Italian Manufacturing in the Crosshairs: 18.4% of Known Cyber Incidents in H1 2026
According to Clusit data presented in Milan on 7 October 2026, manufacturing accounts for 18.4% of known cyber incidents in Italy in the first half of 2026, versus 5.4% globally. What the numbers mean and what to do on the OT floor.
On 7 October 2026, at the opening of the Security Summit OT 2026 in Milan, researchers from Clusit (the Italian Association for Information Security) presented data on successful cyber incidents in the manufacturing sector in the first half of 2026. The event, dedicated to the security of industrial systems and OT infrastructure, is organized by Clusit with Astrea, with support from CSET, ANIPLA and Consorzio PI Italia.
The key figures
The information made available highlights two key figures:
- In the first half of 2026, manufacturing accounts for 18.4% of publicly known cyber incidents in Italy, almost one in five.
- Over the same period, the sector accounts for 5.4% of known incidents worldwide.
- Cybercrime remains the predominant threat, both in Italy and in the rest of the world.
In Italy, manufacturing weighs roughly three and a half times more among known incidents than in the global figure.
How to read the data
One caveat is essential: the percentages refer to known or public incidents, not to all incidents that occurred. They therefore do not measure the real frequency of attacks, but the sector's share among cases that surface from open sources. Many attacks are never disclosed, and the willingness to disclose them varies across countries and sectors.
In addition, at the time of writing we do not have a breakdown by attack type, severity or sub-sector, nor absolute numbers or a comparison with the previous year. For a complete picture it will be worth waiting for the full report and the summit materials to be published. Even with these limits, the gap between 18.4% and 5.4% is wide enough to deserve attention.
Why it matters to plant operators
For production, engineering and IT leaders at industrial companies with plants or suppliers in Italy and Europe, the data suggests that Italian manufacturing is a concrete and visible target. If the prevailing threat is cybercrime, meaning financially motivated activity, what matters most is the ability to halt production and the pressure that follows, more than sophisticated targeted campaigns.
Factory networks often have characteristics that amplify the impact: systems with long lifecycles, patching made difficult by limited maintenance windows, protocols designed without authentication, and growing connections to IT, cloud and external vendors for remote maintenance.
Practical guidance
Without claiming that the Clusit data alone prescribes a recipe, the measures most consistent with this scenario are the fundamentals of OT security:
- Asset inventory: know which PLCs, HMIs, servers and connections really exist in each plant.
- Segmentation: separate IT and OT and divide the plant network into zones, limiting the paths along which malware or ransomware can spread.
- Passive monitoring of industrial traffic: detect new devices, anomalous communications and unexpected commands without disturbing the process.
- Controlled remote access: strong authentication, logged sessions and time-limited vendor access.
- Tested backup and recovery plans, including controller configurations and programs, with drills that also involve production.
In summary
The data presented on 7 October 2026 does not describe the entire risk surface, but it indicates that in the first half of 2026 Italian manufacturing is overrepresented among known incidents compared with the global average. For those leading industrial security, it is a further argument for structured investment in segmentation and monitoring of plant networks, to be refined once the full details of the report are available.