Background Image
 
Request a Demo
Claroty Toggle Search

Press Release

New Research Finds 58% of Cyber-Physical System Operators Say a Cyberattack Has Impacted Operational Environments in the Past Year

Claroty Uncovers Trends Across AI, Business Continuity, and Compliance for Organizations Protecting Mission-Critical Infrastructure

NEW YORK—October 6, 2026—Claroty, the cyber-physical systems (CPS) protection company, today published new research on operational security trends and challenges facing global organizations, including the fact that 58% of CPS operators say they’ve experienced a cyberattack impacting operational environments in the last 12 months. The report, “The Global State of Operational Security 2026: Protecting Operations Evolves as a Core Business Capability,” is based on a global survey of 2,000 business and technology leaders whose organizations manage CPS. The findings reveal that securing operational technology (OT) and CPS is essential to overall operational resilience, business continuity, digital transformation and AI adoption, maintaining compliance standards, and meeting cyber insurance mandates.

Disruptions to Operational Environments Threaten Business Continuity

The survey showed that cyber incidents impacting CPS result in material effects on the health of a business. It’s a fact that’s driving today’s cybersecurity investment priorities: 37% of survey-takers said operational risk and cyber threats are a top driver of investment, followed by digital transformation/modernization (36%) and the risk of business disruption or revenue loss (29%). Other key findings include:

  • The top impacts from operational incidents were: operational downtime (selected by 43% of respondents), safety incidents and hazards (40%), and financial loss (35%)

  • The average financial loss from an incident impacting operations was $1.04 million, and losses hit larger companies hardest: Organizations with at least 5,000 employees saw $1.6M in average losses, and those with at least 10,000 employees saw $2.25M in average losses

  • The average length of operational downtime from a CPS cyber incident was three days, and nearly 10% of respondents reported downtimes ranging from eight to thirty days

  • Third-party access also contributed to operational risk, with 75% saying they suffered at least one incident impacting operations related to third-party access and 49% said they had only partial or no monitoring of third-party connections

  • Despite costly impacts, IT and operational security remain fragmented, with only a mere 16% reporting that they’ve fully integrated the two

Embracing AI Adoption While Managing AI Threats

Respondents indicated they are ready to implement AI across operational environments to improve efficiency and support human-in-the-loop expertise. This is occurring as organizations prepare for a rapid increase in AI-driven attacks against CPS. Survey results include:

  • 30% said effective use of AI, automation, and advanced analytics is a top success factor for digital transformation initiatives

  • 70% said AI is being used in operational environments, and 71% said AI is a baseline cybersecurity procurement requirement

  • Respondents said AI has improved operational efficiency (48%), decision-making (46%), and enabled new business models (37%)

  • Respondents consider AI-powered cyberattacks (selected by 37%) as a greater risk to operational integrity than ransomware (27%), supply chain compromises (23%), and legacy OT assets (21%)

Navigating Compliance Through Proactive Resilience

The complexities of the regulatory environment and the level of expertise required to understand the convergence of IT and OT operations are creating challenges for organizations, but embracing a proactive approach to compliance helps position organizations for operational resilience. The survey findings show:

  • The most common operational barriers threatening the viability of compliance programs are: ongoing IT/OT alignment challenges (29%), legacy technical debt (26%), and limited asset visibility (16%) 

  • The top three compliance barriers facing organizations are: keeping up with evolving regulations, mandates, and frameworks (38%), managing compliance across multiple sites, regions, business units (35%), and implementing policies, controls needed to achieve compliance (34%)

  • 82% of organizations that have fully integrated IT/OT governance have a proactive or structured compliance approach

  • 75% said they have a proactive and structured approach to compliance management

“Businesses have quickly realized that prioritizing operational resilience is key to ensuring robust protection across the world’s most critical infrastructure,” said Sean Tufts, Field CTO at Claroty. “Critical infrastructure organizations are experiencing a seismic shift in the threat landscape, given the proliferation of AI threats and the current geopolitical landscape. This is driving them to re-position from a standard asset-centric mindset to one centered on operational resilience that combines proactive risk reduction with robust recovery capabilities that protect core processes without halting operations.”

The survey shows that operational resilience must be treated as a cybersecurity imperative and core business priority, with assets protected, segmented, and governed to withstand and rapidly recover from a disruptive incident. Bridging IT/OT governance, mandating strict third-party access controls and monitoring, modernizing business continuity plans, and securing AI adoption are the initiatives CIOs and COOs—those most often cited as accountable (39% of respondents) for operational security and its budget (28% said CIOs are owners)—must prioritize in order to maintain the safety and uptime of their operational environments.

To learn more, download the full report: “The Global State of Operational Security 2026: Protecting Operations Evolves as a Core Business Capability”

Methodology

Claroty partnered with Sapio Research to survey 2,000 full-time company founders, C-level executives, vice presidents, directors, and other technology and business managers spanning 16 industries, and more than 40 countries. All respondents are primary decision-makers, part of decision-making teams, or influence technology purchases and implementations.

About Claroty

Claroty empowers organizations to protect the mission-critical infrastructure that underpins modern life. The AI-powered Claroty Platform serves as the single source of operational truth, providing the deepest visibility and broadest protection across cyber-physical systems (CPS), leveraging five core solutions: asset inventory, exposure management, network protection, secure access, and threat detection. Claroty helps organizations operationalize CPS protection through a programmatic approach designed to reduce risk, maintain operational integrity, and meet compliance–whether in the cloud with Claroty xDome or on-premise with Claroty Continuous Threat Detection (CTD). Claroty is deployed by hundreds of organizations at thousands of sites globally. The company is headquartered in New York City and has a presence in Europe, Asia-Pacific, and Latin America. To learn more, visit claroty.com.

Interested in learning about Claroty's Cybersecurity Solutions?

Claroty
LinkedIn Twitter YouTube Facebook