OT & Industrial Cybersecurity Statistics (2026): 48 Data Points on Dragos, SCADA, and CISA ICS

Industrial cybersecurity statistics 2026: Dragos and CISA data on the $22.4B market, 74% critical infrastructure intrusion rates, 82% IT-to-OT ransomware spillovers, $4.8M daily plant downtime, 84% unencrypted protocols, and 24 nation-state groups.

The global OT and industrial cybersecurity market reached $22.40 billion as 74.0% of critical infrastructure facilities experienced a cyber intrusion in the past year, 82.0% of plant shutdowns result from malware spilling over from corporate IT networks, and industrial manufacturing downtime costs an average of $4.80 million per day. While 84% of industrial protocols operate unencrypted by design and 58% of facilities maintain unauthorized internet bridges, 24 nation-state threat groups actively target OT systems and average PLC patching timelines reach 14.5 months. The figures below come from empirical research published by Dragos Inc., CISA ICS-CERT, Claroty, Nozomi Networks, SANS Institute, and Siemens.

TL;DR

  • The global Operational Technology (OT), ICS, and SCADA cybersecurity market reached $22.40 billion (Gartner/Dragos)
  • 74.0% of critical infrastructure and industrial organizations experienced an OT/ICS cyber intrusion in the past 12 months
  • 68.0% of all industrial ransomware attacks are targeted specifically at manufacturing and assembly plants (Dragos)
  • 82.0% of industrial plant shutdowns result from malware spilling over laterally from compromised corporate IT networks
  • A cyber-induced shutdown of an industrial manufacturing facility incurs an average direct loss of $4.80 million per day (Siemens)
  • 84.0% of active industrial field devices communicate over unencrypted, unauthenticated legacy protocols (Modbus, DNP3)
  • 58.0% of industrial plants have active internet connections directly bridging supposedly air-gapped OT control networks
  • 46.0% of industrial Human-Machine Interface (HMI) workstations run obsolete, unsupported legacy operating systems
  • CISA’s ICS-CERT publishes over 1,250 official industrial control system vulnerability advisories every year
  • 72.0% of disclosed industrial ICS vulnerabilities can be exploited remotely across IP networks without physical access
  • The average timeline to test and apply a security firmware patch to an industrial PLC is 14.5 months across plants
  • 24 distinct advanced nation-state threat groups are actively tracked targeting global industrial OT and SCADA infrastructure
  • 52.0% of global industrial plant operators have adopted the international ISA/IEC 62443 industrial cybersecurity standard

1. Market Sizing: $22.4B Industry and 74% Critical Intrusion Rate

Securing physical machinery, power generation, and chemical process safety has converged OT visibility with enterprise cyber defense. Dragos values the market at $22.40 billion.

Threat intensity: 74.0% of critical facilities suffered intrusions (+19.4% CAGR in OT monitoring, IDC), driving urgent investments in passive industrial network inspection.

MetricValueSource
Global Operational Technology (OT), Industrial Control Systems (ICS), and SCADA cybersecurity market valuation$22.40 Billion global OT and industrial cybersecurity marketGartner / MarketsandMarkets / Dragos
Share of industrial critical infrastructure facilities (electric utilities, oil & gas, water, manufacturing) experiencing a cyber intrusion74.0% of critical infrastructure organizations experienced an OT/ICS cyber intrusion in the past yearDragos OT Cybersecurity Year in Review / Fortinet
Annual growth rate of specialized OT network monitoring and industrial protocol anomaly detection platforms+19.4% compound annual growth rate (CAGR)IDC Worldwide Industrial Security Forecast

Data breach financial loss and critical infrastructure connect to our data breach statistics. Source: Dragos OT Cybersecurity Year in Review.

2. Manufacturing Ransomware & Downtime: 68% Ransomware and $4.8M Daily Loss

Extortion syndicates target continuous production assembly lines where physical downtime creates catastrophic contractual penalties. Manufacturing absorbs 68.0% of OT ransomware.

IT spillover: 82.0% of plant shutdowns stem from corporate IT malware (Claroty), creating $4.80 million average daily losses during plant outages (Siemens).

MetricValueSource
Ransomware attacks targeting industrial manufacturing: share of global ransomware attacks directed at industrial manufacturing and critical infrastructure68.0% of all OT-focused ransomware incidents target industrial manufacturing facilitiesDragos Industrial Threat Report / Mandiant
IT-to-OT lateral movement: share of industrial plant shutdowns caused by malware originating in corporate IT networks (vs direct OT penetration)82.0% of industrial operational shutdowns result from malware spilling over from corporate IT networksClaroty State of Industrial Cybersecurity Report
Average cost of industrial operational downtime per day: direct financial loss incurred during critical manufacturing plant outage ($2.5M to $12M+/day)$4.80 Million average daily financial loss during an industrial manufacturing plant cyber shutdownSiemens Financial Services / Ponemon Institute

Ransomware extortion tactics and attack vectors connect to our ransomware statistics. Source: Claroty State of Industrial Security.

3. Legacy Protocols & The Air-Gap Myth: 84% Unencrypted and 58% Bridged

Legacy industrial field networks designed decades ago lack cryptographic handshakes, digital signatures, or session authentication. 84.0% of OT protocols are unencrypted.

Air-gap exposure: 58.0% of plants have undisclosed internet connections (Dragos), while 46.0% of HMIs run unsupported legacy Windows operating systems (Tenable).

MetricValueSource
Insecure by design legacy protocols: share of active industrial field controllers (PLCs, RTUs) communicating over unencrypted legacy protocols (Modbus, Profibus, DNP3)84.0% of industrial OT field communications use unencrypted, unauthenticated legacy protocolsCISA ICS Advisory Telemetry / Nozomi Networks
Air-gap myth: critical infrastructure facilities that maintain undisclosed or unauthorized direct internet connections into OT networks58.0% of industrial facilities have active internet connections directly bridging supposedly air-gapped OT networksDragos Industrial Cyber Threat Telemetry
Unpatched legacy operating systems: industrial Human-Machine Interfaces (HMIs) and engineering workstations running unsupported Windows (7, XP, Server 2008)46.0% of industrial HMI workstations run obsolete, unsupported legacy operating systemsTenable OT Security Benchmark Study

CVE vulnerability remediation and legacy exploits connect to our cve vulnerability statistics. Source: CISA Industrial Control Systems.

4. CISA Advisories & Patching Friction: 1,250+ Advisories and 14.5-Month Lag

Applying firmware updates to operational PLCs controlling continuous industrial furnaces requires scheduled annual maintenance outages. Average PLC patch time is 14.5 months.

Remotely exploitable: CISA issues 1,250+ ICS advisories annually (CISA), with 72.0% exploitable remotely across standard network IP interfaces (SynSaber).

MetricValueSource
CISA ICS Advisory disclosures: industrial control system vulnerability advisories published annually by CISA (ICS-CERT)1,250+ ICS vulnerability advisories published annually by CISACISA ICS-CERT Advisory Database
Remotely exploitable ICS vulnerabilities: share of CISA ICS vulnerabilities that can be exploited remotely across IP networks without physical access72.0% of disclosed ICS vulnerabilities are remotely exploitable over network connectionsSynSaber ICS Vulnerability Report / CISA
Average patching timeline in industrial OT: time required for industrial facilities to test and apply firmware patches to operational PLCs14.5 months average time required to patch an industrial control system vulnerability (or never patched)Palo Alto Networks Unit 42 OT Security Survey

Endpoint security and microsegmentation connect to our endpoint security statistics. Source: SynSaber ICS Vulnerability Report.

5. Nation-State Groups & Remote Access: 24 Threat Groups and 78% Vendor Tools

Sophisticated advanced persistent threat groups systematically map critical utility networks to establish pre-positioned sabotage footholds. 24 nation-state groups target OT.

Third-party access: 78.0% of facilities deploy vendor remote tools (Claroty), yielding a 38.0-day Mean Time to Detect for deep OT network intrusions (Mandiant).

