← All articles

· Graybridge Software

Critical Infrastructure: Legacy OT and Tool Sprawl Undermine Resilience

According to Palo Alto Networks' 2026 report, about 60% of critical infrastructure organizations suffered a significant breach in the past year. Unpatchable OT assets and fragmented security tooling are major contributing factors.

OT securitycritical infrastructureasset visibilitysegmentationIT/OT

Palo Alto Networks has published its "2026 State of Critical Infrastructure Cybersecurity" report, covered by Industrial Cyber on October 9-10, 2026. The survey polled more than 1,600 security leaders across 11 countries and 5 critical infrastructure sectors. Note that this is a survey sponsored by a security vendor, so the figures should be read as an indication of trends rather than an absolute measure. In addition, the source article was reviewed in truncated form, so some closing details may be missing.

Breaches and the Impact on Physical Safety

About 60% of organizations report a significant breach in the past year (the source cites both 60% and 59%, so the exact figure is uncertain). Among those affected, 50% cite physical safety concerns among the effects. Next come:

  • unplanned downtime: 49%
  • production disruption: 46%
  • financial losses: 46%

One in five affected organizations suffered more than one attack, and only 4% report no significant impact.

Visibility and Legacy Assets

68% lack complete, real-time visibility of all OT network assets, and more than half of this gap is attributed to legacy OT. 42% name unpatchable legacy assets as their top risk. The report stresses that this is a consequence of equipment designed for safety and operational continuity, not a failing of the people who manage it.

29% of 2026 CVEs were exploited within 24 hours, against an average of 55 days to deploy a patch.

This gap helps explain why 95% of leaders say they are worried about attacks powered by frontier AI.

Fragmented Tools and Still-Separate IT/OT

74% have not fully integrated IT and OT security operations. Organizations use an average of 7 distinct security tools, with these reported consequences:

  • operational complexity: 59%
  • higher costs: 56%
  • coverage gaps: 46%
  • slower incident response: 41%

Another figure stands out: 51% still prioritize alerts using CVSS scores or manual review, even though 92% consider prioritization important or critical.

Capabilities in Place

Share of organizations reporting that they have:

  • threat intelligence integrated into monitoring: 55%
  • risk prioritization by asset criticality: 53%
  • policy enforcement and access controls: 53%
  • automated detection and response: 52%
  • virtual patching or compensating controls: 40%
  • complete asset visibility: 37%

Only 17% have more than four of these capabilities. On 5G, 84% expect widespread adoption in OT within 2-3 years; the main gaps concern data protection (52%), third-party access (43%) and application security (40%).

What to Do in Practice

If patching cannot protect the assets that worry you most, defense has to shift elsewhere. Some reasonable priorities, consistent with the report's data:

  • build an inventory using passive discovery, which does not disturb processes, starting with legacy assets
  • apply segmentation and compensating controls, including virtual patching, where updating is not possible
  • prioritize alerts by asset criticality and process impact, not just by CVSS
  • reduce tool sprawl by aiming for integrated IT/OT monitoring
  • automate low-risk responses, because exploitation timelines are shorter than patch cycles
  • assess third-party access and data protection before introducing 5G

Allowing for the limits of sponsored research, the message is consistent: in OT, resilience depends less on chasing every vulnerability and more on visibility, isolation and unified response processes.