3 other considerations for OT cybersecurity leaders:
AI is accelerating attacks that require no prior OT expertise
The World Economic Forum’s Global Cybersecurity Outlook 2026 finds that 94% of surveyed leaders expect AI to be the most significant driver of change in cybersecurity in the year ahead. On each side, attackers are using generative AI to accelerate reconnaissance, phishing and payload development, and defenders are embedding AI into asset intelligence, anomaly detection and automated triage. As attack and defense lines are drawn, organizations can expect three effects: an expanded attack surface introduced by AI systems themselves, AI-augmented defense and AI-enhanced attacker tradecraft.10
The threat is no longer theoretical either. In late 2025 and early 2026, an unknown adversary used Anthropic’s Claude and OpenAI’s GPT models to compromise the enterprise IT of Servicios de Agua y Drenaje de Monterrey (SADM), map the internal environment, identify a vNode SCADA/Industrial Internet of Things (IIoT) gateway, classify it as a crown jewel asset and launch a password-spray attack against the IT–OT boundary.11 The breach attempt failed, but the adversary reached Stage 1 of the ICS Cyber Kill Chain with no prior OT expertise, proving that AI has made OT reachable to IT-only adversaries. For OT programs, prevention-only strategies (firewalls, segmentation, patching) are necessary but no longer sufficient. Visibility, detection and response are now baseline requirements.
Regulation is arriving faster than most OT programs can match
Recent research indicates that 89% of OT leaders now expect new regulation within five years, up from 66% in 2025.12 The NIS2 Directive in Europe, evolving Transportation Security Administration (TSA) security directives, the expanded North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) scope and emerging Automated Program Analysis for Cybersecurity (APAC) frameworks are pushing baseline capabilities. These include asset visibility, logging, change detection — and are moving from optional to mandatory. For organizations who are already compliant, the upside is clear: companies see around 50% fewer financial and safety impacts when incidents occur, according to the SANS Institute.13
Plant floor culture must be prepared for OT change
Even the best-designed OT security programs will stall or fail if the plant floor resists. Control room operators, plant engineers and maintenance technicians have spent their careers protecting availability and safety, and seen well-intentioned IT-driven changes disrupt production and, in some cases, endanger workers. Any security tool that scans a network, quarantines a device or forces a credential rotation is, from the plant's perspective, a potential source of unplanned downtime.
Yet the same workforce is essential to the program working. According to 2025 Sans Institute findings, organizations that include frontline plant staff in tabletop exercises are 1.7 times more likely to report strong readiness.14 Even so, additional shows that 95% of manufacturers have already invested or plan to invest in OT cybersecurity platforms within the next five years — meaning the tools are coming to the plant floor whether the culture is ready or not.15
To re-tool plant floor culture for coming OT cybersecurity changes think about:
- Co-design, don’t impose: Bring plant operators and engineers into tool selection, deployment planning and playbook design early. A control system engineer who helps write the organization’s new response runbook will go on to defend it.
- Frame security as availability: Present the value of segmentation, monitoring and incident response (IR) in the language of uptime, safety and mean time to recovery — not risk registers or Common Vulnerability Scoring System (CVSS) scores. Tie security KPIs to overall equipment effectiveness (OEE), unplanned downtime and audit-hour reduction so operations leaders can see the return.
- Pilot on one line before scaling: Deploy a new capability on a single line, cell, unit or plant — with the local team’s active involvement — before scaling. Publish the results, including what went wrong. Credibility on the plant floor is earned in small wins, not enterprise mandates.
- Build local champions: Identify respected plant engineers and control system specialists, invest in their OT security training and certification and empower them to lead in-plant awareness. Peer influence outperforms corporate mandates on a shift floor.
- Sponsor from operations, not just security: A CISO memo alone will not shift a plant culture. Visible collaboration with the plant manager, VP of operations and head of environment, health and safety (EHS) signals that security is an operational priority, not an IT overlay.
- Rewrite the safety-security narrative. Legacy playbooks that treat availability and security as competing goals reinforce the resistance. Update joint IT–OT–safety procedures so that security controls are designed to preserve availability and safety incidents that touch cyber are jointly investigated.
The bottom line
Operational technology is entering a new phase of digital maturity. The organizations that will lead the next decade are the ones treating OT cybersecurity not as an engineering afterthought but as a board-level operational risk to be addressed. This must be anchored to a framework (NIST CSF 2.0 or IEC 62443), integrated into a working operating model, sustained by a plant-floor culture that owns it, and matched to the pace of the adversary. And where in-house capabilities can’t scale to the pace of changing regulations and threats, managed service-driven acceleration may be a faster solution than building from scratch.
Organizations that delay will soon find the cost of catching up significantly compounds pain points — in more regulatory exposure, increased insurance premiums, costly operational downtime and lost competitive ground to peers that already embedded cybersecurity into transformation strategies.