Report by Fortinet
2026 State of Operational Technology and Cybersecurity
Key Findings
71% of organizations reported between one and nine intrusions, up from 47% the previous year.
2% of organizations reported more than 10 intrusions, unchanged from the previous year.
89% of organizations expect increased regulation within five years or less, up from 66% in 2025.
Approximately 23% of organizations have visibility into about half of their OT environment.
24% of organizations reported intrusions in both IT and OT systems, down from 60% in 2025 and the lowest since 2022.
60% of organizations report the CISO has ultimate responsibility for OT cybersecurity, down from 69% in 2025.
81% of organizations plan to assign OT cybersecurity to the CISO within the next year, up from 80% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 0 increased to 5%, up from 1% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 1 increased to 17%, up from 5% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 4 fell to 17%, down from 49% in 2025.
Level 4 maturity for OT security solutions declined to 14%, down from 19% in 2025.
76% of organizations reported phishing as an intrusion.
50% of organizations reported ransomware intrusions, down from 54% in 2025.
There is a 20-point increase in organizations expecting new regulations within two to five years rather than beyond five years.
40% of organizations report their ICS systems are less than five years old, up from 20% in 2025.
Organizations' OT cybersecurity maturity ratings at Level 2 increased to 27%, up from 13% in 2025.
14% of organizations have full visibility into OT systems, up from 5% in 2025.