Claroty: 58% of CPS Operators Hit by Attacks Affecting Operations
A new Claroty survey, reported on October 8, 2026, finds that more than half of cyber-physical systems operators have suffered an attack that affected operations. Third-party access and the IT/OT divide emerge as the weakest points.
On October 8, 2026, Industrial Cyber reported the findings of "The Global State of Operational Security 2026," research from Claroty, a provider of cyber-physical systems (CPS) protection solutions. The survey covered 2,000 business and technology leaders across 16 sectors and more than 40 countries. The headline figure: 58% of respondents say a cyberattack affected their operational environments in the past 12 months.
Impact: Downtime, Safety and Financial Loss
The most frequently cited consequences are operational downtime (43%), safety incidents or hazards to people (40%) and financial losses (35%). The average loss for an incident involving operations is $1.04 million, with higher values for large organizations: $1.6 million for those with at least 5,000 employees and $2.25 million for those with at least 10,000.
Incidents caused an average of three days of downtime, but nearly 10% of respondents reported outages of between 8 and 30 days. The article also cites 94% of organizations being hit with a financial impact and an average cost close to $1.1 million, a slightly different figure from $1.04 million, with no explanation of the gap from the source. These values are therefore best treated as orders of magnitude.
Third Parties: The Most Obvious Weak Spot
The data on access by external vendors and maintenance providers is clear-cut:
- 75% have had at least one incident with operational impact linked to third-party access;
- 49% report only partial monitoring, or none, of third-party connections.
For anyone running plants with remote maintenance of PLCs, supervisory systems or line machinery, the message is concrete: every external access channel should be inventoried, time-limited and monitored.
IT and OT Still Separate
Only 16% say IT and operational security are fully integrated. The main driver of investment is operational and cyber threat risk (37%), followed by digital transformation and modernization (36%) and business disruption or revenue loss (29%).
AI Cuts Both Ways
48% report that AI has improved efficiency and productivity, and 46% that it has improved decision-making. At the same time, 40% flag new cyber, compliance or operational risks and 33% cite operational or change-management difficulties. Only 6% believe AI has had little or no impact.
On the threat landscape, the report (as relayed by the article) cites frontier models, identified as Anthropic's Claude Mythos and OpenAI's GPT-5.6-Cyber, which are said to have significantly shortened the time between a vulnerability's disclosure and the appearance of proof-of-concept exploits. It also recalls attacks linked to Iran and Russia against Western critical infrastructure, including the water sector, and work by Claroty's Team82 on the risks of Internet-exposed assets.
Putting It into Practice
Keep in mind that these are findings from a survey sponsored by a security vendor, and that this summary is based only on the opening part of the article, without its full recommendations. The takeaways that follow remain reasonable:
- inventory and monitor all remote and vendor access, with time-bound authorization and traceability;
- verify that no industrial asset is exposed to the Internet without necessity and protection;
- bring IT and OT teams closer together with shared processes and responsibilities;
- review vulnerability assessment and remediation timelines, now under pressure from faster exploits;
- invest in recovery and resilience capabilities, not just in protecting individual assets.
With one incident in two touching operations, the question is not only how to stop the attack, but how quickly you get back up and running.