Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

Survey: Operational Security Becomes Core to the Business

/ / 6 min read
Featured image for our blog: Survey: Operational Security Becomes Core to the Business

A fundamental shift is happening among technology and business leaders when it comes to cybersecurity: as digital transformation has taken hold, there’s a reprioritization happening that elevates the protection of operations as a core business capability.

Claroty sought to learn more about how chief information officers (CIOs), chief operating officers (COOs), and security leaders are bridging the gap between digital and physical environments. We surveyed 2,000 globally, and today we’re publishing an extensive report that explains the trends supporting these key business initiatives. The report includes insights on:

  • The adoption of artificial intelligence and its use in protecting operations

  • How operational security maintains business continuity

  • Where operational security supports ongoing digital transformation efforts

  • How operational security helps meet compliance and insurability requirements

Sample the survey results: Download “The State of Operational Security 2026”

For CIOs, COOs, and CISOs, the security of operational environments is essential to operational resilience. Cyberattacks are now consequential operational events that can impact physical processes, patient care, worker safety, and overall financial performance for an impacted enterprise. Technology and business leaders face a definitive shift when it comes to defending operations; security is now more than just about attack prevention; it’s transforming into a business continuity and rapid recovery practice.

Operational Exposures’ Impact on Business Continuity

Cyberattacks are targeting operational technology (OT), the internet-of-things (IoT), connected medical devices, and smart commercial environments with increased frequency. Claroty Team82 research published earlier this year warned of the risks of unprotected internet-facing operational assets, and the survey results bear this out by demonstrating real consequences to businesses worldwide. 

  • 58% of respondents experienced cyberattacks that impacted operations

    • Downtime, safety incidents, financial loss were the top three impacts noted by respondents

    • Large organizations with at least 5,000 employees suffered an average financial loss of $1.6M; that average grows to $2.25M for companies of 10,000 or more employees. 

  • On average, downtime from an attack impacting operations was three days

    • 9% of respondents reported downtime between 8 days and 30 days. 

  • Third-access poses tangible risks to operations

    • 75% of respondents suffered at least one incident impacting operations related to third-party access

    • 49% of respondents said they had only partial or no monitoring of third-party connections

AI’s Impact on Digital Transformation—and Operational Security

Respondents recognized AI’s role in digital transformation and procurement, with 70% citing at least limited use of AI in OT/CPS environments. More than 30% said AI, autonomous actions, and advanced analytics were critical to the success of digital transformation initiatives. Operational environments are an area where AI’s ability to deliver context to threat and vulnerability information, and carry out predictive analytics, maintenance, and optimization are invaluable. 

It’s showing already for the business leaders among the respondents; 71% said AI’s ability to enable and inform automation and analytics were baseline cybersecurity procurement requirements. 

AI is a strategic issue moving forward where adoption has to be considered against risk. Survey respondents weighed in on AI usage and impact with mixed results. The majority of respondents report positive impacts, but concede to new risks. 

Close to half of respondents said AI has improved efficiency and productivity, while 40% cautioned that AI has also introduced new operational, security, or compliance risks. Another 33% said AI implementations are creating operational challenges or disruptions that must be managed.

Fragmented Governance of Operational Security

Respondents were clear that strong operational security and risk management was the top success factor driving digital transformation projects. Effective use of AI via automation and advanced analytics and high-quality data and data governance were also highly cited as success factors. But there are areas where fragmentation presents challenges such as in IT and operational security governance, accountability over operational security, and control of security budgets. 

The integration of IT and OT security and risk management under one domain is noted as a key driver of digital transformation, yet only 16% of respondents said IT and operational security governance is fully integrated inside their organizations. Structural problems also remain around operations that include accountability and budget control over operational protection. 84% of accountability is split between the CIO/IT office (39%), the CISO and security teams (28%), and operations (17%), while a similar split (75%) is noted regarding budget control.

Re-Prioritizing Compliance and Operational Resilience

For CIOs and COOs increasingly tasked with operational protection, resilience may soon sit alongside compliance as the guiding force of a security program. Operational resilience ensures that critical assets withstand the impacts of ongoing cyberattacks, and therefore continue to support key business goals, even in the event of compromise. 

Three-quarters of our respondents indicated that mature compliance programs have been established, yet to reach full operational resilience, there are barriers. CIOs, operations, and security teams require visibility and asset inventories in order to reduce the risks from exposures (unpatched vulnerabilities, weak configurations, excessive remote access, legacy technology and protocols), and segment critical assets to limit the blast radius of attacks. This is enhanced resilience and quicker recovery in the event of an incident is achieved. 

In unison, as cyber insurance emerges as a key business initiative, its focus on resilience is being noted in our results. The extensive rigor established by cyber insurance underwriters to determine the insurability of an organization is guided by a checklist of controls and processes in place emphasizing operational resilience—and determining coverage.

Recommendations 

CIOs, COOs, and CISOs are re-orienting programmatic protection of operational assets toward measurable resilience. Operational security must proceed under the assumption that compromise is inevitable, and assets must be protected, segmented, and governed in order to withstand and rapidly recover in the event of a disruptive incident. 

As leaders reach the start of 2027 budget planning cycles, here are four recommendations based on the trends surfaced from the results of this survey:

  • Establish a unified IT and operational governance model co-owned by the CIO, COO, and CISO that united accountability and budget control under one office.

  • Third-party access is a major vulnerability, driving an average of three operational cyber incidents per enterprise; securing vendor access provides immediate exposure reduction and satisfies critical cyber insurance underwriting requirements.

  • Transition business continuity and disaster recovery frameworks from traditional IT failover to cyber-physical restoration. Incidents still cause an average of three days of downtime and more than $1M in financial losses. 

  • Establish proactive AI risk frameworks to safely scale modern operational capabilities. AI adoption is accelerating; integrating robust guardrails and security baselines allows leadership to capture digital transformation efficiency without increasing exposure. 

Download The State of Operational Security 2026. 

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook