Industrial cyber risk is no longer a forecast. The 2026 threat reports, published by the organisations that track operational technology (OT, the systems that run physical processes) attacks for a living, all describe the same year: more attackers, more automation, and manufacturing once again the single most-attacked sector. The numbers are worth reading closely, because they do not just say the threat grew. They say where it now comes in.
In 2025, ransomware against industrial organisations rose 64% and manufacturing was the most-attacked sector for a fifth straight year. IT/OT convergence is the reason, and the risk concentrates at the boundary where corporate and operational networks meet.
This article reads the 2026 data for what it tells a security or operations leader who has to quantify the risk, justify a budget, or answer a regulator. It is the evidence layer for the rest of our work on securing IT/OT convergence.
The threat industrialised in 2025
Three independent reports, using different methods, point the same way.
Dragos, an OT-focused security firm, tracked 119 ransomware groups hitting roughly 3,300 industrial organisations in 2025, up from 80 groups the year before, with attack volume rising 64% year on year. More than two thirds of the victims were in manufacturing. The firm now tracks 26 distinct threat groups targeting industrial systems, 11 of them active during 2025, and named three new ones (Azurite, Pyroxene and Sylvanite).
IBM's X-Force Threat Intelligence Index 2026 found manufacturing was the most-attacked industry for the fifth consecutive year, accounting for 27.7% of all incidents its team responded to across every sector. The most common goal in those incidents was data theft.
Fortinet's 2025 State of Operational Technology and Cybersecurity Report, a survey of more than 550 OT professionals, found that half of organisations reported at least one cybersecurity incident over the year. It also recorded a governance shift: more than 95% have now raised OT security to executive level, and responsibility sitting with a CISO or the C-suite climbed to 52%, against 16% in 2022.
| What the 2026 data shows | Figure (2025) | Source |
|---|---|---|
| Ransomware attack volume against industry, year on year | +64% | Dragos 2026 |
| Industrial organisations hit by ransomware | ~3,300 | Dragos 2026 |
| Share of ransomware victims in manufacturing | more than two thirds | Dragos 2026 |
| Manufacturing as most-attacked sector | 5th year, 27.7% of incidents | IBM X-Force 2026 |
| Organisations reporting one or more incidents | 50% | Fortinet 2025 |
What changed is not just the count. An attack on an industrial site used to be rare and targeted. It is now routine, and run like a business.
Why these numbers point to the IT OT boundary
The reports agree on something more specific than volume: how the attackers get in. They get in through the connections that convergence created.
The 2026 reports point to the same entry points, all of them at the edge of the network rather than inside the plant:
- Public-facing applications. IBM recorded a 44% increase in attacks that began with the exploitation of an internet-facing application.
- Unpatched vulnerabilities. Vulnerability exploitation was the single leading way in, behind 40% of the incidents IBM responded to.
- Exposed perimeter appliances. Dragos, in its 2025 report, found that 22% of the industrial vulnerability advisories it analysed were both exploitable over the network and exposed at the perimeter, up from 16% the year before. The new group Sylvanite took exactly this route, breaking into United States utilities through vulnerabilities in perimeter appliances.
None of that is an attack on a programmable logic controller (PLC) directly. It is an attack on the edge of the network, on the internet-facing applications, the remote-access appliances and the exposed services that did not exist when OT was air-gapped. Ransomware reaches the factory by entering through IT and crossing the seam into OT. That seam is the IT/OT boundary, and it is where convergence put the risk.
This is not theoretical. In March 2019, the LockerGoga ransomware tore through the IT network of Norsk Hydro, one of the world's largest aluminium producers, reaching 22,000 computers across 170 sites. It did not target the industrial controllers, yet automated production lines were shut down and factories fell back to manual operation, pen and paper. The incident cost the company around 70 million US dollars. An IT compromise crossed into production, across a boundary that was never built to contain it.
Norsk Hydro was not an outlier. The same pattern, an IT compromise that ends up halting physical operations, has hit one industry after another:
| Organisation | Year | Sector | What happened |
|---|---|---|---|
| Merck | 2017 | Pharmaceuticals | NotPetya crippled production, including the Gardasil vaccine, with more than 1 billion US dollars in claimed damages. The same NotPetya wave also hit Maersk, Mondelez and Saint-Gobain on the same day. |
| Renault-Nissan | 2017 | Automotive | WannaCry idled five Renault sites and Nissan's Sunderland plant. |
| JBS | 2021 | Food | REvil ransomware shut beef and pork plants in the US, Canada and Australia, and an 11 million US dollar ransom was paid. |
| Colonial Pipeline | 2021 | Fuel and energy | DarkSide ransomware hit the IT and billing systems; the operator shut the pipeline for several days, triggering fuel shortages on the US East Coast. |
| Clorox | 2023 | Consumer goods | An attack that started at the IT help desk caused major product outages and an estimated 356 million US dollars in lost sales. |
In every case the attackers came in through IT. The damage landed on production.
The cost is not only technical
When an industrial site is hit, the consequence is physical, not just informational. Dragos found that of the ransomware cases it handled in 2024, 25% led to a full shutdown of an OT site and 75% caused disruption to operations. Lost production, spoiled material and safety exposure follow from that, which is why OT prioritises availability above all else.
