News item

OT security matures, but visibility lags behind

Organizations are assessing the security of their operational technology (OT) more realistically than before, resulting in lower self-reported maturity levels, according to new research from Fortinet based on responses from more than 700 OT professionals worldwide.

6 July 2026 | 1 minute read

The importance of OT cybersecurity has sunk in at the executive level. Sixty percent of respondents reported that the CISO has ultimate responsibility for OT cybersecurity. While this is down from 69 percent in 2025, this change does not necessarily indicate a decline in executive attention.

The report suggests that some organizations have matured sufficiently to transfer OT risk ownership to other senior leaders, following C-suite involvement in formalizing strategy, funding, and governance. Where it has not already been elevated, over 80 percent of respondents plan to assign OT cybersecurity to the CISO within the next year.

One of the most notable developments is the shift in how organizations assess their own OT cybersecurity. In previous years, respondents rated their environments more highly. However, now that IT and OT teams have more financial resources, have implemented more tools, and have increased their understanding, organizations have a clearer picture of the areas where their security needs improvement, according to the report.

Consequently, the percentage of organizations that place themselves at the highest maturity level (Level 4) fell from 49 to 17 percent. At the same time, the share of organizations at Level 1 rose from 5 to 17 percent and at Level 2 from 13 to 27 percent. This shift does not indicate a decline, but rather a more realistic picture of the current security status, according to the report’s authors. As organizations gain more insight into their OT environments, previously hidden gaps become more visible.

Organizations are detecting incidents more frequently. Whereas last year, 47 percent of respondents reported one to nine intrusions, that percentage has risen to 71.

At the same time, only a quarter of respondents reported that both their IT and OT systems had been compromised, which is a sharp decline from 60 percent in 2025 and the lowest percentage since 2022. This points to more effective network segmentation and better separation between IT and OT environments.

However, achieving full visibility within OT environments remains a challenge for a majority of organizations. The percentage of companies reporting full visibility into OT assets and communication processes did rise, from 5 to 14 percent.

Meanwhile, the modernization of industrial systems continues. Four in ten organizations surveyed said their Industrial Control Systems (ICS) are less than five years old, double the figure from 2025.