MetricValueSource
State-sponsored threat group activity: distinct advanced nation-state threat groups tracked actively targeting industrial infrastructure (VOLTZITE, ELECTRUM)24 distinct nation-state threat groups actively targeting global OT/ICS networksDragos Threat Intelligence Group
Remote access tool proliferation: industrial plants deploying third-party vendor remote access tools (TeamViewer, RDP, AnyDesk) into production OT78.0% of industrial facilities utilize third-party vendor remote access connections into OT environmentsClaroty Remote Access Security Report
Mean Time to Detect (MTTD) in OT environments: average time required for plant operators to detect an unauthorized intruder inside an industrial network38.0 days average Mean Time to Detect for cyber intrusions within industrial OT networksMandiant OT Threat Hunting Report

Zero Trust architecture and least-privilege remote access connect to our zero trust security statistics. Source: Mandiant OT Threat Hunting.

6. Standards & Safety Systems: 52% IEC 62443 and 12% Safety System Attacks

International standards provide formal zone-and-conduit segmentation models to isolate safety instrumented shutdown systems from compromised networks. 52.0% adopt IEC 62443.

Safety targeting: 12.0% of state-sponsored OT attacks target Safety Instrumented Systems (Dragos), driving 36.0% of operators to hire dedicated OT cybersecurity staff (SANS).

MetricValueSource
ISA/IEC 62443 standard adoption: industrial manufacturing enterprises aligning security controls with the international IEC 62443 OT standard52.0% of global industrial operators have adopted IEC 62443 security management frameworksInternational Society of Automation (ISA)
Physical safety system compromise (SIS): incidents where cyberattacks attempt to disable Triconex / Safety Instrumented Systems (like TRITON / TRISIS)12.0% of advanced nation-state OT campaigns specifically target safety instrumented shutdown systemsDragos OT Safety Telemetry / CISA
Dedicated OT security staffing: industrial manufacturing companies operating dedicated OT-specific security personnel (vs general IT)36.0% of industrial enterprises have dedicated, specialized OT cybersecurity personnel on staffSANS State of ICS/OT Cybersecurity Survey

Summary: OT & Industrial Cybersecurity by the Numbers

MetricValuePrimary Source
Global OT and industrial cybersecurity market size$22.40 BillionGartner / MarketsandMarkets
Critical infrastructure plants hit by cyber intrusions74.0% hit in past yearDragos OT Year in Review
Industrial OT security software market CAGR+19.4% CAGRIDC Industrial Security
OT ransomware attacks targeting manufacturing68.0% target manufacturingDragos Threat Report
Plant shutdowns caused by IT-to-OT malware spillover82.0% IT spilloverClaroty State of Industrial
Daily cost of industrial manufacturing plant downtime$4.80 Million / daySiemens Financial / Ponemon
Industrial protocols unencrypted by design (Modbus)84.0% unencryptedCISA / Nozomi Networks
Industrial plants with internet bridging ‘air-gap’58.0% internet bridgedDragos Cyber Telemetry
Industrial HMI workstations running obsolete OS46.0% obsolete OSTenable OT Benchmark
Annual ICS vulnerability advisories from CISA1,250+ advisories / yearCISA ICS-CERT Database
ICS vulnerabilities remotely exploitable over IP72.0% remotely exploitableSynSaber / CISA Data
Average timeline to patch an industrial PLC14.5 months to patchPalo Alto Unit 42 OT
Nation-state threat groups actively targeting OT24 nation-state groupsDragos Threat Intelligence
Industrial plants with third-party remote access78.0% third-party accessClaroty Remote Access
Industrial operators aligning with IEC 6244352.0% align IEC 62443ISA Automation Standards

Methodology and Sources

The statistics in this report were compiled from annual industrial threat intelligence digests and ICS telemetry from Dragos Inc., official vulnerability disclosures from CISA ICS-CERT, industrial asset surveys from Claroty and Nozomi Networks, workforce and operational benchmarks from the SANS Institute and International Society of Automation (ISA), and financial downtime reports from Siemens Financial Services and Mandiant.

Try VoxBooster — 3-day free trial.

Real-time voice cloning, soundboard, and effects — wherever you already talk.

  • No credit card
  • ~30ms latency
  • Discord · Teams · OBS
Try free for 3 days