The data also exposes a blind spot. Dragos reported that only 46% of the OT environments it assessed had adequate network monitoring in place. Where visibility was strong, organisations detected and contained an OT ransomware incident in about 5 days, against an industry-wide average of 42 days. The gap between those two numbers is the difference between a contained event and a shutdown.
Not sure how exposed your IT/OT boundary is? Brixio maps where your operational network meets IT and where the risk concentrates, before any deployment. → Book an OT risk assessment
AI is now on both sides of the boundary
The defining shift in the 2026 reports is artificial intelligence (AI), and it cuts both ways.
On the attacker's side, AI lowers the cost of an attack and raises its speed. IBM titled its 2026 index "AI-Driven Attacks are Escalating", and read alongside Cloudflare's 2026 Threat Report, the two describe several ways automation now changes the threat:
- Faster vulnerability discovery. AI-assisted analysis is part of what drove the 44% rise in attacks through public-facing applications (IBM).
- Stolen AI credentials at scale. More than 300,000 sets of credentials for a single AI service were advertised on criminal markets in 2025 (IBM).
- Attacks that adapt in real time. Attackers use AI to research targets, sift large data sets and adjust their approach as they go (IBM).
- Automated access attempts. 94% of login attempts Cloudflare observed now come from bots, and 63% of logins reuse credentials compromised elsewhere.
Volumetric attacks have scaled with the same automation: a record 31.4 Tbps distributed denial-of-service (DDoS) attack in late 2025, the total number of DDoS attacks more than doubling over the year, and attacks above 1 Tbps growing 700%.
For a converged industrial site, this is the worst combination. The boundary is the entry point, the legacy equipment behind it cannot keep pace, and the attacks now arrive at machine speed.
On the defender's side, the same automation is the answer. An attack that peaks in seconds cannot be met by a human reading a dashboard. It has to be met by automated defence at the network edge:
- DDoS mitigation that triggers in seconds, absorbing volumetric attacks before they reach the convergence layer.
- Machine-learning bot management that separates real users from the automated login attempts now making up most of the traffic.
- A web application firewall that blocks known exploits before they reach an exposed interface, including legacy systems that cannot be patched.
This is the logic behind pairing the IT/OT boundary with AI-driven security: the threat is automated, so the shield has to be too.
The legal imperative: NIS2
The 2026 data changes what a board is exposed to, because the law has moved in parallel. The European Union's NIS2 Directive extends mandatory cybersecurity obligations to 18 sectors and brings manufacturing into scope alongside energy, water, health and transport.
Three points make this a boardroom issue rather than a technical one:
- Personal accountability. Senior management is held responsible for compliance, and governance failures can lead to temporary bans from management roles.
- Financial exposure. Essential entities face fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to 7 million euros or 1.4%.
- A tight clock. A significant incident requires an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a month.
Set against the threat data, the point is blunt. The convergence that exposed the OT boundary also made an industrial cyber incident more likely, and NIS2 turns a failure to manage it into a personal and financial liability for leadership. The detail of meeting those obligations is covered in our work on NIS2 compliance.
What the data tells you to do
The 2026 numbers point to one conclusion. The priority is not another tool that watches inside the OT network, useful as that is. It is to secure the boundary the attackers are actually using: control who can reach operational systems, segment the network so a compromise in IT cannot move into OT, reduce what is exposed to the internet, and put automated defence in front of it.
That is the boundary layer Brixio builds for IT/OT convergence. As a Cloudflare Authorised Service Delivery Partner (ASDP), Brixio deploys it as an overlay around existing equipment, without modifying controllers or stopping production. The companion articles in this cluster go deeper: the difference between IT and OT security, how Zero Trust modernises the Purdue model, how a Cloudflare boundary maps to IEC 62443, the five Cloudflare features that secure the boundary, and why Cloudflare and OT-native vendors are complementary rather than competing. The sector views for manufacturing and energy apply the same approach to specific environments.
Frequently asked questions
Large and growing. Ransomware against industrial organisations rose 64% in 2025, hitting around 3,300 organisations, and manufacturing was the most-attacked sector for a fifth straight year at 27.7% of all incidents. Half of the organisations Fortinet surveyed reported at least one incident over the year.
Because it combines high-value disruption, a deep dependence on uptime and a large, newly connected attack surface. Convergence linked factory systems to corporate IT and the cloud for efficiency, which also exposed equipment that was never designed to be reachable, and attackers concentrate where a shutdown costs the most.
Yes, and the path is specific. The 2026 data shows most intrusions begin at exposed, internet-facing entry points (44% of IBM's cases started with a public-facing application), then move from IT into OT across the boundary. Convergence removed the air gap that used to block that path.
Yes. NIS2 covers 18 sectors and brings manufacturing into scope. It introduces personal accountability for senior management, fines up to 2% of worldwide turnover for essential entities, and a 24-hour deadline to issue an early warning after a significant incident.
On the attack side, AI speeds up vulnerability discovery, scales phishing and credential abuse (94% of login attempts now come from bots), and lets attacks run at machine speed. On the defence side, the same automation is the countermeasure: attacks that peak in seconds can only be absorbed by automated defence at the network edge.
Secure your IT/OT boundary
Brixio assesses where your operational network is exposed and designs the boundary layer before any deployment.
Primary CTA: See how to secure the IT/OT boundary
Secondary CTA: Book an OT risk assessment


