninterrupted
We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.